CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
UPDATES
PRACTICE AREAS
PEOPLE
News and Articles
Digital Personal Data Protection Act,
The Digital Personal Data Protection Act, 2023 Explained in Simple Terms
The Digital Personal Data Protection Act is India's principal legislation governing the processing of digital personal data. For businesses, the law changes how customer, employee, user and other personal information must be collected, used, stored and shared. The framework is built around a balance between individual privacy and lawful use of data. The Act was enacted in 2023, while the Digital Personal Data Protection Rules, 2025 provide the operational framework for several obligations. Importantly, implementation is phased, so businesses need to distinguish between provisions already in force and provisions scheduled to commence later.This guide explains the law in practical language, with particular attention to what businesses need to understand before reviewing their privacy policies, contracts, technology systems and internal processes. What Is the Digital Personal Data Protection Act, 2023? The Digital Personal Data Protection Act, 2023, commonly called the DPDP Act, is India's dedicated statutory framework for digital personal data protection. Parliament enacted the legislation on 11 August 2023. Its stated purpose is to regulate the processing of digital personal data while recognising both an individual's right to protect personal data and the need for organisations to process information for lawful purposes. In practical terms, the law asks businesses to answer several basic questions. Why are you collecting someone's personal data? Have you provided an appropriate notice? Do you have a lawful basis for processing it? Are you collecting more information than necessary? Is the information secure? Can the individual exercise their statutory rights? What happens when the purpose for collection ends? These questions sit at the centre of the new compliance framework. When Does the DPDP Act Apply? The Act primarily concerns digital personal data. It applies to processing within India where personal data is collected in digital form. It also covers information collected in non digital form and subsequently digitised. The law can also apply outside India where processing is connected with offering goods or services to Data Principals in India. This means a foreign company serving Indian customers may need to consider the Indian framework even if its headquarters, servers or parent company are located overseas. There are exclusions. Personal data processed by an individual for a personal or domestic purpose falls outside the Act. Certain publicly available personal data is also excluded in circumstances specified by Section 3. The important point for businesses is scope. A company should assess its actual processing activities rather than assuming the law applies only to technology companies. A manufacturer with an employee database, an online retailer with customer accounts and a professional services firm managing client contacts can all have relevant processing activities. The Three Main Players Under the DPDP Act The Act uses terminology which businesses need to understand. A Data Principal is the individual to whom personal data relates. For a child, the statutory framework also recognises the parent or lawful guardian in the relevant context. A Data Fiduciary is the organisation or person deciding the purpose and means of processing personal data. This is broadly comparable to the concept of a data controller under some international privacy regimes, although the legal frameworks are not identical. A Data Processor processes personal data on behalf of a Data Fiduciary. For example, an online retailer may determine why customer information is collected and how it is used. The retailer may engage a cloud provider or software company to process the information. The retailer can therefore be the Data Fiduciary while the external service provider acts as a Data Processor. The distinction matters because responsibility does not disappear simply because processing is outsourced. What Does “Processing” Mean? Processing is broader than simply collecting information. The Act covers operations such as collection, recording, organisation, storage, adaptation, retrieval, use, sharing, disclosure, transmission, dissemination, restriction, erasure and destruction of digital personal data. This broad definition has practical consequences. A business processes personal data when a customer creates an account. It also processes data when the information is stored in a cloud platform, shared with a payment provider, accessed by customer support staff or deleted after the account is closed. Businesses therefore need to examine the complete data lifecycle. Consent Under the DPDP Act Consent is one of the most important concepts in the Act. Where consent is relied upon, it must be free, specific, informed, unconditional and unambiguous. It must involve a clear affirmative action and relate to the specified purpose for which the information is being processed. This means businesses should reconsider vague consent mechanisms. A pre selected box or a general statement hidden within lengthy terms may not provide the same level of clarity as an appropriately designed consent process. The Rules add further requirements around notices and consent mechanisms. Businesses should also remember one important point: consent is not necessarily required for every processing activity. The Act recognises specified legitimate uses and other statutory grounds. The correct approach is to identify the legal basis for each significant processing activity. What Is a Privacy Notice? A privacy notice tells the Data Principal how their information will be handled. The DPDP framework requires businesses to provide relevant information concerning processing. The 2025 Rules add detail regarding the manner in which notices should be presented. A good notice should be clear enough for an ordinary user to understand. It should not merely reproduce technical or legal terminology. It should explain the purpose of processing, the information involved and how the individual can exercise relevant rights. More importantly, the notice should accurately reflect the organisation's actual practices. If a company says information is used only to provide a service but its marketing team later uses the same information for unrelated advertising, the organisation may create a significant compliance gap. Rights of Data Principals The DPDP Act gives individuals specific rights concerning their personal data. These include rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination. For businesses, these rights require operational processes. An organisation should know who receives a request, how the identity of the requester is verified, which department investigates it, how the response is prepared and how the action is recorded. This becomes particularly important for businesses handling large customer databases. A privacy policy may provide a contact address, but the organisation still needs an internal workflow capable of responding to legitimate requests.  What Happens When a Person Withdraws Consent? The Act provides individuals with the ability to withdraw consent. The withdrawal mechanism should be as easy as the mechanism through which consent was given. The consequences of withdrawal also need to be understood. If an individual withdraws consent, the business must assess whether another lawful basis permits continued processing. If not, relevant processing should cease and applicable erasure requirements should be considered. This is one reason consent management should be integrated with business systems rather than treated as a standalone legal document. Special Rules for Children's Data The DPDP Act gives children additional protection. A child is generally an individual who has not completed eighteen years of age. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian, subject to prescribed exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being. It further restricts tracking and behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. For educational technology companies, gaming platforms, children's applications and other services likely to be used by minors, these provisions require specific attention. Security Obligations Under the Act A business cannot comply merely by obtaining consent. The Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The 2025 Rules provide additional detail regarding security safeguards, including measures relating to organisational and technical controls. Businesses should therefore examine access controls, authentication, encryption where appropriate, monitoring, security testing, incident management and vendor security. Security should be proportionate to the nature and volume of personal data involved. A company holding millions of customer records will generally require a more mature security programme than a small business maintaining a limited customer database.  What Is a Personal Data Breach? The Act defines a personal data breach broadly. It includes unauthorised processing and accidental or unlawful disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data which compromises its confidentiality, integrity or availability. This means a breach is not necessarily a dramatic cyberattack. An employee sending a customer database to the wrong recipient, unauthorised access to an internal system or accidental disclosure of information can potentially create a data protection incident. Businesses therefore need an internal reporting and response mechanism. Legal, security and management teams should know how an incident is escalated and what information needs to be preserved. Data Retention and Erasure The DPDP framework also addresses what happens when personal data is no longer required. Businesses should not treat every piece of information as an asset which must be stored indefinitely. Retention should be linked to the purpose for which the information was collected and any other legal requirement requiring continued retention. For example, a customer database may contain inactive accounts, old marketing records and information retained purely because no one has reviewed it. A proper retention schedule helps businesses identify information which should be removed. Deletion should also be considered across relevant systems, including third party platforms where applicable. Significant Data Fiduciaries The Act creates a special category known as a Significant Data Fiduciary. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as significant based on factors including the volume and sensitivity of personal data, risks to India's sovereignty and integrity, electoral democracy, security of the State, public order and other relevant considerations. Significant Data Fiduciaries have additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor and conducting specified assessments and audits. Large digital platforms and organisations processing significant volumes of sensitive information should therefore monitor whether this category becomes relevant to them. What Is the Data Protection Board of India? The DPDP Act establishes the Data Protection Board of India. The Board is intended to serve as the principal enforcement and adjudicatory body under the framework. The Government established the Board as a body corporate under Section 18. The Board's role includes dealing with contraventions and matters connected with enforcement of the Act. The framework also provides an appeal mechanism. The Telecom Disputes Settlement and Appellate Tribunal is identified as the Appellate Tribunal under the Act. For businesses, this means data protection is no longer simply a matter of internal corporate policy. There is a statutory enforcement structure behind the obligations. Penalties Under the DPDP Framework The financial consequences can be substantial. The Schedule to the Act provides for penalties of up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Certain breaches concerning notification of personal data breaches and children's data can attract penalties of up to ₹200 crore. Other specified breaches can attract penalties of up to ₹50 crore. These figures represent statutory maximums. They do not mean every breach results in the maximum penalty. The enforcement framework considers relevant circumstances when determining an appropriate penalty. Still, the potential exposure makes privacy governance a board level business concern for organisations handling substantial volumes of personal data. How the DPDP Rules, 2025 Fit Into the Framework? The Act establishes the legal framework. The Rules provide practical detail. The Government notified the Digital Personal Data Protection Rules, 2025 in November 2025. The Rules cover areas such as notice requirements, consent mechanisms, security safeguards, breach notifications, rights management, registration of Consent Managers and obligations relevant to Significant Data Fiduciaries. The Rules also provide a phased implementation period. This gives organisations time to adapt their systems. It does not mean businesses should wait until the final commencement date before starting their compliance work. Technology changes can take months. Contract revisions can take longer where multiple vendors or international group entities are involved. Understanding the Phased Commencement The DPDP Act does not become fully operational through a single commencement date. The Government's notification provides different commencement dates for different provisions. Sections 2, 18 to 26, 35 to 43 and specified parts of Section 44 commenced on 13 November 2025. Other provisions are scheduled to commence one year later, while the main operational provisions, including Sections 3 to 5 and Sections 7 to 17, are scheduled to commence eighteen months after 13 November 2025. This phased structure is important when writing internal compliance plans. A business should identify whether a requirement is currently operational, scheduled for commencement or already applicable through another existing law or sectoral regulation. Does the DPDP Act Replace Every Other Privacy Requirement? No. The DPDP framework needs to be read alongside applicable sectoral laws and regulations. Financial institutions, insurers, telecommunications companies, healthcare businesses and other regulated entities may have additional requirements concerning information security, outsourcing, technology systems and data management. The constitutional right to privacy also remains relevant. In Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the Supreme Court recognised privacy as a constitutionally protected right. The judgment remains an important part of India's broader privacy jurisprudence. Businesses should therefore avoid treating the DPDP Act as an isolated compliance exercise. What Should Businesses Do Now? The most useful starting point is a data inventory. A business should identify the personal data it collects, the purpose of collection, the systems in which it is stored, the people who can access it and the third parties who receive it. The organisation should then review its privacy notices and consent mechanisms. The next stage should involve vendor contracts. Cloud service providers, payroll companies, analytics platforms, customer relationship management systems and marketing providers can all form part of the data processing chain. Businesses should also establish a breach response procedure, a retention framework and a process for handling Data Principal requests. Finally, legal requirements should be mapped against actual technology. A privacy policy cannot protect a business if the application's underlying architecture collects or shares information in a different manner. Organisations handling substantial or complex data flows may also benefit from advice from top-rated data privacy lawyers, particularly where international transfers, children's data, technology vendors or regulatory investigations are involved.  Why DPDP Compliance Is Also a Commercial Issue Data protection affects more than regulatory risk. Investors may examine how a business acquired its customer database. Enterprise clients may ask for privacy warranties before signing a contract. Buyers conducting due diligence may review consent records, security incidents and vendor agreements before acquiring a company. A weak privacy framework can therefore create commercial friction. A mature data governance programme can make transactions easier because the business can demonstrate how personal information is collected, used, protected and deleted. This is especially relevant for companies planning international expansion. Businesses should also consider privacy when drafting technology contracts, employment documents and commercial agreements. A best corporate law firm can help integrate privacy obligations into wider corporate and contractual structures. Conclusion The Digital Personal Data Protection Act represents a significant development in India's privacy framework. It places greater responsibility on organisations which decide why and how digital personal data is processed. For businesses, the most important lesson is simple: privacy compliance should be built into operations rather than added after a problem occurs. Organisations should understand their data flows, establish appropriate legal bases for processing, provide meaningful notices, maintain suitable consent mechanisms, protect personal data, respect individual rights and establish procedures for breaches and deletion. The DPDP Rules, 2025 now provide much of the operational detail required to translate the Act into business practice. However, implementation is phased, so organisations should verify the commencement status of individual provisions before setting compliance deadlines. The official Digital Personal Data Protection Act, 2023 on India Code and DPDP Rules and official MeitY publications should remain the primary sources for checking the statutory text and current implementation position. Frequently Asked Questions (FAQs) Q1. What is the Digital Personal Data Protection Act, 2023? The Digital Personal Data Protection Act, 2023 is India's principal statutory framework for regulating the processing of digital personal data. It establishes obligations for Data Fiduciaries and rights for Data Principals, together with an enforcement mechanism and financial penalties. Q2. Who needs to comply with the DPDP Act? The Act can apply to organisations processing digital personal data in India and, in certain circumstances, organisations outside India offering goods or services to individuals in India. Q3. Is consent always required under the DPDP Act? No. Consent is one lawful basis for processing. The Act also recognises specified legitimate uses and other statutory circumstances. Businesses should assess the appropriate legal basis for each processing activity. Q4. What is a Data Fiduciary? A Data Fiduciary is an entity or person which determines the purpose and means of processing personal data. Q5. What rights do individuals have under the DPDP Act? Data Principals have rights relating to access to information, correction and erasure, grievance redressal and nomination, subject to the Act and applicable Rules. Q6. Does the DPDP Act protect children's data? Yes. Section 9 provides additional protection for children's personal data, including requirements concerning verifiable parental consent and restrictions on certain tracking, behavioural monitoring and targeted advertising activities. Q7. What is the maximum penalty under the DPDP Act? The highest scheduled penalty is up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Other contraventions have separate statutory maximums. Q8. Does the DPDP Act apply to foreign companies? It can apply where processing outside India is connected with offering goods or services to Data Principals in India. Q9. What is a Significant Data Fiduciary? It is a Data Fiduciary or class of Data Fiduciaries notified by the Central Government based on specified factors. Such entities face additional governance, audit and accountability obligations. Q10. When should businesses begin preparing for DPDP compliance? Businesses should begin preparation before the relevant provisions become operational. Data mapping, contract reviews, system changes and consent mechanisms can require considerable time.
Data Protection Laws,
Data Protection Laws in India: A Complete Guide for Businesses
Businesses operating in India increasingly depend on personal data for customer acquisition, employee management, payments, marketing, analytics and digital services. As a result, Data Protection Laws have become an important part of corporate compliance rather than a matter limited to the information technology department. India now has a dedicated statutory framework through the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The framework is being introduced through a phased commencement structure, making it important for businesses to understand both the law and its implementation timeline. This guide explains the present Indian data protection framework, the obligations businesses need to prepare for, the continuing relevance of the earlier legal regime, sector specific requirements, penalties, children's data, cross border processing and practical steps for compliance. Top Four Ranking Resources for “Data Protection Laws” Search results for this subject are changing quickly because India's new privacy regime is moving from legislation towards implementation. The following resources provide useful coverage of the current framework: Data Protection Laws and Regulations 2026: India Data Protected: India Data protection and cybersecurity laws in India Data Protection Laws in India: Complete Guide for Businesses The leading material generally covers the DPDP Act, scope, consent, individual rights, security, breach notification, children's data, cross border transfers and enforcement. A stronger business focused approach also needs to explain the phased commencement of the new regime and how organisations should manage the transition from the older framework. How India's Data Protection Framework Has Evolved India's privacy framework did not begin with the DPDP Act. For many years, protection of personal information was spread across the Information Technology Act, 2000, the Information Technology Rules, contractual principles, sectoral regulations and constitutional jurisprudence. Section 43A of the Information Technology Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 were particularly relevant to businesses handling sensitive personal data. The framework required reasonable security practices and addressed matters such as privacy policies, consent and disclosure of sensitive information. The constitutional position also changed significantly with the Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. A nine Judge Bench recognised privacy as a constitutionally protected right linked to liberty, dignity and autonomy. The Court also held privacy is not absolute and restrictions must satisfy constitutional requirements including legality, legitimate need and proportionality. The DPDP Act represents a major shift because it establishes a dedicated statutory framework for digital personal data. What Are the Main Data Protection Laws in India? The principal modern framework is the Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025. The DPDP Act received Presidential assent on 11 August 2023. It establishes the concepts of Data Fiduciaries and Data Principals and regulates the processing of digital personal data. Its provisions address lawful processing, notice, consent, legitimate uses, security safeguards, children's data, Significant Data Fiduciaries, individual rights, cross border processing and enforcement. The Government notified the DPDP Rules, 2025 in November 2025. The Rules provide operational detail for several obligations under the Act. They also introduce a phased implementation timetable rather than making every obligation effective on the same day. This distinction is important. A business should not describe the entire DPDP framework as immediately enforceable in the same way across all provisions. Understanding the DPDP Act's Phased Implementation The commencement notification dated 13 November 2025 divides the Act into different implementation stages. Several institutional provisions, including provisions relating to the Data Protection Board, commenced on 13 November 2025. Certain other provisions are scheduled to commence one year later. The core provisions dealing with processing, notice, consent, general obligations, children's data, Significant Data Fiduciaries, individual rights, exemptions and penalties are scheduled to commence eighteen months after 13 November 2025, which falls on 13 May 2027. The Rules follow a similar phased structure. Rules 1, 2 and 17 to 21 commenced upon publication. Rule 4 is scheduled one year after publication, while Rules 3, 5 to 16, 22 and 23 are scheduled eighteen months after publication. For businesses, the practical lesson is simple. Preparation should begin before the compliance deadline. Privacy notices, contracts, consent architecture, data inventories and technical controls cannot always be redesigned immediately. Who Is Covered by the DPDP Act? The Act applies to the processing of digital personal data within India where the data is collected in digital form or is digitised subsequently. It can also apply to processing outside India where such processing is connected with offering goods or services to Data Principals in India. This makes the law relevant to foreign businesses serving Indian customers, even where the technical infrastructure or parent organisation is located overseas. The key regulated entity is the Data Fiduciary. In simple terms, this is the person or organisation which determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary. Businesses therefore need to consider their own processing activities as well as the external vendors handling data on their behalf. What Counts as Personal Data? The DPDP Act adopts a broad concept of personal data. It concerns data about an individual who is identifiable by or in relation to such data. Examples can include a person's name, telephone number, email address, identification information, account details, employment information, customer records and other information connected with an identifiable individual. Importantly, the Act focuses on digital personal data. A business should therefore examine how paper records become digitised and subsequently enter its information systems. Businesses should not limit their assessment to customer databases. Employee records, recruitment platforms, vendor contacts, marketing databases, website enquiries and customer support systems can also contain personal data. Consent and Lawful Processing Consent is a central part of the DPDP framework. Where consent is relied upon, the Act requires it to be free, specific, informed and unambiguous, with a clear affirmative action. A Data Principal must also be able to withdraw consent. The processing undertaken following consent must remain connected with the purpose for which consent was obtained. This has practical consequences for website forms and applications. A statement buried in lengthy terms and conditions may not provide a sound basis for a consent based processing activity. Businesses should instead consider whether their notice clearly explains the relevant purpose and whether the user can understand what they are agreeing to. The Act also recognises certain legitimate uses. Therefore, consent is not the only possible ground for every processing activity. Businesses should identify the appropriate legal basis rather than automatically seeking consent for everything. Notice Requirements for Businesses Transparency is a fundamental part of the framework. The DPDP Act requires notice to be given in connection with the processing of personal data. The Rules provide further detail concerning the form and content of notices. A good privacy notice should be understandable to its intended audience. It should explain what personal data is being processed, the purpose of processing and the relevant rights and mechanisms available to the Data Principal. The notice should also match reality. If a privacy policy says information is collected only for account administration but the business subsequently uses the same information for targeted marketing, the organisation may create a mismatch between its published position and actual processing. Rights of Data Principals Individuals are referred to as Data Principals under the DPDP Act. The framework provides rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination. Businesses therefore need operational processes for responding to rights requests. It is not enough to place an email address in a privacy policy. The organisation should determine who receives requests, how identity is verified, how requests are logged, which internal teams respond and how deadlines are monitored. A central register of privacy requests can help create an audit trail. Children's Data Receives Additional Protection The DPDP Act imposes additional obligations concerning children's personal data. A child is generally defined as an individual who has not completed eighteen years of age. The Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being. It prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. Businesses operating educational platforms, gaming services, children's applications and other products likely to be used by minors therefore require specific compliance controls rather than relying solely on a general privacy policy. Security Safeguards and Data Breaches Security is not merely a technical consideration under the DPDP framework. Section 8 requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. The Rules provide further requirements concerning security safeguards and breach response. A mature compliance programme should therefore connect legal requirements with actual security controls. Access management, encryption where appropriate, authentication, monitoring, vulnerability management, incident response and vendor security should be assessed according to the nature and volume of data processed. The organisation should also have a documented breach response procedure. A legal team should not discover the incident for the first time after a technical team has already taken external action. Data Retention and Erasure Data protection is not only about how information is collected. It also concerns how long information remains in an organisation's systems. The DPDP framework places importance on erasure once the purpose for which personal data was processed is fulfilled, unless retention is necessary for a legal purpose. Businesses should therefore create retention schedules. For example, information collected for a temporary marketing campaign should not necessarily remain indefinitely in a CRM system. Former employee information, customer accounts and inactive user profiles may also require separate retention assessments. Data deletion should extend beyond the main production database where appropriate. Backups, archives and third party systems should also be considered. Significant Data Fiduciaries The DPDP Act creates a separate category known as a Significant Data Fiduciary. The Government may notify an organisation or class of organisations as Significant Data Fiduciaries based on factors specified in the Act, including the volume and sensitivity of personal data processed, risk to the sovereignty and integrity of India, risk to electoral democracy, security of the State, public order and other relevant factors. Significant Data Fiduciaries face additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor and undertaking specified assessments and audits. Businesses likely to fall within this category should not wait for notification before building suitable governance structures. Cross Border Data Processing International businesses should pay particular attention to Section 16 of the DPDP Act and the Rules concerning transfers and availability of personal data outside India. The Act permits the Central Government to restrict transfers of personal data outside India to notified countries or territories. The Rules also contemplate restrictions concerning making personal data available to foreign States or entities under their control. This does not mean every business must automatically store all personal data exclusively in India. Instead, organisations should understand the applicable restrictions, their infrastructure arrangements, group data flows and vendor locations. Cloud hosting agreements and intra group data sharing arrangements deserve particular attention where personal data moves across jurisdictions. Sector Specific Regulations Still Matter The DPDP Act does not eliminate every other regulatory obligation affecting personal information. Businesses in financial services, insurance, securities, healthcare, telecommunications and other regulated sectors may remain subject to sector specific requirements. For example, regulatory directions issued by authorities such as the Reserve Bank of India, Securities and Exchange Board of India and Insurance Regulatory and Development Authority of India can impose additional requirements concerning data security, outsourcing, technology governance and information handling. This creates a layered compliance environment. A fintech business should therefore assess both the DPDP framework and applicable financial sector requirements rather than treating the DPDP Act as its only privacy obligation. What Happens to the Earlier IT Act Framework? The transition from the older framework needs careful attention. Section 44(2) of the DPDP Act provides for omission of Section 43A of the Information Technology Act. However, this particular amendment has a later commencement date under the phased notification. It is scheduled to take effect on 13 May 2027. This is an important distinction for businesses preparing compliance policies in 2026. The older provisions should not simply be treated as having disappeared immediately after enactment of the DPDP Act. Organisations should assess the framework applicable to their activities during the transition period. Penalties for Non Compliance The DPDP Act provides for substantial financial penalties. The Schedule permits penalties of up to ₹250 crore for failure to take reasonable security safeguards, up to ₹200 crore for certain breach notification failures, and up to ₹200 crore for breaches concerning children's data. Significant Data Fiduciary failures can attract penalties of up to ₹150 crore. Other breaches can attract penalties of up to ₹50 crore. These figures represent statutory maximums rather than automatic fines. Section 33 requires the Board to consider factors including the nature, gravity and duration of the breach, the type of data affected, whether the breach is repetitive, any gain or loss involved, mitigation measures, proportionality and the likely impact of the penalty. The financial exposure is therefore significant, but the broader commercial consequences can also include customer disputes, contractual claims, investor concerns and reputational damage. How Businesses Can Prepare for Data Protection Compliance The first practical step is a data mapping exercise. A business should identify what personal data it collects, where it comes from, why it is processed, where it is stored, who can access it and which third parties receive it. The next step is to compare actual practices with privacy notices and contractual documents.Businesses should then review their consent mechanisms, retention practices, security controls, vendor agreements and incident response procedures. Contracts with Data Processors deserve particular attention. Organisations should establish clear responsibilities concerning security, confidentiality, breach reporting, assistance with rights requests and deletion or return of information.Businesses should also establish internal ownership. Privacy compliance usually involves legal, information technology, cybersecurity, human resources, marketing, product and procurement teams. Without defined responsibility, compliance gaps can remain unnoticed. For organisations requiring specialist advice, engaging best data privacy law firms may be appropriate where processing involves sensitive commercial operations, large datasets, international transfers or significant regulatory exposure. Why Data Protection Should Be Treated as a Business Function Privacy compliance can influence more than regulatory risk. A company preparing for investment may face questions concerning its customer database, employee information, technology vendors and international data flows. A company entering an enterprise contract may be required to provide detailed privacy assurances. A business preparing for an acquisition may need to demonstrate how its data was collected and whether its processing practices comply with applicable law. Privacy therefore has a direct connection with corporate value. A well organised data governance programme can make due diligence easier, reduce operational uncertainty and give management a clearer understanding of one of its most important business assets. A passionate corporate lawyer can also help connect privacy requirements with corporate contracts, employment documentation, technology agreements, intellectual property arrangements and broader governance requirements. Conclusion India's data protection framework has moved from a fragmented model towards a dedicated statutory regime. The DPDP Act, 2023 and DPDP Rules, 2025 provide the foundation for regulating digital personal data while recognising individual rights and placing accountability on organisations processing personal information.For businesses, compliance should not begin with rewriting a privacy policy. It should begin with understanding the data itself. Organisations should know what information they hold, why they collect it, how they use it, where it travels, which vendors process it and when it should be removed. They should also understand how the rules apply to children, international operations, security incidents and Significant Data Fiduciaries. The phased implementation of the DPDP framework gives businesses time to prepare. It does not remove the need for preparation. A sound privacy programme should ultimately connect legal requirements with actual business operations. When privacy notices, contracts, technology systems and internal processes all tell the same story, compliance becomes considerably more defensible. Frequently Asked Questions Q1. What are the main Data Protection Laws in India? The principal statutory framework for digital personal data is the Digital Personal Data Protection Act, 2023, together with the Digital Personal Data Protection Rules, 2025. The constitutional right to privacy and sector specific regulatory requirements also form part of India's wider privacy landscape. Q2. Is the DPDP Act currently applicable to all businesses? The Act has commenced in phases. Several institutional provisions came into force on 13 November 2025, while the principal operational provisions concerning processing and many business obligations are scheduled for 13 May 2027. Businesses should therefore distinguish between enacted provisions and provisions currently in force. Q3. What is a Data Fiduciary? A Data Fiduciary is an individual or organisation which determines the purpose and means of processing personal data under the DPDP framework. Q4. Is consent mandatory for every type of personal data processing? No. Consent is an important legal basis, but the DPDP Act also recognises specified legitimate uses. Businesses should determine the appropriate legal basis for each processing activity rather than assuming consent is always required. Q5. Does the DPDP Act apply to foreign companies? It can. The Act applies to processing outside India where the processing is connected with offering goods or services to Data Principals in India. Q6. What rights do individuals have under the DPDP Act? Data Principals have rights including access to information about their personal data, correction and erasure, grievance redressal and nomination, subject to the statutory framework. Q7. What is the maximum penalty under the DPDP Act? The highest scheduled penalty can extend to ₹250 crore for failure to take reasonable security safeguards. Other specified contraventions carry separate maximum penalties. The actual amount is determined following the statutory process and relevant factors. Q8. Does India have a separate law for children's personal data? The DPDP Act provides specific protections for children's personal data under Section 9. These include parental consent requirements and restrictions concerning detrimental processing, tracking, behavioural monitoring and targeted advertising, subject to prescribed exemptions. Q9. Do businesses need a Data Protection Officer? Not every organisation automatically needs a Data Protection Officer under the same requirements. Additional obligations apply to Significant Data Fiduciaries, including the appointment of a Data Protection Officer based in India. Businesses should assess whether they fall within the relevant category. Q10. What should a business do before the main DPDP obligations become effective? Businesses should map personal data, review notices and consent mechanisms, assess vendor contracts, establish retention policies, strengthen security controls, prepare breach response procedures and create processes for handling Data Principal rights.  
Children's Data Consent,
Legal Risks for Businesses Processing Children's Data Without Proper Consent
Businesses increasingly collect information from children through educational platforms, gaming applications, social networks, healthcare services, e commerce platforms and other digital products. As this activity grows, Children's Data Consent has become a significant legal and compliance issue in India. Under the Digital Personal Data Protection Act, 2023, businesses processing a child's personal data must obtain verifiable consent from a parent or lawful guardian before processing, subject to prescribed exemptions. The law also imposes separate restrictions on tracking, behavioural monitoring and targeted advertising directed at children.For businesses, the issue is not simply whether a consent box exists. The real question is whether consent was obtained from the right person, in a verifiable manner, before processing began, and whether the organisation's subsequent activities remain within the permitted legal framework. Top Four Search Results for “Children's Data Consent” Search results for this emerging legal topic vary considerably because the Indian DPDP framework is still being implemented. The most relevant results identified during the research include specialist explanations of Section 9 and the parental consent mechanism, alongside academic and professional commentary. DPDP Act India: Section 9, Processing of Children's Data DPDP Reference Hub: Children's Data and Verifiable Consent NMIMS Law Review: Parental Consent and the DPDP Rules CheckDPDP: Verifiable Parental Consent under the DPDP Act The stronger content opportunity lies in moving beyond a simple explanation of parental consent. Businesses also need to understand the consequences of invalid consent, the distinction between consent and permission for specific processing activities, vendor exposure, security obligations, retention issues and the interaction between the Act and the notified Rules. What the DPDP Act Requires When Businesses Process Children's Data? Section 9 of the DPDP Act creates a special framework for processing personal data belonging to children. The Act defines a child as an individual who has not completed eighteen years of age. This threshold is important for Indian businesses because it is broader than the age threshold used in some other major privacy regimes. Before processing a child's personal data, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. The requirement is not limited to particularly sensitive information. It applies to personal data of a child, subject to the exemptions created under the statutory framework. Section 9 also contains two important restrictions beyond consent. A Data Fiduciary must not process children's personal data in a manner likely to cause a detrimental effect on the child's well being. It must also not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, subject to prescribed exemptions. This means parental consent should never be treated as a universal permission slip. A parent providing consent does not automatically authorise every form of data use. Why Invalid Children's Data Consent Creates Legal Exposure? The first risk arises when a business processes children's personal data without obtaining the required parental consent. Consider a learning application which allows a child to create an account independently. If the application begins collecting identifiable information before the required consent process is completed, the business may have difficulty demonstrating compliance with Section 9. The problem can become more serious where the business has no reliable record of how consent was obtained. A database entry stating "parent consent received" may not be sufficient if the organisation cannot demonstrate the verification process, date, relevant account and scope of the consent. A defensible consent system therefore requires more than an affirmative action by a user. It requires an auditable process. Verifiable Parental Consent Is Different from Ordinary Consent The DPDP Rules, 2025 provide the mechanism for verifiable parental consent. Rule 10 requires a Data Fiduciary to adopt appropriate technical and organisational measures to obtain verifiable consent from the parent before processing a child's personal data. The business must also exercise due diligence to establish whether the person identifying themselves as the parent is an identifiable adult. Rule 10 permits verification by reference to reliable identity and age information already available with the Data Fiduciary, or information voluntarily provided by the individual, including information made available through a virtual token issued by an authorised entity. This approach creates an important compliance distinction. A business cannot simply assume a person is a parent because the person has clicked "I am the parent". The organisation needs a reasonable and documented method for satisfying the statutory verification requirement. At the same time, the Rules do not require businesses to collect every conceivable identity document. A proportionate system should be designed around the statutory requirements, the nature of the service and the information already available to the organisation. Consent Does Not Permit Behavioural Tracking of Children One of the most important legal risks arises when businesses assume parental consent permits behavioural monitoring. Section 9 separately restricts tracking and behavioural monitoring of children. This means a business cannot necessarily justify behavioural profiling merely because a parent has approved the child's account. For example, an application might collect information about how long a child watches particular videos, which games they play, what educational content they select and how frequently they return. If this information is used to construct behavioural profiles, the business needs to assess whether the activity falls within the statutory prohibition or an applicable exemption. This is particularly relevant for advertising technology and recommendation systems. Product teams should therefore review analytics software, cookies, software development kits, pixels and similar technologies rather than focusing only on information deliberately collected through registration forms. Targeted Advertising Creates a Separate Compliance Risk Section 9 also restricts targeted advertising directed at children. The restriction matters because many digital businesses depend upon advertising systems operated by third party platforms. A business may not directly select an advertisement for a particular child. Its application may instead send user information to an advertising network which determines the advertisements displayed. From a compliance perspective, the technical architecture still needs careful examination. Businesses should understand what information is transferred to advertising providers, whether a child can be identified, whether the system creates profiles and whether advertising technology can distinguish children from adult users. The commercial arrangement with the advertising provider should also be reviewed alongside the technical configuration. Processing Without Consent Can Create Contractual and Commercial Problems Privacy non compliance is not confined to regulatory exposure. Businesses increasingly make representations about data protection in investment documents, customer contracts, vendor agreements and enterprise procurement questionnaires. A material privacy failure may therefore create contractual concerns if the organisation has represented compliance with applicable law. Investor due diligence can also expose weaknesses in children's data practices. An investor examining an education technology company, gaming platform or children's application may ask how age verification works, whether parental consent is documented, which vendors process children's data and whether the organisation has experienced privacy incidents. Poor documentation can therefore affect the commercial value of a business even before a regulatory authority becomes involved. Third Party Vendors Can Multiply the Risk Many businesses do not process children's data entirely within their own systems. Cloud infrastructure providers, analytics companies, customer relationship management platforms, messaging providers, advertising networks and outsourced support teams may all receive personal information. A business remains responsible for understanding these data flows.Suppose an application has a compliant parental consent mechanism but an analytics tool begins collecting information before consent is recorded. The organisation may still face a compliance problem. This is why vendor due diligence should form part of children's privacy governance. Contracts should address permitted processing, security safeguards, confidentiality, incident reporting, assistance with regulatory obligations and deletion or return of information where appropriate. Businesses reviewing their broader privacy and data protection laws framework should also map every third party receiving children's personal data. Excessive Data Collection Can Create an Additional Risk Consent does not make unnecessary collection appropriate. Businesses sometimes collect extensive information because it may become useful later. For children's services, this approach creates unnecessary privacy exposure. A business should consider whether each data field is genuinely required for the stated service.An educational platform may need a student's age group to provide appropriate learning material. It may not need precise location information. A gaming application may require an account identifier but have no genuine need for access to a child's contact list. Data minimisation reduces the consequences of a security incident and makes the organisation's compliance position easier to demonstrate. Security Failures Can Compound Consent Problems A business can obtain valid parental consent and still face legal exposure if children's personal data is inadequately protected. The DPDP Act imposes obligations on Data Fiduciaries concerning reasonable security safeguards. The Act also provides significant financial penalties for specified contraventions. A consent process therefore needs to sit alongside appropriate access controls, authentication, monitoring, secure storage and incident response procedures. Internal access should also be limited. Employees should receive access based on their actual responsibilities rather than unrestricted access to children's information. Security testing should cover both the application and the systems supporting the consent process. Poor Consent Records Can Become a Serious Evidentiary Problem One of the most overlooked risks is the inability to prove compliance. A business should be able to establish when consent was obtained, who provided it, how the person was verified and what processing was covered. The organisation should also understand how consent withdrawal is handled. If a parent withdraws consent, the business needs a process for responding appropriately and updating relevant systems. Simply changing a status field in one database may not be sufficient if children's information remains accessible through other systems or third party platforms. Good record keeping therefore has both legal and operational value. Businesses Need to Consider the DPDP Implementation Timeline The DPDP Act and Rules are being brought into force in stages. The Central Government notified the DPDP Rules, 2025 on 13 November 2025. The Rules provide different commencement periods for different provisions. Rules 3, 5 to 16, 22 and 23 are scheduled to commence eighteen months after publication. The corresponding commencement notification under the Act similarly places Sections 3 to 5, Sections 6 to 17 and several related provisions eighteen months after 13 November 2025. Section 9 therefore falls within the later commencement group. Businesses should not interpret the phased timeline as a reason to delay preparation. Rebuilding account registration, age assurance, parental verification, analytics and advertising architecture can take considerable time. Early preparation is particularly important for platforms with a large existing child user base. What Businesses Should Do Before Processing Children's Data? The starting point should be a detailed data mapping exercise. The business should identify where children's personal data enters the organisation, where it is stored, who can access it, which vendors receive it and how long it is retained. The next step should be an assessment of the registration and consent journey. The organisation should determine whether it can identify child users appropriately, whether parental verification works reliably and whether processing begins only after the required consent has been obtained.Technology should then be reviewed. Analytics, advertising, recommendation engines, cookies and software development kits should all be assessed. The objective is to ensure the actual technology reflects the organisation's legal position. Businesses should also review contracts with processors and vendors. Finally, the organisation should establish internal responsibility. Legal, product, engineering, marketing, security and compliance teams should understand their respective responsibilities. For organisations dealing with complex privacy questions, obtaining advice from a best corporate lawyer can help integrate data protection requirements with commercial contracts, technology arrangements and broader corporate governance. Exemptions Need Careful Legal Assessment The DPDP framework does provide exemptions for specified classes of Data Fiduciaries and purposes. The final Rules contain a Fourth Schedule setting out certain classes and purposes for which specified child related obligations do not apply, subject to conditions. Examples include certain healthcare activities, educational activities and child safety functions. Businesses should not assume an exemption applies simply because their service falls within a broad industry category. The conditions attached to an exemption matter. An educational institution, for example, may have a prescribed basis for tracking or behavioural monitoring when the activity is restricted to educational activities or the safety of enrolled children. The same principle cannot automatically be extended to commercial profiling for unrelated purposes. The safest approach is to document the precise statutory basis for any exemption relied upon. Common Mistakes Businesses Should Avoid A business may believe it is compliant because its privacy policy refers to children. This is insufficient if the underlying consent mechanism does not meet the statutory requirements. Another common mistake is relying entirely on self declared age information. Businesses also overlook third party analytics and advertising tools. A platform may appear compliant at the user interface level while collecting information through embedded technologies in the background. Another problem is treating parental consent as permission for all subsequent processing. Section 9 contains separate restrictions, including restrictions on tracking, behavioural monitoring and targeted advertising. Finally, businesses sometimes wait until enforcement becomes imminent before reviewing their systems. Privacy compliance is considerably easier when considered during product development rather than retrofitted into an established platform. Conclusion Processing children's personal data without proper consent is not simply a privacy policy issue. It can create regulatory, contractual, operational, security and commercial risks for businesses operating in India.The DPDP framework places children in a specially protected category. Businesses need verifiable parental consent before processing children's personal data where Section 9 applies. They must also consider separate restrictions concerning detrimental effects on well being, tracking, behavioural monitoring and targeted advertising. The strongest compliance approach begins with understanding the data flow. Businesses should know what they collect, why they collect it, how parental consent is verified, where the information goes, who can access it and when it should be deleted. Most importantly, legal compliance should match the technology in use. A carefully drafted policy cannot protect a business if its application behaves differently from the policy. The official Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 should remain the primary references when assessing current obligations and commencement dates. Frequently Asked Questions (FAQs) Q1. What is Children's Data Consent under Indian law? It refers to the verifiable consent of a parent or lawful guardian required before a Data Fiduciary processes personal data belonging to a child, subject to applicable exemptions under the DPDP framework. Q2. Who is considered a child under the DPDP Act? The DPDP Act defines a child as an individual who has not completed eighteen years of age. The Central Government may notify a lower age for specified circumstances where the statutory conditions are satisfied. Q3. Is a child's own consent sufficient? No. Where Section 9 applies, the Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing the child's personal data. Q4. What does verifiable parental consent mean? Rule 10 requires appropriate technical and organisational measures and due diligence to establish whether the individual identifying themselves as the parent is an identifiable adult. Verification may rely on reliable information already held by the Data Fiduciary or information voluntarily provided through specified mechanisms. Q5. Does parental consent allow targeted advertising to children? No. Section 9 separately prohibits targeted advertising directed at children, subject to prescribed exemptions. Parental consent should not be treated as permission to disregard this restriction. Q6. Can businesses track children if parents have given consent? Businesses must separately examine the prohibition on tracking and behavioural monitoring under Section 9. Consent does not automatically override this statutory restriction. Prescribed exemptions may apply in limited circumstances. Q7. What happens if a business processes children's data without proper consent? The business may face regulatory consequences under the DPDP framework, alongside contractual, commercial, reputational and investor due diligence risks. The applicable consequences depend on the nature and circumstances of the contravention. Q8. Can schools and healthcare providers rely on exemptions? Certain exemptions exist under the Fourth Schedule, but they are limited and conditional. A business or institution should establish the exact statutory basis and conditions before relying upon an exemption. Q9. When should businesses begin preparing for children's data compliance? Businesses should begin preparation before the relevant provisions become operational. Consent architecture, age assurance, vendor arrangements and technology controls can require substantial redesign, particularly for platforms with a large existing user base.  
Data Privacy Compliance,
Data Privacy Compliance for Apps and Websites Used by Children in India
Children increasingly use mobile applications and websites for education, gaming, entertainment, healthcare, shopping and communication. For businesses operating these platforms, Data Privacy Compliance is becoming a product design issue as much as a legal requirement. India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 introduce specific safeguards for children's personal data, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. For an app or website used by children, privacy compliance cannot be reduced to a privacy policy or consent button. Businesses need to understand what data they collect, how they identify child users, how parental consent is verified, which vendors receive the information and how the data is eventually deleted. What Data Privacy Compliance Means for Children's Apps and Websites? Data privacy compliance refers to the legal, organisational and technical measures used by a business to collect, use, store, disclose and delete personal data in accordance with applicable law. For children's platforms, the compliance burden becomes more specific because Indian law gives children enhanced protection.The DPDP Act defines a child as an individual who has not completed eighteen years of age. This is significant for businesses accustomed to international privacy frameworks, where the age threshold for children's consent may be lower. A platform serving teenagers in India therefore needs to consider the Indian threshold when designing its privacy controls. The legal framework is built around the concept of a Data Fiduciary. Broadly, this is the organisation deciding why and how personal data is processed. An app operator, website owner or education platform may fall within this role even when technical processing is performed by third party service providers. The organisation remains responsible for understanding its data processing activities and implementing appropriate safeguards. Why Children's Data Requires a Different Compliance Approach? Children may have a different understanding of privacy risks and may be less capable of assessing the long term consequences of sharing personal information. An application may collect a child's name, age, photograph, location, device information, educational records, voice recordings or behavioural information.Some of these details may appear harmless when considered individually. Their combination can create a much more detailed picture of a child. For example, an educational application may know a student's name, school, learning performance, location and usage patterns. A gaming platform may collect information about play behaviour and interaction patterns. A children's social platform may receive photographs, messages and information about social relationships. Businesses should therefore examine the complete data environment rather than reviewing individual data fields in isolation. What Does the DPDP Act Say About Children's Personal Data? Section 9 of the DPDP Act contains specific provisions concerning processing of personal data belonging to children. Before processing such data, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian in the prescribed manner. The provision also prevents processing likely to cause a detrimental effect on a child's well being. The Act further prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This distinction is important. Parental consent is not a blanket permission for every form of processing. Suppose a parent approves an account for an educational application. The business cannot automatically assume the approval permits behavioural profiling or targeted advertising. Each processing activity still needs to be assessed against the statutory restrictions and applicable exemptions. Businesses should therefore design their privacy architecture around the complete lifecycle of children's data. Understanding Verifiable Parental Consent A major compliance issue is the difference between ordinary consent and verifiable parental consent. A child clicking an acceptance button does not satisfy the statutory requirement where parental consent is required. The business needs a mechanism capable of establishing the identity and adult status of the person providing consent as the parent or lawful guardian. Rule 10 of the DPDP Rules, 2025 sets out requirements concerning verifiable consent. It requires Data Fiduciaries to adopt appropriate technical and organisational measures and exercise due diligence to establish whether the individual identifying themselves as a parent is an identifiable adult. The Rules contemplate reliance on reliable identity and age information already available with the Data Fiduciary, as well as information voluntarily provided by the parent or qualifying virtual tokens. This gives businesses some flexibility in designing their consent systems. It does not, however, mean every verification method will automatically be sufficient. The business needs to assess whether its process genuinely supports the statutory requirement and whether the information collected for verification is itself handled responsibly. How Apps Should Approach Age Assurance Age assurance is one of the practical challenges for child focused platforms. An application may ask a user to enter their date of birth. Yet a simple self declaration may not establish whether the information is accurate. Businesses therefore need to assess the nature of their service, the risks associated with the data being collected and the appropriate method for identifying child users. The objective should not be indiscriminate collection of identity documents. Collecting excessive information merely to prove age can create another privacy risk. A well designed approach should consider proportionality, data minimisation and security alongside the need for reliable age assurance. For some platforms, age information may already be available through a verified parent account. For others, a separate parental verification process may be necessary. The correct approach will depend on the service, user journey and applicable legal requirements. Privacy Notices Need to Be Designed for Real Users A privacy notice is often treated as a legal document placed at the bottom of a website. For children's services, this approach is unlikely to be sufficient from a practical compliance perspective. The DPDP framework places emphasis on clear information concerning personal data and the purpose for processing. The Rules also establish requirements concerning notices and consent. Businesses should therefore consider how the privacy information appears during registration, parental verification and subsequent use of the service. The parent should be able to understand what information is collected, why it is needed and how it will be used.The notice should also correspond with the actual technology. If an application says it collects information only to provide educational services but embedded technologies collect additional behavioural information, the organisation may create a significant compliance gap. Tracking and Behavioural Monitoring Need Particular Attention Children's applications often rely on analytics. Analytics can help businesses understand which features users prefer, where users leave an application and how the service performs. However, businesses need to distinguish between technical analytics and activities falling within the statutory restriction on tracking or behavioural monitoring of children. The same technology may have different privacy implications depending on how it operates. For example, collecting aggregated technical information for security or service reliability may differ from creating a persistent behavioural profile of an identifiable child for commercial purposes. Product and legal teams should therefore assess analytics tools individually. A privacy review should include software development kits, cookies, pixels, advertising technologies, crash reporting tools and other third party components embedded in the application. Targeted Advertising to Children Advertising is another significant area of risk. Section 9 specifically prohibits targeted advertising directed at children, subject to prescribed exemptions. Businesses should therefore examine whether advertising systems use information about child users to determine which advertisements they see. This assessment should not stop with the company's own advertising platform. Third party advertising networks may receive information through software integrated into an application or website. An organisation should know which third parties receive information, why they receive it and whether their processing is compatible with the business's obligations. Advertising contracts and technical configurations should therefore be reviewed together. Third Party Vendors Can Create Hidden Privacy Risks Children's apps rarely operate entirely on their own infrastructure. Cloud providers may host databases. Analytics providers may process usage information. Customer support platforms may receive account information. Payment service providers may process transaction details. Communication tools may handle emails, messages or notifications. Each relationship creates a potential data flow. Businesses should maintain a record of relevant vendors and understand the role each vendor plays. Contracts should address confidentiality, security, permitted processing, incident management, deletion and assistance with regulatory obligations where appropriate. The business should also know whether a vendor uses further service providers. This is where data protection rules should be considered alongside the actual technical architecture. Legal documentation should not exist separately from the way the application operates. Data Minimisation Should Start at Product Design One of the most effective ways to reduce privacy risk is to avoid collecting unnecessary information. Before introducing a new feature, the product team should ask a simple question: does this feature genuinely require the proposed personal data? A children's learning platform may not need a precise location to deliver a mathematics lesson. A gaming application may not need access to a contact list to provide gameplay. A website may not need a child's photograph simply because an optional profile feature is available. Reducing unnecessary collection limits exposure in the event of unauthorised access and makes compliance easier to manage. Privacy should therefore be considered during product development rather than added after the application has been launched. Security Safeguards Are Part of Privacy Compliance Privacy and security are related but distinct. Privacy determines whether personal data is collected and used appropriately. Security focuses on protecting the information from unauthorised access, alteration, disclosure or loss. For children's platforms, both areas require careful attention. The DPDP Act places obligations on Data Fiduciaries concerning reasonable security safeguards. The Act also provides significant financial penalties for specified contraventions. The Schedule includes a penalty of up to ₹200 crore for breach of obligations relating to children. Businesses should therefore consider access controls, secure authentication, encryption where appropriate, vulnerability management, monitoring, secure software development and incident response procedures. Internal access should also be restricted according to business need. A developer does not necessarily need access to a complete database containing children's personal information. Data Retention and Deletion Should Be Planned Early A common privacy weakness is indefinite retention. Businesses sometimes retain information because deleting it appears inconvenient or because the organisation may need it in the future. This approach can increase privacy and security exposure. For children's applications, retention should have a clear business and legal rationale. The organisation should understand what information is retained, where it is stored, who can access it and when it should be deleted or anonymised. Deletion should also extend to relevant systems where appropriate. Removing information from the primary database while retaining copies in other systems, backups or third party platforms may leave the business with an incomplete deletion process. A documented retention framework can help avoid this problem. The DPDP Rules Are Being Implemented in Phases Businesses should pay close attention to commencement dates. The DPDP Rules, 2025 were notified in November 2025. They establish a phased implementation structure rather than making every provision operational on the same date. MeitY's official materials identify later commencement dates for several substantive requirements. The child specific provisions under Section 9 and Rule 10 are scheduled to commence eighteen months after publication of the Rules. On the notified timeline, this places commencement in May 2027. Businesses should not interpret the future commencement date as a reason to postpone preparation. Changing an application's registration process, consent architecture, databases and third party integrations can take considerable time. Organisations serving children should use the transition period to identify gaps and test their systems. Building a Practical Compliance Framework for Children's Apps A strong compliance programme begins with a data inventory. The organisation should identify every category of children's personal data collected through its application or website. It should then map where the information travels, which systems store it and which vendors process it. The next stage is to assess age assurance and parental verification.The business should then review its privacy notice, consent mechanism, analytics systems, advertising technology, vendor contracts, retention practices and security controls. Testing is equally important. A business should test what happens when a child attempts to register, when a parent provides consent, when consent is withdrawn and when a user moves from a child status to adulthood. It should also test unsuccessful verification attempts and incomplete registration journeys. Privacy compliance should be treated as an operational process rather than a one time legal exercise. How Businesses Can Strengthen Governance Responsibility should be allocated internally.Product teams need to understand privacy requirements before introducing new features. Developers need clear rules concerning personal data access. Marketing teams should know the restrictions applying to children's advertising. Procurement teams should review third party data processing arrangements. Senior management should also receive visibility into significant privacy risks. A business may have an excellent privacy policy yet remain exposed because its application behaves differently from the policy. Regular reviews can identify such gaps before they become regulatory or commercial problems. For businesses with complex data flows, engaging a best corporate law firm can also help integrate privacy obligations with contracts, technology arrangements, corporate governance and broader regulatory requirements. Common Mistakes Businesses Should Avoid One common mistake is treating a date of birth field as complete age verification. Another is assuming parental consent permits every type of data processing. Businesses also sometimes overlook third party software embedded within their websites and applications. Advertising tools, analytics services and software development kits can create additional data flows. Another recurring issue is collecting more information than necessary for age verification. Some businesses also rely heavily on written policies without testing whether their technology actually follows those policies. The strongest approach is to connect legal requirements with product design, technical controls and operational procedures. Conclusion Children's data protection requires more than a well drafted privacy policy. For apps and websites used by children in India, businesses need to connect legal requirements with product design, age assurance, parental verification, data minimisation, security, advertising controls, vendor management and retention practices.   Frequently Asked Questions (FAQs) Q1. What is Data Privacy Compliance for children's apps in India? It is the process of ensuring an application or website collects, uses, stores, shares and deletes children's personal data in accordance with applicable Indian privacy requirements, including the DPDP Act and DPDP Rules. Q21. What age is considered a child under India's DPDP framework? The DPDP Act defines a child as an individual who has not completed eighteen years of age. Q3. Is parental consent required for children's apps in India? Section 9 requires verifiable parental or lawful guardian consent before processing a child's personal data, subject to prescribed exemptions. Q4. Can an app simply ask the child to confirm their age? A child's own declaration does not replace the statutory requirement for verifiable parental consent where Section 9 applies. Businesses need an appropriate mechanism for identifying and verifying the parent or lawful guardian. Q5. Can children's apps use behavioural analytics? Businesses need to carefully assess whether their analytics activities amount to tracking or behavioural monitoring covered by Section 9. The DPDP Act prohibits tracking and behavioural monitoring of children, subject to prescribed exemptions. Q6. Can businesses show targeted advertisements to children? Section 9 prohibits targeted advertising directed at children, subject to prescribed exemptions. A business should therefore assess its advertising architecture rather than relying solely on parental consent. Q7. Do children's websites need a privacy policy? A privacy notice is an important part of a compliant privacy framework, but a policy alone does not establish compliance. Businesses also need appropriate consent, governance, security, data handling and operational controls. Q8. When will the child specific DPDP requirements take effect? The child specific requirements under Section 9 and Rule 10 are scheduled for commencement eighteen months after notification of the Rules in November 2025, placing their scheduled commencement in May 2027. Businesses should verify the latest government notifications before relying on any commencement date. Q9. What is the penalty for violating children's data obligations? The DPDP Act provides for significant financial penalties. The Schedule specifies a penalty of up to ₹200 crore for breach of obligations relating to children. Q10. Should businesses conduct a children's data audit? Yes. An audit can identify what children's information is collected, how it moves through the organisation, which third parties receive it and whether the existing product architecture supports applicable privacy requirements.
MHCO Updates
SEBI Update
REGULATORY UPDATE | SEBI ORDERS VARANIUM CLOUD TO RESTORE & DISGORGE FUNDS OVER IPO & RIGHT ISSUE FRAUD
The Securities and Exchange Board of India (“SEBI”) on 25 August 2025 passed a Final Order against Varanium Cloud Limited (“VCL”) and its key management for alleged fraudulent and misleading activities in connection with its Initial Public Offer (IPO), Rights Issue and subsequent disclosures. BACKGROUND The proceedings stemmed from SEBI’s preliminary examination pursuant to media reports and complaints regarding VCL’s financial statements and corporate announcements, which led to an Interim Order dated 10 May 2024 against VCL and its MD/Chairman, Harshwardhan Hanmant Sabale (Mr Sabale). VCL raised approximately Rs 40.39 crore through its IPO in September 2022 (primarily for Edge Data Centres and Edmission Digital Learning Centres) and proposed a further Rs. 48.45 crore through a Rights Issue in September 2023. SEBI examined the utilisation of issue proceeds, financial statements, Prospectus disclosures, corporate announcements, related-party transactions, and the role of directors, the CFO, the merchant banker and other intermediaries. SEBI’S FINDINGS SEBI found that VCL misrepresented its financial statements and prospectus by showing fictitious sales and purchases, and that its disclosures on utilisation of IPO proceeds (including the Statement of Deviation dated 17 November 2023) were incorrect and misleading. SEBI found that IPO and Rights Issue proceeds of Rs. 62.51 crore were diverted to related parties and other entities, including Rs. 32.73 crore transferred directly to Mr Sabale’s personal account. BM Traders (operated by Mr Raj Jagtani) received Rs. 19.66 crore in aggregate from the issue proceeds, of which Rs. 15.60 crore was transferred onwards; and that no adequate evidence of genuine business purpose was produced. SEBI found several business announcements by VCL to be false and unsubstantiated. SEBI also found that the Company also failed to support the substantial increase in reported revenues (including those of its US subsidiary) with invoices, contracts or employee details. Pending litigation was omitted from the Letter of Offer, and the Prospectus contained material omissions and misstatements. Liability was fastened on the Company, its MD, Executive Directors and CFO. SEBI found that the lead manager, First Overseas Capital Limited (FOCL), failed to exercise independent due diligence and did not disclose pending litigation. SEBI rejected FOCL’s defence that  it  could  rely  on  the  Company’s  representations  and  third-party  reports. Athos Capital Advisors Private Limited (ACAPL) and Mr Jinesh Mehta were held to have aided and abetted the misrepresentations; ACAPL received approximately Rs. 2.50 crore from VCL, and Mr Mehta admitted drafting portions of the Prospectus and assisting with fundraising. SEBI’S DIRECTIONS VCL was directed to bring back Rs. 62.51 crore (with 12% p.a. interest) within three months. Mr Sabale was directed to disgorge unlawful gains of Rs. 128.77 crore (with 12% p.a. simple interest) to the Investor Protection and Education Fund. VCL and Mr Sabale were debarred from the securities market for 7 years. ACAPL and Mr Jinesh Mehta were debarred for 2 years; Mr Raj Jagtani/BM Traders for 4 years; the Executive Directors and CFO (Mr Vinayak Jadhav, Mr Mukundan Raghavan and Mr Fahim Shaikh) for 1 year; and FOCL for 2 years (to run consecutively with an earlier debarment). Monetary penalties were also imposed, including Rs. 20.40 crore on Mr Sabale, Rs. 13 crore on VCL and Rs. 10.10 crore on Mr Raj Jagtani. Proceedings against the Company Secretary (Ms Hetal Somani) and a Non-Executive Director (Mr Kalpesh Acharekar) were disposed of without directions or penalty, the allegations against them being found unsustainable. MHCO COMMENT The order is significant for its treatment of misrepresentation in financial statements and public-issue disclosures, diversion of IPO and Rights Issue proceeds, and the accountability of directors, KMPs and intermediaries. It reiterates that a lead manager must conduct independent due diligence and cannot merely rely on the issuer’s representations or third-party reports. SEBI did not fasten liability on every director or officer; allegations against the Company Secretary and non-executive director were dropped for want of material. Overall, SEBI characterised the matter as a fraudulent scheme of raising public funds on misleading disclosures, followed by diversion of proceeds and creation of a false picture of the Company’s performance. The restoration, disgorgement, debarment and penalty directions reflect the seriousness with which the conduct was viewed. By: Mr. Bhushan Shah, Partner Mr. Abhishek Nair, Associate Ms. Sayali Kshirsagar, Associate
Rea Estate
BOMBAY HIGH COURT ALLOWS REFUND OF STAMP DUTY PAID ON CANCELLED DEVELOPMENT AGREEMENT
The Bombay High Court, vide judgment dated 20 August 2026 in Sai Innovation v. Joint District Registrar and Collector of Stamps, Pune City & Ors. (Writ Petition No. 7566 of 2016), has held that a Development Agreement which fails to achieve its intended purpose and is subsequently cancelled can qualify for refund of stamp duty under Section 47(c)(5) of the Maharashtra Stamp Act, 1958 (“the Stamp Act”), and that such an agreement can avail the extended limitation period under the proviso to Section 48(1) where stamp duty has been calculated with reference to Article 25 of Schedule I. Background: Sai Innovation had entered into a Development Agreement (“said Agreement”) dated 15 April 2013 with the owners of land at Village Mauje Balewadi, Pune, for development of approximately 8,000 sq. metres of land and paid stamp duty under Article 25 read with Article 5 of Schedule I to the Stamp Act. The owners were unable to obtain sanction of the building plans within a reasonable time, and disputes subsequently arose between the parties. The said Agreement was therefore cancelled by a registered Deed of Cancellation (“said Deed”) dated 18 February 2014, registered on 24 February 2014, and the consideration received was returned. Sai Innovation thereafter applied on 7 April 2014 for refund of the stamp duty. The Respondent Nos 1&2 vide their orders dated 11 August 2014 and 6 December 2014 (“Impugned Orders”) respectively, rejected the refund application of the Petitioner, principally on the ground that the said Agreement was not a “conveyance” and therefore did not fall within the proviso to Section 48(1) of the Stamp Act. Issue: The Court dealt with the following issues: Whether the said Agreement had failed to achieve its intended purpose to attract Section 47(c)(5) of the Stamp Act; Whether a Development Agreement could avail the benefit of the proviso to Section 48(1), particularly where stamp duty was calculated as per Article 25 of Schedule I; Whether the reference to “actual, open possession” in Clause 13 of said Agreement be interpreted as transfer of possession to the developer, notwithstanding Clause 11 of the said Agreement which described the developer as a licensee; and Whether the Respondents could subsequently rely upon the alleged transfer of possession as a ground for rejecting the refund claim, when the refund claim had initially been rejected by the Impugned Orders on other grounds, and the issue of possession did not form part of the reasons recorded in those orders. Key Findings The Court, while differentiating between Section 47 and Section 48 of the Stamp Act, held that while Section 47 is the main provision that gives the right to a refund of stamp duty, Section 48 only deals with the time limit. In the present case, the proposed development under the said Agreement was never acted upon, and the parties later cancelled the said Agreement by the said Deed. As a result, the transaction had clearly failed to achieve its intended purpose under Section 47(c)(5) of the Stamp Act. The Court therefore said the refund claim had to be examined first under Section 47 and could not be turned down simply by pointing to the limitation period. On the question of possession, the Court held that Clause 13 of the said Agreement could not be read in isolation from Clause 11. Although Clause 13 referred to “actual, open possession”, Clause 11 expressly described the developer’s rights as those of “a licensee for development”. Reading the Agreement as a whole, the Court concluded that the developer was granted only a limited contractual licence to enter the property and undertake development activities, and that there was no transfer of legal or exclusive possession. The Court also noted that the absence of a separate possession receipt, by itself, did not establish that possession had been transferred. Held In light of the above reasoning, the Court allowed the writ petition and quashed the Impugned Orders passed by the Respondents. The Court held that the refund application was filed within the extended period prescribed under the proviso to Section 48(1) of the Stamp Act and, accordingly, rejected the Respondents’ objection that the claim was barred by the ordinary six-month limitation period. MHCO Comment Parties seeking refund of stamp duty on a cancelled Development Agreement should note that Section 47 governs the substantive entitlement to refund, while the proviso to Section 48(1) determines the applicable limitation period. Further, the legal character of a Development Agreement should be assessed by reading the same meaningfully and not in isolation from other clauses provided therein. By: Mr. Bhushan Shah, Partner Ms. Meeta Kadhi, Associate Partner Mr. Saptadip Nandi Chowdhury, Associate
SEBI Update
REGULATORY UPDATE | SEBI IMPOUNDS ₹ 3.67 CR FROM TWO ENTITIES FOR ALLEGED MANIPULATIVE TRADES DURING CLOSING AUCTION SESSION
BACKGROUND The Securities and Exchange Board of India (“SEBI”) passed an Ex-Parte Interim Order dated 19 August 2026 against Copthall Mauritius Investment Limited (“Copthall”) and Mansi Share and Stock Broking Private Limited (“Mansi”) in relation to alleged manipulative trading during the Closing Auction Session (“CAS”) on the BSE SENSEX expiry day. SEBI's CAS framework, introduced vide Circular dated 16 January 2026 and made effective from 3 August 2026, provides for determination of the closing price through a dedicated auction mechanism based on the interaction of buy and sell orders. The framework replaced the earlier methodology based on the volume-weighted average price (“VWAP”) for securities covered under the CAS framework, which determined the price of securities based on the closing price of the security or focused on the weight of trades executed in the last 30 minutes of the trading session. Now, under the CAS framework, the price of securities is determined based on buy and sell orders in a single pool, executed at a single equilibrium price in a dedicated 20-minute daily auction timeline. SEBI’S FINDING SEBI prima facie found that the trading activity of Copthall and Mansi was linked to their outstanding SENSEX option positions and was undertaken to influence the Indicative Equilibrium Price (“IEP”) and closing price of the SENSEX so as to obtain a favourable payoff from their expiry-day F&O positions. On 13 August 2026, SEBI's surveillance observed three sharp movements in the SENSEX during the CAS. Upon examination of the trade and order logs, SEBI observed that these movements coincided with large and aggressive buy orders placed by Copthall and sell orders placed by Mansi in SENSEX constituent securities, which were subsequently cancelled. SEBI accordingly examined the trading activity of the two entities and its linkage with their outstanding SENSEX option positions. SEBI noted that the material on record did not prima facie indicate that the two Noticees acted in concert. Rather, each appeared to have adopted a separate strategy to move the SENSEX in a direction favourable to its respective F&O positions. SEBI'S DIRECTIONS SEBI directed that the bank accounts of Copthall and Mansi be impounded to the extent of ₹2,96,16,000 and ₹71,64,773 respectively, aggregating a total of ₹3,67,80,773. SEBI also debarred the noticees from accessing the securities markets and prohibited them from participating in the CAS, including placing, modifying or cancelling orders. Restrictions were also imposed on their bank and demat accounts, transfer/redemption of securities and disposal of assets without SEBI's permission. They were further directed to cooperate with SEBI's ongoing examination/investigation. MHCO COMMENT The order is significant in the context of the newly introduced CAS framework and SEBI's surveillance of potential attempts to influence the closing price through order placement and cancellation. The order demonstrates that SEBI is examining the nature, timing and price of orders, their impact on the IEP, subsequent cancellation of orders and the corresponding F&O positions of the concerned entities. The directions are interim in nature and are based on prima facie findings pending further investigation. SEBI has expressly clarified that the detailed investigation is to proceed independently of the prima facie observations contained in the interim order. Notably, SEBI has not alleged that Copthall and Mansi acted in concert. The findings against the two entities are based on their respective trading patterns and F&O positions. Since the order is ex-parte and interim in nature, the findings remain subject to SEBI's further examination, as well as the Noticees' replies and opportunity of hearing. By: Mr. Bhushan Shah, Partner Ms. Sayali Kshirsagar, Associate
IBC Update
IBC UPDATE - REMOVAL OF INTERIM MORATORIUM FOR PERSONAL GUARANTORS APPLIES TO PENDING PROCEEDINGS
Recently, the Bombay High Court in the case of Tata Capital Financial Services Limited v. Neel Motors LLP & Ors., held that the amendment introducing Section 96(4) of the Insolvency and Bankruptcy Code, 2016 (“IBC”) applies to insolvency applications filed before that date which remain pending. The Court consequently held that the interim moratorium under Section 96 ceased to operate against the personal guarantors from 26 May 2026, enabling Tata Capital to pursue limited interim relief under Section 9 of the Arbitration and Conciliation Act, 1996 (“Arbitration Act”). FACTS: The Petitioner, Tata Capital Financial Services Limited (“Tata Capital”) extended financial assistance to Respondent No. 1, Neel Motors LLP, under a Channel Finance Agreement. Respondent Nos. 2 to 4 were individual guarantors and partners of Neel Motors LLP, while Respondent No. 5 was a separate LLP acting as guarantor. The Letters of Guarantee contained arbitration clauses with Mumbai as the seat. In 2021, Tata Capital filed a petition under Section 9 of the Arbitration Act seeking interim protection. Approximately one month prior to filing the Section 9 petition, Tata Capital had initiated Corporate Insolvency Resolution Process (“CIRP”) against Neel Motors under the IBC. The CIRP ultimately failed and Neel Motors was ordered to be liquidated by the NCLT, Mumbai, on 1 April 2022. Thereafter, in June 2022, Tata Capital initiated insolvency proceedings under Section 95 of the IBC against Respondent Nos. 2, 3 and 4, who were the individual guarantors (“Guarantors”). The filing of the Section 95 applications triggered the interim moratorium under Section 96, stalling the Section 9 petition. The legal position changed with the insertion of Section 96(4) into the IBC which came into force on 26 May 2026. The amendment provided that Section 96 would not apply where an application was filed for initiating an insolvency resolution process in respect of a personal guarantor to a corporate debtor. Relying upon the amendment, Tata Capital sought consideration of its pending Section 9 petition. The principal issue before the Court was whether Section 96(4) could apply to Section 95 applications which had been filed before 26 May 2026 but continued to remain pending on the date of the amendment. Tata Capital’s Case Tata Capital contended that, in view of the newly inserted Section 96(4), the moratorium under   Section 96 no longer operated against the individual guarantors and the expression “where an application is filed” was sufficiently broad to include pending applications. It further relied upon the legislative purpose behind the amendment, that it was intended to “remove any perverse incentives” associated with the initiation of individual insolvency proceedings. Considering the considerable delay since filing of the Section 9 petition, Tata Capital only sought disclosure of the guarantors’ assets and an injunction restraining them from selling, transferring, alienating, encumbering or otherwise dealing with such assets pending arbitration. Guarantor’s Case The guarantors opposed the application, contending that such an interpretation would give the amendment retrospective effect. They submitted that the expression “where an application is filed” covers only applications filed after 26 May 2026 and could not extend to applications which had already been filed. Any other interpretation, according to the guarantors, would retrospectively alter the legal consequences attached to the pending proceedings. They further argued that although insolvency proceedings are not strictly recovery proceedings, both the insolvency and arbitration proceedings were directed towards recovery of the same debt and Tata Capital should therefore not be permitted to pursue both simultaneously Court’s Finding The Hon’ble Court held that the expression “where an application is filed” in Section 96(4) encompasses applications which had already been filed and continued to remain pending before the adjudicating authority. Had the legislature intended to restrict the provision only to applications filed after 26 May 2026, it could have expressly used language to that effect. The Court distinguished between retrospective and retroactive operation, relying upon the Supreme Court’s decision in Securities and Exchange Board of India v. Rajkumar Nagpal, the Court observed that a provision is retrospective when it operates backwards and impairs vested rights, whereas a retroactive provision operates prospectively on a character or status originating in the past. The existence of antecedent facts does not, by itself, make its application retrospective. Accordingly, the moratorium under Section 96 operated against Respondent Nos. 2 to 4 until 25 May 2026 but ceased from 26 May 2026 when Section 96(4) came into force. The pending Section 9 petition was therefore no longer barred by the IBC moratorium. The Court further acknowledged the possibility of a conflict of interest where the creditor initiating insolvency proceedings may also be pursuing claims against the individual guarantor. However, it held that such considerations could not override the express statutory language, particularly when Section 96(4) was agnostic as to the identity of the person who initiated the Section 95 proceedings. MHCO Comment Pending proceedings can be affected by a new provision without the provision necessarily being retrospective. The decisive factor is whether the provision changes completed past rights or operates prospectively upon an existing/pending legal status. Section 96(4) therefore lifted the Section 96 moratorium prospectively from 26 May 2026 even in respect of Section 95 applications filed prior to the amendment coming into force. By: Mr. Bhushan Shah, Partner Ms. Neha Lakshman, Associate Partner
LIFE AT MHCO
Need Help? Chat with us