10 min read August 2026

Verifiable Parental Consent Is the Hardest Line in India's Privacy Law — And NGOs Sit Right on It

NGOs face a real challenge while trying to perform verified consent capture from a parent or legal guardian of a minor. This article highlights some of the options available for NGOs to comply.

Every NGO that touches a child's data, from an enrolment form for a nutrition programme, a health record at a mobile clinic, a beneficiary ID for a scholarship, a case file at a child protection shelter, has to answer a question the Digital Personal Data Protection Act, 2023 treats as non-negotiable: is the consent from a parent or a "legal" guardian and is that consent verifiable?

Section 9(1) of the DPDP Act says that before processing any personal data of a child, a data fiduciary must obtain the verifiable consent of the parent or lawful guardian. Rule 10 of the DPDP Rules, 2025 adds the operational detail: the fiduciary must adopt "appropriate technical and organisational measures" and exercise "due diligence" to confirm that the person identifying themselves as the parent is in fact an adult, identifiable if required by law. A child is anyone under 18 — a uniform, bright-line threshold, stricter than GDPR's 16 or COPPA's 13. Self-declaration ("I confirm I am the parent") does not meet the bar. Penalties for getting Section 9 wrong run up to ₹200 crore.

For a fintech or an e-commerce platform, this is a hard compliance problem. For an NGO, it's a hard compliance problem sitting directly on top of the population least equipped to clear the bar the law has set — and that combination is worth examining honestly, not just checking off.

The verification problem: proving the 'who'

Rule 10 gives data fiduciaries three routes to verify a parent: identity details the fiduciary already holds, identity details the parent voluntarily provides, or a "virtual token" issued by a regulated entity — in practice, this has coalesced around mobile OTP, Aadhaar-linked-mobile OTP, and DigiLocker-based identity checks. Each of these proves that someone controls a specific credential. None of them independently proves that this someone is the specific child's parent or legal guardian — there is no real-time government API a private data fiduciary can call to confirm a family relationship. What the law actually asks for is a defensible, traceable process — not courtroom-grade proof of parentage.

That gap matters more for NGO beneficiary populations than it does for a typical app's user base:

None of this is a reason to default to the weakest option. It's the reason "verifiable" has to be engineered as a layered, evidenced process rather than a single checkbox — and why NGOs, of all data fiduciaries, need to be honest about where their verification is strong and where it's a best-effort proxy.

The literacy and language problem: informed consent isn't solved once you've verified identity

DPDP consent has to be "free, specific, informed, unconditional, unambiguous, with a clear affirmative action." Verifying who clicked "agree" says nothing about whether they understood what they agreed to — and this is where the law itself acknowledges the gap. Guidance on the "best interests of the child" standard that data fiduciaries must apply explicitly lists inequalities in literacy of the parents as a factor to weigh, alongside age, disability, and social environment. That's a rare instance of a privacy law naming literacy as a legal design constraint, not just a UX nicety.

The scale of the gap is worth sitting with. Independent estimates put digitally literate households in rural India as low as a quarter to a third of the population; roughly two-thirds of women nationally are unable to send or receive an email. India also has 22 scheduled languages and hundreds of spoken dialects — a consent notice available only in English, or only in English and Hindi, is not meaningfully "clear and simple" to a parent in rural Odisha, a tribal belt in Chhattisgarh, or a migrant labour settlement, even if that parent is perfectly literate in their own language.

Put together, this means two separate failure modes can happen independently:

  1. Verification succeeds, comprehension fails. The right adult enters the right OTP, but never actually understood what "Health Records Processing" or "Customer Research & Surveys" meant, because the notice was in verbiage beyond the understanding of the data principal and also the concept of a "data processor" is not part of their frame of reference.
  2. Comprehension succeeds, verification fails. A field worker carefully explains the programme's data use in the parent's own language, the parent genuinely understands and agrees — but there's no auditable, traceable artefact proving that consent was captured from a verified adult, which is what Section 9 actually requires as evidence.

An NGO's consent architecture has to solve for both at once. Solving only the verification half produces technically compliant, ethically hollow consent. Solving only the comprehension half produces ethically sound, legally unverifiable consent. Either one, alone, leaves an NGO exposed.

Why this lands harder on NGOs than on most data fiduciaries

Four things compound here. First, NGO beneficiary bases overlap heavily with exactly the populations the digital-divide data describes — lower income, rural, lower female literacy, single or absent-parent households — which means the verification and comprehension gaps aren't edge cases for an NGO, they're closer to the median case. Second, the data categories NGOs typically process for children — health, nutrition, protection case history, disability status — sit in the same sensitive territory Section 9 was written to guard most tightly, so the cost of a consent failure isn't abstract; it's a vulnerable child's data moving without a defensible legal basis. Third, NGOs are usually the least resourced to build in-house identity verification infrastructure, which makes the self-declaration shortcut tempting precisely where the law is least forgiving of it. And finally, NGOs rely on donor funds for which they have to provide PII information in order to satisfy donor compliance. For this, consent verification is paramount.

There is no perfect solution — and the law doesn't pretend there is

It's worth saying plainly: no verification mechanism available today — to an NGO, a startup, or a large enterprise — proves parentage or guardianship with certainty. Aadhaar OTP proves control of a mobile number tied to an Aadhaar record. DigiLocker proves control of a government-issued digital identity. Neither cross-checks a family relationship against a civil registry, because that registry, in a form usable for real-time consent, doesn't exist for private data fiduciaries to query. What Rule 10 asks for is "appropriate technical and organisational measures" and "due diligence" — a defensible standard of care, evidenced and repeatable, not an unattainable guarantee.

That's the right way to frame any consent product in this space, including Flip's own: it demonstrates intent and due diligence, not infallibility.

What a good-faith, defensible consent flow looks like in practice

Bolt, the parental-consent module inside Flip, is a useful worked example of what "due diligence" can look like operationally, precisely because it doesn't try to claim more certainty than the underlying rails can support.

A few design choices worth calling out:

This is a defensible architecture for the identity-and-audit-trail half of the problem. It is explicitly not a claim that Aadhaar OTP proves guardianship, and it's not a solution to the comprehension half on its own.

What technology alone doesn't solve — and what NGOs still have to build around it

Two gaps remain even with a well-built verification flow, and NGOs should plan for both rather than treat the technology as the whole answer:

The honest takeaway

Section 9 sets one of the strictest bars in the DPDP Act deliberately — a ₹200-crore penalty ceiling, a bright-line 18-year threshold, no self-declaration, and prohibitions that apply even where consent exists. That severity is calibrated to who's exposed if it goes wrong. For NGOs, the populations most likely to trigger a genuine verification gap and the populations the law is built to protect are frequently the same people — which is exactly why "verifiable consent" can't be treated as a form field to fill in once and forget.

Getting this right doesn't mean waiting for a perfect verification technology that doesn't exist yet. It means building a layered, evidenced, purpose-specific process now — one that's honest about what it proves and what it doesn't — before a beneficiary programme scales to the point where retrofitting consent becomes far more expensive than designing for it from day one.

READY TO TAKE THE NEXT STEP?

Ready for DPDP-compliant consent management?

Flip, built on the Qila Blockchain, is India's blockchain-based Privacy-as-a-Service platform. Flip helps enterprises comply with the DPDP Act, GDPR, and CCPA through immutable consent management, tamper-proof audit trails, and API-first integration with existing enterprise systems.