Education & ed-tech DPDP · children's data

Verifiable guardian consent for learners under 18

An ed-tech platform where many learners are under 18, and the sign-up flow could not tell a guardian from a child.

Book a demo Last reviewed 18 September 2026

Illustrative scenario - not a named customer. Built from how Promiz works, to show the shape of a deployment.

What was the problem?

Learners signed up with an email address and a date of birth that nobody checked. A large share were minors, but the same analytics pixels, ad-retargeting tags and engagement nudges ran for every account. Parents sometimes created the account, sometimes the child did, and the platform had no record of which. When a school asked how the platform handled children’s data, the honest answer was that it handled it the same way as everyone else’s.

Section 9 requires verifiable consent from a parent or guardian before processing a child’s data, and forbids tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 sets out how the guardian is verified. Rule 12 and the Fourth Schedule exempt certain classes of processing, such as some educational activities, but the exemption has to be claimed for a purpose and recorded. The platform had no mechanism for any of this.

What was set up in Promiz?

  1. 01

    DigiLocker guardian check at sign-up

    When a learner’s date of birth shows they are under 18, the flow asks for a guardian. The guardian is verified as an adult through DigiLocker before any purpose beyond account creation is enabled.

  2. 02

    Child-restriction flags on every purpose

    Each purpose in the notice carries a child-restriction flag. Analytics, retargeting and behavioural nudges are marked restricted, so they never activate on an account flagged as a child’s, regardless of what the guardian ticks.

  3. 03

    Cookie scanner and tag blocking

    The scanner keeps the list of pixels and tags on the learning site current. Each tag is mapped to a purpose and stays blocked until that purpose is allowed, which for a child account means the restricted ones never fire.

  4. 04

    Fourth Schedule exemptions recorded per purpose

    Purposes that fall under an educational exemption are recorded as such at the organisation level and applied per purpose, so the platform can show which processing rests on the exemption and which on guardian consent.

  5. 05

    A privacy portal for guardians

    Guardians sign in with a one-time code, see every purpose for the child’s account, withdraw any of them, and raise access, correction or erasure requests that land in a queue with a deadline.

What changed?

  • Every child account now has a verified adult guardian on the record before optional processing begins.
  • Tracking and targeted advertising cannot run on a child account, because the restriction is enforced at the purpose and tag level rather than by policy.
  • The platform can answer a school’s question with the consent record, the exemption register and the tag map, instead of a statement of intent.
  • Guardians manage the child’s consents and requests themselves, with a clock on each request.

Outcomes are described qualitatively on purpose. Promiz does not publish figures from illustrative scenarios.

Bring one purpose. Leave with the proof.

A 30-minute session on your own use case.

  1. 5 min Find your DPDP gaps for that purpose
  2. 20 min Build the notice, collect consent, withdraw it, and close the task
  3. 5 min Download the receipt and verify the chain

Book your demo

Enter your website. We scan its cookies before the call and show you the results.

Reply within 1 business day