·The Hindu·15 marks·250–350 words

Examine the adequacy of India's data protection framework in safeguarding children's privacy on digital platforms, drawing lessons from international litigation against Big Tech.

In this answer
  1. Existing safeguards: strengths
  2. Where it falls short
  3. Lessons from Big Tech litigation

Since K.S. Puttaswamy (2017) recognised informational privacy as intrinsic to Article 21, India has built a statutory scaffolding for children's data. Its text is ambitious, but its design assumptions and enforcement architecture leave the child user only partially protected.

Existing safeguards: strengths

  • Section 9, DPDP Act, 2023 requires verifiable parental consent before processing the data of anyone below 18 [1].
  • Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children — precisely the practices litigated abroad — with penalties extending to ₹200 crore [1].
  • The DPDP Rules, 2025, notified in November 2025, operationalise consent through DigiLocker-verified virtual tokens and due diligence on the claimed guardian [2].
  • IT Rules, 2021 add intermediary due-diligence and time-bound grievance redressal [3].

Where it falls short

  • The framework is consent-centric, not design-centric: it regulates advertising, not the engagement algorithms and infinite-scroll features that drive compulsive use.
  • No age-appropriate design code or statutory duty of care, unlike the EU's Digital Services Act approach.
  • Phased compliance over 18 months plus exemptions for education, healthcare and real-time safety defer protection for the interim [2].
  • The Data Protection Board is executive-appointed; penalties flow to the exchequer, with no compensation for the affected child, and no mandated independent audit of platform safety claims.

Lessons from Big Tech litigation

  • Meta's settlement of up to $17.1 billion with at least 47 U.S. States (August 2026) confirms that liability now attaches to addictive design and under-13 data collection [4].
  • Its independent auditor with expansive access, plus an injunction against misleading safety claims, models continuous oversight rather than a one-time fine [4].
  • Meta admitted no wrongdoing [4] — showing that money alone is weak deterrence; structural and disclosure remedies matter more.

India's framework is therefore adequate in principle but untested in practice. Codifying age-appropriate design, mandating independent algorithmic audits, and strengthening the Board's autonomy would convert paper rights into real protection — aligning digital governance with Article 21 and SDG 16.2 on ending abuse of children.

Sources

  1. 1The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYSection 9 verifiable parental consent; ban on tracking/targeted ads at children; Schedule penalty up to ₹200 crore
  2. 2Government notifies DPDP Rules, 2025 — PIBDigiLocker-based verifiable consent, exemptions, 18-month phased compliance
  3. 3IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, MeitYintermediary due diligence and grievance redressal
  4. 4Why is Meta's $17.1-billion settlement significant? — The Hindusettlement value and State coverage, independent auditor and injunction, absence of admission of wrongdoing

More from this note