Site icon Privacy Desk

Why Safeguarding Personal Data of Children is Crucial for Businesses in India

28 September 2023
Chinmay Verma and Gajendra Maheshwari

In an increasingly digital world, personal data has become a valuable commodity. For businesses, the collection and processing of personal information are often vital to delivering products and services effectively. However, amid this data-driven landscape, there is a vulnerable demographic that requires special attention: children.

Safeguarding the personal data of children is not just an ethical imperative but also a legal necessity, particularly in India, where the data protection landscape is evolving rapidly.

In this article, we will delve into why it is crucial for businesses to prioritize the protection of children’s data and explore the implications of India’s data protection law – The Digital Personal Data Protection Act, 2023 (DPDPA) on businesses collecting data of children.

Why Protecting Children’s Data Matters

Protection of Children’s Data Under DPDPA

The DPDPA contains specific provisions that impose additional requirements for collecting and processing personal data of children. All individuals under the age of 18 years are covered within the definition of children under the DPDPA.

The key provisions concerning data of children are summarized below:

In addition to these specific provisions, business must adhere to other general provisions under the DPDPA to process personal data in a compliant manner. Some of the important general provisions are highlighted below in the context of the data pertaining to children:

Lastly, Businesses that are found to be in breach of the provisions regarding safeguarding personal data of children and not observing the prescribed obligations may attract a penalty of up to INR 200 Crore. Thus, businesses must initiate processes to ensure their compliance with the provisions of the DPDPA to reduce the risk of attracting a financial penalty.

Way Forward

As per recent reports, the Minister of State for Electronics and Information Technology has said that the Data Protection Board and additional guidelines will be put in place within one month. Large tech companies – that already have EU GDPR compliant measures in place, are likely to be given approximately 6 months to comply with DPDPA, whereas MSMEs will be given 12 months to fine tune their systems to comply with the DPDPA.

However, age gating measures, which are to be implemented by businesses that process personal data of children (to verify the age of the user) may be provided an extended timeline as developing the DPDPA compliant age verification mechanisms are technically complex processes.

Conclusion

Safeguarding the personal data of children is not just a legal requirement; it is also a moral obligation for businesses. India’s data protection law recognizes this by imposing specific obligations and responsibilities on organizations that handle children’s data.

Businesses collecting data of children must prioritize the compliance with these regulations to protect their reputation, maintain parental trust, and, most importantly, ensure the privacy and safety of children in the digital age. By doing so, they not only fulfil their legal obligations but also contribute to creating a safer online environment for the youngest members of society.

Disclaimer: This article is the copyright of Reinheads Consulting LLP. It is not intended to be a form of solicitation or advertising. The information contained herein is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is viewed or that it will continue to be accurate thereafter. No person should act on such information without appropriate professional advice based on the circumstances of a particular situation. This information is not to be considered as legal advice or opinion and the firm shall not be liable for any action taken by the user, directly or indirectly, on the basis of such material.


Exit mobile version