<- Back to blog

23 September 2026 - 4 min read

Does India's Data Protection Law Already Cover Apps Your Child Uses

Does India's Data Protection Law Already Cover Apps Your Child Uses

Short answer

  • The DPDP Act's children's-data protections are not fully in force yet, as of this writing
  • Once fully in effect, it will require verifiable parental consent before an app processes a child's data
  • It will also ban tracking, behavioral monitoring, and targeted ads aimed at children
  • An app that never collects any data in the first place isn't waiting on any of this to apply

India's Digital Personal Data Protection Act treats anyone under 18 as a child, a stricter line than most countries draw, and it sets out real rules for apps that collect a child's data. Whether those rules are actually enforceable today, right now, is a separate and less commonly understood question.

What does India's DPDP Act actually say about children's data?

Any platform processing a child's personal data, anyone under 18, needs verifiable consent from a parent or guardian first. The Act also explicitly bans tracking, behavioral monitoring, and targeted advertising aimed at children outright, regardless of consent. Penalties for getting this wrong run into the hundreds of crores, among the stricter child-data regimes in the world, well beyond what the US or EU require.

Is this already the law today, or is it still coming into effect?

Still coming into effect, and this matters more than the headline rules themselves. The Act commences in stages rather than all at once. As of the most recent tracking available, only the first stage, setting up the Data Protection Board itself, is actually in force. The substantive rules, including the children's-data protections, remain dormant, with full enforcement expected around May 2027. An app that isn't yet built around verifiable parental consent isn't necessarily breaking the law today, though that's expected to change.

What counts as "processing a child's data" under this law?

Broadly, anything a platform collects, stores, or acts on that identifies or relates to a specific child, usage patterns, location, contact details, behavior used to personalize content or ads. The law is aimed squarely at platforms that build a profile of a child over time, whether for recommending content, targeting ads, or simply tracking what they do.

An app that collects nothing isn't waiting on any consent framework to catch up.

Get it on Google Play->

So does this mean an app I already use is currently breaking the law?

Not necessarily, and it's worth being precise here rather than alarmist. Since the children's-data provisions haven't fully commenced yet, an app collecting a child's data today isn't automatically violating DPDP specifically, though it may still raise other concerns. What's genuinely useful to know as a parent is less about legal enforcement today and more about which apps are already built the way this law is heading, and which ones will need to change significantly once it does.

Does this matter for an app that doesn't collect any data at all?

Less than for one that does, by design. CrenelView has no internet permission at all, so it isn't technically capable of collecting, storing, or sending any data anywhere, which means there's no consent framework to build, no tracking to stop, because none of that is happening in the first place. That's not a claim about complying with DPDP specifically, it's simply true regardless of which regulation is in force at any given moment.

The law is catching up to a real problem. An app with nothing to collect was never part of that problem to begin with.

See why there's no data collection to regulate in the first place.

Get it on Google Play->

Share this