Beyond Parental Consent: Can Consent Meaningfully Protect Children’s Privacy in the Age of Algorithms?


Imagine you’re a parent. You’re downloading a popular video-sharing application for your twelve-year-old child. Before the child can create an account, the platform requests parental verification. You provide your identity by uploading proof, confirm that you’re an adult, read the privacy policy, perhaps only briefly, or not at all, and click “I Agree.”

From a compliance standpoint, the platform has complied with its obligation under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). You, the parent, have provided your consent successfully in accordance with the provisions of the Digital Personal Data Protection Rules, 2025 (“DPDP Rules, 2025“).

But what happens next? For months, perhaps years, the app quietly builds a digital shadow of the child. It tracks every like and skip, registers every influence, notes her favourite creators, and pinpoints the exact hour she is most vulnerable to engagement. The platform continuously collects and analyses all this information to personalise future recommendations. The parent gave consent once, but the algorithm never stopped learning. This raises an important question: if the DPDP Act prohibits behavioural monitoring of children, can parental consent meaningfully protect children’s privacy when recommendation algorithms necessarily rely on continuous behavioural observation?

India’s DPDP Act and the DPDP Rules, 2025, have significantly strengthened the existing framework governing the collection of children’s data. While these address challenges in verifying parental consent and safeguarding broader children’s rights in data collection, they fail to address questions about algorithmic profiling, behavioural monitoring, and children’s autonomy in the digital age.

The DPDP Framework: A Stronger Approach to Verifiable Parental Consent

Section 9 of the DPDP Act establishes a distinct regime for processing children’s personal data. It requires Data Fiduciaries to obtain verifiable parental consent before processing a child’s personal data. Unlike the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which required only privacy policies and clear consent without any meaningful age-verification mechanism, the DPDP framework recognises that simply asking users to confirm their age is fundamentally insufficient.

The DPDP Rules, 2025, have now laid out what “verifiable parental consent” means. Under Rule 10, Data Fiduciaries must implement technical and organisational safeguards to ensure an identifiable adult provides parental consent.

The rules permit platforms to rely on:

  • identity and age details already available with the Data Fiduciary;
  • government-backed identity and age information voluntarily provided by the parent; or
  • a Digital Locker-based virtual token linked to identity verification.

These mechanisms are a significant improvement over the previous legal framework that largely relied on privacy policies and general consent requirements. The new law introduces practical, objective methods for age and identity verification and effectively reduces opportunities for children to bypass parental controls. From a compliance perspective, at least, the law addresses who is actually consenting. The more difficult question, however, isn’t whether consent was validly given, but whether consent was ever enough.

Is Parental Consent Really Enough?

Once a parent has given valid consent, the child begins using the platform. From this point onwards, recommendation systems quietly start working in the background. Suppose another child likes football. He starts watching football videos on YouTube Shorts. Soon, the platform starts recommending more football content. If he suddenly switches to watching comedy videos instead, the recommendations change almost immediately. This is precisely how recommendation algorithms work, and it is also where the legal puzzle begins.

Section 9 of the DPDP Act does more than require parental consent. It restricts Data Fiduciaries from behaviorally monitoring or tracking children, or directing targeted advertisements at them. The obvious question, then, is this: can recommendation algorithms even function without monitoring behaviour? After all, an algorithm cannot recommend content unless it first observes what a user watches, skips, likes, searches for, or spends time viewing. This creates an interesting interpretative challenge. Does every recommendation algorithm amount to behavioural monitoring, or is there a distinction between improving a user’s experience and profiling a child’s behaviour?

At present, the DPDP Act does not define “behavioural monitoring” precisely. As a result, platforms and regulators will eventually have to determine where legitimate personalisation ends and prohibited monitoring begins.

The Act itself hints that this tension was anticipated, even if not fully resolved. Section 9(5) empowers the Central Government to exempt certain Data Fiduciaries from the behavioural monitoring ban for children above a specified age, provided the Fiduciary demonstrates that its processing is “verifiably safe.” Furthermore, Rule 10, read with the Fourth Schedule, carves out general exemptions for specific processing purposes. Yet, neither the DPDP Act nor the DPDP Rules, 2025 define what constitutes “verifiably safe” processing or where benign algorithmic personalisation ends and prohibited behavioural monitoring begins. The statutory safety valve exists on paper, but without defined standards, platforms and regulators are left with a mechanism they cannot yet use in practice.

The Privacy Paradox

Another issue receives far less attention. And it’s the verification process itself. Ironically, protecting children’s privacy often forces platforms to collect more personal data before they can collect less. To verify parental consent, platforms may need to rely on the mechanisms prescribed under Rule 10 of the DPDP Rules, 2025, such as government-issued identity details, proof of age, or a DigiLocker verification token.

In other words, the law requires additional processing of parents’ personal data to ensure that children’s personal data is protected and processed lawfully. Under the DPDP Rules, lawmakers have sought to strike a careful balance by allowing secure government-backed verification methods rather than repeated collection of identity documents. Even so, the situation highlights an interesting policy tension: sometimes privacy protection itself requires more personal data collection at the very beginning.

Children’s Privacy Cannot Depend Only on Parents.

A broader question also goes beyond compliance. Suppose a parent fully understands the privacy policy and gives consent knowingly. Should that automatically mean the child has no say over how extensively their online behaviour is analysed? International law increasingly recognises children as independent rights-holders. Consistent with this approach, the United Nations Convention on the Rights of the Child (UNCRC) provides that the best interests of the child must remain a primary consideration in all actions concerning children.

Against this backdrop, parental consent should not operate as a blanket permission for data fiduciaries to engage in extensive data processing. Rather, it should function as one safeguard among many designed to protect children’s privacy. The DPDP Act, read with the DPDP Rules, reflects this by imposing direct obligations on platforms, suggesting that protecting children’s privacy continues even after parental consent is obtained.

Conclusion

The DPDP Act, 2023, and the DPDP Rules, 2025, have meaningfully strengthened India’s framework for protecting children’s personal data by introducing specific, verifiable standards for parental consent.

Still, consent is only the starting point, as the bigger challenge is determining how Section 9’s prohibition on behavioural monitoring applies to recommendation algorithms that depend on observing user behaviour. Ultimately, protecting children’s privacy in today’s algorithm-driven digital ecosystem will require more than just valid, verified parental consent. It will require ensuring that the technologies that children use every day operate within the limits set by law and uphold their best interests.


Mananika Deb, currently an undergraduate student at National Law University and Judicial Academy, Assam, has contributed this article to the blog.

We will be happy to hear your thoughts

Leave a reply

Som2ny Network
Logo
Compare items
  • Total (0)
Compare
0
Shopping cart