Confidential Dispatch
At a glance

The DPDP Act flatly bans tracking, behavioural monitoring, and targeted advertising directed at children under 18 — and unlike most of the Act, parental consent can’t switch it back on. In practice that means no behavioural analytics, no ad-targeting SDKs, and no personalised profiling aimed at a confirmed minor, whatever the parent agreed to. A narrow set of notified exemptions carves back safety-related location tracking and age-appropriate content filtering, but only for their specific purpose — not as a general licence to profile.

Educational resource only. This explains the ban on tracking and targeting children under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice.

The situation

Most of your growth and monetisation stack assumes you can watch what users do and act on it — analytics to understand behaviour, recommendation engines to keep them engaged, ad networks to make money. For users who are children, the DPDP Act switches a large part of that off, and it does so with a prohibition rather than a consent toggle. Understanding exactly what’s banned — and the few things that aren’t — is what keeps a general-audience product on the right side of the line once minors are in the mix.

What the rule actually prohibits

The Act draws a bright line: no behavioural monitoring of children, and no advertising targeted at them. Section 9 of the DPDP Act, alongside the consent requirement, prohibits a Data Fiduciary from undertaking tracking or behavioural monitoring of children, and from directing targeted advertising at them. It’s phrased as a flat prohibition on those activities, not a “high-risk processing you may do with extra safeguards.” Two distinct things are caught: the watching (building a behavioural picture of the child over time) and the acting on it commercially (using any profile to serve them ads tuned to who they are). A product can fall foul of the rule on either limb — you don’t need to be running ads to breach the tracking ban, and you don’t need elaborate profiling to breach the targeting ban.

Why parental consent can’t override it

This is the part teams miss: getting verifiable parental consent unlocks processing the child’s data, not profiling the child. Almost everything else in the Act runs on consent — get valid consent and you may process for the stated purpose. The tracking-and-targeting ban is deliberately different. It sits outside the consent mechanism, so even a parent who has genuinely, verifiably consented to your service cannot consent you into behaviourally monitoring or ad-targeting their child. The consent covers the processing the service actually needs; it is not a green light to profile. Designing on the assumption that “we’ll just get the parent to agree” is a dead end here — there’s no version of parental agreement that legitimises the banned activities.

What tracking and targeting mean in practice

The ban bites on ordinary product machinery, not just obvious ad-tech — here’s where it lands:

  • Behavioural analytics that build a per-user picture — event tracking tied to a child’s identity to model their habits, engagement patterns or preferences over time.
  • Recommendation and personalisation engines that profile the individual child to decide what to show them next, where the mechanism is behavioural monitoring of that child.
  • Third-party ad SDKs and tracking pixels in a child’s session — the advertising and retargeting infrastructure that follows a user to serve tuned ads.
  • Targeted advertising directed at the child, whether first-party or through an ad network, based on who the child is or what they’ve done.

What generally isn’t caught: aggregate, non-individual measurement that doesn’t build a profile of a specific child, and the processing genuinely required to deliver the service the child asked for. The test is whether you’re monitoring the individual child’s behaviour or targeting them — not whether data is touched at all. For confirmed-minor accounts, the safe default is to suppress the behavioural and ad-targeting layers entirely rather than trying to thread each one.

The narrow exemptions that carve back

A defined set of purposes is exempted — but the exemption is the purpose, not the sector. The Rules exempt certain uses from the tracking/targeting restriction where they serve a child’s genuine interest — notably real-time location tracking done for the child’s safety, and age-appropriate content filtering or access control. So a school-transport operator tracking a bus for child safety, or a service filtering content to keep it age-appropriate, has a defined basis for that specific processing. The limit that matters: the exemption attaches to the specific purpose actually being pursued, not to a sector you can label yourself with. “We’re broadly educational” or “it’s for their benefit” doesn’t convert commercial behavioural profiling into exempt safety processing. Match what you’re actually doing to the exempted purpose before relying on it, and don’t stretch a safety carve-out to cover engagement or monetisation.

What this means for your product

Treat a confirmed-minor account as a profiling-free zone by default, and make that the switch your age-assurance flips. The cleanest way to comply is architectural: when your age-assurance identifies a user as under 18, that flag should disable behavioural analytics, personalisation-by-profiling, and every ad-targeting integration for that account — automatically, not as a manual policy someone has to remember. Route the exempted purposes (a genuine safety-tracking feature, content filtering) through their own narrow, documented path rather than leaving the general profiling stack on. Done this way, the rule stops being a minefield you tiptoe through per feature and becomes one clear state your system can be in — and that state is also, not coincidentally, the one that keeps you clear of the Act’s highest penalty tier.

FAQ

Can I track or target a child if the parent consents?

No. The tracking, behavioural-monitoring and targeted-advertising ban sits outside the consent mechanism. Verifiable parental consent lets you process the child’s data for the service; it does not permit profiling or ad-targeting the child.

Does the ban stop me using any analytics at all for minors?

Not aggregate, non-individual measurement that doesn’t build a profile of a specific child. What’s prohibited is behavioural monitoring of the individual child. In practice, the reliable approach is to switch off per-user behavioural analytics for confirmed-minor accounts.

Are recommendation engines allowed for child users?

Only if they don’t rely on behaviourally monitoring or profiling the individual child. A recommendation mechanism built on tracking that child’s behaviour to personalise their experience is the kind of monitoring the rule targets.

What are the exemptions to the no-tracking rule?

Defined purposes serving the child’s interest — chiefly real-time location tracking for the child’s safety, and age-appropriate content filtering or access control. They apply to that specific purpose only, not to a whole sector or to commercial profiling dressed up as safety.

How is this different from the parental-consent requirement?

They’re two separate obligations. Verifiable parental consent is the gate to processing a child’s data at all; the no-tracking, no-targeting rule is a standing prohibition on specific activities that applies even after consent is validly obtained.

Reviewed by Confidential Dispatch Editorial Team
Last updated 19 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →