Digital Life

Government fixes wording of data law's child-safety clause ahead of 2027 rules

· 4 min read
WhatsAppX
Representative image: teenager using smartphone

Representative image: Pexels / Pixabay

MeitY's October 5, 2026 order corrects the DPDP Act's wording on children's data and data audits; the child-consent rules take full effect in May 2027.

What Happened

The Ministry of Electronics and Information Technology (MeitY) has issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026, correcting the wording of two provisions of India's data protection law, including the one that protects the personal data of children. The order, numbered S.O. 5458(E) and dated October 5, 2026, was issued under Section 43(1) of the Digital Personal Data Protection Act, 2023 and was published in the official gazette in the first week of October; most reports give October 7 as the publication date. The ministry has described the changes as drafting corrections that clear up ambiguity, not new obligations.

Key Facts

  • The order is the Digital Personal Data Protection (Removal of Difficulties) Order, 2026, S.O. 5458(E), dated October 5, 2026.
  • It was issued under Section 43(1) of the DPDP Act, 2023, which lets the government remove difficulties in applying the law.
  • Section 9(1) now reads "child or of a person with disability", making clear it covers the personal data of a child and, separately, of a person with a disability who has a lawful guardian.
  • In Section 10(2)(c)(ii), the word "audit" is replaced with "data audit", for large companies classed as Significant Data Fiduciaries.
  • Under the Act, a "child" is anyone who has not completed 18 years of age.
  • Companies must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data, and may not track, monitor or profile children or target advertising at them based on their behaviour.
  • Reports differ on whether the order took effect on October 6 or October 7, 2026.

Why It Matters

For most young Indians, the headline is not the comma-level correction but the law it touches. Under India's data protection law, everyone under 18 counts as a child. That means apps, games and social media platforms will need a parent's or guardian's verifiable consent before they handle a teenager's personal data, and they are barred from tracking teenagers' behaviour to build profiles or to show them targeted ads.

The order fixes a wording problem in exactly that part of the law. Before the change, Section 9(1) referred to the data of a "child or a person with disability", and the ministry said the missing word had blurred the parallel between the two groups. Adding the word "of" makes it explicit that the protection applies to a child's data, and separately to the data of a person with a disability who has a lawful guardian. Clear wording matters because companies build their systems to the letter of the law, and courts interpret it the same way.

The second correction changes "audit" to "data audit" for Significant Data Fiduciaries, the largest handlers of personal data, so that their periodic audit is clearly an audit of how they handle data, rather than any other audit.

None of this changes what young users can do online today. The main obligations of the DPDP rules, including the consent requirements for children, come fully into force in mid-May 2027, and businesses are preparing for that phase. When that happens, teenagers can expect sign-up processes that ask for a parent's approval, and fewer ads that seem to follow them from app to app.

ProvisionBeforeAfter
Section 9(1)"child or a person with disability""child or of a person with disability"
Section 10(2)(c)(ii)"audit""data audit"

Impact

Short-term: Nothing changes for users right away; legal and compliance teams update their reading of the law.

Long-term: Clearer wording should make it harder for platforms to argue over how the child-data rules apply when they come into force in 2027.

Who is affected: Under-18 users and their parents, people with disabilities who have lawful guardians, and apps, games and platforms that handle young users' data.

Key Takeaway

MeitY's October 5, 2026 order tidies the wording of India's data law on children's data, ahead of 2027 rules requiring parental consent for under-18s and banning ads that track them.

Questions and Answers

What did the DPDP Removal of Difficulties Order, 2026 change?

It made two wording corrections to the DPDP Act, 2023: it clarified that Section 9(1) covers the data "of" a child or "of" a person with disability, and it changed "audit" to "data audit" for Significant Data Fiduciaries.

Who counts as a child under India's data protection law?

Anyone who has not completed 18 years of age.

Will teenagers need a parent's permission to use apps?

Under the DPDP rules, platforms must get verifiable consent from a parent or lawful guardian before processing a child's personal data. Those obligations come into force in mid-May 2027.

Can apps show targeted ads to teenagers?

The Act bars companies from tracking, monitoring or profiling children and from directing behaviour-based advertising at them.

Disclaimer: Prepared by the Peepals newsroom from publicly available sources with AI assistance. Information is accurate to the best of our knowledge at the time of publication and may change. Images may be representative. Not professional advice. Report an error via our contact page.

PG

Sourced and fact-checked by the Peepals Global Editorial Team

Reported, fact-checked and published by the Peepals Global Editorial Team.

More from Peepals Yuva

The week's top stories, in your inbox. Free.

The most important, fact-checked stories from all seven publications, once a week.