HALVERTON & CO.

Technology & AI Law · 4 October 2026 · 7 min read

AI Chatbots, Companion Apps and Children: The DPDP Act’s Under-18 Rules

An infographic on the DPDP Act’s under-18 rules showing verifiable parental consent, age-appropriate design and the bans on tracking and targeted advertising for children.

Teenagers were among the first to adopt AI chatbots and companion apps, for homework help, for practising languages, and increasingly for company. That raises hard questions everywhere, but in India the legal question is unusually clear: under the Digital Personal Data Protection Act, 2023, anyone under 18 is a child, and processing their personal data comes with strict conditions.

This guide explains what the DPDP Act and DPDP Rules require for children’s data, why AI chatbots, companion apps and edtech products are most exposed, what verifiable parental consent looks like in practice, and the penalties and remedies involved. It builds on our DPDP Act compliance checklist.

Why the under-18 rule changes everything for AI products

Most international privacy laws set the digital age of consent at 13 to 16. The DPDP Act sets it at 18. Under the Act, a “child” is anyone who hasn’t completed 18 years, and for a child the “Data Principal” includes the parent or lawful guardian. That single definition brings most school and college-age users of AI chatbots, companion apps, gaming platforms and edtech tools inside the strictest part of the law.

For AI products, the problem is structural. Chatbots and companion apps work by collecting conversations, often deeply personal ones, and many improve their models or personalise responses using that data. When the user is 15 or 17, every one of those steps involves children’s data, and under the DPDP Act each step needs a lawful basis that works for children.

The main obligations apply from 13 May 2027, when the Act’s substantive provisions and the DPDP Rules come fully into force. That’s close enough that AI and edtech products launched today should be designed for them now.

What the DPDP Act requires for children’s data

Section 9 of the DPDP Act sets out three core rules. First, before processing any personal data of a child, a Data Fiduciary must obtain the verifiable consent of the parent or lawful guardian. Second, it must not undertake processing that is likely to cause any detrimental effect on the well-being of a child. Third, it must not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children.

Section 9 DPDP Act: the three core rules for children
RuleWhat it means for AI products
Verifiable parental consentAge assurance at sign-up, a way to verify the parent, and a provable consent record
No detrimental effectSafeguards against harmful content, manipulation and dependency, especially in companion apps
No tracking, monitoring or targeted adsNo behavioural profiling or ad targeting for under-18 accounts, subject to limited notified exemptions

The third rule is the one that collides most directly with AI products. Many companion apps and chatbots personalise responses by building profiles of users’ interests, moods and habits. Edtech platforms analyse learning behaviour. Free apps fund themselves through targeted advertising. When the user is a child, each of these may amount to tracking, behavioural monitoring or targeted advertising, which the Act prohibits, subject to limited exemptions notified by the government.

The DPDP Rules allow certain classes of Data Fiduciaries, such as clinical establishments, educational institutions and childcare providers, and certain purposes, such as protecting a child’s safety, to be exempted from some of these restrictions where processing is limited to what’s necessary. Check the exact classes and purposes in the Rules before relying on an exemption. A general-purpose AI chatbot or companion app is unlikely to fall within them, so it should assume the full rules apply.

“Verifiable” is the key word. Rule 10 of the DPDP Rules requires a Data Fiduciary to adopt appropriate technical and organisational measures to ensure that the person giving consent is the child’s parent, and that the parent is an identifiable adult. It allows verification using reliable identity and age details the Data Fiduciary already holds, a virtual token issued by an authorised entity, or services such as DigiLocker.

For AI chatbots and companion apps, this means a simple “I am over 18” checkbox won’t do. Products likely to be used by children need an age assurance step at sign-up, a route for verifying the parent where the user is under 18, and a way to record that consent so it can be proved later. Products not intended for children should still take reasonable steps to keep them out, and should respond quickly when they discover a child user.

Age assurance is also a product decision with trade-offs. Collecting more identity data to verify age creates its own privacy risks, so the aim should be the least intrusive method that is still reliable. Design choices also matter. Turning off behavioural profiling and targeted advertising for under-18 accounts, minimising conversation data retention, avoiding the use of children’s chats to train models, and adding well-being safeguards (such as limits on romantic or harmful content in companion apps) all reduce risk under the “detrimental effect” rule. Consent records should be structured so they can interoperate with the consent managers that begin registering in November 2026.

Companion apps, edtech and gaming: special risks

AI companion apps face the sharpest scrutiny. A product designed to form an emotional bond with a user, if used by a 16-year-old, raises questions about well-being, manipulation and dependency. Those are exactly the risks the “detrimental effect” rule is aimed at. Founders building companion products should consider whether to exclude minors entirely, and how to enforce that exclusion credibly. Where an AI agent acts autonomously in conversation, liability questions arise too; see our guide to AI agent liability in India.

Edtech platforms have a different problem. Their core users are children, so verifiable parental consent and the ban on tracking hit their business models directly. Schools that deploy AI tutors should check whether the platform, the school or both are Data Fiduciaries, and contracts should allocate responsibility clearly.

Parents and schools are also becoming more demanding customers. Procurement questionnaires from schools increasingly ask how an edtech or AI product handles children’s data, and a clear, documented answer is becoming a competitive advantage as much as a compliance requirement. Gaming and social apps with chat features should remember that other laws apply alongside the DPDP Act, including the IT Rules on harmful content, the Protection of Children from Sexual Offences Act, 2012 for any sexual content involving children, and consumer protection law on dark patterns aimed at young users. For real-money games, see the Online Gaming Act 2025. Synthetic images of minors raise separate risks; see our guide to deepfakes and personality rights. If you serve European users, the EU AI Act adds its own duties.

Penalties, remedies and quick answers

Breach of the additional obligations relating to children can attract a penalty of up to ₹200 crore under the Schedule to the DPDP Act, one of the highest penalty tiers in the law, alongside up to ₹250 crore for failing to take reasonable security safeguards. Parents can raise a grievance with the platform and, once that process is exhausted, complain to the Data Protection Board. Where an app exposes a child to harmful content or exploitation, parents can also report it on the National Cyber Crime Reporting Portal, approach the police and, in serious cases, seek urgent relief from the courts. For businesses, the strongest defence is evidence: age assurance records, parental consent logs, and documented decisions to switch off profiling and targeted advertising for minors.

Quick answers

Who is a child under the DPDP Act?

Anyone who hasn’t completed 18 years of age.

Can AI chatbots show targeted ads to teenagers in India?

No. The DPDP Act bans tracking, behavioural monitoring and targeted advertising directed at children, subject to limited notified exemptions.

What is the penalty for breaching children’s data rules?

Up to ₹200 crore under the Schedule to the DPDP Act, once the main obligations apply from 13 May 2027.

Related reading: opening a UK university campus in India.

Final word

At Halverton & Co., we advise founders, technology companies, investors and individuals on children’s data compliance, AI product design, edtech and DPDP disputes. We practise in Jharkhand, Maharashtra and before the Supreme Court of India, and act as fractional legal counsel for technology-driven businesses that need senior legal support without a full in-house legal team. Halverton & Co. is built on a simple idea: Where tech needs law! If this issue affects you or your business, write to us at office@halvertonandco.com, or get in touch, and we’ll help you work out where you stand.

This article reflects the law and developments reported up to early October 2026. It is for general information only and is not legal advice. Please take advice on your specific facts before acting.

Related practice area

Technology & AI Law

Contracts, data protection and AI policies for products that handle other people’s data.

View the practice area
Email this
  • An infographic titled Consent Managers Go Live showing what becomes mandatory from 13 November 2026 under Rule 4 of the DPDP Rules and what it means for data fiduciaries.
    Technology & AI Law

    Consent Managers Go Live: What November 2026 Means for DPDP Compliance

    On 13 November 2026, one specific part of India’s data protection law switches on: the registration of consent managers. It is not the DPDP compliance deadline most businesses face, but it changes the consent environment they will operate in.

    Nikhil Prasad Singh · 3 Oct 2026 · 7 min read
  • A founder writing out DPDP Act compliance steps on a large chart in a courtyard office, with a framed compliance plan certificate and data protection law books beside him.
    Technology & AI Law

    DPDP Act Compliance Checklist for Small Businesses and Startups in India

    If you collect a phone number on a WhatsApp order form or run an app with a sign-up page, India’s data protection law applies to you, whatever your size. Here is a practical checklist, the deadlines, the penalties and your remedies.

    Ritik Yadav · 5 Oct 2026 · 15 min read

This article is part of our Technology and AI law guides.

Questions

Write to us about what you are building.

This article is general information, not legal advice for your situation. If something here applies to your business, tell us briefly what you are working on.