People's rights

Children's data and verifiable parental consent, guardians of persons with disability, the children's exemptions, and the rights to access, correction, erasure, grievance redressal and nomination, with the Data Principal's own duties.

Module 3 of 6, 10 minutes, 6 lessons

Questions this module answers

  • How does the DPDP Act handle children's data?
  • What are the rights of Data Principals under the DPDP Act?
  • How long can companies store personal data under the DPDP Act?
  • How should organizations handle Data Subject Rights requests under the DPDP Act?
  • What is the Right to Nominate under the DPDP Act?

Figures use one colour per role, throughout the course:

  • Data Principal
  • Data Fiduciary
  • Data Processor
  • Consent Manager
  • Government and Board

This module covers what the Act gives the people whose data you hold: special protection for children and persons with disability, and the rights to access, correction, erasure, grievance redressal and nomination, with the duties that come alongside them. Rules 9applies from 13 May 2027, 10applies from 13 May 2027, 11applies from 13 May 2027, 12applies from 13 May 2027 and 14applies from 13 May 2027, and the Fourth Scheduleapplies from 13 May 2027, apply from 13 May 2027.

Before processing a child's personal data, Section 9(1) requires the verifiable consent of her parent, and Section 9(2) and 9(3) forbid harmful processing, tracking, behavioural monitoring and targeted advertising even with that consent. From 13 May 2027, Rule 10applies from 13 May 2027 requires you to check that the person consenting is an identifiable adult.

Processing a child's personal data: four tests
  1. Are you about to process personal data of a child?

    Section 9(1)
    If noSection 9's rules for children do not apply.

    If yes, go to the next test.

  2. Have you obtained the verifiable consent of her parent or lawful guardian, before processing?

    Section 9(1)
    If noDo not process. Consent comes first.

    If yes, go to the next test.

  3. Have you checked that the person consenting as parent is an identifiable adult?

    Rule 10(1)
    If noRule 10(1) names how to check: by reference to reliable details of identity and age you already hold, or details provided voluntarily by the individual or through a virtual token issued by an authorised entity.

    If yes, go to the next test.

  4. Would the processing track or behaviourally monitor her, target advertising at her, or be likely to harm her well-being?

    Section 9(2) and 9(3)
    If yesForbidden, even with the parent's consent.

    If no, you may proceed.

  5. You may process the child's personal data, within the consent given.

    Section 9

Rule 10 applies from 13 May 2027. Rule 12 and the Fourth Schedule lift the consent and tracking tests for some classes and purposes, as a later lesson shows; the well-being test is never lifted.

Read the full lesson, with every provision it rests on (2 min)

Section 9(1) requires a Data Fiduciary, before processing any personal data of a child, to obtain the "verifiable consent" of the parent, in the manner prescribed. The Explanation to Section 9(1) makes "consent of the parent" include the consent of a lawful guardian where applicable. Module 1 covered who counts as a child under the Act.

Two prohibitions sit beside consent and apply even when the parent agrees. Section 9(2) forbids processing that is "likely to cause any detrimental effect on the well-being of a child". Section 9(3) forbids tracking or behavioural monitoring of children, and targeted advertising directed at children.

Rule 10 prescribes how verifiable consent works. Under Rule 10(1), the Data Fiduciary must adopt appropriate technical and organisational measures to ensure the parent's verifiable consent is obtained before processing, and must observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required under Indian law. It checks this by reference to either reliable identity and age details it already holds (Rule 10(1)(a)), or identity and age details voluntarily provided by the individual or through a virtual token mapped to such details, issued by an authorised entity (Rule 10(1)(b)). An "adult" is an individual who has completed eighteen years (Rule 10(2)(a)). Authorised entities include those entrusted by law or by government with issuing such details, and details verified by a Digital Locker service provider count (Rule 10(2)(b)).

The four illustrations to Rule 10, whoever starts the sign-up, turn on one fact. If the parent is already a registered user who has given her identity and age details, the Data Fiduciary checks that it holds reliable details and that she is an identifiable adult. If she is not, it checks by reference to details issued by an entity entrusted by law or the Government, or a token mapped to them; she may use a Digital Locker service provider to share them.

Rule 10(1) describes the check by reference to reliable identity and age details the Data Fiduciary holds, or details provided voluntarily by the individual or through a virtual token issued by an authorised entity. Rule 10 applies from 13 May 2027.

Persons with disability who have a lawful guardian

For a person with disability who has a lawful guardian, Section 9(1) requires the guardian's verifiable consent before processing. From 13 May 2027, Rule 11applies from 13 May 2027 requires you to verify that a court, a designated authority or a local level committee appointed that guardian under the applicable guardianship law.

Consent through a lawful guardian: verify the appointment
  1. Someone says she is the lawful guardian of a person with disability

    Rule 11(1)
  2. Verify who appointed her

    A court of law, a designated authority, or a local level committee, under the law applicable to guardianship.

    Rule 11(1)
  3. Match the appointment to the right law

    Long-term impairment that leaves her unable to take legally binding decisions despite support: the Rights of Persons with Disabilities Act, 2016. Autism, cerebral palsy, mental retardation (the Rule's term) or a combination, including severe multiple disability: the National Trust Act, 1999.

    Rule 11(2)(b)
  4. Obtain the guardian's verifiable consent before processing

    Section 9(1)

Rule 11 applies from 13 May 2027. The check is on who appointed the guardian, not an assessment of the disability.

Read the full lesson, with every provision it rests on (2 min)

Section 9(1) also covers a person with disability who has a lawful guardian. Before processing her personal data, the Data Fiduciary must obtain the verifiable consent of that lawful guardian, in the manner prescribed.

Rule 11 prescribes the check. When an individual identifies herself as the lawful guardian of a person with disability, the Data Fiduciary must observe due diligence to verify that the guardian was appointed by a court of law, by a designated authority, or by a local level committee, under the law applicable to guardianship (Rule 11(1)).

Rule 11(2) explains who is meant. A "person with disability" means an individual with a long-term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society, and who, despite adequate and appropriate support, is unable to take legally binding decisions. It also includes an individual with autism, cerebral palsy, mental retardation (the Rule's term), or a combination of two or more of these, including severe multiple disability, who despite such support is unable to take legally binding decisions (Rule 11(2)(d)).

The law applicable to guardianship depends on which description fits. For the first group it is the Rights of Persons with Disabilities Act, 2016 and its rules; for the second it is the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 and its rules (Rule 11(2)(b)). The designated authority and the local level committee are bodies set up under those two Acts (Rule 11(2)(a) and 11(2)(c)).

Two practical points. First, Rule 11 is about verifying the appointment, not about assessing the person's disability yourself; the check is whether a court, designated authority or local level committee appointed this guardian. Second, the prohibitions in Section 9(2) and 9(3) speak of children; for a person with disability, Section 9 turns on the guardian's verifiable consent. Rule 11 applies from 13 May 2027.

Where the children's rules do not apply

Rule 12applies from 13 May 2027 and the Fourth Scheduleapplies from 13 May 2027 lift the parental-consent rule and the tracking and advertising ban for named classes, such as clinics, schools and crèches, and named purposes, such as a child's safety, each only on its stated condition. The ban on processing likely to harm a child's well-being, Section 9(2), is never lifted.

What the Fourth Schedule lifts, and for whom

Part A: classes of Data Fiduciary

  • Clinical establishments, mental health establishments and healthcare professionals: health services to the child, as far as needed to protect her health
  • Allied healthcare professionals: supporting a treatment and referral plan they recommended for the child, as far as needed to protect her health
  • Educational institutions: tracking and behavioural monitoring for their educational activities or the safety of enrolled children
  • Individuals caring for children in a crèche or day care centre: tracking and behavioural monitoring for the children's safety
  • Transport providers engaged by a school, crèche or centre: tracking the children's location for their safety while travelling to and from it
Rule 12(1)

Part B: purposes

  • A power, function or duty under Indian law, in the child's interests
  • A subsidy, benefit, service, certificate, licence or permit provided in the child's interests
  • Creating a user account used only for communication by email
  • Tracking a child's real-time location for her safety and protection or security
  • Keeping information, services or advertisements likely to harm her well-being from reaching her
  • Confirming that a Data Principal is not a child, and due diligence under Rule 10
Rule 12(2)

Each entry lifts only Section 9(1) and 9(3), and only on its condition. Section 9(2), the ban on processing likely to harm a child's well-being, still applies to everyone. From 13 May 2027.

Read the full lesson, with every provision it rests on (2 min)

Section 9(4) allows the Rules to lift Section 9(1) and 9(3), consent and the tracking and advertising ban, for classes of Data Fiduciaries or purposes, subject to conditions. Rule 12 does this through the two Parts of the Fourth Schedule. The exemption never lifts Section 9(2): processing likely to harm a child's well-being stays forbidden for everyone.

Part A of the Fourth Schedule names classes of Data Fiduciaries (Rule 12(1)), each with a condition:

  • a clinical establishment, mental health establishment or healthcare professional, restricted to health services to the child, to the extent necessary to protect her health;
  • an allied healthcare professional, restricted to supporting a treatment and referral plan such a professional recommended for the child;
  • an educational institution, restricted to tracking and behavioural monitoring for its educational activities or the safety of its enrolled children;
  • an individual caring for infants and children in a crèche or day care centre, restricted to tracking and monitoring for their safety;
  • a transport provider engaged by a school, crèche or centre, restricted to tracking the children's location for safety while travelling to and from it.

Part B names purposes (Rule 12(2)): exercising a power or duty under Indian law in the interests of a child; providing a subsidy, benefit, service, certificate, licence or permit in a child's interests; creating a user account limited to communication by email; determining a child's real-time location for her safety; keeping harmful information, services or advertisements from reaching her; and confirming that a Data Principal is not a child, including due diligence under Rule 10applies from 13 May 2027.

Each entry is restricted "to the extent necessary". Rule 12 and the Fourth Schedule apply from 13 May 2027.

Separately, Section 9(5) lets the Central Government notify, for a Data Fiduciary whose processing of children's data is "verifiably safe", an age above which it is exempt from all or any obligations under Section 9(1) and 9(3).

Access, correction and erasure

Section 11 lets a Data Principal ask what personal data you process about her and whom you shared it with, and Section 12 lets her have it corrected, completed, updated or erased. You must erase on request unless the specified purpose or a law in force requires you to keep it.

Access, correction and erasure: what she can ask, and what you must do
  • A summary of her personal data and your processing activities

    Section 11(1)(a)
  • Who else has it

    The identities of all other Data Fiduciaries and Data Processors you shared it with, and a description of what was shared. Not required for sharing with a Data Fiduciary authorised by law, on its written request, to prevent, detect or investigate offences or cyber incidents (Section 11(2)).

    Section 11(1)(b)
  • Any other information that is prescribed

    Section 11(1)(c)
  • Correction, completion and updating

    Correct inaccurate or misleading data, complete incomplete data, and update it.

    Section 12(2)
  • Erasure

    Erase it unless keeping it is necessary for the specified purpose or to comply with a law in force.

    Section 12(3)
  • A published way to ask

    From 13 May 2027, publish on your website or app how to make a request, and any username or other identifier she must give.

    Rule 14(1)

These rights run against the Data Fiduciary she gave consent to, including for data she voluntarily provided for a specified purpose. Sections 11 and 12 set no response deadline of their own.

Read the full lesson, with every provision it rests on (2 min)

Section 11(1) gives a Data Principal the right to ask the Data Fiduciary to whom she previously gave consent, including personal data she voluntarily provided for a specified purpose (the first legitimate use in module 2), for:

  • a summary of her personal data being processed and the processing activities (Section 11(1)(a));
  • the identities of all other Data Fiduciaries and Data Processors with whom her data has been shared, with a description of what was shared (Section 11(1)(b));
  • any other information about her personal data and its processing that is prescribed (Section 11(1)(c)).

Section 11(2) makes one exception: the sharing details need not be given where the data went to another Data Fiduciary authorised by law, on its written request, for preventing, detecting or investigating offences or cyber incidents, or for prosecution or punishment.

Section 12(1) gives her the right to correction, completion, updating and erasure of that personal data, in line with any other law's requirements. On a request, the Data Fiduciary must correct inaccurate or misleading data, complete incomplete data, and update it (Section 12(2)). On an erasure request, it must erase her personal data unless retention is necessary for the specified purpose or to comply with a law in force (Section 12(3)).

Rule 14applies from 13 May 2027 sets how requests reach you. Every Data Fiduciary must prominently publish on its website or app the means by which a Data Principal can make a request, and any particulars, such as a username or other identifier, needed to identify her under its terms of service (Rule 14(1)). She then makes the request using those means and particulars (Rule 14(2)). An "identifier" includes a customer file number, application reference number, enrolment ID, email address, mobile number or licence number (Rule 14(5)).

Sections 11 and 12 set no response deadline of their own; the ninety-day ceiling in Rule 14(3) belongs to grievances, as the next lesson explains. Rule 14 applies from 13 May 2027.

Grievances, and the person who answers

Section 13 gives a Data Principal readily available means of grievance redressal, and she must use them before approaching the Board. From 13 May 2027, Rule 14(3)applies from 13 May 2027 requires you to publish a response period of no more than ninety days, and to respond within it.

A grievance, from receipt to the Board
  1. Before any grievance

    Publish the route, the response period and a contact

    On your website or app: how to make a request, the identifier needed, your response period, and the business contact information of your Data Protection Officer, if applicable, or a person who can answer.

    Rule 14(3)
  2. Date of receipt

    She raises a grievance with you

    About any act or omission in your obligations about her personal data, or in her exercise of her rights.

    Section 13(1)
  3. Within your published period, at most ninety days

    Respond

    Your system must be able to respond within the period you publish, and every response about her rights names your contact person (Rule 9).

    Rule 14(3)
  4. Only after that

    She may approach the Board

    She must first exhaust your grievance route.

    Section 13(3)

Rules 9 and 14 apply from 13 May 2027. Ninety days is the ceiling for the period you publish, not a target.

Read the full lesson, with every provision it rests on (2 min)

Section 13(1) gives a Data Principal the right to "readily available means of grievance redressal" from a Data Fiduciary or Consent Manager, for any act or omission in performing its obligations about her personal data or in the exercise of her rights. Section 13(2) requires a response within the prescribed period. Section 13(3) requires her to exhaust this route before approaching the Board, so a grievance system that works is also your first chance to settle a matter before it becomes a complaint.

Rule 14(3) prescribes the period. Every Data Fiduciary and Consent Manager must prominently publish on its website or app the period under its grievance redressal system for responding to grievances, which must be "a reasonable period not exceeding ninety days". It must also implement appropriate technical and organisational measures so the system actually responds within that period. Ninety days is a ceiling, not a target, and the system must be able to respond within the period you publish.

Rule 9applies from 13 May 2027 names the person behind the system. Every Data Fiduciary must prominently publish on its website or app, and mention in every response to a communication about the exercise of a Data Principal's rights, the business contact information of the Data Protection Officer, if applicable, or of a person able to answer, on the Data Fiduciary's behalf, the Data Principal's questions about the processing of her personal data.

Put together, a small business needs four things on its website or app: how to make a request and what identifier to give (Rule 14(1)), the grievance response period (Rule 14(3)), the contact person (Rule 9), and a working process behind them. Log each request and grievance with its date of receipt, since the period runs from then (Section 13(2)).

Rules 9 and 14 apply from 13 May 2027.

Nomination, and the Data Principal's duties

Section 14 lets a Data Principal nominate someone to exercise her rights if she dies or becomes incapable, and Section 15 sets five duties she owes, such as not impersonating anyone and not filing false or frivolous grievances. From 13 May 2027, Rule 14(4)applies from 13 May 2027 lets her nominate one or more individuals.

What the Data Principal may do, and what she must do

Her right to nominate

  • She may nominate any other individual to exercise her rights in the event of her death or incapacity. Section 14(1)
  • Incapacity means being unable to exercise those rights because of unsoundness of mind or infirmity of body. Section 14(2)
  • She may nominate one or more individuals, in line with your terms of service and any applicable law. Rule 14(4)

Her duties

  • Comply with all applicable laws while exercising her rights. Section 15(a)
  • Not impersonate another person when providing her personal data for a specified purpose. Section 15(b)
  • Not suppress material information when providing her personal data for a State-issued document, unique identifier, proof of identity or proof of address. Section 15(c)
  • Not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board. Section 15(d)
  • Give only verifiably authentic information when seeking correction or erasure. Section 15(e)

Rule 14 applies from 13 May 2027. She nominates using the means and particulars you require, so your published request route should cover nomination.

Read the full lesson, with every provision it rests on (1 min)

Section 14(1) gives a Data Principal the right to nominate any other individual who will, in the event of her death or incapacity, exercise her rights under the Act and the Rules. "Incapacity" means being unable to exercise those rights because of unsoundness of mind or infirmity of body (Section 14(2)).

Rule 14(4) sets the mechanics. She may nominate one or more individuals, in line with the Data Fiduciary's terms of service and any applicable law, using the means and furnishing the particulars the Data Fiduciary requires. So your published request route under Rule 14(1) should cover nomination too, and your records should be able to hold a nominee against a Data Principal's account. Rule 14 applies from 13 May 2027.

Section 15 then sets out duties the Data Principal owes. She must:

  • comply with all applicable laws while exercising her rights (Section 15(a));
  • not impersonate another person when providing her personal data for a specified purpose (Section 15(b));
  • not suppress material information when providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities (Section 15(c));
  • not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board (Section 15(d));
  • furnish only verifiably authentic information when exercising her right to correction or erasure (Section 15(e)).

These duties do not shift your obligations onto her. As module 2 explained, a Data Fiduciary stays responsible for compliance even if a Data Principal fails in her duties. Section 15(e) does mean that information she supplies for a correction or erasure should be verifiably authentic. What the Board can do about a breach of these duties is covered in module 5.