Section 9 of DPDP Act 2023 establishes special protections for children and persons with disability. Section 9(1) Children: Data Fiduciary shall before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian. The Data Fiduciary shall obtain consent in such manner as may be prescribed. Section 9(2) Prohibition Children: Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. Section 9(3) Prohibition Tracking + Targeted Ads: Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children. Section 9(4) Exemption: Central Government may by notification exempt the processing of personal data by certain classes of Data Fiduciaries or for certain purposes from the application of provisions of sub-sections (1) + (3) + subject to such conditions as may be specified. Section 9(5) Lowered Age: Central Government may by notification + having regard to such circumstances as may be specified + by notification lower the age above which a Data Fiduciary is exempt from certain provisions of sub-sections (1) + (3) (e.g. mature minor exception for online safety + education). Child Definition: Section 2(f) - an individual who has not completed the age of 18 years (full majority age unlike GDPR 16 or US COPPA 13). Operational implementation: age verification at user onboarding + parental consent mechanism + Aadhaar eKYC for parent + nominal consent records + parental dashboard + ability to revoke + special UX for child users + content moderation + safety by design + child-friendly privacy policy + Consent Manager registration of parental consent + parental review and control + interface with mature-minor-recognition framework + COPPA-equivalent integration + EU AI Act 5(1)(a) prohibition on AI exploiting vulnerabilities of children. Coordinates with UN Convention on the Rights of the Child + Children Rights and Business Principles (UNICEF) + COPPA (US) + GDPR Art 8 (age 16 default + Member State lowering to 13) + AADC Age Appropriate Design Code (UK ICO) + Online Safety Act 2023 (UK) + Australia eSafety Commissioner + Online Safety Act 2021 + India JJ Act 2015 + India POCSO Act 2012 + India Online Gaming + India National Education Policy 2020 + Cyber Surakshit Bharat for children. DPDP Sec 9 Children + PwD applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.