If your platform has users under 18, DPDPA Section 9 requires verifiable guardian consent before any personal data processing — most platforms have neither the age gate nor the consent workflow to prove it.
What DPDPA Section 9 actually requires
If your platform has users who might be under 18, DPDPA has already assigned you a compliance obligation you likely cannot demonstrate today.
Under Section 9 of the Digital Personal Data Protection Act, processing personal data of a child — defined as anyone under 18 — requires verifiable parental or guardian consent obtained before any processing begins. The burden of proof sits with the Data Fiduciary — not with the parent, and not with the user.
Age-gating before data collection
Platforms must determine whether a user is a child before collecting any personal data — not after onboarding. A birth date field at the end of a 12-step signup flow does not constitute a gate. The age determination must precede data collection — architecturally, not just in policy.
Verifiable guardian consent — what "verifiable" means
Age verification mechanisms that ask users to self-declare their birth date do not satisfy DPDPA. The law requires a reliable means of verifying that the guardian providing consent is actually an adult. This requires a consent flow specifically designed for guardian-authorised data processing — not a modified standard consent modal where a parent clicks "I agree" on behalf of a child.
Additionally: DPDPA explicitly prohibits tracking, monitoring, or profiling the behaviour of children — and prohibits targeted advertising to users identified as children. If your analytics or personalisation engine touches records of users who are or may be under 18, that processing requires immediate review.
No behavioural profiling — the hidden exposure
Most platforms running product analytics, A/B tests, and personalisation engines do not segment by age before processing. If any of those users are under 18, the platform is conducting prohibited behavioural profiling of children under DPDPA Section 9 — and the analytics vendor receiving that data is processing it without a valid consent basis.
The same prohibition extends to ad retargeting pixels: if a pixel fires on a session belonging to a user under 18, that event is a DPDPA violation regardless of whether the platform knew the user's age.
Platforms most exposed are not children's apps
The platforms with the highest Section 9 exposure are not children's apps — they are platforms where child users are incidental but not impossible: education platforms, gaming, consumer fintech with family accounts, social features in productivity tools, and healthcare platforms with minor patient records.
For these platforms, the regulatory position "we assumed our users were adults" will not be accepted by the Data Protection Board as a defence.
How Consentica implements guardian consent
Consentica by OpenBlockAI provides a guardian consent workflow specifically designed for DPDPA Section 9: age-gating logic at the point of data collection, a guardian-addressed consent flow separate from standard user onboarding, withdrawal propagation for guardian-revoked consents, and an audit trail logging the consent event against the guardian identity — not the child's record.
Implement guardian consent in one sprint cycle. Do not wait for the first Section 9 enforcement action to map your exposure.
