All articles
News & Analysis 8 min read 30 September 2026 Primitra

Children's Data Under the DPDP Act: What TikTok's £12.7m UK Fine Means for Indian Businesses

TikTok has dropped its appeal and accepted a £12.7m UK fine for mishandling children's data. Here is what Indian SMEs and startups should take from it before the DPDP Act's children's data rules bite in May 2027.

On 24 September 2026, the UK Information Commissioner's Office announced that TikTok had withdrawn its appeal and accepted a £12.7 million fine first issued in 2023. The case was about children's data: kids under 13 using the platform, no proper age checks, and no parental consent. If your Indian business collects personal data from anyone under 18, this case is worth ten minutes of your time, because the rules on children's data under the DPDP Act are stricter than the UK rules TikTok fell foul of.

What the ICO found against TikTok

According to the ICO's announcement, it estimated that up to 1.75 million UK children under 13 were using TikTok in 2020, even though TikTok's own terms did not allow them to open accounts. The regulator found three connected failures:

  • TikTok did not carry out adequate checks to identify and remove underage users.
  • Users, and children in particular, were not given clear information about how their data was collected, used and shared.
  • TikTok did not obtain parental consent, even though it ought to have known under-13s were on the platform.

TikTok also dropped a second appeal against an ICO information notice. That clears the way for a separate investigation, opened in February 2025, into how TikTok uses the data of 13 to 17 year olds in its recommender systems.

Notice the phrase "ought to have been aware". A regulator will not accept "our terms say no kids" as a defence if your product plainly attracts them.

Children's data under the DPDP Act: the Indian rules

India draws the line higher than the UK. Under the Digital Personal Data Protection Act, 2023, a "child" is anyone under 18. The UK and US thresholds for parental consent sit at 13, so a large group of teenagers who can sign up freely elsewhere count as children in India.

Section 9 of the Act sets three obligations for any Data Fiduciary processing a child's personal data:

  1. Verifiable parental consent must be obtained before processing (Section 9(1)).
  2. You must not process a child's data in a way likely to cause a detrimental effect on the child's well-being (Section 9(2)).
  3. You must not undertake tracking, behavioural monitoring or targeted advertising directed at children (Section 9(3)).

The penalty ceiling for failing these additional obligations is up to ₹200 crore per instance, set out in the Schedule to the Act. Like other DPDP obligations, Section 9 takes full effect at the end of the 18-month transition from the Rules' notification on 13 November 2025, which places it around 13 May 2027.

What verifiable parental consent looks like under Rule 10

Rule 10 of the DPDP Rules, 2025 explains how "verifiable" is meant to work. A Data Fiduciary must adopt appropriate technical and organisational measures and use due diligence to check that the person claiming to be the parent is an identifiable adult. It can rely on:

  • reliable identity and age details it already holds (for example, where the parent is an existing verified user), or
  • identity and age details voluntarily provided by the individual, or through a virtual token issued by an authorised entity, which includes details made available through a DigiLocker service provider.

The Rule's own illustrations cover four scenarios: the child starts sign-up or the parent does, and the parent is either already a registered user or not. In each case, you confirm the parent is a verifiable adult before creating the child's account.

A bare "I am over 18" tick box will struggle to meet this standard.

The exemptions are narrower than many businesses assume

The Fourth Schedule to the Rules relieves certain entities and purposes from Sections 9(1) and 9(3). Listed classes include clinical establishments and healthcare professionals, allied healthcare professionals, educational institutions, crèches and child day-care centres, and transport providers engaged by those institutions. Each exemption is tied to a condition, such as providing health services to the child, or tracking and behavioural monitoring for the institution's educational activities or for children's safety.

What these exemptions do not cover is just as important. A school can track attendance without parental consent. An edtech app selling to that school's students does not automatically inherit the exemption. Neither can anyone use the carve-outs for analytics, profiling or ad targeting. Section 9(2), the bar on detrimental processing, is not exempted at all.

Which Indian businesses should pay attention

It is easy to assume this is a problem for social media giants. The exposed businesses are often smaller:

  • Edtech and coaching platforms with students aged 13 to 17 signing up directly.
  • Gaming and fantasy apps whose age gate is a single date-of-birth field.
  • D2C and e-commerce brands selling school supplies, toys, cosmetics or sneakers to teenagers, often with retargeting pixels running.
  • Fitness, sports academies and hobby classes that collect children's health or location data through WhatsApp forms and spreadsheets.

If any of these sound familiar, the TikTok test applies: would a regulator say you ought to have known children were using your service?

A six-step plan before May 2027

  1. Map where minors appear. List every sign-up form, lead form, app and offline register where someone under 18 could enter data. Include vendors who collect on your behalf.
  2. Set an honest age gate. Ask for age neutrally, without nudging users to lie, and log the answer. Decide what happens when a user says they are under 18.
  3. Build the parental consent flow. Choose a Rule 10 route that fits your product: verified parent accounts, DigiLocker-based age tokens, or another reliable method. Keep consent records you can show the Board.
  4. Switch off tracking for minors. Audit analytics SDKs, ad pixels and recommendation logic. Any profile flagged as a child should be excluded from behavioural monitoring and targeted advertising.
  5. Test your exemption claims. If you rely on the Fourth Schedule, write down which entry applies, which condition you meet, and where the processing stops.
  6. Run a focused impact assessment. A short privacy impact assessment on your children's data flows will surface most of the gaps above in one exercise.

For the wider obligations, our DPDP Act compliance guide sets out how children's data fits alongside notice, consent and breach reporting.

The takeaway

TikTok spent three years contesting a fine and ended up paying it anyway, with a second investigation now moving. Indian regulators are newer, but Section 9 hands them clearer tools and a higher age threshold than the ICO had. Businesses that fix age checks and parental consent now will spend far less than those that retrofit them under a Board inquiry.

This article is general guidance, not legal advice. Please consult a qualified professional for advice on your specific situation.

Want to see where you stand? Start with our free DPDP compliance checklist, or talk to our team about reviewing your children's data flows.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation