Version 1.0 • CURRENT
DPDP Rules 2025 Time Period for Deletion & Child Data
RULE 10

Verifiable consent for processing of personal data of child

Official Statutory Text MeitY Gazette Notified Section 40 Delegated Authority
Plain-Language Compliance Breakdown (Editorial Analysis)

What this means: Apps must verify that a parent actually gave permission for a child to use the app.

The safest way for a company to verify a parent's age without hoarding sensitive ID cards (like Aadhaar) is by allowing the parent to prove their age using an authorized "virtual token" provider, such as the government's DigiLocker service.

Key Practical Takeaways for Compliance Teams

  • Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
  • Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 10.
  • Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.
← PREVIOUS RULE Rule 8: Time period for specified purpose to be deemed as no longer being served NEXT RULE → Rule 13: Additional obligations of Significant Data Fiduciary
Statutory text reproduced under open access public domain principles. This reader is designed for educational and compliance decision support.