Children's Data Protection in the Age of EdTech and Platform Design
Introduction : A child using a learning application, a school attendance tracker, a voice-activated toy or a social platform generates a surprisingly broad set of personal data: an identity profile, created when accessing the platform; behavioural data from each interaction with the app; educational data, including performance and areas of difficulty; voice data, if the child interacts via voice with toys or learning assistants; and location data, stored on the device the child uses to access the platform. Some of this data is collected explicitly for its learning and protective functions: attendance tracking, educational performance analysis, voice-to-text interaction, filtering of inappropriate content based on location or age. The same data, however, can be used without explicit consent to increase engagement, serve targeted advertising, or build profiles of children. Children's data protection law addresses the ways in which such data may and may not be collected and processed by an entity.
This blog discusses the ways in which India's Digital Personal Data Protection Act, 2023, and international data protection laws address age verification, parental consent, targeted advertising, profiling and the tension between data minimisation and retention in platforms used by children. It also provides a compliance checklist for schools, application developers and platform operators.
Legal Provisions
A. The Digital Personal Data Protection Act, 2023
Section 2(f) of the DPDP Act defines a 'child' as an individual who has not completed the age of eighteen years – a relatively high threshold compared to international standards, and potentially encompassing a substantial proportion of teenage users. Section 9(1) of the DPDP Act stipulates that a Data Fiduciary processing personal data of a child shall obtain verifiable consent of the parent or lawful guardian. Section 9(2) prohibits any processing of a child’s personal data that is likely to have any detrimental effect on the wellbeing of the child. Most notably, Section 9(3) of the DPDP Act prohibits the tracking, behavioural monitoring and targeted advertising to children, with limited exceptions for verifiably safe use-cases such as healthcare, educational or child-safety services.
Section 9(4) allows the Central Government to notify exemptions or reduced processing obligations for certain Data Fiduciaries or processing activities for children, including those outlined in Section 9(3). The manner in which verifiable parental consent is obtained falls under the jurisdiction of rules the government may issue under the Act; rules likely to affect Section 9’s implementation include the Consent Manager framework, separate subsections of which may apply to children’s data processing.
B. International Comparisons: COPPA, GDPR Article 8, Children’s Code
The United States’ Children’s Online Privacy Protection Act (COPPA) of 1998 and its implementing regulations, 16 CFR Part 312, apply to operators of websites or online services directed to children under the age of 13, and require parental consent prior to collecting personal information from said children, with specific methods of verification outlined in the FTC’s COPPA Rule. Article 8 of the GDPR stipulates the default age of consent to information-society services as sixteen, with member states able to lower the threshold to thirteen, and requires controllers to make ‘reasonable efforts to verify’ parental consent, with no specific methods of verification mentioned. The UK’s Age Appropriate Design Code, also known as the Children’s Code, is a statutory code of conduct for online service providers under the Data Protection Act, 2018, targeting services ‘likely to be accessed by children’ and mandating, among other things, high privacy settings by default, absence of tracking or profiling unless safety features, appropriate safeguards or parental consent are present, and a ban on ‘nudge techniques’.
Legal Analysis
A. Age Verification: The Threshold Problem
Age verification presents a dilemma for platforms and applications: determining a user’s age, particularly in regards to whether they are a child, usually requires obtaining more data than would be necessary for a general audience, potentially presenting a privacy risk to the user. A self-reported age has limited value as a verification method, but can allow for broad inferences about a user’s maturity or potential receptivity to certain topics; a government-issued ID or a biometric scan, on the other hand, is considerably more intrusive, while presenting only marginal benefits in terms of security. The tension between the value of data and the potential harm to privacy is acute in the case of children, particularly in light of Section 9(3)’s near-total prohibition on profiling and targeted advertising to minors. It is notable that India’s DPDP Act uses a relatively high threshold of 18 years for determining a child, compared to COPPA’s 13 and the GDPR’s proposed range of 13 to 16. This implies that a significantly larger number of users on any given platform would be considered children and would therefore be entitled to the additional protections of Section 9.
While the DPDP Act does not explicitly prescribe a method of age verification, the rules the government may issue on parental consent and verifiable age may affect an entity’s ability to comply with the Act. Entities must therefore identify a method of age verification which would be appropriate for their scale and risk level: while high-profile corporations may use biometric scans or government-issued ID, a small business may find such an approach unviable. The FTC’s COPPA Rule implements a similar balancing act, mandating reasonable, but not specific, verification methods and outlining a Safe Harbor program with explicitly approved options.
B. Parental and Guardian Consent: What Makes Consent ‘Verifiable’
The DPDP Act’s Section 9(1) requirement of verifiable parental consent sits between the GDPR’s relatively lenient ‘reasonable efforts’ and COPPA’s extensive enumeration of permissible verification methods. The latter act’s Safe Harbor program (16 CFR § 312.5(b)) essentially codifies the industry practices of verifiable parental consent, including mailing or faxing a consent form, credit-card or other payment-system verification, toll-free phone call verification with human operators, video-conference verification, and checking government-issued ID against a database and deleting it afterwards. Similar principles may be extrapolated to the creation of the Consent Manager, a framework designed by the DPDP Act’s rules-making committee to manage parental consent, likely with an emphasis on technology-driven solutions.
While COPPA’s Safe Harbor and the GDPR’s ‘reasonable efforts’ do not specify particular technologies or methods, platforms utilising them have to consider their practical implementation and the likelihood of their being deemed satisfactory by regulators. In particular, platforms which process a significant volume of children’s data should err on the side of caution when devising parental-consent mechanisms, and consider COPPA’s explicitly approved methods as a baseline, even if operating within the GDPR’s more flexible framework.
C. Targeted Advertising and Behavioural Profiling
Under Section 9(3), the DPDP Act explicitly prohibits tracking, behavioural targeting and targeted advertising to children with limited exceptions, making its provisions considerably stricter than those of COPPA or the GDPR. While COPPA allows for targeted advertising with parental consent and the GDPR only restricts automatically targeted advertising with no explicit prohibition, the DPDP Act considers such practices prohibited by default, with potential exceptions carved out for specific use-cases on a per-platform basis. Targeted advertising to children has been a frequent source of regulatory intervention: the FTC’s actions against Google / YouTube and Musical.ly (TikTok) are prominent examples of targeted advertising and tracking of children resulting in heavy fines and restrictions. It is therefore incumbent upon platforms processing children’s data to consider advertising to minors as a restricted activity, even when explicitly permitted by the COPPA or GDPR rules.
D. Retention and the Excessive Collection Problem
Data minimisation and storage limitations are incompatible with the requirements of schools and educational platforms to retain certain data about students’ performance, behaviour and attendance for extended periods of time. While Section 8(7) of the DPDP Act requires a Data Fiduciary to delete personal data upon the cessation of the specific purpose for which it was collected, as well as any retention which exceeds the requirements of law, there are few explicit limitations on the retention of children’s data. In particular, schools bound by education-specific regulations to retain data about students’ academic performance and behaviour may find the DPDP Act’s requirements compatible with their obligations. However, any entity which collects data about children’s behaviour, voice or location must carefully assess its retention policies: the DPDP Act does not prohibit the retention of data itself, only the retention beyond the cessation of purpose or beyond legal requirements. Storage limitations must therefore be applied on a per-data category basis, with entities which have obtained extensive information about a child’s behaviours, voice or location considering the imposition of shorter retention periods.
E. The Accessibility-Safety-Minimisation Trilemma
The DPDP Act and international regulations do not always distinguish between processing of children’s data which is beneficial to them and processing which is merely incidental to an adult user’s activity. Certain features, such as the ability to utilise voice assistants or utilise speech-to-text technology, have been developed primarily for children and can present a safety risk if not managed correctly. However, the same tools can be crucial to a child with physical disabilities who is unable to type or speak clearly. This creates a dilemma: Section 9 of the DPDP Act, which prohibits profiling of children, might be interpreted to prohibit the use of voice assistants or other tools which collect voice data to determine a child’s speech patterns. Section 9(4), however, explicitly states that verifiably safe processing uses are not subject to the same restrictions, which could be utilised as a basis for creating exemptions for accessibility features. Similar arguments could be made for adaptive learning systems or other tools which are beneficial for children, particularly those with special needs. The DPDP Act’s rules-making process will therefore play an important role in defining the boundaries of processing children’s data in such contexts.
Relevant Case Laws
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India): The nine-judge bench of the Supreme Court of India unanimously ruled that the right to privacy is a fundamental right, protected under the Constitution’s Article 21. This provided the judiciary with a legal basis for upholding the DPDP Act and regulating processing of children’s data, in particular those under the age of 18 who are unable to give informed consent or do not have any alternative.
United States v. Google LLC and YouTube, LLC, No. 1:19-cv-2642 (D.D.C. 2019): The FTC and the Attorney General of New York secured a $170 million settlement — $136 million fine from Google, with 34 million going to the State of New York, as a result of COPPA violations. Specifically, YouTube had collected persistent identifiers from users of child-directed content without parental consent and used the information to serve targeted advertisements. The court ordered YouTube to modify its policies in regards to child content, including implementing channel-level identification and disabling targeted advertising features on child-oriented channels.
United States v. Musical.ly, Inc. (operating as TikTok), No. 2:19-cv-1439 (C.D. Cal. 2019): The FTC secured a 5.7 million fine from Musical.ly, the precursor to TikTok, for its COPPA violations. The company had collected personal information from users under the age of 13 without parental consent and failed to respond to parental deletion requests.
United States v. Epic Games, Inc., No. 5:22-cv-00518 (E.D.N.C. 2022): The FTC secured a $275 million penalty for COPPA violations in the Fortnite video game, alleging that Epic collected personal information from child players without parental notice or consent and enabled default voice and text chat that exposed children to harassment, alongside a separate $245 million judgement against Epic Games for its violations of COPPA and other FTC Acts. The COPPA-related damages were the largest ever imposed by the FTC in a single case.
Information Commissioner’s Office, Monetary Penalty Notice: TikTok Information Technologies UK Limited and TikTok Inc. (2023) (United Kingdom): The Information Commissioner’s Office fined TikTok £12.7 million for its repeated violations of the UK GDPR, specifically the lack of verifiable parental consent mechanisms and the use of default public settings for child accounts.
Data Protection Commission (Ireland), Decision in the Matter of TikTok Technology Limited, Inquiry Reference IN-21-9-1 (September 2023): The Data Protection Commission of Ireland fined TikTok €345 million for its violations of the GDPR, including the use of default publicly accessible privacy settings, the ‘family pairing’ feature which allowed an adult account to control a child account without verifying the relationship, and the use of ‘dark patterns’ for child accounts in breach of the data-protection-by-design obligations of Article 25 GDPR.
Compliance Checklist
The requirements discussed in this blog translate into specific recommendations depending on whether an entity is a school, an app developer or a platform operator. As such, this section contains three separate checklists, each addressing the most pressing compliance concerns for a given entity.
1. For Schools and Educational Institutions
Establish a list of EdTech tools used by the school or educational institution, and ensure that parental consent is obtained for each of them, either on an individual basis or through a blanket approval for all services provided by the entity; consider contracting language which prohibits targeted advertising and behavioural profiling by any of the organisation’s EdTech partners; determine retention schedules for each category of data collected about students, rather than operating on an indefinite, automatic retention basis; appoint a representative within your organisation tasked with reviewing EdTech contracts or new tools, ensuring the institution’s data protection compliance.
2. For App Developers
Establish an age assurance procedure for your application or platform which would be appropriate for the risk level; consider implementing parental consent procedures which would satisfy the requirements of the DPDP Act and similar regulations, particularly regarding verifiability; disable behavioural tracking, profiling and targeted advertising by default for any child account, and consider those restrictions as permanently applicable, even after the user leaves said age bracket; establish defaults for location tracking and microphone access which would apply to child accounts, and only enable the permissions if explicitly requested by the user (ideally with separate consent); apply data-minimisation principles in your application or website, collecting only the data necessary for a given functionality rather than using broader permissions and utilising all available data for personalisation.
3. For Platform Operators
Conduct a data-protection impact assessment for any features involving profiling, recommendation algorithms or targeted advertising for a mixed audience of adults and children; review third-party SDKs which utilise analytics or advertising features and ensure that they do not collect data from child accounts, since responsibility for the collection practices of third-party vendors falls on the platform operator; ensure that your platform’s defaults for children, teenagers and young adults are consistent with the Children’s Code, even if operating in a jurisdiction which does not explicitly adopt them, and consider applying stricter restrictions than mandated by local laws; establish individual retention policies for each category of data collected about children on the platform, and set up automated deletion of that data upon the expiry of retention periods or individual user requests.
Conclusion
The issues discussed in this blog are not separate compliance concerns which can be addressed in isolation. Age assurance and parental consent, targeted advertising, data retention and the accessibility-safety dilemma are deeply interconnected, and an issue in one area often creates complications in another. A subpar age verification mechanism defeats many of the improvements in other areas. Similarly, a weak parental consent mechanism creates difficulties for every aspect of children’s data processing. The issues of targeting and profiling of children through advertising are frequent sources of regulatory intervention – the FTC’s enforcement actions against Google / YouTube and Musical.ly / TikTok are examples of such intervention.
The same issues apply to platforms utilising analytics or advertising SDKs which collect data from children without parental consent or with insufficient safeguards. The DPDP Act presents stricter requirements than many of the international equivalents, particularly COPPA, and entities which operate across multiple jurisdictions should be mindful of the requirements of each. However, the recommendations of this checklist should allow any organisation to meet the requirements of the DPDP Act and international equivalents, including those pertaining to parental consent, targeting, data minimisation and retention.
Author: Saumitra Yadav in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at Khurana & Khurana, Advocates and IP Attorney
Endnotes
Digital Personal Data Protection Act, 2023, s. 2(f) (India).
Digital Personal Data Protection Act, 2023, s. 9(1) (India).
Digital Personal Data Protection Act, 2023, s. 9(2) (India).
Digital Personal Data Protection Act, 2023, s. 9(3) (India).
Digital Personal Data Protection Act, 2023, s. 9(4) (India).
Digital Personal Data Protection Act, 2023, s. 8(7) (India).
Children's Online Privacy Protection Act, 1998, 15 U.S.C. §§ 6501–6506; Children's Online Privacy Protection Rule, 16 C.F.R. Part 312 (United States).
General Data Protection Regulation (EU) 2016/679, art. 8.
Information Commissioner's Office, Age Appropriate Design Code: A Code of Practice for Online Services, issued under the Data Protection Act, 2018 (United Kingdom).
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).
United States v. Google LLC and YouTube, LLC, No. 1:19-cv-2642 (D.D.C. 2019).
United States v. Musical.ly, Inc., No. 2:19-cv-1439 (C.D. Cal. 2019).
United States v. Epic Games, Inc., No. 5:22-cv-00518 (E.D.N.C. 2022).
Information Commissioner's Office, Monetary Penalty Notice: TikTok Information Technologies UK Limited and TikTok Inc. (2023) (United Kingdom).
Data Protection Commission (Ireland), Decision in the Matter of TikTok Technology Limited, Inquiry Reference IN-21-9-1 (September 2023).




Comments