Solutions
TruePrivacy for
EdTech
Children's data compliance under GDPR and DPDP Section 9
EdTech platforms serve learners under 18 — triggering verifiable parental consent, tracking bans, and heightened penalties under the DPDP Act, alongside GDPR's child-consent rules. TruePrivacy makes children's data governance operational.

Common challenges
- DPDP treats everyone under 18 as a child — most learners on Indian edtech platforms need verifiable parental consent
- Absolute bans on tracking, behavioural monitoring, and targeted advertising directed at children
- The educational-institution exemption is narrow and commercial platforms cannot assume they inherit it
- GDPR child-consent ages (13–16) differ from DPDP's 18, forcing jurisdiction-aware flows
- Learning analytics and engagement personalisation sit uncomfortably close to prohibited profiling
How TruePrivacy helps
- Verifiable parental consent flows using token-based adult verification — no identity document hoarding
- Child-mode enforcement: analytics, advertising SDKs, and behavioural profiling switched off for child accounts
- Age-gating with tiered assurance proportionate to feature risk
- Jurisdiction-aware consent: DPDP's under-18 rule for India, GDPR's member-state ages for the EU
- Age-of-majority re-consent journeys when learners turn 18
Platform capabilities
Verifiable Parental Consent Engine
Configurable flows for token-based adult verification, voluntary identity details, or existing-record matching. Stores consent, verification method, and reference identifiers with immutable audit trails — and handles lawful-guardian consent for persons with disabilities through a document-verified pathway.
Child-Mode Processing Controls
A per-account processing profile that disables advertising identifiers, behavioural analytics, retargeting pixels, and engagement profiling for child accounts — enforced at SDK configuration and pipeline level, with verification reports proving the controls are technically active.
Age Assurance Orchestration
Tiered assurance mapped to feature risk: declared age with contradiction signals as baseline, stronger verification gates in front of higher-risk features like social interaction. Outcomes and methods are retained; verification inputs are discarded in line with minimisation.
Institutional Exemption Mapping
Deployment-level classification distinguishing school-fiduciary contracts from direct consumer accounts, with each processing activity mapped to the exempted purpose it relies on — so exemption reliance is documented per account population, not assumed platform-wide.
Learning Analytics Governance
An inventory of every model and analytics pipeline touching learner data, classified against DPDP's tracking and behavioural-monitoring prohibitions and GDPR profiling rules, with child-account exclusions enforced and documented for auditors.
Majority-Transition Re-Consent
Automated detection of learners reaching 18 (or the applicable GDPR consent age), triggering re-consent journeys, retiring parental controls, and recording the basis switch — so no account keeps processing on a parental basis that has lapsed.
Key features
What our customers say
We rebuilt our onboarding around TruePrivacy's parental consent flow in three weeks. Parents verify as adults through a token check — we never see their documents — and every child account automatically runs with tracking and ads disabled. Our board finally stopped asking about the ₹200 crore penalty.
Vikram Shenoy
Co-founder & CTO, LearnSprint
Frequently asked questions
The parent completes a verification step confirming they are an identifiable adult — via details already held, voluntarily provided identity details, or a virtual token from government-backed digital identity infrastructure such as DigiLocker-linked mechanisms. TruePrivacy stores the consent, the verification method, and a reference identifier, not the underlying documents, giving you the audit trail the DPDP Rules expect with minimal data collected.
Assessment of learning progress in the child's educational interest is defensible; building behavioural profiles for engagement optimisation or ad targeting is prohibited regardless of consent. TruePrivacy's processing inventory lets you classify each analytics use, disable the prohibited categories for child accounts at the SDK and pipeline level, and document the reasoning for the rest.
The DPDP Rules exempt educational institutions for specified educational purposes — but a commercial platform contracting with schools is not automatically inside that class. TruePrivacy lets you map each deployment: institutional deployments where the school is the fiduciary relying on its exemption, and direct-to-consumer accounts where full Section 9 compliance applies. You see exactly which accounts run under which regime.
Parental consent does not silently convert into the learner's own consent. TruePrivacy tracks dates of birth, triggers a re-consent journey at majority, and transitions the account: the learner consents in their own right, parental controls retire, and previously disabled processing categories can be enabled only after the learner's fresh consent.
TruePrivacy applies jurisdiction-aware rules from one configuration: DPDP's under-18 parental consent and prohibitions for Indian data principals, and the applicable member-state digital consent age (13–16) with parental authorisation for younger EU users. Consent records, notices, and DSR deadlines follow the regime attached to each account.
Privacy compliance for EdTech
Join forward-thinking teams using TruePrivacy to automate their privacy operations.
Free 14-day trial · No credit card required · Setup in minutes