CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
UPDATES
PRACTICE AREAS
PEOPLE
News and Articles
Parental Consent,
Parental Consent Requirements for Businesses Collecting Data from Minors
Businesses increasingly interact with minors through education platforms, gaming applications, social networks, healthcare services, retail platforms and digital entertainment. In India, Parental Consent has become a central compliance consideration for organisations processing children's personal data under the Digital Personal Data Protection Act, 2023. The law treats an individual below eighteen years as a child and requires verifiable consent from a parent or lawful guardian before processing the child's personal data, subject to specified exemptions. The requirement is more substantial than adding a consent checkbox to an application. Businesses need a reliable process for identifying child users, verifying the adult providing consent, recording the consent, controlling subsequent processing and demonstrating compliance when required. What Does Parental Consent Mean Under Indian Data Protection Law? The DPDP Act places specific obligations on a Data Fiduciary when processing personal data belonging to a child. Section 9 requires verifiable consent from the child's parent or, where applicable, lawful guardian before processing begins. The statutory explanation expressly recognises consent from a lawful guardian within the meaning of parental consent. The requirement reflects an important legal distinction. A child's affirmative action on a website or application is not automatically sufficient. The business must establish the authority of an adult who is providing consent on the child's behalf. This makes parental verification a separate compliance exercise from ordinary user consent. The distinction is particularly relevant for platforms where children can create accounts independently. A company may know the age of the user but still need a process to establish who is giving consent and whether the person is an adult parent or lawful guardian. Who Is Considered a Child Under the DPDP Act? The DPDP Act adopts a clear age threshold. A child means an individual who has not completed eighteen years of age. This is important for businesses serving teenagers because the Indian framework does not generally stop enhanced child protection at thirteen, sixteen or another lower age used in some international privacy regimes. Businesses should therefore examine their user base carefully. A service may be designed for adults but still attract users below eighteen. In such cases, the organisation needs to consider how its systems identify or otherwise deal with child users. Age assessment is consequently an important part of privacy governance. It should be considered during product design rather than treated solely as a legal policy issue. Why a Simple Consent Checkbox May Not Be Enough? A conventional consent mechanism usually records an affirmative action from the user. For ordinary data processing, the organisation may rely on the Data Principal's consent in accordance with the statutory framework. Children's data introduces another layer. Rule 10 of the Digital Personal Data Protection Rules, 2025 requires a Data Fiduciary to adopt appropriate technical and organisational measures to ensure verifiable consent from the parent before processing a child's personal data. The organisation must also exercise due diligence to check whether the person claiming to be the parent is an adult and is identifiable where required for compliance with Indian law. Consequently, a declaration such as “I am the parent” may not provide sufficient evidence by itself. An organisation needs a process capable of establishing the adult's identity and age through an appropriate verification method. How Must Businesses Verify the Parent? The final Rules provide two principal routes for verification. First, the Data Fiduciary may rely on reliable identity and age details already available with it. This could be relevant where the parent is an existing verified user of the service. Second, the parent may voluntarily provide identity and age information, or provide a virtual token mapped to such information. The Rules recognise tokens issued by an authorised entity and also refer to information or tokens made available and verified through a Digital Locker service provider. The framework therefore does not prescribe a single universal technology for every business. Instead, it establishes an outcome. The organisation needs appropriate technical and organisational measures and must exercise due diligence concerning the adult claiming parental status. This gives businesses some flexibility in designing their consent architecture while placing responsibility on them to make the mechanism reliable. What Does Verifiable Consent Look Like in Practice? Consider a child attempting to create an account on an educational application. The platform may first identify the user as a child. The system can then direct the parent to a separate verification process. If the parent is already a verified user, the business may use reliable identity and age information already held by it. If the parent is not an existing user, the Rules contemplate voluntary submission of identity and age details or an appropriate virtual token. The business should then retain appropriate records showing the consent process. The important point is sequencing. Where Section 9 applies, the consent requirement arises before processing of the child's personal data. A business should therefore avoid designing a process where extensive child data is collected first and parental verification occurs later. The architecture should minimise the information collected before verification. What About Lawful Guardians? The DPDP Act expressly extends the concept of parental consent to a lawful guardian where applicable. The Rules separately address verification concerning persons with disabilities who have a lawful guardian. Rule 11 requires due diligence to establish the guardian's appointment by a court, designated authority or local level committee under the applicable guardianship law. Businesses should therefore avoid treating every adult who claims responsibility for a child as automatically authorised to provide consent. The nature of the relationship can matter. Where a service is likely to receive consent from guardians rather than biological parents, the organisation should ensure its verification process reflects the applicable legal position. Parental Consent Does Not Permit Every Form of Processing Obtaining consent does not give a business unrestricted permission to process children's data. Section 9 contains additional safeguards. A Data Fiduciary must not undertake processing likely to cause a detrimental effect on the well being of a child. The Act also prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This is an important distinction for businesses. A company cannot assume its compliance obligations end once a parent approves the account. The organisation must examine what happens to the child's information after consent. For example, analytics, recommendation engines, behavioural profiling and advertising technologies should be assessed separately. A valid consent mechanism cannot automatically authorise processing prohibited by Section 9. Are There Exemptions From Parental Consent? Yes. The DPDP Rules, 2025 establish limited and conditional exemptions under Rule 12 and the Fourth Schedule. The exemptions apply to specified classes of Data Fiduciaries or specified purposes, subject to conditions. Part A of the Fourth Schedule includes certain healthcare establishments and professionals, educational institutions and specified childcare and transport arrangements. The exemption depends on the purpose and conditions attached to the relevant category. The Rules also recognise specified purposes in Part B. Businesses should be careful when relying on these exemptions. Being an educational institution or healthcare provider does not create a blanket exemption from children's data requirements. The processing must fall within the relevant category and satisfy the applicable conditions. An exemption analysis should therefore be documented rather than assumed. What Businesses Should Consider Before Collecting a Minor's Data? The first step should be data mapping. A business should identify where children's information enters its systems, what categories are collected, why each category is required and which employees, vendors or technology providers can access it. The next consideration is age assurance. The organisation needs to understand how it identifies users who may be children and how the parental verification process will operate. The consent journey should then be mapped from beginning to end. This includes the notice presented to the parent, verification method, consent record, withdrawal mechanism and subsequent handling of the child's information. Businesses should also review their technology stack. Third party analytics tools, advertising software, customer relationship platforms and software development kits may collect or infer information independently of the main application. A privacy review limited to the company's own database may therefore miss important processing activities. Privacy Notices Must Match the Actual Consent Process A privacy notice should not promise one form of processing while the technology performs another. The DPDP Rules require notices to provide clear information about personal data being collected and the purpose for processing. The Government's explanatory note emphasises standalone, understandable notices and transparent information necessary for informed consent. For services used by minors, businesses should ensure the notice, parental consent interface and actual data practices remain consistent. If the application uses information for personalisation, analytics or another purpose, the business should assess whether the purpose is adequately described and legally permitted. This alignment is also important from an evidentiary perspective. A company should be able to demonstrate how its stated privacy practices correspond with its technical operations. Consent Records Should Be Auditable A business should be able to answer a basic question: how can you demonstrate which parent provided consent, for which child, for what processing and when? Consent records can help answer this question. The organisation should consider recording relevant information about the consent event without unnecessarily retaining additional identity information. Excessive retention creates its own privacy and security concerns. The consent architecture should also accommodate withdrawal where applicable. A parent should not face an unnecessarily complicated process simply because consent was initially provided electronically. Record keeping, access controls and retention periods should therefore form part of the overall privacy governance framework. Businesses Should Review Third Party Contracts Children's data frequently moves beyond the primary platform. A gaming company may use cloud hosting. An EdTech business may use analytics software. A healthcare application may rely on external infrastructure or communication providers. Each relationship can create a separate risk. Businesses should examine whether vendors process children's data, what information they receive, where it is stored, whether they can appoint sub processors and how they respond to security incidents. Contracts should reflect the actual processing relationship and allocate appropriate responsibilities. This is an area where data privacy lawyers can assist businesses in reviewing consent architecture, privacy notices, vendor arrangements and regulatory exposure. The objective should be to ensure legal documents reflect real technical practices rather than operating as standalone paperwork. Security Is Part of Children's Data Governance Parental consent does not remove cybersecurity obligations. The DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The statutory penalty framework also provides significant financial exposure for specified contraventions, including a penalty of up to ₹200 crore for breach of obligations relating to children. Security controls should therefore be proportionate to the data being processed. Businesses should consider access restrictions, authentication, encryption where appropriate, secure development practices, vulnerability management, monitoring and incident response. The organisation should also limit internal access. Not every employee involved with a children's service needs access to the underlying personal data. When Will the Parental Consent Rules Apply? This is an important current legal point. The final Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4 is scheduled to commence one year later, while Rules 3 and 5 to 16, along with Rules 22 and 23, are scheduled to commence eighteen months after publication. Rule 10 therefore has a scheduled commencement date of 13 May 2027. The Data Security Council of India also identifies 13 May 2027 as the commencement date for Rule 10 and the corresponding Section 9 obligations. This does not mean businesses should wait until 2027 to start preparing. Consent architecture can require changes to databases, onboarding flows, identity verification, contracts and advertising systems. Organisations with significant child user bases may need substantial lead time. How Businesses Can Prepare Now? A sensible preparation programme should begin with a children's data inventory. The organisation should identify whether it actually needs to collect personal data from minors. If the service can operate without collecting such information, redesigning the user journey may be simpler than implementing a complex verification system. Where collection is necessary, businesses should develop an age assurance and parental verification framework. The next step should be testing. A consent system should be tested against different user journeys, including an existing parent user, a new parent, a child attempting to register independently and situations where consent is withdrawn. Technology teams should also examine third party tools. A platform may have a compliant registration page while an embedded analytics tool continues behavioural tracking. Finally, the business should establish governance. Responsibility for children's data should be clearly assigned. Internal policies should address consent records, access, retention, security incidents and vendor management. Businesses with broader corporate structuring, technology contracts or regulatory questions may also wish to involve a corporate law firm when integrating privacy obligations with their wider legal framework. Common Mistakes Businesses Should Avoid One common mistake is treating an age declaration as equivalent to parental verification. Another is collecting a child's information before completing the required verification process. Businesses also risk assuming consent permits behavioural monitoring or targeted advertising. Section 9 imposes separate restrictions on these activities, subject to prescribed exemptions. Another problem arises when businesses rely on an exemption without checking its conditions. Finally, some organisations focus heavily on the privacy policy but overlook their software, vendors and internal data flows. A defensible privacy programme must cover the complete lifecycle of the information. Conclusion Parental consent under India's DPDP framework is not merely a procedural checkbox. It requires businesses to think carefully about age assurance, adult verification, consent records, data minimisation, security and the purposes for which children's information is processed. The most important compliance distinction is between recording consent and proving verifiable parental consent. Businesses need systems capable of demonstrating who provided consent and ensuring the processing permitted by the consent remains within the boundaries of Indian data protection law. The final Rules provide businesses with a defined framework for verification, including reliance on reliable identity and age information and qualifying virtual tokens. They also introduce limited exemptions for specified organisations and purposes. With the principal child data provisions scheduled for commencement in May 2027, businesses have an opportunity to address these issues before they become urgent operational requirements.   Frequently Asked Questions (FAQs) Q1. Is parental consent mandatory for collecting children's data in India? Under Section 9 of the DPDP Act, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. Q2.What age is considered a minor under the DPDP Act? For the purposes of the DPDP Act, a child is an individual who has not completed eighteen years of age. Q3.What is verifiable parental consent? Verifiable parental consent requires a Data Fiduciary to use appropriate technical and organisational measures and exercise due diligence to establish that the person providing consent as a parent is an identifiable adult. Rule 10 permits reliance on reliable identity and age details or voluntarily provided information or qualifying virtual tokens. Q4.Is an OTP sufficient for parental consent? An OTP may be part of a broader verification process, but businesses should not assume an OTP alone automatically satisfies the statutory concept of verifiable consent. The organisation must consider whether its complete process establishes the adult's identity and age as contemplated by Rule 10. Q5.Can a child provide consent for their own data? Where Section 9 applies, the statutory framework requires verifiable consent from the parent or lawful guardian before processing the child's personal data. Q6.Can businesses track children's online behaviour after obtaining parental consent? Section 9 prohibits tracking or behavioural monitoring of children, subject to prescribed exemptions. Parental consent should not be treated as a general authorisation to undertake prohibited processing. Q7.Can companies use targeted advertising for children? Section 9 prohibits targeted advertising directed at children, subject to prescribed exemptions. Q8.Are schools exempt from obtaining parental consent? The Rules provide limited exemptions for specified educational processing. The exemption is conditional and should be assessed against the relevant provisions of the Fourth Schedule. Q9.When will Rule 10 of the DPDP Rules apply? Rule 10 is scheduled to commence eighteen months after publication of the Rules on 13 November 2025. The scheduled date is 13 May 2027. Q10.What is the penalty for violating children's data obligations? The DPDP Act's Schedule provides for a penalty of up to ₹200 crore for breach of the obligations relating to children. The actual penalty depends on the nature and circumstances of the contravention.
Children’s Data Protection,
Children’s Data Protection Under India’s DPDP Act: What Businesses Need to Know
The rapid growth of digital services for children has made Children's Data Protection an important legal issue for businesses operating in India. Educational platforms, gaming companies, healthcare providers, social platforms, e commerce businesses and family focused applications may collect information from users below eighteen years of age. India’s Digital Personal Data Protection Act, 2023 introduces specific safeguards for such processing, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. The Digital Personal Data Protection Rules, 2025 now provide greater operational clarity, although the substantive children’s data provisions are subject to the Act’s phased commencement framework. For businesses, the issue extends well beyond publishing a privacy policy. Organisations need to examine their products, consent mechanisms, technology infrastructure, advertising practices, contracts and internal governance before the relevant provisions become operational. What Does Children’s Data Protection Mean Under the DPDP Act? The DPDP Act takes a broad approach to the protection of children’s personal data. Section 2(g) defines a child as an individual who has not completed eighteen years of age. This age threshold is important because businesses cannot simply adopt the age threshold used under another country's privacy regime and assume it will satisfy Indian requirements. Section 9 of the Act specifically deals with processing personal data of children. Before processing such data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian in the prescribed manner. The provision also requires businesses to ensure their processing does not cause a detrimental effect on the well being of a child. Further, subject to prescribed exemptions, the Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. This creates a higher compliance threshold than ordinary personal data processing. A business must therefore understand not only what information it collects, but also how its product uses information after collection. A child’s name, age, photograph, account details, location, educational information or online activity may all form part of a wider data processing ecosystem. Why the DPDP Act Matters to Businesses? The DPDP Act establishes a framework for digital personal data processing in India. It places obligations on Data Fiduciaries, meaning organisations which determine the purpose and means of processing personal data. The distinction is commercially significant. A company does not avoid responsibility simply because another company provides the technical infrastructure used for processing. Cloud providers, analytics vendors, software providers and other processors may support the service, but the business still needs to understand its own statutory responsibilities. The Act also creates rights for Data Principals and establishes an enforcement structure through the Data Protection Board of India. The statutory framework therefore moves privacy away from being purely an internal policy issue and towards formal organisational accountability. For businesses dealing with children, this accountability becomes particularly important because the law treats children's data as requiring additional safeguards. The Current Legal Position and Commencement Timeline One of the most important points for businesses is the phased implementation of the DPDP framework. The Central Government notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. The Rules provide for different commencement dates. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4 is scheduled to commence one year after publication, while Rules 3 and 5 to 16, along with Rules 22 and 23, are scheduled to commence eighteen months after publication. The Act follows a similar phased approach. India Code records Sections 2, 18 to 26, 35 to 43 and specified provisions of Section 44 as commencing on 13 November 2025. Substantive provisions including Sections 3 to 5, Sections 7 to 17 and other specified provisions are scheduled to commence eighteen months from that date. Section 9 falls within this later group. Accordingly, as of August 2026, businesses should distinguish between provisions already operational and provisions scheduled to commence later. This distinction is important for legal accuracy. Businesses should not describe every DPDP obligation as fully enforceable today. At the same time, waiting until the final commencement date would be commercially unwise. Product changes, vendor negotiations, consent architecture and internal governance can take months to implement. Verifiable Parental Consent Is Central to Compliance The most visible obligation concerning children's data is parental consent. Section 9 requires verifiable consent from the parent or lawful guardian before processing a child's personal data. The final Rules provide greater detail on how verification is expected to work. Rule 10 requires a Data Fiduciary to adopt appropriate technical and organisational measures and conduct due diligence to establish whether the person presenting themselves as a parent is an identifiable adult. Verification may rely on reliable identity and age information already available to the Data Fiduciary or information voluntarily provided by the individual or through a virtual token issued by an authorised entity. This creates an important design challenge. A business must verify parental authority without creating an unnecessarily intrusive identity collection process. Collecting excessive information from parents can create additional privacy and security risks. The consent mechanism should therefore be designed around necessity, proportionality and security. A simple declaration such as “I am the parent” may not be sufficient where the law requires verifiable consent. Businesses should document the verification methodology and retain appropriate evidence of consent. The Restrictions on Tracking and Behavioural Monitoring The DPDP Act takes a particularly cautious approach to children's behavioural data. Section 9 restricts tracking and behavioural monitoring of children, along with targeted advertising directed at children, subject to prescribed exemptions. This can affect technologies businesses commonly use for analytics and personalisation. For example, a platform may use cookies, device identifiers, engagement data, location information or interaction histories to understand user behaviour. For an adult audience, these practices may form part of ordinary analytics. A child focused service requires a much more careful assessment. Businesses should therefore review software development kits, analytics tools, advertising pixels, recommendation systems and third party tracking technologies before deployment. The question should not simply be whether the technology collects personal data. The business should ask whether it tracks or monitors the behaviour of children and whether the proposed activity falls within a permitted exemption. Targeted Advertising to Children Requires Particular Caution Advertising models based on user profiling can create significant legal concerns. A business may collect information about content preferences, browsing behaviour, purchasing patterns or engagement levels and use it to deliver personalised advertisements. Section 9 places a specific restriction on targeted advertising directed at children, subject to prescribed exemptions. This means marketing teams should not treat children's advertising as merely another segmentation exercise. Businesses need to understand how their advertising systems identify audiences and whether child users can enter those audiences. This becomes more complicated for platforms serving both adults and children. Age assurance, account design and advertising controls may therefore need to work together. A company should also examine whether external advertising partners receive information about child users and what contractual restrictions apply to such processing. Exemptions Under the DPDP Rules The Rules recognise certain exemptions from specific children's data obligations. The explanatory note published by the Ministry of Electronics and Information Technology identifies specific classes of organisations, including certain healthcare professionals, educational institutions and childcare providers, which may benefit from exemptions for defined purposes. The exemptions are subject to conditions and are not a blanket permission to process children's personal data without safeguards. For example, processing may be permitted for activities connected with healthcare, education, child safety or transportation, depending on the applicable category and conditions. This purpose based approach matters. An educational institution should not assume its entire database is exempt merely because it is an educational institution. The organisation should identify the precise processing activity and establish whether it falls within the relevant statutory exemption. A written exemption assessment can be valuable during internal compliance reviews. Data Minimisation Should Start at Product Design Children's privacy cannot be managed effectively if a business collects excessive information from the outset. A useful question is simple: does the service genuinely need every piece of information being collected? An educational application may need a child's name, class and learning records to provide its service. It may not need precise location data, extensive behavioural profiles or unrelated demographic information. Data minimisation reduces both compliance exposure and cybersecurity risk. Product teams should therefore involve privacy considerations before new features are released. A feature which creates a new category of children's data should trigger a review before development is completed. Privacy by design is considerably easier than restructuring a mature product after launch. Privacy Notices and Consent Records Businesses should ensure their privacy notices accurately describe their processing activities. The DPDP Rules introduce specific notice requirements, including clear information about the personal data being processed and the purpose for processing. The Government's explanatory note emphasises accessible information and transparency for Data Principals. For children's services, the privacy notice should align with the parental consent process. A common compliance weakness occurs when the privacy notice describes one processing purpose while the product performs additional analytics or marketing activities. The legal document, application interface and internal data practices should therefore remain consistent. Businesses should also maintain reliable records showing how and when consent was obtained. Consent records may become important when responding to complaints, regulatory enquiries or internal audits. Children's Data and Third Party Vendors Modern businesses rarely operate entirely within their own technology environment. An application may use external cloud hosting, analytics, customer support software, communication services, payment platforms and advertising networks. Every such relationship should be examined where children's personal data is involved. The business should know what information is shared, why it is shared, where it is stored, how long it is retained and what happens when the relationship ends. Vendor contracts should contain appropriate provisions dealing with confidentiality, security, permitted processing, breach reporting, deletion, subcontracting and assistance with legal obligations. A business should also maintain an up to date inventory of relevant vendors. It is difficult to demonstrate effective privacy governance when the organisation does not know who has access to its data.  Security Obligations Cannot Be Separated From Children's Privacy Consent alone does not protect children's information. A business can have a perfectly designed consent mechanism and still face serious exposure if its databases, applications or vendor systems are insecure. The DPDP framework requires Data Fiduciaries to adopt reasonable security safeguards. The statutory penalty framework provides significant financial exposure for specified breaches, including penalties of up to ₹250 crore for failure to take reasonable security safeguards and up to ₹200 crore for breach of obligations relating to children. Security controls should therefore be proportionate to the nature and volume of data handled. Access restrictions, authentication, encryption where appropriate, secure software development, monitoring, vulnerability management and incident response should form part of the wider governance framework. Employee awareness is also important. A child’s information may be exposed through simple operational mistakes such as incorrect email distribution, insecure file sharing or excessive employee access. What Happens After a Data Breach? Businesses should have an incident response procedure before an incident occurs. The response should establish who investigates the breach, who makes legal decisions, who communicates with affected parties and who manages regulatory engagement where required. Children's information can present distinctive risks. A breach involving a child's location, photograph, school details or behavioural information may create consequences beyond ordinary commercial inconvenience. Incident response should therefore consider the nature of the affected information and the potential impact on children. The DPDP framework contains specific requirements concerning personal data breaches, while the Rules provide operational detail for breach intimation. Businesses should ensure their technical and legal teams understand the applicable requirements before an incident occurs. Artificial Intelligence Creates New Children's Data Questions AI based products create another layer of complexity. A business may use children's data to personalise educational content, generate recommendations, analyse performance or develop machine learning systems. Before using information for a new purpose, the organisation should examine whether the proposed processing is consistent with the original purpose, notice and applicable consent framework. A company should not assume data collected for one service can automatically be reused to train a commercial AI system. AI governance should therefore be integrated into children's data governance. Product teams should identify whether AI tools receive personal data, whether external providers process it and whether the proposed use is necessary for the service. What Businesses Should Do Before Section 9 Becomes Operational? Businesses handling children's data should use the transition period to conduct a detailed privacy readiness assessment. The first stage should be data mapping. Identify where children's information enters the organisation, what categories are collected, where the information is stored and which internal teams and external vendors can access it. The second stage should involve an age and consent assessment. Determine how the business will identify child users and how it will obtain and verify parental consent where required. The third stage should focus on product design. Review analytics, behavioural monitoring, recommendation engines, advertising systems and location features. The fourth stage should involve contractual review. Vendor and partner agreements should reflect the organisation's actual data processing arrangements. The final stage should involve governance. Assign responsibility for privacy compliance, consent records, data inventories, incident response and regulatory developments. Businesses can consult the official Digital Personal Data Protection Rules, 2025 published by MeitY for the notified regulatory text and commencement information. Why Businesses Should Prepare Before the Legal Deadline? The transition period should not be viewed as a reason to postpone compliance. A privacy programme may require changes to software architecture, account creation, consent flows, databases, advertising technology and contracts. These changes cannot always be completed immediately. Early preparation also gives businesses an opportunity to identify commercially unnecessary data collection. For example, a company may discover it has been collecting precise location information simply because an analytics tool automatically captures it. Removing unnecessary collection may be easier than creating a complex legal justification for retaining it. The objective should be to build a product where privacy safeguards support the business model rather than obstruct it. The Role of Legal Advisers in Children's Data Compliance Children's data compliance involves several disciplines. Technology teams understand the systems. Product teams understand the user journey. Marketing teams understand advertising practices. Security teams understand infrastructure. Legal professionals connect these activities with statutory requirements. Businesses may therefore benefit from involving data privacy law firms when reviewing complex children's data processing arrangements, particularly where the service involves large scale processing, behavioural technology, international vendors or sensitive categories of information. A legal review should examine the actual product rather than only the privacy policy.  The right questions include whether parental consent is genuinely verifiable, whether the business collects more information than necessary, whether tracking technologies operate on child accounts, whether vendors receive children's data and whether the business can demonstrate compliance through reliable records. The objective is practical risk management, not paperwork for its own sake. Where the organisation has wider corporate governance or commercial contracting concerns, a corporate lawyer can also help connect privacy requirements with shareholder arrangements, technology contracts, vendor agreements and business operations. Conclusion India's DPDP framework represents a significant shift in how businesses must approach children's personal data. Section 9 places specific emphasis on verifiable parental consent, child well being and restrictions on behavioural monitoring, tracking and targeted advertising. The DPDP Rules, 2025 provide additional operational detail and introduce specified exemptions for certain organisations and purposes. For businesses, the strongest response is early preparation. Children's privacy should be considered during product development, vendor selection, marketing planning and technology design rather than being addressed only when a regulatory deadline approaches. A defensible compliance framework should allow the organisation to answer five basic questions clearly: What children's data do we collect? Why do we need it? Who can access it? How do we obtain and record consent? When do we delete it? Businesses able to answer these questions with evidence will be better placed to manage the legal, operational and reputational risks associated with children's personal data. Frequently Asked Questions (FAQs) Q1. What is Children's Data Protection under the DPDP Act? It refers to the additional legal safeguards applicable to processing personal data belonging to individuals who have not completed eighteen years of age. Section 9 of the DPDP Act specifically addresses children's personal data. Q2. What age is considered a child under India's DPDP Act? A child is an individual who has not completed eighteen years of age. Q3. Is parental consent mandatory for children's data? Section 9 requires verifiable consent from the parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. Q4. Can businesses track children online? Section 9 restricts tracking and behavioural monitoring of children, subject to prescribed exemptions. Businesses should therefore review analytics, advertising and profiling technologies used on child facing services. Q5. Can businesses show targeted advertisements to children? Targeted advertising directed at children is restricted under Section 9, subject to prescribed exemptions. Q6. Does the DPDP Act apply only to children's apps? No. The relevant obligations can affect any Data Fiduciary processing personal data of children. This can include education, healthcare, gaming, retail, entertainment and other digital services. Q7. Are schools exempt from children's data requirements? The Rules provide specific exemptions for certain educational institutions and specified purposes. These exemptions are conditional and should not be interpreted as a general exemption from all DPDP obligations. Q8. When will Section 9 become applicable? Section 9 is scheduled to commence eighteen months after 13 November 2025, alongside other substantive provisions listed in the commencement notification. This places the scheduled commencement date at 13 May 2027, subject to any subsequent notification or amendment. Q9. What penalties can apply for children's data violations? The DPDP Act's Schedule provides for a penalty of up to ₹200 crore for breach of the additional obligations relating to children. Other contraventions carry different maximum penalties. Q10. Is a privacy policy enough for compliance? No. Businesses need a broader framework covering data mapping, consent management, security safeguards, vendor governance, retention, rights management, incident response and internal accountability.  
Children's Data Privacy,
Data Privacy Laws for Businesses Handling Children's Personal Data in India
Children increasingly interact with digital platforms for education, entertainment, gaming, communication and financial services. As businesses collect names, photographs, contact details, location information, account credentials, academic records and behavioural information from young users, Children's Data Privacy has become a significant legal and governance issue in India. The Digital Personal Data Protection Act, 2023 introduces specific obligations for organisations processing children's personal data, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. The Digital Personal Data Protection Rules, 2025 provide further operational detail. For businesses, the issue is no longer limited to having a privacy policy. It involves understanding what data is collected, why it is collected, how parental consent is established, who receives the information, how long it is retained and how the organisation responds when something goes wrong. What Is Children's Data Privacy Under Indian Law? The Digital Personal Data Protection Act, 2023 defines a child as an individual who has not completed eighteen years of age. This is a considerably broader age threshold than some international privacy regimes. Section 9 of the Act creates additional safeguards specifically for processing personal data belonging to children. The Act applies to digital personal data. This includes information collected in digital form as well as personal data collected in non digital form and subsequently digitised, subject to the Act's scope and exclusions. For a business, this means a child's data should not be treated as an ordinary customer dataset. The organisation needs to determine whether the user is a child, whether parental consent is required, whether an exemption applies and whether the proposed processing could adversely affect the child's well being. The Supreme Court's privacy jurisprudence also provides an important constitutional backdrop. In Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the Supreme Court recognised privacy as a fundamental right. The later judgment specifically discussed the importance of protecting children's digital footprints and recognised the need for special protection for children's privacy. India's Current Legal Framework for Children's Data Privacy India's principal statutory framework is the Digital Personal Data Protection Act, 2023, supported by the Digital Personal Data Protection Rules, 2025. The Act establishes the concepts of Data Fiduciaries and Data Principals. A business deciding the purpose and means of processing personal data generally falls within the role of a Data Fiduciary. A child whose personal data is processed is a Data Principal. Section 9 is the central provision for children's data. It requires the Data Fiduciary to obtain verifiable consent from the parent or lawful guardian before processing a child's personal data. The provision also prohibits processing likely to cause a detrimental effect on the well being of a child. In addition, it prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This framework is important for more than children's apps. EdTech platforms, healthcare providers, gaming businesses, e commerce platforms, social platforms, educational institutions, childcare providers and businesses offering services to families may all need to examine whether their activities involve children's personal data. When Do the Children's Data Provisions Take Effect? This point requires particular care because the DPDP Act and Rules have a phased commencement structure. The Central Government issued the commencement notification on 13 November 2025. Several institutional provisions came into force immediately. However, Sections 3 to 5, most of Section 6, Sections 7 to 17 and several other substantive provisions, including Section 9 dealing specifically with children's personal data, are scheduled to come into force eighteen months after 13 November 2025. This places the scheduled commencement of Section 9 on 13 May 2027. The same phased approach applies to the relevant provisions of the DPDP Rules, 2025. Rule 10, which deals with verifiable consent for processing children's personal data, falls within the provisions scheduled to commence eighteen months after publication. As of August 2026, businesses therefore have an important preparation window. The fact that the principal children's data obligations are not yet fully operational does not make preparation unnecessary. Organisations handling children's information should use the transition period to redesign their systems, contracts, consent mechanisms and governance arrangements. What Does Verifiable Parental Consent Mean? Parental consent under the DPDP framework is more demanding than simply displaying a checkbox stating, "I am the parent". The 2025 Rules provide an operational mechanism for verifying the person providing consent. Rule 10 requires a Data Fiduciary to adopt appropriate measures to verify whether the person giving consent is the parent or lawful guardian and whether the person is an identifiable adult. The Ministry's explanatory note refers to reliable identity details and virtual tokens mapped to such details. The Rules also contemplate situations where a parent is already registered with the service and circumstances where identity details may need to be provided through mechanisms such as Digital Locker. For businesses, the practical challenge is significant. The consent journey must be reliable without collecting excessive information from parents merely to establish their authority. An organisation should therefore consider data minimisation while designing parental verification. Collecting more identity information than necessary may create a second privacy problem while attempting to solve the first. Restrictions on Tracking and Behavioural Monitoring One of the most significant aspects of India's children's privacy regime is the restriction on tracking and behavioural monitoring. Businesses often rely on analytics tools to understand how users interact with their websites or applications. They may use cookies, device identifiers, location signals, engagement histories or other technical information to understand user behaviour. Where a user is a child, these practices require careful examination. Section 9(3) expressly prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This creates an important distinction between providing a service and profiling its users. An educational platform may need certain information to provide lessons, assess performance or maintain account security. It does not automatically follow that the same platform can use the child's behavioural information to build advertising profiles. Businesses should map every category of analytics and advertising technology used on a child facing service. Third party SDKs and advertising technologies deserve particular attention because a company may remain responsible for how personal data is processed even where technical processing is performed through external vendors. Can Schools, Healthcare Providers and Childcare Businesses Rely on Exemptions? The DPDP Rules recognise certain exemptions from some of the obligations under Section 9. The Fourth Schedule contains specific classes of Data Fiduciaries and prescribed conditions. These include certain healthcare establishments and professionals, educational institutions and childcare providers. The exemptions are purpose specific and subject to conditions. This distinction is important. An educational institution cannot assume every form of data processing is automatically exempt simply because it is a school. The relevant processing must fall within the prescribed class and purpose. For example, processing necessary for educational activities may be treated differently from using children's information for unrelated commercial profiling or promotional activities. Businesses should therefore document the precise statutory basis for relying on an exemption rather than treating an exemption as a blanket permission. Privacy Notices Must Be Designed for the Actual Processing A privacy notice should tell users what information is being collected and why it is needed. Under the 2025 Rules, the notice requirements include clear and understandable information about the personal data being processed and the specific purpose for processing. The notice also needs to provide a means through which the Data Principal can access relevant information and exercise applicable rights. For children's services, the consent experience should be designed around the parent or lawful guardian where parental consent is required. A lengthy privacy policy hidden behind multiple links is unlikely to provide a strong operational solution. The business should separate the legal document from the actual user journey. The consent interface, privacy notice, account creation process and internal records should tell the same story. Data Minimisation Becomes Especially Important Children's privacy compliance is not simply about obtaining consent. Businesses should ask whether each item of information is genuinely necessary for the service. If a platform needs an email address to create an account, collecting detailed location information may require separate justification. If a learning service needs assessment results, collecting unrelated behavioural information may increase legal and security exposure. Data minimisation also reduces the consequences of a breach. A business cannot lose information it never collected. This principle should be reflected in product design, database architecture, analytics configuration and vendor contracts. Security Safeguards and Children's Personal Data The sensitivity of children's information makes information security a central compliance concern. The DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The statutory schedule allows a penalty of up to ₹250 crore for breach of the obligation concerning reasonable security safeguards. A breach of the additional obligations relating to children can attract a penalty of up to ₹200 crore. These figures demonstrate why cybersecurity cannot be treated solely as an IT issue. A business handling children's information should consider access controls, encryption where appropriate, authentication, secure development practices, logging, vulnerability management, backup security and incident response procedures. Employees should also understand how children's information is handled. Human error remains a significant source of privacy incidents. Vendor and Third Party Risk Many businesses do not process all personal data internally. Cloud service providers, analytics companies, customer relationship platforms, communication tools, payment providers and software developers may process information on behalf of the business. This creates contractual and operational risk. A company should know which vendors receive children's personal data, what information they receive, why they receive it, where it is processed and how it is deleted. Vendor agreements should address confidentiality, security obligations, permitted processing, incident reporting, subcontracting, deletion and assistance with regulatory requirements. A privacy programme is only as strong as its weakest significant data processor. What Happens When a Data Breach Occurs? A business should have an incident response plan before a breach occurs. The response should identify who investigates the incident, who decides whether notification is required, who communicates with affected individuals and who liaises with regulators or authorities where necessary. The DPDP Act contains specific obligations concerning personal data breaches and provides penalties for failure to comply with applicable notification requirements. For businesses serving children, incident response should also consider the potential real world consequences of disclosure. A leaked email address is one concern. Exposure of a child's location, school information, photographs or behavioural profile can create substantially different risks. The response should therefore be proportionate to the nature of the information involved. Children's Data and Artificial Intelligence The growth of artificial intelligence creates another layer of complexity. Businesses may use children's information to train models, personalise educational content, generate recommendations or analyse performance. Before doing so, the business should identify the purpose of processing and determine whether the proposed use is permitted under the applicable legal framework. Using data collected for education to train a commercial model may raise questions about purpose, notice, consent and fairness. The business should not assume the original consent automatically covers every later use. Data governance should therefore extend to AI systems, analytics tools and automated decision making processes. How Businesses Should Prepare Before the Rules Fully Apply? Businesses handling children's personal data should begin with a data mapping exercise. The organisation should identify where children's data enters its systems, what categories are collected, which teams access it, which vendors receive it, where it is stored and when it is deleted. The next step should be an assessment of the user journey. If parental consent will be required, the organisation should determine how it will identify children, verify parents and maintain evidence of consent without collecting unnecessary information. The organisation should then review its advertising and analytics architecture. Tracking technologies directed at children's activity require particular scrutiny because Section 9 specifically addresses behavioural monitoring and targeted advertising. Contracts should also be reviewed. Vendor agreements, data processing arrangements, confidentiality clauses and security obligations should reflect the organisation's actual data practices. Finally, internal accountability should be established. Someone should be responsible for maintaining the data inventory, reviewing privacy controls, managing incidents and keeping the business informed about regulatory developments. Why Businesses Should Not Wait Until May 2027? The eighteen month transition period may appear generous, but privacy compliance is rarely solved by changing a single document. A business may need to modify its application, database, consent architecture, vendor arrangements, marketing technology, privacy notices and internal procedures. Technology changes take time. Vendor negotiations take time. Product teams need time to test new consent flows. Early preparation also allows businesses to identify practices which may be commercially attractive but legally difficult to defend. India's data protection regime is moving towards a more structured accountability model. Businesses should therefore treat children's privacy as a product governance issue rather than a compliance formality. Organisations looking for guidance on India's evolving data protection laws should rely primarily on the legislation, notified Rules, government notifications and authoritative regulatory material. The Role of Legal and Compliance Teams Legal review should not begin only after a privacy incident. Where a business regularly handles children's information, legal advisers should work with product, technology, security and marketing teams from an early stage. The role of commercial lawyers can extend beyond drafting privacy notices. They can help assess contractual arrangements, advertising models, vendor obligations, consent mechanisms, regulatory exposure and commercial implications of data processing practices. A good legal review asks practical questions. What is the business trying to achieve? What information does it actually need? What legal basis supports the processing? Is parental consent required? Can the same objective be achieved with less information? Who else receives the data? What happens if the user withdraws consent? How will the company respond to a breach? These questions connect legal compliance with actual business operations. Key Takeaway India's approach to children's personal data is moving towards stronger accountability and more active protection. The DPDP Act, 2023 places particular emphasis on verifiable parental consent, child wellbeing and restrictions on tracking, behavioural monitoring and targeted advertising. The DPDP Rules, 2025 add practical mechanisms for implementing these requirements. For businesses, compliance should begin with understanding the data lifecycle. The organisation needs to know what information it collects, why it needs it, who can access it, which third parties receive it and when it should be deleted. Product design, cybersecurity, contracts and legal governance should then work together. The strongest approach is not to treat children's privacy as a document prepared shortly before a regulatory deadline. It is to build privacy safeguards into the way the business collects and uses information from the outset. Frequently Asked Questions (FAQs) Q1. What is Children's Data Privacy in India? Children's Data Privacy refers to the legal and organisational safeguards applicable when businesses process personal data relating to individuals below eighteen years of age. The DPDP Act, 2023 contains specific protections for children's personal data. Q2. What age is considered a child under the DPDP Act? Under the DPDP Act, a child is an individual who has not completed eighteen years of age. Q3. Is parental consent required to process children's personal data? Section 9 requires verifiable consent from a parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. Q4. Can businesses use targeted advertising for children? Section 9 prohibits targeted advertising directed at children, subject to the exemptions prescribed under the law. Businesses should therefore review advertising technology carefully before using it in services accessed by children. Q5. Is behavioural tracking of children allowed in India? Section 9 of the DPDP Act prohibits tracking or behavioural monitoring of children, subject to prescribed exemptions. Q6. When will Section 9 of the DPDP Act become effective? Section 9 is scheduled to come into force eighteen months after 13 November 2025, meaning the scheduled commencement date is 13 May 2027, subject to any subsequent government notification or change. Q7. Do educational institutions have any exemptions? The DPDP Rules provide specified exemptions for certain classes of Data Fiduciaries, including educational institutions, subject to prescribed conditions and purposes. The exemption should not be treated as a blanket exemption from all privacy obligations. Q8. What penalties can apply for violating children's data obligations? The Schedule to the DPDP Act provides for a penalty of up to ₹200 crore for breach of the additional obligations relating to children under Section 9. Other breaches can attract different maximum penalties. Q9. Does a privacy policy alone make a business compliant? No. A privacy policy is only one component of a wider privacy framework. Businesses also need appropriate consent mechanisms, data governance, security controls, contractual safeguards, retention practices and processes for handling rights requests and incidents. Q10 Should startups prepare for children's data obligations before they become effective? Yes. Businesses handling children's personal data should use the transition period to review their products, consent mechanisms, technology, contracts and internal controls. Waiting until the statutory provisions become operational may leave insufficient time for meaningful implementation.
Contract Management,
Why Many New Businesses Overlook Contract Management in the Early Stage?
A new business usually begins with a simple priority: win customers, deliver the product and keep cash moving. Legal paperwork often comes later. This is why Contract Management is frequently overlooked during the early stage. Founders may sign agreements through email, save documents in different folders and rely on memory for renewal dates or commercial commitments. The problem becomes visible only when a customer disputes an obligation, a supplier changes its terms, confidential information is misused or an important contract expires without anyone noticing. For an early stage business, contract management is not merely an administrative function. It is a practical system for controlling legal obligations, commercial relationships and avoidable risk. What Contract Management Really Means Contract management is the process of managing an agreement from the moment a business identifies the need for it until the agreement is completed, renewed, amended or terminated. Modern contract lifecycle frameworks generally cover initiation, drafting, negotiation, approval, execution, performance monitoring and closure. This distinction matters for new businesses. A signed contract is not the end of the process. It is the point at which the parties begin performing their obligations. Consider a technology startup which signs a one year software services agreement. The founder may focus on the negotiated fee and scope of work. Six months later, the business may discover an automatic renewal clause, a minimum purchase commitment or a liability cap it no longer considers commercially suitable. If nobody was responsible for monitoring the agreement, the opportunity to renegotiate may already have passed. Effective contract management keeps such obligations visible. Why Founders Often Ignore Contracts in the Early Stage? The reason is rarely deliberate neglect. It is usually a consequence of limited resources. Founders often perform several roles simultaneously. They manage sales, finance, recruitment, product development and investor discussions. Legal administration competes with activities perceived as more urgent. There is also a misconception about contract volume. A business may have only ten or fifteen agreements during its first year. Founders therefore assume a formal system is unnecessary. Yet a small contract portfolio can contain significant exposure. A single customer agreement may govern a large portion of revenue. A supplier agreement may affect business continuity. An employment agreement may deal with confidential information and intellectual property. A lease can create a substantial financial commitment. Contract value is therefore more important than contract count. The Difference Between Drafting and Managing a Contract Drafting determines what the parties agree. Management determines whether the agreement continues to work as intended. A carefully drafted agreement can still cause problems if the business does not monitor it. Suppose a services contract requires delivery within defined timelines. The legal document may contain an escalation mechanism, service levels and payment consequences. If the operational team never receives the relevant deadlines, the business may breach its own obligations despite having negotiated a strong agreement. Contract management creates the connection between legal terms and daily business activity. This is one of the most important gaps in early stage businesses. Founders may involve lawyers before signing but fail to involve the legal or operations function after execution. The Legal Framework Governing Contracts in India The primary legislation governing contracts in India is the Indian Contract Act, 1872. It deals with matters including proposal and acceptance, competency, free consent, lawful consideration and object, performance, breach, indemnity, guarantee and agency. Section 10 sets out the basic requirements for agreements to become contracts, subject to the other provisions of the Act. Contractual arrangements may also be affected by sector specific legislation, company law, tax law, intellectual property legislation, data protection requirements and state specific stamp laws. Founders should therefore avoid treating every agreement as a generic commercial document. The legal requirements can vary depending on the nature of the transaction, parties involved, subject matter, governing law and place of execution. Why Informal Agreements Create Problems? Early stage businesses frequently rely on emails, WhatsApp messages, purchase orders and verbal commitments. Electronic communications can have legal significance. The Information Technology Act, 2000 recognises electronic records and electronic signatures and contains Section 10A concerning contracts formed through electronic means. This does not mean every informal conversation is a suitable substitute for a carefully drafted commercial agreement. The central problem is uncertainty. If the parties disagree later, they may have different understandings about price, scope, delivery, intellectual property ownership, confidentiality, termination or liability. A fragmented email trail can make the dispute harder to resolve. A written agreement should therefore record material commercial terms clearly rather than leaving important matters to assumptions. Contract Risks New Businesses Commonly Miss One recurring problem is unclear scope. If a customer and service provider understand the deliverables differently, a dispute can arise even when both believe they acted reasonably. Payment terms can create another problem. Businesses sometimes focus on the headline price while overlooking advance payments, taxes, credit periods, late payment provisions, set offs and milestone conditions. Termination clauses also deserve close attention. A business should understand how an agreement can end, how much notice is required and what happens to outstanding obligations after termination. Liability provisions are equally important. Indemnities, exclusions, limitation of liability clauses and warranties can materially change the financial consequences of a dispute. Intellectual property provisions are particularly important for technology businesses. The contract should make it clear who owns pre existing material, newly created work product, source code, designs, documentation and improvements. Confidentiality provisions should also reflect the nature of information being exchanged.  Contract Management and Corporate Authority A new company should also consider who has authority to enter into agreements on its behalf. This becomes particularly important when founders, employees or business development personnel negotiate contracts with customers and suppliers. The company should have an internal approval structure appropriate to its size and risk profile. High value transactions, long term commitments, related party arrangements and unusual liability provisions may require higher level review. The Companies Act, 2013 also contains specific requirements concerning interested directors and certain contracts or arrangements involving companies. Section 184 requires disclosure of a director's interest in specified contracts or arrangements and restricts participation in the relevant Board discussion in the circumstances prescribed by law. Contract management should therefore connect commercial decision making with corporate governance. Stamp Duty Should Not Be an Afterthought Stamp duty is another area often missed when businesses focus only on commercial terms. The Indian Stamp Act, 1899 contains provisions concerning instruments chargeable with stamp duty. State amendments and state specific stamp legislation can also be relevant, depending on the document and place of execution. A contract should therefore be reviewed for applicable stamping requirements before execution or within the legally prescribed framework. The consequences of inadequate stamping can depend on the applicable law and circumstances. Businesses should obtain advice where the agreement involves significant commercial value or a complex transaction. Why Contract Storage Matters? Finding the latest signed version of an agreement should not require a search through an employee's inbox. A basic contract repository should contain the executed agreement, amendments, schedules, supporting documents and relevant correspondence. Access should be controlled according to the sensitivity of the information. The repository should also capture practical information such as the parties, effective date, expiry date, renewal provisions, notice period, payment obligations and responsible business owner. The aim is simple: someone should be able to understand the status of an agreement without reading every email exchanged during negotiation.  Managing Renewals and Expiry Dates Automatic renewal clauses deserve particular attention. A contract may renew automatically unless notice is given within a specific period. Missing the notice window can lock the business into another contractual period. The same problem can arise with leases, software subscriptions, insurance arrangements, maintenance contracts and vendor agreements. A simple reminder system can prevent avoidable costs. The responsible person should receive notice sufficiently early to allow commercial review and renegotiation. The key point is not merely recording the expiry date. The business should record the date by which action must be taken. Contract Management During Business Expansion Contract complexity usually increases as a business grows. A company entering new markets may work with distributors, channel partners, consultants, logistics providers, technology vendors and overseas customers. Different jurisdictions may introduce additional considerations concerning governing law, dispute resolution, taxation, foreign exchange, data transfers and regulatory compliance. For businesses considering business setup in india, contract management should be considered alongside corporate structuring rather than after commercial operations begin. Early discipline makes expansion easier because the business already has approved processes, contract records and defined authority levels.  Contract Management and Business Expansion in India Expansion often creates a second challenge: contracts start being negotiated by different teams using different terms. One sales employee may offer a generous liability position. Another may use a different payment structure. A third may promise intellectual property rights without internal approval. This inconsistency creates legal and commercial exposure. Businesses planning Business Expansion in India should therefore establish core contract principles before transaction volume becomes difficult to control. Standard templates can be used for recurring arrangements, while material deviations can be escalated for legal review. The objective is not to make every agreement identical. It is to ensure deviations are deliberate. A Practical Contract Management Process for a New Business A young company does not necessarily need sophisticated contract management software. It first needs a disciplined process. Every new agreement should begin with a clear business purpose. The parties and commercial objectives should be identified before drafting. The agreement should then undergo an appropriate legal and commercial review. Once the parties agree, the person authorised to sign should execute the final version. The signed document should be stored centrally. After signing, responsibility should move to the person responsible for performance. Important obligations, payment dates, milestones, renewal periods and notice requirements should be recorded. Before expiry or renewal, the business should assess performance and commercial value. This process is simple enough for a small company and can become more sophisticated as the business grows. When Should a Startup Introduce Formal Contract Management? The answer is earlier than many founders expect. A startup does not need dozens of agreements before establishing basic controls. Once it starts entering recurring customer, supplier, employment, consultant, technology or partnership arrangements, it has enough contractual exposure to justify a structured process. The system can initially be a well maintained central repository combined with a contract register and clear approval responsibilities. As contract volume increases, specialised contract lifecycle management technology may become useful. Current industry guidance increasingly emphasises centralised repositories, standard templates, approval workflows and obligation tracking. Technology should support a sound process rather than substitute for one. What Good Contract Management Looks Like Good contract management does not mean involving lawyers in every email. It means knowing which agreements require detailed legal review and which routine documents can follow an approved process. It means knowing who can approve a contract, who can sign it, where the final version is stored and who owns the obligations afterwards. It also means reviewing contracts when circumstances change. A supplier may become strategically important. A customer may request new services. A regulatory change may affect the relationship. A business may enter a new jurisdiction. The contract should not remain static while the commercial relationship changes around it. Why Early Contract Discipline Pays Off Later Contract problems often remain invisible until a business is under pressure. A funding round may trigger legal due diligence. A large customer may request warranties and indemnities. An acquisition may require a review of change of control provisions. A dispute may require the business to locate historic agreements quickly. If contracts have been managed properly from the beginning, these exercises become easier. The company can demonstrate its contractual relationships, identify material obligations and explain how agreements are approved and maintained. This strengthens legal readiness without turning contract management into unnecessary bureaucracy. Frequently Asked Questions (FAQs) Q1. What is Contract Management? Contract Management is the systematic process of creating, reviewing, negotiating, approving, executing, monitoring, renewing and terminating business agreements. It covers both the legal document and the obligations arising from it. Q2. Why is contract management important for startups? Startups often have limited resources and significant dependence on a small number of customers, suppliers and employees. A single poorly managed agreement can therefore have a disproportionate financial or operational impact. Q3. Is contract management necessary for a small business? Yes. The process does not need to be complex. A central repository, contract register, approval process and renewal calendar can provide meaningful protection even for a small company. Q4. What contracts should a new business manage? Common categories include customer agreements, supplier contracts, employment agreements, consultancy agreements, non disclosure agreements, technology licences, leases, distribution agreements, partnership arrangements and investment documents. Q5. Is an email agreement legally valid in India? Electronic contracts can be legally recognised in India. Section 10A of the Information Technology Act, 2000 addresses the validity of contracts formed through electronic means. However, the enforceability of a particular arrangement depends on its facts and applicable law. Q6. Who should manage contracts in a startup? Responsibility can be divided between founders, finance, operations, sales and legal advisers depending on the size of the business. One person should nevertheless have clear ownership of the contract register and compliance calendar. Q7. What happens after a contract is signed? The business should store the executed version, record important obligations, monitor performance, track payment and delivery milestones, monitor renewal or termination dates and retain amendments with the original agreement. Q8. Should every startup use contract management software? Not necessarily. A small business can begin with a structured manual process. Software becomes more useful when contract volume, teams, jurisdictions or compliance requirements make manual tracking difficult. Q9. Why should contracts be reviewed before renewal? Renewal provides an opportunity to assess performance, pricing, service levels, liability exposure and changing business needs. Automatic renewal provisions can also create obligations if the required notice is missed. Q10. What is the contract lifecycle? The contract lifecycle generally begins with identifying the need for an agreement and continues through drafting, negotiation, approval, execution, performance monitoring, amendment, renewal or termination and retention. Different frameworks divide these stages differently, but the underlying principle remains the same.
MHCO Updates
SEBI Update
REGULATORY UPDATE | SEBI IMPOUNDS ₹ 3.67 CR FROM TWO ENTITIES FOR ALLEGED MANIPULATIVE TRADES DURING CLOSING AUCTION SESSION
BACKGROUND The Securities and Exchange Board of India (“SEBI”) passed an Ex-Parte Interim Order dated 19 August 2026 against Copthall Mauritius Investment Limited (“Copthall”) and Mansi Share and Stock Broking Private Limited (“Mansi”) in relation to alleged manipulative trading during the Closing Auction Session (“CAS”) on the BSE SENSEX expiry day. SEBI's CAS framework, introduced vide Circular dated 16 January 2026 and made effective from 3 August 2026, provides for determination of the closing price through a dedicated auction mechanism based on the interaction of buy and sell orders. The framework replaced the earlier methodology based on the volume-weighted average price (“VWAP”) for securities covered under the CAS framework, which determined the price of securities based on the closing price of the security or focused on the weight of trades executed in the last 30 minutes of the trading session. Now, under the CAS framework, the price of securities is determined based on buy and sell orders in a single pool, executed at a single equilibrium price in a dedicated 20-minute daily auction timeline. SEBI’S FINDING SEBI prima facie found that the trading activity of Copthall and Mansi was linked to their outstanding SENSEX option positions and was undertaken to influence the Indicative Equilibrium Price (“IEP”) and closing price of the SENSEX so as to obtain a favourable payoff from their expiry-day F&O positions. On 13 August 2026, SEBI's surveillance observed three sharp movements in the SENSEX during the CAS. Upon examination of the trade and order logs, SEBI observed that these movements coincided with large and aggressive buy orders placed by Copthall and sell orders placed by Mansi in SENSEX constituent securities, which were subsequently cancelled. SEBI accordingly examined the trading activity of the two entities and its linkage with their outstanding SENSEX option positions. SEBI noted that the material on record did not prima facie indicate that the two Noticees acted in concert. Rather, each appeared to have adopted a separate strategy to move the SENSEX in a direction favourable to its respective F&O positions. SEBI'S DIRECTIONS SEBI directed that the bank accounts of Copthall and Mansi be impounded to the extent of ₹2,96,16,000 and ₹71,64,773 respectively, aggregating a total of ₹3,67,80,773. SEBI also debarred the noticees from accessing the securities markets and prohibited them from participating in the CAS, including placing, modifying or cancelling orders. Restrictions were also imposed on their bank and demat accounts, transfer/redemption of securities and disposal of assets without SEBI's permission. They were further directed to cooperate with SEBI's ongoing examination/investigation. MHCO COMMENT The order is significant in the context of the newly introduced CAS framework and SEBI's surveillance of potential attempts to influence the closing price through order placement and cancellation. The order demonstrates that SEBI is examining the nature, timing and price of orders, their impact on the IEP, subsequent cancellation of orders and the corresponding F&O positions of the concerned entities. The directions are interim in nature and are based on prima facie findings pending further investigation. SEBI has expressly clarified that the detailed investigation is to proceed independently of the prima facie observations contained in the interim order. Notably, SEBI has not alleged that Copthall and Mansi acted in concert. The findings against the two entities are based on their respective trading patterns and F&O positions. Since the order is ex-parte and interim in nature, the findings remain subject to SEBI's further examination, as well as the Noticees' replies and opportunity of hearing. By: Mr. Bhushan Shah, Partner Ms. Sayali Kshirsagar, Associate
IBC Update
IBC UPDATE - REMOVAL OF INTERIM MORATORIUM FOR PERSONAL GUARANTORS APPLIES TO PENDING PROCEEDINGS
Recently, the Bombay High Court in the case of Tata Capital Financial Services Limited v. Neel Motors LLP & Ors., held that the amendment introducing Section 96(4) of the Insolvency and Bankruptcy Code, 2016 (“IBC”) applies to insolvency applications filed before that date which remain pending. The Court consequently held that the interim moratorium under Section 96 ceased to operate against the personal guarantors from 26 May 2026, enabling Tata Capital to pursue limited interim relief under Section 9 of the Arbitration and Conciliation Act, 1996 (“Arbitration Act”). FACTS: The Petitioner, Tata Capital Financial Services Limited (“Tata Capital”) extended financial assistance to Respondent No. 1, Neel Motors LLP, under a Channel Finance Agreement. Respondent Nos. 2 to 4 were individual guarantors and partners of Neel Motors LLP, while Respondent No. 5 was a separate LLP acting as guarantor. The Letters of Guarantee contained arbitration clauses with Mumbai as the seat. In 2021, Tata Capital filed a petition under Section 9 of the Arbitration Act seeking interim protection. Approximately one month prior to filing the Section 9 petition, Tata Capital had initiated Corporate Insolvency Resolution Process (“CIRP”) against Neel Motors under the IBC. The CIRP ultimately failed and Neel Motors was ordered to be liquidated by the NCLT, Mumbai, on 1 April 2022. Thereafter, in June 2022, Tata Capital initiated insolvency proceedings under Section 95 of the IBC against Respondent Nos. 2, 3 and 4, who were the individual guarantors (“Guarantors”). The filing of the Section 95 applications triggered the interim moratorium under Section 96, stalling the Section 9 petition. The legal position changed with the insertion of Section 96(4) into the IBC which came into force on 26 May 2026. The amendment provided that Section 96 would not apply where an application was filed for initiating an insolvency resolution process in respect of a personal guarantor to a corporate debtor. Relying upon the amendment, Tata Capital sought consideration of its pending Section 9 petition. The principal issue before the Court was whether Section 96(4) could apply to Section 95 applications which had been filed before 26 May 2026 but continued to remain pending on the date of the amendment. Tata Capital’s Case Tata Capital contended that, in view of the newly inserted Section 96(4), the moratorium under   Section 96 no longer operated against the individual guarantors and the expression “where an application is filed” was sufficiently broad to include pending applications. It further relied upon the legislative purpose behind the amendment, that it was intended to “remove any perverse incentives” associated with the initiation of individual insolvency proceedings. Considering the considerable delay since filing of the Section 9 petition, Tata Capital only sought disclosure of the guarantors’ assets and an injunction restraining them from selling, transferring, alienating, encumbering or otherwise dealing with such assets pending arbitration. Guarantor’s Case The guarantors opposed the application, contending that such an interpretation would give the amendment retrospective effect. They submitted that the expression “where an application is filed” covers only applications filed after 26 May 2026 and could not extend to applications which had already been filed. Any other interpretation, according to the guarantors, would retrospectively alter the legal consequences attached to the pending proceedings. They further argued that although insolvency proceedings are not strictly recovery proceedings, both the insolvency and arbitration proceedings were directed towards recovery of the same debt and Tata Capital should therefore not be permitted to pursue both simultaneously Court’s Finding The Hon’ble Court held that the expression “where an application is filed” in Section 96(4) encompasses applications which had already been filed and continued to remain pending before the adjudicating authority. Had the legislature intended to restrict the provision only to applications filed after 26 May 2026, it could have expressly used language to that effect. The Court distinguished between retrospective and retroactive operation, relying upon the Supreme Court’s decision in Securities and Exchange Board of India v. Rajkumar Nagpal, the Court observed that a provision is retrospective when it operates backwards and impairs vested rights, whereas a retroactive provision operates prospectively on a character or status originating in the past. The existence of antecedent facts does not, by itself, make its application retrospective. Accordingly, the moratorium under Section 96 operated against Respondent Nos. 2 to 4 until 25 May 2026 but ceased from 26 May 2026 when Section 96(4) came into force. The pending Section 9 petition was therefore no longer barred by the IBC moratorium. The Court further acknowledged the possibility of a conflict of interest where the creditor initiating insolvency proceedings may also be pursuing claims against the individual guarantor. However, it held that such considerations could not override the express statutory language, particularly when Section 96(4) was agnostic as to the identity of the person who initiated the Section 95 proceedings. MHCO Comment Pending proceedings can be affected by a new provision without the provision necessarily being retrospective. The decisive factor is whether the provision changes completed past rights or operates prospectively upon an existing/pending legal status. Section 96(4) therefore lifted the Section 96 moratorium prospectively from 26 May 2026 even in respect of Section 95 applications filed prior to the amendment coming into force. By: Mr. Bhushan Shah, Partner Ms. Neha Lakshman, Associate Partner
Litigation
SUPREME COURT CLARIFIES INHERITANCE RIGHTS WHERE PROPERTY IS JOINTLY HELD IN THE NAMES OF TWO WIDOWS UNDER THE INDIAN SUCCESSION ACT, 1925
The Supreme Court, in Shakuntala & Ors. v. Robert Anthony & Ors. (Civil Appeal arising out of SLP(C) No. 9449 of 2020, judgment dated 30 July 2026), has held that where immovable property is purchased and registered in the joint names of two wives of a common husband, the property vests in the two wives themselves, and Section 33 of the Indian Succession Act, 1925 (“the Act”) which governs succession to the estate of a male intestate survived by a widow and lineal descendants cannot be applied to the entirety of such property merely because the husband had provided the purchase consideration. The Court set aside the concurrent (and mutually inconsistent) findings of the Trial Court, First Appellate Court and the High Court of Chhattisgarh, and worked out the succession afresh by applying Sections 33, 35 and 38 of the Act separately to each wife's share. Background: One Mattus Anthony (“MA”) had two wives, Filomina and Shyam Bai. In 1959, MA purchased a parcel of land for a consideration of INR 300 in the joint names of his two wives. Filomina had three children (the plaintiffs), while Shyam Bai had one son, John Anthony, who predeceased her in 1985 leaving behind his widow and four children (defendant Nos. 1 to 5). Filomina died in 1985, MA died intestate in 1991, and Shyam Bai died in 2000. In 2002, defendant Nos. 1 to 5 (the widow and children of John Anthony) sold half of the property, i.e., their understood share, to defendant No. 6. The plaintiffs, contending that the property was joint ancestral property in which they too had a share, challenged the sale as void. Figure: Family Tree of Mattus Anthony and the parties to the litigation Family Tree: The Trial Court decreed the suit, holding the sale deed invalid for want of consent of all co-owners and granting the plaintiffs a one-fourth share. The First Appellate Court reversed this, holding that each wife independently held a half share in the property (since it was purchased in their joint names), that the defendants, as legal heirs of John Anthony, were entitled to Shyam Bai's half, and that the 2002 sale deed was accordingly valid. The High Court, in second appeal, took yet another view: applying Section 33 of the Act on the footing that MA had died intestate leaving behind two widows and lineal descendants, it held that both widows, together, were entitled to one-third of the property, while the plaintiffs – treated as MA's only “lineal descendants” because John Anthony was held not to qualify as such – were entitled to the remaining two-thirds. Issue Before the Court: The principal question before the Supreme Court was whether Section 33 of the Act, which applies to the estate of a male who dies intestate, could be applied to property that was purchased in the joint names of MA's two wives, or whether the property had to be treated as belonging to the two wives themselves, with succession to each wife's share being worked out independently. Key Findings of the Court: The Court held that Section 33 of the Act, on its plain text, applies only to the property of a deceased male intestate. Since the property in question was purchased and registered in the names of MA's two wives, it was, in law, their property and not MA's, notwithstanding that MA had provided the consideration. The High Court's application of Section 33 to the entire property was accordingly held to be misconceived, since it proceeded on the incorrect premise that the property vested in MA and passed on his death to his widows and lineal descendants. Having held that the property vested independently in the two wives, the Court worked out succession separately to each half. As Filomina predeceased MA, the Court applied Section 35 of the Act (which gives a surviving husband the same rights over his intestate wife's property as a widow would have over her intestate husband's property). Applying Section 33 through the mechanism of Section 35, MA became entitled to one-third of Filomina's half share, with the remaining two-thirds devolving directly upon her children (the plaintiffs). On MA's own death intestate in 1991, the one-third share he had inherited from Filomina devolved equally upon all four of his children through both wives the three plaintiffs and John Anthony as tenants-in-common, there being no concept of joint family property, as under Hindu law, applicable to succession under the Indian Succession Act. As regards Shyam Bai's half share (together with the portion she in turn received through MA), the Court held that since Shyam Bai's own son, John Anthony, had predeceased her, the property devolved on her surviving grandchildren (defendant Nos. 2 to 5) under Section 38 of the Act, which governs the case of an intestate survived by grandchildren but no surviving child. On this basis, the defendants' entitlement was confined to Shyam Bai's share (as enlarged by the portion received through MA), and did not extend to any part of Filomina's share, contrary to the High Court's view that the two widows' shares should be pooled together and treated as a single one-third block. Treatment of Ancillary Contentions: The Court noted two further contentions that were not seriously pressed by the parties and did not call for detailed adjudication. First, on the question of benami, reliance was placed on Valliammal v. Subramaniam (2004) 7 SCC 233, for the proposition that intention and source of funds are relevant to a benami transaction; however, since it was undisputed that MA had purchased the property in the names of his two wives out of love and affection, no case of benami arose. Second, the validity of MA's second marriage to Shyam Bai was not in dispute between the parties, who were agreed that the controversy was confined to the extent of inheritance rights and not the existence of Shyam Bai's status as MA's widow. MHCO Comment: This decision offers useful guidance on succession disputes arising out of property held in the names of multiple wives of a common husband under the Indian Succession Act, 1925. The Court's central holding that property registered in the name of a person is that person's property in the eyes of the law, irrespective of who funded the purchase (absent a proven case of benami)  reaffirms settled principles of ownership and cautions against conflating source-of-funds with title. Equally significant is the Court's demonstration of how Sections 33, 35 and 38 of the ISA interact and must be applied sequentially, and separately, wherever succession opens up more than once within the same family (here, on the deaths of Filomina, MA and Shyam Bai in turn), rather than being collapsed into a single, composite application of Section 33 to the family's property as a whole. The decision will be of particular relevance in estate planning and succession litigation involving Christian families with blended households, where property is often held jointly in the names of multiple spouses, and underscores the importance of tracing title and the chain of succession event-by-event rather than treating the ultimate distribution as a single-step exercise.   By: Ms. Purvi Asher, Partner Ms. Ananya Sakpal, Associate Disclaimer: This legal update is intended for general information purposes only and does not constitute legal advice. Readers are advised to seek specific legal advice before acting upon any information contained herein.
Litigation
LITIGATION UPDATE | BOMBAY HC | PROSPECTIVE FSI CANNOT DELAY DEEMED CONVEYANCE
Recently, the Bombay High Court in the case of Ariisto Realtors Private Limited v. District Deputy Registrar, Co-operative Societies, reaffirmed the position that deemed conveyance cannot be withheld indefinitely by the builder, to exploit additional FSI made available by a change in the FSI Regime. FACTS: The Petitioner, Aristo Realtor Private Limited (“Developer”) was granted the right to construct a building, "Ariisto Cloud”, under a Development Agreement dated 3 March 2010. Another building had been constructed on the same plot by a different developer, Kum Kum Apartments Co-Operative Housing Society Limited (“Kum Kum CHSL”).   Pursuant to disputes between the Developer, landowners and Kum Kum CHSL, a Tripartite Deed of Irrevocable Perpetual Lease dated 9 September 2011, was entered into by which all FSI over and above 2674.13 square meters, was to be utilised solely by the Developer. Though the future additional FSI and TDR was to exclusively belong to the landowners, the Developer was given the right to utilise the same by paying additional consideration of Rs.51,000/- per square meter to the landowners.   The Developer claimed that additional FSI of 841.16 square meters was made available in terms of Development Control and Promotion Regulations, 2034 (“DCPR, 2034”) on 8 May 2018 and filed an application dated 23 October 2024 with the Municipal Corporation for utilisation of additional FSI.   Meanwhile, the flat purchasers of Ariisto Cloud formed a Society in June 2016 and demanded conveyance of the land vide a letter dated 16 August 2024. Upon the Petitioner’s failure to convey the land om their favour, the Society filed a deemed conveyance application. The Society's first deemed-conveyance application (No. 179 of 2024) was rejected as premature by the Competent Authority on 10 March 2025, on the following grounds and the Society was given the liberty to reapply: The construction of the building was incomplete; The Petitioner was yet to consume unutilised FSI admeasuring 81.03 sq.m; and The Petitioner was entitled to utilize additional FSI by paying the landowners additional consideration at Rs.51,000/- per sq meter.   Following consent terms between the Society and the landowners on 16 June 2025, under which the landowners expressed willingness to convey the land to the Society, the Society filed a fresh Application (No. 56 of 2025), now asserting that construction was complete and only 3.25 square meters of FSI remained unconsumed. The Competent Authority allowed this application on 14 July 2025, granting a certificate of unilateral deemed conveyance in the Society's favour.   The developer challenged this order before the Bombay High Court by way of a writ petition.   Developer’s Case The Developer contended that the Development Agreement granted them the right to exercise an option to purchase any future FSI from the landowners by paying the additional consideration of Rs.51,000/- (Rupees Fifty-one thousand only) per square meter of such additional FSI/TDR to the Owners. Owing to DPCR 2034, the Developer was now entitled to a substantial FSI of 841.16 sq.mts. The Developer argued that the land could be conveyed to the Society only after such additional FSI had been exploited by it. Court’s Findings The Hon’ble Court held once a society has been formed, the Developer must convey the land to the Society within a period of 4 months, as prescribed by Rule 9 of the Maharashtra Ownership of Flats (Regulation of the Promotion of Construction, Sale, Management and Transfer) Rules, 1964 (“MOFA Rules”).  Relying on its earlier decision in Flagship Infrastructure Ltd. vs. The Competent Authority, the Court reaffirmed that the word period in Rule 9 denotes a fixed, definite block of time running from registration of the society and cannot be contractually extended by clauses permitting the promoter to retain title pending further construction or future FSI exploitation; such clauses are void to that extent. The Society was formed on 28 June 2016 and the Developer was under the statutory obligation to convey the land and building to the society within 4 months of 28 June 2016. The Court relied on its decision in Lakeview Developers vs. Eternia Co-operative Housing Society Limited, which held that once a developer has exhausted the sanctioned development potential and the obligation to convey has crystallised, any subsequent benefit accruing from an increase in FSI cannot be availed of by a developer who has failed to convey the property despite being under a legal obligation to do so. Any increase in FSI, that is available subsequent to the date on which conveyance ought to have taken place, belongs to the Society, and a defaulting developer cannot retrospectively claim a right to exploit it. MHCO Comment Builders must note that they cannot rely on a prospective increase in FSI, even where purportedly reserved by contract to defer or resist deemed conveyance once the society has been registered and the statutory period to initiate deemed conveyance has begun. By: Mr. Bhushan Shah, Partner Ms. Neha Lakshman, Associate Partner Disclaimer: This legal update is intended for general information purposes only and does not constitute legal advice. Readers are advised to seek specific legal advice before acting upon any information contained herein.
LIFE AT MHCO
Need Help? Chat with us