One morning as I was about to leave for the court I received a call. It was from a pre-school. The operator wanted to know if I was considering nursery admission for my son, who would be turning three soon. It struck me for a second. Yes, I had submitted an online form for scheduling a visit to the school months ago. I had filled in his name and date of birth, mandatory fields on the form. During my visit, I mentioned I would only pursue admission after he turned three. That was the extent of our interaction.
I had never consented to them retaining his details. I had never been told they would. And yet, here was a school — an institution built around the trust of parents calling me months later with my child's information neatly filed away.
This is not a peculiar situation in India these days. Almost every parent faces uninvited calls and messages from schools, coaching centres, and EdTech platforms. Children's privacy is violated in one and many other ways in India. Sadly, it has become an acceptable norm. The violation is not only limited to privacy. Social media intermediaries who are conveniently using the lack of proactive regulation as an excuse, are serving as the biggest platform for child sexual content. This article discusses everyday breach of children's data, their digital rights and how effective the present framework has been so far.
The Substantive Framework of DPDP Act, 2023 And Where It Falls Short
India's Digital Personal Data Protection Act, 2023 (“Act”), which received Presidential assent on August 11, 2023, is the country's first comprehensive data protection statute. Its substantive obligations form the operative core of the Act — the notice requirement under Section 5, the consent standard under Section 6, the children's specific protections under Section 9. Section 12 further gives a data subject the right to correction, completion, updating and erasure of digital personal information.
The general obligation of data fiduciary under Section 8. The obligations include the responsibility to abide by the provisions of the Act, irrespective of any agreement in force. Data Fiduciary may appoint a data processor for processing activities under a valid contract. Wherever the digital data is used to make a decision that affects the data principal and when it is disclosed to another data fiduciary, the data must be, in that case, complete, consistent and accurate. Section 8(4) requires the Data Fiduciary to adopt effective technical measures that effectively implements the provisions of this Act. It means, merely saying in the Privacy Policy or any document that “We are DPDP compliant” is not enough. There must be a technical measure in place that makes sure the provisions are complied with, not just on paper. Section 8(5) is crucial here. It imposes liability of the Data Fiduciary to protect personal data in its possession and prevent breach of such data. This liability is absolute on Fiduciary irrespective of the facts, whether or not the data was processed by its data processor. Further, in the event of breach it is the responsibility of the Data Fiduciary to intimate of such breach to the Data Protection Board and the Data Principal. Section 8(7) has limited the ability of the data fiduciary to retain data. The fiduciary is required to erase data unless its retaining is compulsory for compliance of law in force. Otherwise, the data fiduciary is required to delete data if the consent is withdrawn or the purpose for which it was collected is no longer served, whichever is earlier. Moreover, it is the responsibility of the Data Fiduciary to cause the erasure of such data.
The liability of Data Fiduciaries is huge. The Fiduciaries are, undoubtedly, construed as the ultimate bearers of digital personal data.
Giving effect to the above provisions, Section 33 deals with adjudication and penalty in case of breach. These are the provisions that create enforceable duties, confer rights on individuals, and expose non-compliant entities to penalties of up to Rs. 250 crore.
However, these substantive obligations do not become enforceable until May 13, 2027. The Data Protection Board constituted under Section 18 of the DPDPA exists as a legal entity but has no appointed Chairperson and no Members. MeitY advertised for these appointments as recently as June 6, 2026. A body without members cannot adjudicate a complaint, impose a penalty, or issue a direction.
For children specifically, Section 9(1) requires verifiable parental or guardian consent before any personal data of a child is processed. Section 9(2) absolutely prohibits processing of children’s personal data which could be detrimental to their well-being. What could be detrimental to a child’s well being? In my understanding, it could be anything that could cause emotional, psychological, physical or social harm to anyone under 18. For example, the feed of a 14- year old girl is filled with weight loss content, cosmetics ads or anything that questions the ways she looks. The language of Section 9(2) leaves questions for speculation.
Section 9(3) prohibits tracking, behavioural monitoring, and targeted advertising directed at children. Targeted advertising is when a user’s web history, location, habits, private actions are used to build a profile. It’s called profiling. The profiles are used to display custom-tailored advertisements. In the context of children, it could be an app displaying a video game console to a 11-year old because he kept watching video about video games. Children are subject to targeted advertisement everyday while this provision is waiting to be enforced. The question here is, in the absence of its enforceability, would the infringers of Section 9(3) be held accountable? How would the law protect the children against the target advertising happening now?
Section 5 and Section 6 is applicable to the data principal. The definition of “Data Principal” includes the child and her parents or guardians. When I submitted that online school form, I was engaging with a Data Fiduciary. Section 9(1) required the school to give me a notice before collecting my son's data. Section 6 required consent to be specific and informed not deemed from the act of submitting a form. Section 9(1) required verifiable parental consent before processing a child's personal data. The lack of enforceability of the substantive obligation gave the school free pass to process my child’s data without my consent. That’s a violation of an existing law. Moreover, the school's privacy policy, still framed under the Information Technology Act, 2000, treats form submission as implied consent to retention and future contact. Under the substantive provisions of the DPDPA, that consent is inadequate. Under the current enforcement reality, it is consequence-free.
Several pre-schools now offer parents live CCTV access to classrooms as a safety feature. A classroom of fifteen toddlers watched simultaneously by fifteen sets of parents means every child is monitored by adults who are strangers to them, without consent from the parents of the other children. Section 9(1) prohibits monitoring of children without verifiable parental consent. The consent of one parent does not authorise the surveillance of every other child in the frame.
That said Rule 12(1) of the DPDP Rules, 2005 (“Rules”) read with Part A of Fourth Schedule exempts an educational institution from Section 9(1) which is parental consent requirement and Section 9(3) prohibiting behavioural tracking of children. The educational institution can process the children data for tracking and behavioral monitoring for 1) educational activities and 2) safety of children.
Not just schools, clinical establishments, healthcare professionals, facilities like crèche including an individual who is associated with such facilities are allowed processing of children’s data. However, they are subject to limitations described in their respective fields.
The rules, in my opinion, appear to be contradictory to the legislative intent of Section 9 and the whole Act. I have discussed one such example above. In the name of safety, could a child be monitored by another parent or guardian?
The contemporary violation of children’s rights on social media- An ongoing issue
Like every parent, I follow some paediatricians on social media. Often, my feed is filled with videos by doctors filming child patients. Sadly, most of them are infants or toddlers. The video vividly describes the diagnosis and its treatment in the name of awareness. The views cross millions. The child has not consented to anything. They may not yet be able to speak.
The DPDP Rules permit processing only to the extent necessary for provision of health services and protection of child’s health. A paediatrician who posts such content is simultaneously in breach of the National Medical Commission Registered Medical Practitioner (Professional Conduct) Regulations, 2023, which explicitly prohibit posting patient-related imagery on social media, and processing a child's health data without the specific, informed consent required under Section 6 and Section 9 (1) of the DPDPA. A parent's consent to medical treatment does not extend to Instagram distribution. The child's health data, once published, is indexed, searchable, and permanent. When that child turns eighteen, there is no mechanism under Indian law to demand its removal.
This concern deepens when one considers who these child patients often are. Paediatricians with large Instagram followings frequently document cases from public hospitals and lower-income clinical settings. The parents of these children are many from economically marginalised communities with limited digital literacy. They may not fully understand what it means for their child's medical condition to appear in a video viewed by millions. They may not know that consent given in a clinical setting does not automatically extend to social media distribution. Consent given by a parent who does not know what Instagram is, what algorithmic amplification means, or what permanent digital indexing cannot meet the standard set under Section 6. The child whose medical condition is viewed by millions because their parent did not understand what they were agreeing to is not protected by the DPDPA.
Section 9 regulates Data Fiduciaries which are entities that determine the purpose and means of processing personal data. It does not regulate parents acting in their personal capacity. The Act treats parental consent as the solution to children's data protection. It has not considered the situation where the parent is the problem. I believe this is another challenge, the Act and its Rules have failed to address.
The ongoing dissemination of child sexual contents on social media
Instagram and other social media platforms, as intermediaries under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, bear no proactive obligation to assess whether content featuring child patients violates a child's independent privacy rights. Their obligations are merely reactive. Social media intermediaries have no active regulation that requires them to proactively scan the contents that violate children’s privacy or child sexual material and remove them immediately. Not just that, the algorithm also facilitates such contents if prompted in the same direction. Resultant, social media is filled with such illegal contents. In fact, in a recent BBC documentary it was pointed out how Instagram algorithm serves explicit child sexual contents when a user views the similar contents.
Social media, which is as huge as the world today, is hiding behind the shell reactive obligation. Meaning, they are only liable to take action and remove illegal content if it is identified and reported. This is a serious issue which has put the privacy and safety of children in danger. All the while, the major content platform is sitting there and doing nothing unless prompted to do so. This is a major gap in the law that has overlooked the crisis happening now. The DPDP Rules permit processing only to the extent necessary for provision of health services and protection of child’s health.
A scrutiny of laws around the world
Foreign jurisdictions have recognised the privacy gaps earlier and legislated more specifically.
The United States has governed children's data in educational settings for over five decades through the Family Educational Rights and Privacy Act ("FERPA"), 20 U.S.C. § 1232g; 34 CFR Part 99 (1974). FERPA bars schools receiving federal funding from disclosing personally identifiable student information to third parties without written parental consent. Non-compliance risks federal funding — a consequence that creates genuine institutional compliance pressure. The Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. §§ 6501-6506; 16 C.F.R. Part 312, substantially amended in April 2025, requires separate parental consent for third-party disclosures and expands personal information to include biometric identifiers. The FTC may impose penalties of $43,280 per violation.
The European Union's General Data Protection Regulation — Regulation (EU) 2016/679 — provides the most comprehensive framework currently in force. Article 8 sets the age of digital consent at sixteen. Article 9 designates health data as a special category requiring explicit consent which is a materially higher standard than ordinary personal data. A paediatrician posting a child patient's medical video on Instagram is processing special category data under Article 9. Explicit, purpose-specific consent must be demonstrated by the doctor. India's DPDPA has no equivalent. Health data is processed under the same consent standard as an email address.
In 2024, California enacted AB 1409, requiring parents who earn income from content featuring their children to set aside a portion in a trust for the child. It is the first law anywhere to recognise a child's economic rights in content created about them by their own parents. The Dutch Data Protection Authority has issued guidance holding that a parent sharing a child's information publicly may independently violate that child's own privacy rights. A parent does not have unlimited authority over their child's privacy.
The Irish Data Protection Commission fined Meta €405 million in 2022 for mishandling children's data on Instagram. These are not aspirational standards. They are precedents with financial consequences.
India has none of this. No enforcement history under the DPDPA. No sector-specific guidance for schools, pre-schools, or EdTech platforms. No heightened protection for children's health data. No recognition of children's independent privacy rights against parental oversharing. No penalties yet imposed.
The child has a fundamental right to privacy under Article 21 of the Constitution, as affirmed unanimously by a nine-judge bench in Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1. Justice D.Y. Chandrachud's concurring opinion specifically held that informational privacy, the right to control one's personal data is a component of this fundamental right. Children are citizens. That right belongs to them. What they do not have is any enforcement mechanism against the institutions, doctors, parents, or platforms whose conduct currently compromises it without consequence.
But a constitutional right without a functional enforcement body, sector-specific guidance, heightened protection for sensitive data, and platform obligations is a right that exists only on paper. Section 33 of the DPDPA prescribes penalties of up to Rs. 250 crore for violations of children's data obligations. The provision is enacted. The Board that would impose those penalties has no members. The ubi jus ibi remedium “where there is a right, there is a remedy” remains, for now, an aspiration rather than a reality for India's children.
Unlike India’s reactive framework, several foreign jurisdictions have enacted proactive obligations specifically targeting child sexual content on platforms. In the United States, the PROTECT Our Children Act, 2008, 18 U.S.C. § 2258A, mandates that electronic service providers who obtain actual knowledge of apparent child sexual abuse material must proactively report it to the National Center for Missing and Exploited Children CyberTipline, failure of which attracts criminal liability.
The United Kingdom’s Online Safety Act, 2023, goes further by requiring all in-scope platforms, including social media services, to conduct proactive risk assessments of potential child sexual abuse and exploitation and to implement safety-by-design measures before harm occurs. The European Union’s Digital Services Act, Regulation (EU) 2022/2065, imposes mandatory annual systemic risk assessments on Very Large Online Platforms — a category that includes Instagram with specific reference to risks of dissemination of illegal content involving minors, and obliges platforms to implement reasonable mitigation measures commensurate with those risks.
Australia’s Online Safety Act, 2021, likewise empowers the eSafety Commissioner to issue proactive industry codes requiring platforms to detect and remove child sexual abuse material. Taken together, these frameworks establish an emerging global standard of proactive platform responsibility for child sexual content —a standard against which India’s current intermediary regime, which imposes no equivalent proactive duty outside the narrow CSAM reporting obligation under Rule 4(4) of the IT Intermediary Guidelines Rules, 2021, falls conspicuously short.
That leaves us with the question, Is India failing to protect the rights of its children while the world is far ahead from us? Across the world, platforms are being fined, regulated, and held to account for what they serve to children. In India, the same platforms operate under the same algorithms, serving the same content, facing no consequence. A child in Germany has legal protection from Instagram. A child in India has a constitutional right and no one to enforce it.