At a glance
The DPDP Act’s consent rules reach beyond children: where a person with a disability has a lawful guardian, you must obtain that guardian’s verified consent before processing their personal data (Section 9). Rule 11 sets the bar — confirm the guardian was actually appointed by a court, a designated authority under the disability law, or a local level committee, not just accept a claim of guardianship. It’s a different, stricter verification than the parental-consent route, and it’s easy to miss.
Educational resource only. This explains the guardian-consent requirement for persons with a disability under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice.
The situation
Most discussion of “verified consent” under the DPDP Act focuses on children. But Section 9 quietly carries a second group with it: persons with a disability who have a lawful guardian. If your business serves anyone in that situation — and banks, insurers, healthcare providers, welfare and disability-service organisations routinely do — you owe a guardian-consent duty that most compliance checklists skip entirely. It’s a narrow requirement, but a real one, and the verification it asks for is unlike the parental version.
Who this actually applies to
This applies only where a person with a disability has a lawful guardian — not to every person with a disability. The distinction matters, and getting it wrong in either direction is a failure. A great many persons with disabilities manage their own affairs and give their own consent, exactly like any other adult — assuming otherwise is both wrong and disrespectful, and processing their data through a “guardian” they don’t have would itself be improper. The Section 9 guardian duty is triggered specifically when a person has been placed under a lawful guardian — a guardian formally appointed under India’s disability laws or by a court. In that situation, and only then, the guardian stands in for consent, and you must obtain and verify it before processing the person’s personal data. So the first question isn’t “does this person have a disability” — it’s “has a lawful guardian been appointed for them.”
Why Rule 11 is about verifying an appointment
A claim of guardianship isn’t enough — Rule 11 requires you to confirm the guardian was genuinely appointed, and by whom. Rule 11 of the DPDP Rules requires a Data Fiduciary to exercise due diligence to verify that the person claiming to be the guardian was appointed through a recognised legal route — specifically, by a court of law, by a designated authority under the Rights of Persons with Disabilities Act, 2016 (its Section 15 mechanism), or by a local level committee under the National Trust Act, 1999 (its Section 13 mechanism). The point is that lawful guardianship of an adult is a formal legal status conferred by one of those bodies — not something a family member can simply assert. Your verification has to reach the appointment itself: is there a real, legally-conferred guardianship behind this person’s claim to consent on another’s behalf? Taking “I’m their guardian” at face value doesn’t meet the bar.
How it differs from parental consent
Parental consent verifies an adult’s identity; guardian consent verifies a legal appointment — different checks, different evidence. The children’s route (Rule 10) is about confirming that the person consenting is an adult and is genuinely the child’s parent or guardian — largely an identity-and-relationship check. Rule 11 is about confirming a legal status: that a court or a designated disability-law authority actually appointed this person as guardian. So the evidence is different — you’re looking for the appointment order or the authority’s record, not just an adult ID. Treating the two as the same, or reusing a parent-style checkbox for guardianship, misses what Rule 11 is asking for. The two provisions sit side by side in Section 9 precisely because they cover different situations that both need consent given on someone else’s behalf, verified in their own way.
Building the check into your consent flow
Design for the case where a lawful guardian consents, without assuming it for everyone. In practice:
- Default to the person’s own consent. Persons with disabilities consent for themselves unless a lawful guardian has been appointed. Build the normal consent flow as the standard path, not a guardian flow imposed by assumption.
- Have a guardian path for when it applies. Where a lawful guardian is involved, route to a step that captures and verifies the guardianship — the appointment order or record from the court, the designated authority, or the local level committee.
- Verify the appointment, then record it. Confirm the guardian was appointed through one of the Rule 11 routes, and log what you verified and how — the same demonstrable-record discipline the rest of the Act runs on.
- Keep processing tied to the person’s benefit and purpose. Guardian consent authorises the processing the person actually needs — it isn’t a broader licence over their data.
FAQ
Does DPDP require guardian consent for every person with a disability?
No. It applies only where a person with a disability has a lawful guardian appointed under the law. Persons with disabilities who manage their own affairs give their own consent, like any adult — assuming a guardian where none exists is itself a mistake.
What does Rule 11 actually make me check?
That the person claiming to be the guardian was appointed by a court, a designated authority under the Rights of Persons with Disabilities Act, 2016, or a local level committee under the National Trust Act, 1999 — the legal appointment, not just a stated relationship.
How is this different from verifying parental consent?
Parental consent (Rule 10) mainly verifies that the consenting person is an adult and the child’s parent or guardian. Guardian consent (Rule 11) verifies a legal appointment of guardianship for a person with a disability — a status-verification, needing the appointment record rather than just an adult ID.
Which businesses does this affect most?
Any that process the personal data of persons with disabilities who have lawful guardians — commonly banks, insurers, healthcare providers, and welfare or disability-service organisations. If that’s part of your user base, this duty applies to that slice of it.
Is guardian consent a blanket authority over the person’s data?
No. It authorises the processing the person genuinely needs, for the stated purpose. It doesn’t hand the guardian — or you — an open-ended licence over their personal data.