Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook β†’

To Check If You're a Child, India Must Check Everyone: The DPDP Age-Verification Reckoning

A July 31 Delhi roundtable exposed the core flaw in India's DPDP age-verification plan: to prove a user is a child, every adult must verify too.

D
DPDPBot Research Team
πŸ• 10 min read

#To Check If You're a Child, India Must Check Everyone: The DPDP Age-Verification Reckoning

Here is the uncomfortable arithmetic at the heart of India's plan to keep children safe online: to confirm that one user is a child, a platform has to confirm the age of every user β€” including every adult. That single line, argued and re-argued at a closed-door MediaNama roundtable in New Delhi on 31 July 2026, is why DPDP age verification has quietly become the most consequential unresolved question in Indian data protection this year. The Digital Personal Data Protection Act, 2023 demands "verifiable parental consent" before anyone processes a child's data, and the government now favours a graded, Aadhaar-anchored system to deliver it. The roundtable's blunt conclusion: the cure may be more invasive than the disease.

For once, this is not a distant compliance abstraction. Two Indian states have already announced bans, the Supreme Court has floated Aadhaar-based age gates from the bench, and the DPDP Rules 2025 have set a hard May 2027 deadline for the machinery to actually work. Businesses that touch children's data β€” edtech, gaming, social, and a long tail of consumer apps β€” are being asked to build age-assurance systems before anyone has agreed on what those systems should be.

#What actually happened this week

On 31 July, MediaNama convened policymakers, technologists, lawyers, child-psychiatrists and digital-rights researchers at The Claridges in New Delhi for a session titled "Age Verification and Restricting Social Media for Children." It was not a government event, but it was the most serious cross-disciplinary stress test yet of the Centre's emerging position β€” and it landed in the same 48-hour window as sharp international coverage warning that "India's child safety plan would force every adult to submit biometrics via Aadhaar."

The agenda made the stakes explicit. Participants examined the Centre's proposed graded framework, which splits minors into three brackets β€” roughly 8–12, 12–16 and 16–18 β€” with escalating obligations for platforms at each tier. That is a meaningfully different design from the single hard line drawn by Australia (under-16) or by earlier UK and EU proposals. India is not choosing between "ban" and "no ban"; it is trying to build a sliding scale of restriction that maps onto how children's digital maturity changes with age.

The problem is that a sliding scale needs to know where every user sits on it. And in India, as the TechPolicy.Press analysis put it this week, "all age verification in practice becomes Aadhaar verification." That is the reckoning.

#Why the DPDP Act makes this unavoidable

The pressure traces directly to the statute. Section 9 of the DPDP Act treats anyone under 18 as a child and imposes three hard duties on Data Fiduciaries: obtain verifiable parental consent before processing a child's data, do not undertake tracking or behavioural monitoring of children, and do not run targeted advertising directed at them. Unlike the US model under COPPA, which caps at 13, India's threshold is 18 β€” one of the highest in the world β€” which sweeps in the entire teenage user base of every mainstream platform.

The Act says what must happen but not how. That gap fell to the Digital Personal Data Protection Rules, 2025, notified by MeitY on 13 November 2025. Rule 10 spells out the technical and organisational measures a Data Fiduciary must take to obtain verifiable parental consent: it must first check whether the person in front of it is a child, and if so, validate the identity and age of the adult claiming to be the parent. The Rules point to two acceptable routes β€” identity and age details "already available to" the fiduciary, or virtual tokens issued by a government-authorised entity, in practice an Aadhaar-linked DigiLocker token.

Read Rule 10 carefully and the paradox surfaces on its own. You cannot "first check whether the person is a child" without running an age check against everybody who walks through the door. A gate that only inspects the people who look young is not a gate; a gate that inspects everyone is mass age verification. And once mass age verification defaults to Aadhaar, the country has quietly built an identity checkpoint in front of ordinary online activity.

#The Aadhaar collapse

This is the specific Indian twist that separates the DPDP debate from Australia's or Britain's. In most jurisdictions, "age assurance" can be satisfied by a spread of methods β€” credit-card checks, ID document scans, third-party estimation, AI facial age-estimation. In India, the government's own preferred rails run through the Aadhaar–DigiLocker stack, because that is the infrastructure that already exists at population scale. The result, as digital-rights experts warned at the roundtable, is that a policy nominally about age becomes a policy about identity.

Officials are alive to the criticism and have proposed a privacy-preserving wrapper: rather than sharing an Aadhaar number, a user would receive a disposable, single-use token confirming only "over 18" or "eligible," which is meant to be destroyed after the transaction so the government cannot log which app or site was accessed. On paper, that is a genuine improvement over handing platforms raw Aadhaar data.

But the TechPolicy.Press critique this week made the durable objection: those safeguards are design choices, not legal guarantees. Nothing in the DPDP Act itself mandates that the tokens be non-linkable or non-retained. A future rule change, a "minor" technical tweak, or a security carve-out could convert an anonymous age check into a linkable identity trail β€” the textbook definition of mission creep. Aadhaar, the argument runs, was originally justified for delivering subsidies; extending it to police online anonymity is exactly the kind of scope expansion the Supreme Court's own Puttaswamy privacy jurisprudence was meant to guard against.

There is a delicious irony here that Indian compliance teams should not miss: even as one plan leans on Aadhaar for age, the Supreme Court has separately been questioning whether Aadhaar should be limited to identity proof only and has held in other contexts that an Aadhaar card is not conclusive proof of date of birth. The state is simultaneously being told Aadhaar is too unreliable to prove age in a courtroom and being asked to make it the nation's primary age gate online.

#The courts and the states are not waiting

Two other forces are pushing this from theory toward implementation, and both create friction with the DPDP framework.

The Supreme Court has weighed in from the bench. Hearing petitions tied to objectionable online content, the Court favoured an autonomous regulator for digital content and suggested Aadhaar-based age verification before users can access potentially "obscene" material β€” a warning screen followed by an age confirmation. The bench stressed the regulator must be independent of both platforms and the state. Judicial enthusiasm for Aadhaar age gates gives the executive's plan powerful cover, but it also risks hard-coding one identity system into constitutional expectation before the DPDP machinery is even live.

The states have jumped ahead of the Centre. Karnataka used its 2026–27 budget on 6 March to announce intent to ban social media for under-16s; Andhra Pradesh followed with a draft framework targeting under-13s within 90 days; Goa is reportedly considering its own version. None has published a working age-verification mechanism. This is a federalism problem as much as a privacy one: data protection is a central subject governed by the DPDP Act, yet states are legislating access rules that would require the very age-assurance infrastructure the Centre has not finished designing. A patchwork of state bans layered on a single national consent regime is a compliance nightmare waiting to happen.

#The dissent: fix the design, not the door

The most important counter-argument is not "do nothing." It is that age verification is aimed at the wrong target. An earlier Meta-sponsored roundtable in Bengaluru concluded that "age verification as currently proposed will not work," and that view carried into the July session. The reasoning: gates are trivially defeated β€” 39% of UK children already bypass age checks, mostly by simply lying about their age β€” while imposing surveillance costs on the entire adult population.

The proposed alternative is a "digital duty of care." Instead of interrogating who the user is, regulate what the product does: ban addictive design for minor accounts β€” infinite scroll, autoplay, engagement streaks, gamification and dopamine-driven recommendation β€” and mandate maximum-privacy defaults and strict data minimisation for young users. Notably, that framing maps almost perfectly onto Section 9's existing prohibitions on tracking, behavioural monitoring and targeted advertising. In other words, the DPDP Act may already contain the more defensible tool; the fight is over whether India also bolts an identity checkpoint on top of it.

#How the world is drawing the line

India is legislating in a crowded global moment, and the comparisons are instructive rather than decorative. Australia's Online Safety Amendment (Social Media Minimum Age) Act took effect on 10 December 2025, barring under-16s from accounts on ten named platforms and threatening civil penalties up to AUD 49.5 million (about USD 33 million) for providers that fail to take "reasonable steps." The UK has gone further into behavioural territory, switching on default midnight-to-6am social media curfews for 16- and 17-year-olds.

Against that backdrop, India's graded three-tier model is more nuanced than a flat ban β€” but nuance is expensive. A single line ("no accounts under 16") is crude yet cheap to state; three brackets with escalating duties demand exactly the granular, reliable, population-scale age signal that critics say only Aadhaar can provide in India, and that privacy advocates say Aadhaar should not provide. The GDPR, by contrast, leaves age of consent to member states (13–16) and pointedly does not prescribe a national identity gate β€” a reminder that "verifiable" need not mean "government-verified."

#What Indian businesses should do now

The temptation is to wait for final clarity. That is a mistake, because the deadlines are fixed even while the mechanism is not. The consent-manager provisions of the DPDP framework take effect on 13 November 2026, and the substantive obligations β€” including Section 9's children's-data duties β€” become fully enforceable on 13 May 2027. Practical steps that survive whichever way the age-verification design lands:

  • Map your minor exposure. Identify every data flow that could involve an under-18 user, not just the products you market to children. Section 9's 18-year threshold is broad.
  • Design for parental-consent capture now. Build the workflow to validate a parent's identity and record consent through a consent-management layer that can plug into DigiLocker-style tokens without hard-wiring to any single vendor.
  • Strip addictive and tracking features for young accounts regardless of the final ban debate β€” this is already required by Section 9 and is the one path everyone in the room agrees on.
  • Treat age signals as sensitive. If you run age estimation or store verification tokens, apply data minimisation and short retention; do not become the linkable trail the token system was designed to avoid.
  • Watch the states. A Karnataka or Andhra Pradesh access ban could impose obligations beyond the DPDP baseline for users in those jurisdictions.

#The bottom line

The 31 July roundtable did not resolve India's age-verification question β€” it sharpened it. The country has a mandate it cannot ignore (Section 9), a mechanism it has not finalised (Rule 10's tokens), an infrastructure that keeps collapsing back to one identity system (Aadhaar), and a chorus of experts arguing the whole approach mistakes the door for the disease. Somewhere in the next nine months, between the November 2026 consent-manager milestone and the May 2027 enforcement wall, India will have to decide whether protecting children online is worth asking every adult to prove they are one.

For businesses, the message is simpler than the politics: the parental-consent and children's-data obligations are coming on a fixed clock, and the compliance work β€” consent capture, feature restrictions, data minimisation β€” is the same no matter which age-assurance mechanism wins. Build the parts everyone agrees on first. See our DPDP compliance resources and consent management guide to start.

The DPDPBot Research Team tracks Indian data-protection developments daily. This post reflects reporting available as of 1 August 2026; the government's age-verification rules remain under active consultation.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready β€” all in one platform.

Start free trial