Rule 10 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Rule 10 says how a Data Fiduciary makes sure a parent's consent to processing a child's personal data is verifiable. It must adopt technical and organisational measures and check, by reference to reliable identity and age details, that the person who says she is the parent is an identifiable adult.
Rule 10 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. Before processing any personal data of a child, a Data Fiduciary must adopt appropriate technical and organisational measures so that verifiable consent of the parent is obtained, and observe due diligence that the person claiming to be the parent is an adult (completed eighteen years) who is identifiable. It checks against details it already holds, or details given voluntarily directly or through a token from an authorised entity.
Rule 10 and the Act
Section 9(1) of the Act requires verifiable consent of the parent or lawful guardian before processing a child's personal data, in the manner prescribed. Rule 10 is that manner for parents; rule 11 is the manner for the lawful guardian of a person with disability. The Act's text is covered in Section 9 of the DPDP Act: verifiable parental consent. Exemptions from section 9(1) and (3) are in rule 12; see rule 12 and the Fourth Schedule, Part A.
Rule 1(4) places rule 10 in the group that comes into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The "verifiable consent" label itself is defined in rule 2(1)(d) as consent "as specified in rule 10 or 11"; see rules 1 and 2.
Apps for children, schools' online services and gaming platforms often ask how this rule fits their sign-up flow, and a legal consultation can walk through it.
Rule 10(1): measures and due diligence
"A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to" two sources:
| Source | Text |
|---|---|
| (a) | "reliable details of identity and age of the individual available with the Data Fiduciary" |
| (b)(i) | "details of identity and age, voluntarily provided ... by the individual" |
| (b)(ii) | details provided "through a virtual token mapped to such details, which is issued by an authorised entity" |
Notice what the rule asks for and what it does not. It asks for two things: measures so that verifiable consent is obtained before processing, and due diligence that the claimed parent is an identifiable adult. It does not fix a method. The Data Fiduciary may rely on details it already holds (a), or take details the individual gives voluntarily (b), including through a token. The phrase "if required in connection with compliance with any law for the time being in force in India" qualifies the identifiability of the adult. The rule does not say how the relationship between parent and child is proved; it speaks of the individual "identifying herself as the parent" and of due diligence about adulthood and identifiability.
Rule 10(2): the defined words
| Term | Meaning in rule 10(2) |
|---|---|
| "adult" | An individual who has completed the age of eighteen years |
| "authorised entity" | (i) an entity entrusted by law or by the Central Government or a State Government with the issuance of details of identity and age or a virtual token mapped to such details; or (ii) a person appointed or permitted by that entity for such issuance; the definition "also includes details of identity and age or token made available and verified by a Digital Locker Service Provider" |
| "Digital Locker service provider" | Such intermediary, including a body corporate or an agency of the appropriate Government, as may be notified by the Central Government, in accordance with the rules made in this regard under the Information Technology Act, 2000 (21 of 2000) |
Drafting notes: the definition of "authorised entity" ends with a hanging limb ("and also includes details of identity and age or token made available and verified by a Digital Locker Service Provider"), which is not an entity but details; clause (c) ends with a semicolon and nothing follows it; and the term is printed both as "Digital Locker Service Provider" and "Digital Locker service provider". All are quoted as printed. A list of notified Digital Locker service providers is not in the Rules.
The Rules' own Illustration
C is a child, P is a parent and DF is a Data Fiduciary. A user account of C is sought to be created on DF's online platform, by processing C's personal data.
- Case 1: C tells DF she is a child and declares P as her parent. DF enables P to identify herself through its website, app or other appropriate means. P says she is a registered user who has previously made her identity and age details available to DF. Before processing C's data to create her account, DF checks that it holds reliable identity and age details of P and that P is an identifiable adult.
- Case 2: Same start, but P says she is not a registered user. Before processing, DF checks that P is an identifiable adult by reference to identity and age details issued by an entity entrusted by law or the Government with maintaining those details, or to a virtual token mapped to them. P may voluntarily make such details available using the services of a Digital Locker service provider.
- Case 3: P is opening an account for C, identifies herself as the parent and says she is a registered user who previously gave DF her identity and age details. DF checks that it holds reliable details and that P is an identifiable adult.
- Case 4: P is opening an account for C and says she is not a registered user. DF checks as in Case 2.
The four cases turn on two facts: who starts (the child or the parent), and whether the parent is already a registered user. Where she is registered, DF relies on the details it holds. Where she is not, DF goes to an outside source or a token.
Our own example, separate from the Illustration: LearnLoop (invented) offers a reading app. A ten-year-old, Arjun, tries to sign up. LearnLoop asks him to name a parent. His mother, Kavita, is not a registered user. LearnLoop asks her to verify through a government-issued identity token; once it confirms she is an identifiable adult, it processes Arjun's data to create the account.
What rule 10 does not say
- It does not define "child"; the Act's meaning applies under rule 2(2).
- It does not name a particular document, app or portal.
- It does not state a penalty. For penalties see the Schedule to the Act.
- The Act bars tracking and targeted advertising directed at children in section 9(3); see that section. Rule 12 gives exemptions.
For a plain-language overview written before the Rules, see children's data protection under section 9.
Need help with child sign-up flows?
If your product can be used by children, the sign-up flow, token checks and records are what a regulator would read. Speak to our legal team to map your flow to rule 10 before launch.
Key takeaways
- Rule 10 starts eighteen months after the date of publication of the Gazette (rule 1(4)).
- Verifiable consent of the parent must be obtained before processing any personal data of a child.
- The Data Fiduciary observes due diligence that the individual is an adult who is identifiable, against reliable details it holds or details given voluntarily, including through a virtual token from an authorised entity.
- "Adult" means completed eighteen years.
- The text of rule 10(2) has several printing slips.
- Later amendments and notifications should be checked.
Read next
- Rule 11: verifiable consent of the lawful guardian of a person with disability
- Rule 12, Part A: exempt classes (clinical, educational and creche)
- Section 9 of the DPDP Act: verifiable parental consent
- Children's data protection under section 9
Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.
