Skip to main content
Home/Blog/India's DPDP Act in 2026: Consent, the Children's Advertising Ban and What Advertisers Must Build Before 2027
Back to Intelligence Hub
regulationIndiaRisk Level: high

India's DPDP Act in 2026: Consent, the Children's Advertising Ban and What Advertisers Must Build Before 2027

India's data-protection law bans targeted advertising to under-18s outright and rebuilds consent from the ground up — and its substantive obligations bite in 2027, so the work starts now.

Updated June 30, 2026· Originally published June 30, 202613 min readAuditSocials Research
TweetShare
Quick Answer

India's Digital Personal Data Protection Act, 2023 (the DPDP Act) is the country's comprehensive data-protection law, and its implementing Digital Personal Data Protection Rules were notified in November 2025 with a staggered commencement — which means that, as of mid-2026, the law is enacted but most of its substantive operational obligations are not yet enforceable, with the heaviest duties (notice standards, security, breach reporting, children's verifiable-consent procedures, Significant Data Fiduciary obligations and data-principal rights) scheduled to take effect around May 2027, after an 18-month implementation runway from the Rules' November 2025 notification. For advertisers, two features dominate. First, consent: the Act requires consent that is free, specific, informed, unconditional and unambiguous with a clear affirmative action, given against a plain-language notice, with no pre-ticked boxes and fresh consent if the purpose changes — which forces unbundling of broad 'marketing and analytics' permissions. Second, children: the Act defines a child as anyone under 18, requires verifiable parental consent before processing a child's data, bars processing likely to harm a child's well-being, and — critically — prohibits tracking, behavioural monitoring of children and targeted advertising directed at children, an absolute prohibition the Rules do not waive for advertisers (the narrow exemptions cover health, education and childcare, not marketing). The Act is enforced by the Data Protection Board of India, with penalties under its Schedule reaching up to ₹250 crore for a failure to take reasonable security safeguards, and ₹200 crore for breaches of the children's obligations. Cross-border transfers follow a negative-list model — permitted except to countries the government restricts, none notified as of mid-2026. Map the cross-border legal layer with the Legal Compliance Scan, screen audience and consent flows with the AI Compliance Audit, and track commencement on the Policy Change Tracker.

India's DPDP Act in 2026: Consent, the Children's Advertising Ban and What Advertisers Must Build Before 2027

What the DPDP Act Is and the 2027 Timeline

The Digital Personal Data Protection Act, 2023 is India's comprehensive personal-data law, and its implementing Digital Personal Data Protection Rules were notified in November 2025 after a draft consultation earlier that year. For advertisers, the most important practical fact is not just what the law says but when it bites: the Rules use a staggered commencement, so as of mid-2026 the law is enacted but most of its substantive obligations are not yet enforceable.

Under that phased structure, the early-commencing provisions cover the constitution and functioning of the Data Protection Board, while the operational compliance machinery — notice standards, security safeguards, breach reporting, the children's verifiable-consent procedure, Significant Data Fiduciary obligations and data-principal rights — is scheduled to take effect around May 2027, eighteen months after the Rules were notified in November 2025. The correct framing is therefore "build now, comply by 2027," not "nothing applies yet."

"A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
— Digital Personal Data Protection Act, 2023, Section 9"

This guide explains the consent and notice rules, the children's-data prohibitions that most affect advertising, the obligations on the largest data handlers, the penalty structure, and the cross-border model — and what global brands should be building now. Map the surrounding international picture with the EU compliance reference, and define terms in the compliance glossary.

Children's Data and the Advertising Ban

The children's-data rules are the single most consequential part of the DPDP Act for advertisers, because they go further than most comparable regimes and they are not waivable by parental consent.

The Children's Prohibitions

  • Under-18 definition: the Act defines a child as anyone who has not completed 18 years — a markedly higher threshold than, for example, the US COPPA standard of under 13.
  • Verifiable parental consent: before processing a child's personal data, a Data Fiduciary must obtain the verifiable consent of a parent or lawful guardian.
  • No detrimental processing: processing likely to cause a detrimental effect on a child's well-being is prohibited.
  • No tracking or targeted ads to children: a Data Fiduciary must not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children — an absolute prohibition.

Crucially, the Rules' exemptions from these restrictions are narrow and entity-or-purpose specific — covering uses such as healthcare, education and childcare — and there is no exemption for advertising. That means the prohibition on behavioural tracking and targeted advertising directed at under-18s stands without an advertiser carve-out, and parental consent does not unlock it. Because the definition reaches everyone under 18, any audience that may include older teenagers is affected, which makes age assurance and the suppression of behavioural targeting for under-18s a design requirement rather than an option. For the contrasting US children's regime, see the COPPA amendments guide, and screen youth-adjacent targeting and copy with the Keyword Risk Checker.

Significant Data Fiduciaries and Penalties

The Act imposes a heavier tier of obligations on the largest and highest-risk data handlers, and it backs the whole regime with substantial penalties adjudicated by a dedicated regulator.

SDF Obligations and the Penalty Schedule

ItemWhat it means
Significant Data Fiduciary (SDF)Designated by government on volume, sensitivity and risk; must appoint an India-based Data Protection Officer, conduct independent audits and Data Protection Impact Assessments, and exercise due diligence over its algorithms
Security-safeguards breachPenalty up to ₹250 crore for failing to take reasonable security safeguards
Breach-notification failurePenalty up to ₹200 crore
Children's-obligations breachPenalty up to ₹200 crore
SDF-obligations breachPenalty up to ₹150 crore
Residuary breachPenalty up to ₹50 crore

Penalties are imposed by the Data Protection Board of India after inquiry, and they are not automatic — the Board weighs the nature, gravity and duration of the breach and any mitigation. Because penalties are assessed per contravention, a single incident can implicate more than one Schedule entry, so the exposure compounds. The figures are large enough that a global brand designated as an SDF, or one that mishandles children's data, faces material risk once the substantive provisions commence. Track commencement and any SDF designations on the Policy Change Tracker, and audit data-driven decisioning with the AI Compliance Audit.

Cross-Border Transfers and Advertiser Impact

The DPDP Act takes a notably open approach to international data transfers compared with the EU, and combined with the consent and children's rules it defines a clear to-do list for global advertisers.

Transfers and the Build List

  • Negative-list transfers: the Act permits transferring personal data to any country except those the government notifies as restricted — the opposite of the EU's adequacy "whitelist" — and as of mid-2026 no restricted-country list has been notified, so transfers are broadly permitted, subject to sectoral rules.
  • Rebuild consent capture: move from bundled to specific, purpose-bound, revocable consent, with plain-language notices and easy withdrawal.
  • Implement age assurance: build verifiable parental consent and suppress behavioural targeting and tracking for under-18s across any audience that may include them.
  • Prepare governance: if likely to be designated an SDF, plan for an India-based DPO, audits, DPIAs and algorithmic due diligence.

The timeline is the strategic point: because the substantive obligations are scheduled to commence around 2027, brands have a genuine runway, but the consent re-architecture and the children's-data controls are non-trivial engineering and policy work that should start now rather than near the deadline. Treat the open transfer regime as current-but-revocable, since the government can notify restrictions later. For the European contrast on transfers and consent, see the EU compliance reference, and map the multi-jurisdiction picture with the Legal Compliance Scan.

DPDP Compliance Checklist

  • [ ] Mapped Indian personal-data flows across marketing, CRM and analytics
  • [ ] Replaced bundled consent with specific, informed, purpose-bound opt-ins
  • [ ] Removed pre-ticked boxes and implemented easy consent withdrawal
  • [ ] Built plain-language notices itemising data, purposes and rights
  • [ ] Implemented verifiable parental consent for any processing of under-18 data
  • [ ] Suppressed behavioural tracking and targeted advertising directed at under-18s
  • [ ] Confirmed no reliance on a non-existent advertising exemption for children's data
  • [ ] Planned SDF governance (India-based DPO, audits, DPIAs, algorithm due diligence) if likely designated
  • [ ] Treated cross-border transfers as open but monitored for any restricted-country list
  • [ ] Confirmed the current Rules and commencement dates against official MeitY and Board sources

Frequently Asked Questions

Is India's DPDP Act in force, and what applies in 2026 versus 2027?
India's Digital Personal Data Protection Act, 2023 is enacted law, and its implementing Digital Personal Data Protection Rules were notified in November 2025, but the regime uses a staggered commencement, so as of mid-2026 the law exists while most of its substantive operational obligations are not yet enforceable — the heaviest duties are scheduled to take effect around May 2027, which makes 2026 a preparation year rather than a compliance deadline. This timing nuance is the single most important thing for advertisers to get right, because it is easy to either overreact (assuming everything applies immediately) or underreact (assuming nothing applies until 2027 and so doing nothing). The accurate position is in between. Under the phased structure, the provisions that commenced early concern the constitution and functioning of the Data Protection Board of India — the regulator that will adjudicate and enforce — so the enforcement body is being stood up. The operational compliance machinery, however, commences later: the notice standards, security-safeguard requirements, breach-notification process, the verifiable-consent procedure for children, the additional obligations on Significant Data Fiduciaries, and the data-principal rights are scheduled to take effect around May 2027, eighteen months after the Rules were notified in November 2025. That means the consent re-architecture, the children's-data controls and the governance obligations that will define day-to-day compliance are on a 2027 horizon. For advertisers and global brands, the strategic implication is a genuine but finite runway. The work required to comply — unbundling consent, building specific purpose-based opt-ins and plain-language notices, implementing verifiable parental consent and suppressing behavioural targeting for under-18s, and standing up SDF governance if designated — is substantial engineering and policy effort that cannot be completed overnight, so starting in 2026 is the prudent course even though the obligations are not yet enforceable. It also means brands should not make irreversible product or marketing decisions on the assumption that the rules are already live, nor delay foundational work until they are. Because the exact commencement schedule and the precise content of the Rules govern, and because dates and details can be refined, confirm the current status against official sources from the Ministry of Electronics and Information Technology and the Data Protection Board rather than relying on a summary. Track commencement and any further notifications on the Policy Change Tracker, and begin mapping data flows with the AI Compliance Audit. The organizing principle is that the DPDP Act is enacted but its substantive obligations commence around 2027, so 2026 is for building consent, children's-data and governance controls rather than a moment when compliance is already mandatory.
What does the DPDP Act require for consent and notice?
The DPDP Act requires that personal data be processed on the basis of consent that is free, specific, informed, unconditional and unambiguous, given through a clear affirmative action and limited to the personal data necessary for the specified purpose, and that this consent be given against a plain-language notice — a standard high enough that most existing bundled marketing-permission flows will need to be rebuilt. Each element of the consent definition does work. 'Free' means consent cannot be coerced or made a condition of unrelated service. 'Specific' means it must relate to defined purposes rather than a catch-all, so a broad 'marketing and analytics' acceptance fails the test. 'Informed' means the individual must understand what they are agreeing to, which is why consent is tied to a notice. 'Unconditional' and 'unambiguous with a clear affirmative action' rule out implied consent, pre-ticked boxes and inaction as forms of agreement — the person must take a positive step. And the data-minimisation tie-in — consent limited to the data necessary for the specified purpose — means an organisation cannot use a single consent to justify collecting more than that purpose requires. The notice requirement complements this: a Data Fiduciary must give the individual a standalone, plain-language notice that itemises the personal data being collected, the specific purposes for which it will be processed, and how the individual can withdraw consent, exercise their rights and lodge a complaint. Two further rules shape ongoing operations. First, withdrawal of consent must be as easy as giving it, so a one-click opt-in cannot be paired with a burdensome opt-out. Second, if the purpose of processing changes, fresh consent is required for the new purpose; consent given for one purpose cannot be silently extended to another. For advertisers, the cumulative effect is that the familiar pattern of obtaining one broad consent at signup to cover retargeting, CRM marketing, personalisation and analytics will not survive, because that bundled approach is neither specific nor purpose-limited. Compliant practice requires separating purposes, obtaining specific informed consent for each, capturing only the data each purpose needs, and providing straightforward withdrawal. The Act also envisions Consent Managers — registered intermediaries through which individuals can grant, manage and withdraw consent in an interoperable way — as part of the consent infrastructure, with that framework commencing later in the rollout. Build and test these flows now rather than at the deadline. Screen consent and audience-building flows with the AI Compliance Audit, and map how India's consent rules sit alongside other regimes with the Legal Compliance Scan. The organizing principle is that DPDP consent must be free, specific, informed, unconditional and unambiguous against a plain-language notice, with easy withdrawal and fresh consent on purpose change — which forces the unbundling of broad marketing permissions.
Does the DPDP Act ban targeted advertising to children?
Yes — the DPDP Act prohibits a Data Fiduciary from undertaking tracking or behavioural monitoring of children or targeted advertising directed at children, and because the Act defines a child as anyone who has not completed 18 years of age, this is a far-reaching prohibition that applies to everyone under 18, not just young children, and it is not unlocked by obtaining parental consent. This is the provision that most directly reshapes advertising practice in India, and it is stricter than many comparable regimes in two respects. First, the age threshold is high: where the US COPPA framework focuses on under-13s, the DPDP Act treats anyone under 18 as a child, so the prohibition reaches the entire teenage population, including 16- and 17-year-olds who are often within scope of mainstream advertising elsewhere. Second, the prohibition on tracking, behavioural monitoring and targeted advertising directed at children is absolute in the sense that it is not a default that parental consent can override — parental consent is required to process a child's data at all under the verifiable-parental-consent rule, but it does not create a route to then behaviourally target or track that child. The Act layers several protections for children together: before processing a child's personal data, a Data Fiduciary must obtain the verifiable consent of a parent or lawful guardian; it must not undertake processing likely to cause a detrimental effect on a child's well-being; and it must not track or behaviourally monitor children or direct targeted advertising at them. The implementing Rules do provide some carefully limited exemptions from the children's restrictions, but these are narrow and tied to specific entities and purposes — such as healthcare providers, educational institutions and childcare services acting for healthcare, education or child-safety purposes — and, importantly, there is no exemption for advertising. That absence is decisive: advertisers cannot rely on any carve-out to behaviourally target or track under-18s. The practical implications are significant. Any audience that may include under-18s must have behavioural targeting and tracking suppressed for those users, which in turn makes robust age assurance a design requirement rather than an optional safeguard, because an advertiser that cannot tell who is under 18 cannot reliably honour the prohibition. Brands marketing products with teenage appeal, or operating broad-audience campaigns, need to engineer for this rather than assume it will not affect them. For the contrasting and narrower US approach, see the COPPA amendments guide, and screen youth-adjacent targeting and creative with the Keyword Risk Checker. The organizing principle is that the DPDP Act bans tracking, behavioural monitoring and targeted advertising directed at anyone under 18, with no advertising exemption and no parental-consent override, so age assurance and the suppression of behavioural targeting for under-18s are mandatory.
What are the penalties under the DPDP Act and who enforces it?
The DPDP Act is enforced by the Data Protection Board of India, which adjudicates breaches and imposes monetary penalties under the Act's Schedule, and those penalties are substantial — reaching up to ₹250 crore for a failure to take reasonable security safeguards, with other breaches carrying their own ceilings, so the financial exposure once the substantive provisions commence is material, particularly for large data handlers and for any organisation that mishandles children's data. The penalty Schedule sets different maximums for different categories of breach. The highest ceiling, up to ₹250 crore, attaches to a failure to take reasonable security safeguards to prevent a personal-data breach, reflecting the seriousness with which the regime treats security. A failure to notify the Board or affected individuals of a data breach carries a ceiling of up to ₹200 crore. Breaches of the additional obligations relating to children — the verifiable-parental-consent requirement and the prohibitions on detrimental processing and on tracking and targeted advertising directed at children — carry a ceiling of up to ₹200 crore, which underscores how seriously the children's protections are backed. Breaches of the additional obligations imposed on Significant Data Fiduciaries carry a ceiling of up to ₹150 crore, and there is a residuary category for other breaches of the Act or Rules with a ceiling of up to ₹50 crore. Two structural points matter for assessing real-world exposure. First, the penalties are not automatic: the Data Protection Board imposes them after an inquiry, and in determining the amount it weighs factors such as the nature, gravity and duration of the breach, the type of personal data affected, and whether the organisation took mitigating action or exercised due diligence — so a strong compliance posture can reduce exposure even where a breach occurs. Second, because penalties are assessed per contravention, a single incident can implicate more than one entry in the Schedule, meaning the exposures can stack rather than being capped at one figure. For a global brand, the most acute risks are being designated a Significant Data Fiduciary (which adds obligations and a dedicated penalty exposure) and any mishandling of children's data (given the ₹200 crore ceiling and the strict, no-exemption prohibitions). The prudent response is to treat security safeguards, breach-response readiness and children's-data controls as the highest priorities in the compliance build, since they carry the largest penalties. Confirm the exact Schedule figures and the Board's procedures against official sources because the detail governs. Track Board designations and enforcement on the Policy Change Tracker, and stress-test cross-jurisdiction exposure with the Legal Compliance Scan. The organizing principle is that the Data Protection Board of India imposes Schedule-based penalties up to ₹250 crore for security failures and ₹200 crore for children's-data breaches, assessed per contravention and after inquiry, so security and children's-data controls are the highest-stakes priorities.
How does the DPDP Act handle cross-border data transfers, and what should global advertisers build now?
The DPDP Act handles cross-border data transfers through a negative-list, or 'blacklist,' model — personal data may be transferred to any country except those the central government specifically notifies as restricted — which is the opposite of the European Union's adequacy 'whitelist' approach, and as of mid-2026 no restricted-country list has been notified, so transfers out of India are broadly permitted, subject to any sectoral rules and to future change. This open posture is advertiser-friendly relative to the EU regime, because it does not require an adequacy finding or a transfer mechanism for each destination; the default is that transfer is allowed unless the government has restricted the specific country. However, advertisers should treat this as current-but-revocable rather than permanent, because the government retains the power to notify restrictions later, and sector-specific regulators (for example in financial services) may impose their own localisation or transfer constraints that sit alongside the DPDP framework. So the right planning assumption is openness today with the possibility of tightening. Beyond transfers, the more demanding work for global advertisers is the substantive build that the Act requires, and because the obligations are scheduled to commence around 2027 there is a real but finite runway to complete it. The build list has four main elements. First, rebuild consent capture: move from broad, bundled permissions to specific, informed, purpose-bound and revocable consent given against plain-language notices, with withdrawal as easy as granting, and fresh consent when purposes change. Second, implement children's-data controls: build verifiable parental consent for processing under-18 data, and suppress behavioural tracking and targeted advertising directed at under-18s across any audience that may include them, which in practice requires robust age assurance because the under-18 definition is broad and there is no advertising exemption. Third, prepare governance for the heightened tier: if the organisation is likely to be designated a Significant Data Fiduciary, plan for an India-based Data Protection Officer, independent audits, Data Protection Impact Assessments and due diligence over algorithmic systems. Fourth, stand up data-subject-rights and breach-response processes so the organisation can honour access, correction and erasure requests and notify breaches when those provisions commence. The strategic message is that the consent re-architecture and the children's-data controls are non-trivial engineering and policy initiatives that should begin in 2026, not be deferred to the deadline, while the transfer position can be treated as open but monitored. For the European contrast on transfers and consent, see the EU compliance reference, and map the multi-jurisdiction build with the Legal Compliance Scan. The organizing principle is that DPDP transfers are open by default under a negative-list model with no restricted countries yet notified, while the real work for global advertisers is rebuilding consent, implementing children's-data controls and preparing governance ahead of the 2027 commencement.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Meta Rejection Predictor first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#India DPDP#Data Protection#Consent#Children's Privacy#Targeted Advertising#Cross-Border Data#Data Fiduciary#Ad Compliance#India Regulation#2026 Policy#Advertisers#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources