India has corrected two drafting ambiguities in the DPDP Act, clarifying verifiable consent requirements and confirming that Significant Data Fiduciaries must conduct periodic data audits.

India Clarifies Child Consent and Data Audit Rules Under DPDP Privacy Law

The420 Web Correspondent
8 Min Read

India has issued a targeted clarification to its Digital Personal Data Protection Act, removing two drafting ambiguities related to children’s data and the audit obligations of companies classified as Significant Data Fiduciaries.

The Ministry of Electronics and Information Technology issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026 under Section 43 of the DPDP Act.

The order makes two textual changes to the law.

One clarifies how the consent requirement applies to children and persons with disabilities who have lawful guardians.

The other makes clear that periodic audits required from Significant Data Fiduciaries are specifically data audits rather than a broader undefined category of audit.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Section 9(1) of the DPDP Act requires companies to obtain verifiable consent before processing the personal data of a child.

It also applies where personal data belongs to a person with disability who has a lawful guardian.

The original wording referred to the “personal data of a child or a person with disability”.

The government said the missing word “of” before “a person with disability” created a grammatical disjunction that could obscure the intended meaning.

The amended provision now refers to the “personal data of a child or of a person with disability”.

The change is small in wording but removes uncertainty over how the sentence should be read.

It confirms that the consent requirement applies separately and in parallel to both categories.

The order does not introduce a fresh consent regime for children.

Under the existing DPDP framework, a Data Fiduciary must obtain verifiable parental consent before processing a child’s personal data.

Where the individual is a person with disability who has a lawful guardian, verifiable consent must come from that lawful guardian.

The 2025 DPDP Rules already explain how companies are expected to verify that the person giving consent is an adult parent or lawful guardian.

For children, the rules require companies to use reliable identity information or a virtual token linked to such identity details when verifying the adult providing consent.

The latest order therefore clarifies the statute rather than changing the underlying compliance mechanism.

Significant Data Fiduciaries Get Audit Clarification

The second correction affects organisations that may be designated as Significant Data Fiduciaries.

These companies face additional obligations under Section 10 of the DPDP Act because of factors such as the volume and sensitivity of data they process, risks to individual rights and possible effects on sovereignty, security or public order.

Section 10 already requires such organisations to appoint an independent data auditor to carry out a data audit.

A separate provision also required them to conduct periodic “audit”.

The government said that wording could create confusion over whether the two requirements referred to different types of audits.

The 2026 order now replaces the second reference to “audit” with “data audit”.

That aligns the terminology across the provision and makes clear that both obligations concern data-protection compliance.

Why the Audit Change Matters

The difference between a general corporate audit and a data audit can be substantial.

A financial audit examines accounts and financial reporting.

A data audit is focused on how an organisation collects, processes, stores, protects and governs personal information.

It can examine consent systems, access controls, retention policies, data-sharing arrangements and compliance with statutory privacy duties.

The government said the clarification was needed to prevent inconsistent interpretation by regulatory or supervisory authorities.

For large digital businesses, that gives greater certainty about what kind of periodic review will be expected under the DPDP framework.

Significant Data Fiduciaries Face Extra Obligations

The DPDP Act allows the government to designate certain organisations as Significant Data Fiduciaries based on the nature and scale of their data processing.

Once designated, they must meet additional compliance requirements.

These include appointing a Data Protection Officer based in India, appointing an independent data auditor and carrying out periodic data audits.

They may also be required to conduct assessments and take other prescribed measures to manage privacy risks.

The latest correction does not expand those obligations.

It simply narrows the interpretation of the existing audit requirement.

Child Data Remains One of the Strictest Areas of the Law

India’s privacy framework places additional restrictions on the processing of children’s information.

Apart from verifiable parental consent, the DPDP Act prohibits processing that is likely to have a detrimental effect on a child’s well-being.

It also generally prohibits tracking or behavioural monitoring of children and targeted advertising directed at them, subject to specified exemptions.

The DPDP Rules provide limited exemptions for some entities such as healthcare providers, educational institutions and childcare providers where processing is necessary for defined purposes connected with health, education or safety.

The October clarification does not change those protections.

Changes Arrive Ahead of Full Compliance Deadline

The DPDP Rules were notified in November 2025 with a phased implementation schedule.

The government provided an 18-month transition period for several major substantive obligations so that companies could rebuild their privacy and compliance systems.

Sections 9 and 10, which cover child-data processing and Significant Data Fiduciary obligations, are scheduled to become operational in March 2027.

That gives affected organisations several months to update consent mechanisms, audit frameworks and internal documentation using the clarified statutory wording.

Companies Do Not Need an Entirely New Compliance Programme

Businesses should not interpret the order as requiring a separate privacy programme.

The government described the problems being corrected as textual and editorial.

Companies that process children’s data should continue building systems for verifiable parental consent.

Organisations likely to be classified as Significant Data Fiduciaries should ensure their audit documentation, internal policies and engagement with independent auditors clearly refers to data audits.

The legal obligations themselves remain substantially the same.

Government Used Its Power to Remove Implementation Difficulties

Section 43 of the DPDP Act gives the central government limited power to issue orders where difficulties arise in implementing the legislation.

The government relied on that provision to correct the two ambiguities.

The order says the changes are intended to give effect to the original legislative intent rather than introduce new policy.

That is important because a removal-of-difficulties order is not being used here to rewrite the wider privacy framework.

Instead, it is correcting wording before the affected provisions become fully operational.

What this means for you

For ordinary users, the change does not reduce protections around children’s personal data. For businesses, the message is mainly about compliance clarity: parental or guardian consent requirements remain in place, while large designated data processors should prepare specifically for periodic data-protection audits rather than treating the requirement as a general corporate audit.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected