The Supreme Court’s recent concern over minors on social media highlights the urgent need for DPDP compliance
The increasing use of social media, educational platforms, healthcare applications, gaming platforms and other digital services by children has brought privacy and protection of children’s personal data into sharp focus.
Recent proceedings before the Supreme Court concerning the ability of minors to open social-media accounts have highlighted an important question: Are digital platforms doing enough to ensure that children’s personal data is processed in accordance with Indian law?
The discussion has also brought the Digital Personal Data Protection Act, 2023 (DPDP Act) into greater public attention.
Special protection for children
The DPDP Act recognises that children require a higher level of protection. Section 9 places specific obligations on organisations processing the personal data of children, including requirements relating to verifiable parental consent and restrictions on certain forms of processing.
The Digital Personal Data Protection Rules, 2025 provide further details on how parental or guardian consent is to be verified. The Rules contemplate mechanisms through which a Data Fiduciary can establish that consent has been provided by the child’s parent or legal guardian.
This is particularly important for organisations whose websites or applications are regularly accessed by children, including:
- Social-media and digital-content platforms
- Educational and EdTech platforms
- Healthcare and childcare organisations
- Gaming and entertainment platforms
- E-commerce and consumer applications
- Financial and insurance platforms
- Organisations operating websites or applications that collect personal information from users
DPDP compliance is not merely a privacy-policy exercise
The DPDP framework requires organisations to look beyond simply publishing a privacy policy.
A responsible organisation should examine what personal data it collects, why it collects it, how consent is obtained, how consent is recorded, where the data is stored, who can access it, how long it is retained and what happens when the individual exercises his or her rights.
For children, the organisation must additionally consider whether the user is a child and, where applicable, whether verifiable parental consent has been obtained before processing the child’s personal data.
The 2025 Rules also provide for specified exemptions for certain organisations and activities, including certain healthcare, educational and childcare-related processing, subject to the conditions prescribed in the Rules.
Why organisations should act now
The Government notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025. The Rules prescribe a phased commencement framework, giving organisations time to establish the systems and processes required for compliance.
This transition period should not be viewed as a reason to postpone compliance.
Implementing data protection within an organisation can require changes to:
People + Processes + Technology + Contracts + Documentation + Governance
Organisations should therefore consider undertaking a DPDP readiness assessment or audit and prepare a practical compliance roadmap.
What organisations should consider implementing
A practical DPDP compliance programme may include:
- Personal Data Mapping – identifying what personal data is collected and where it moves.
- Data Inventory – identifying categories of personal data and the purposes for processing.
- Consent Management – creating appropriate mechanisms for obtaining, recording and withdrawing consent.
- Children’s Data Controls – identifying child users and implementing appropriate parental-consent mechanisms.
- Privacy Notices – ensuring that notices are clear, accessible and legally compliant.
- Data Retention & Deletion – establishing appropriate retention periods and deletion procedures.
- Data Security Measures – implementing reasonable safeguards against unauthorised access, breaches and misuse.
- Data Principal Rights – establishing procedures for receiving and responding to requests from individuals.
- Vendor and Contract Management – reviewing arrangements with processors, technology providers and other third parties.
- Incident and Breach Response – establishing a documented procedure for responding to personal-data breaches.
- Employee Awareness and Training – ensuring that employees understand their responsibilities in handling personal data.
- Documentation and Governance – maintaining evidence that the organisation has actually implemented its DPDP compliance programme.
The larger message
The debate surrounding children and social-media accounts demonstrates that data protection is no longer only an IT issue.
It is increasingly a matter of corporate governance, legal compliance, technology, risk management and consumer trust.
Every organisation that collects or processes digital personal data should therefore ask a basic question:
If our data-processing practices were examined today, could we demonstrate that we are complying with the DPDP framework?
The answer should not depend upon waiting for a complaint, data breach, regulatory action or court intervention.
DPDP compliance should be treated as an ongoing organisational process—not as a one-time exercise.
Organisations that start by understanding their data, identifying compliance gaps and implementing practical procedures can build a stronger foundation for responsible and lawful processing of personal data.
This article is intended for general awareness and does not constitute legal advice. The applicability of particular DPDP obligations depends on the nature of the organisation, its processing activities and the applicable provisions and commencement dates.