top of page

Children's Data Privacy On Edtech Platforms Under The Digital Personal Data Protection Act, 2023: Compliance Obligations And Enforcement Gaps.

Aug 4
2 min read

Updated: Aug 5

This article is written by Sarthak Bajaj, pursuing BBA.LL.B. (Hons.) from National University of Study and Research in Law (NUSRL), Ranchi.


The Digital Personal Data Protection Act, 2023 ('DPDPA' or 'the Act') is the first ever detailed statutory framework to govern personal data in India. Perhaps the most human stakes included in the provisions of Section 9 are the increased obligations imposed on data fiduciaries that process the personal data of children.


The pandemic years thrust the EdTech industry into a situation where millions of Indian children are now engaged with platforms that harvest, process and even monetise their data. Section 9 is tailored to this situation. The structural basis of the Act's child protection framework is problematic, however, as it is often difficult, if not impossible, to operationalise. There is a requirement for verifiable parental consent; however, there is no definition of how consent will be verified. The monitoring behaviour of children is not allowed; however, the term is not specified. There are no rules for EdTech in particular. What is the outcome? An Act which has good intentions and questionable feasibility in practice.


This article addresses the compliance requirements that Section 9 places on "EdTech" data fiduciaries, identifies areas of enforcement loopholes that currently leave Section 9 compliance hollow, and recommends adaptation of the GDPR and the United States' COPPA as models for reforming Section 9. The central point being made is that the DPDPA needs to be supplemented via secondary legislation, sector-specific regulatory guidance, and a specific EdTech rule if it is to be used as a real protection for children's data rights rather than a statutory ‘shoehorn’.


DISCLAIMER: The views and opinions expressed in this research article, submitted by students and/or other contributors in their personal capacity, are solely those of the author(s) and do not, in any manner whatsoever, reflect or represent the views, opinions, advice, or official position of PACTEDGE LEGAL LLP (“PACTEDGE”). PACTEDGE makes no representations or warranties, whether express or implied, as to the completeness, accuracy, reliability, or currency of any facts, data, analysis, or legal propositions contained herein and shall not, to the fullest extent permitted by applicable law, be liable for any loss, injury, damage, or consequence arising directly or indirectly from any reliance placed upon this publication. The entire contents of this research article, including without limitation its text, structure, compilation, selection and arrangement of material, are and shall remain the exclusive intellectual property of PACTEDGE LEGAL LLP, protected under applicable copyright and other intellectual property laws. No part of this publication may be copied, reproduced, stored in a retrieval system, transmitted, adapted, published, communicated to the public, distributed, or otherwise made available in any form or by any means, whether electronic, digital, mechanical, photocopying, recording or otherwise, nor shared or reposted on any platform or medium, without the prior written consent of PACTEDGE LEGAL LLP; any unauthorised use shall constitute infringement and may attract civil and/or criminal consequences, without prejudice to any other rights or remedies available to PACTEDGE LEGAL LLP in law or equity.




 
 
 

Recent Posts

See All

Comments


bottom of page