DPDP Act Compliance for EdTech Platforms
Verifiable parental consent and children's data governance for learning platforms
With everyone under 18 a child under the DPDP Act, most Indian edtech users trigger Section 9: verifiable parental consent, bans on tracking and targeted ads, and ₹200 crore penalty exposure. TruePrivacy makes children's data compliance a product feature, not a blocker.
What DPDP Act requires of edtech
Verifiable parental consent
Before processing a child's data, verify the consenting parent is an identifiable adult — via reliable identity details or government-backed virtual tokens.
No tracking or targeted ads to children
Absolute prohibitions that consent cannot override — behavioural profiling and ad targeting must be off for child accounts.
Narrow institutional exemptions
Educational institutions are exempted for specified purposes — commercial platforms cannot assume they inherit this.
Age-gating without over-collection
Determining who is a child without building an identity-document honeypot.
Majority transitions
Parental consent lapses at 18 — learners must consent in their own right.
Notify-everything breach regime
Every breach touching learner data triggers intimations to parents and the Data Protection Board — with children's data breaches drawing the sharpest scrutiny.
How TruePrivacy helps
Parental consent engine
Token-based adult verification with consent, method, and reference identifiers recorded — no document hoarding.
Child-mode enforcement
Advertising IDs, behavioural analytics, and retargeting technically disabled per child account, with verification reports.
Exemption mapping
School-fiduciary deployments distinguished from direct-to-consumer accounts, purpose by purpose.
Tiered age assurance
Declared age plus contradiction signals as baseline; stronger gates only before higher-risk features.
Re-consent at majority
Automated detection and transition journeys when learners turn 18.
“Parental consent was going to cost us our onboarding funnel — that was the fear. The token-based verification flow converts in under a minute, and child-mode enforcement is technical, not a policy PDF. Section 9 went from an existential risk to a signed-off feature.”
Frequently asked questions
How do parents verify without uploading documents?
The DPDP Rules contemplate virtual tokens from government-backed identity infrastructure — a yes-this-is-an-adult assertion plus a reference identifier, without the platform storing documents. TruePrivacy implements this flow and records the verification method per consent.
Is our recommendation engine 'behavioural monitoring'?
Personalisation that builds a behavioural profile of a child over time sits in the risk zone; adaptive learning tied to educational progress is more defensible. TruePrivacy's processing inventory classifies each pipeline, disables the prohibited categories for child accounts, and documents the reasoning for the rest.
We sell to schools — are we exempt?
The exemption belongs to educational institutions for specified purposes; a commercial platform is not automatically inside it. TruePrivacy maps institutional deployments (school as fiduciary) separately from consumer accounts, so exemption reliance is documented, not assumed.
What happens when a learner turns 18?
Parental consent doesn't silently become the learner's own. TruePrivacy triggers a re-consent journey at majority, retires parental controls, and records the basis switch — enabling previously disabled processing only after fresh consent.
Get DPDP Act-ready
Book a 30-minute demo and see how TruePrivacy handles DPDP Act compliance for edtech.
Free 14-day trial · No credit card required · Setup in minutes