
Introduction
WhatsApp has started asking some users in India to confirm they are over eighteen before they can keep using the app. On its face, it looks like nothing more than another screen to tap through, the kind of prompt people barely register before moving on. But the timing tells a different story. This age declaration prompt sits directly on the path toward Section 9 of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the provision that governs how platforms may process a child’s personal data. It also exposes a gap that every consumer platform operating in India will eventually have to close. Asking someone their age is not the same as verifying it. Self-declaration, however common as an industry default, was never built to satisfy a law that uses the word verifiable.
The Limits of Self-Declaration Under the Act
A date of birth field that a user fills in on their own only ever captures a claim, not a fact. Nothing is stopping a thirteen-year-old from typing in a birth year that clears the threshold, and the platform has no real way of knowing whether the person on the other end is who they say they are. Platforms have relied on this model for years because it is cheap, frictionless, and defensible as a good faith effort under regimes that do not demand more.
The DPDP Act demands more. Section 9 requires a Data Fiduciary to obtain verifiable consent from a parent or lawful guardian before processing the personal data of anyone below eighteen. Rule 10 of the DPDP Rules, 2025 (the “Rules”) goes further, requiring that this consent be tied to an authenticated adult established through a reliable identity and age source, not simply collected as a form entry. WhatsApp’s current prompt functions more like an age gate than a genuine consent verification mechanism, and that distinction is really the whole compliance question.
Why the Timeline Matters More Than the Feature
The DPDP Act’s rollout has moved in stages rather than through a single effective date. The Data Protection Board was constituted in November 2025, the provisions relating to Consent Managers are set to take effect in November 2026, and the major operative provisions of the Act, including Section 9 in full force, are scheduled for May 2027. Read against that calendar, WhatsApp’s test looks less like a response to an existing legal obligation and more like an early move to build and calibrate the infrastructure well before the deadline arrives.
That is, on its own, a sound compliance strategy. An age assurance and parental consent system cannot be assembled in the weeks before an enforcement date. It needs testing at scale, handling for edge cases such as shared devices and multiple children in one household, and integration with whatever authentication source the final rules settle on, whether that is a DigiLocker-linked flow or an encrypted token drawn from a government-issued identity document. The lesson for other platforms is not to wait for the compliance deadline before starting to build. It is to treat the eighteen-month runway the way WhatsApp appears to be treating it, as the actual working period.
The Part the Rules Still Leave Open
Even for a platform moving early, the destination is not entirely fixed. The Rules sketch two broad pathways for age and identity verification an Aadhaar-linked DigiLocker mechanism in which a parent’s credentials get associated with a child’s account, and an electronic token system in which a government identity document is converted into a limited disclosure credential. Neither has been finalised into an operative technical standard, and both raise their own data minimisation questions, since an age verification system that ends up collecting more identity data than the purpose requires ends up creating a second compliance problem while solving the first.
Section 9 asks for verifiable consent, not a comprehensive identity check. Platforms building toward the deadline need to design systems that authenticate the parental relationship and the age threshold without defaulting to broad identity capture simply because it happens to be the more available technical option.
\What Other Platforms Should Take Away
For any Indian entity operating a consumer platform, whether social, gaming, ecommerce, or otherwise, the real takeaway from WhatsApp’s test has nothing to do with WhatsApp itself. Age assurance has moved from a policy line item to an engineering requirement, and it now carries a real penalty attached. Section 9 breaches carry penalties running up to two hundred crore rupees, among the highest under the Act.
Building a compliant mechanism involves more than a front-end prompt. It requires a documented basis for how the platform distinguishes a genuine parental relationship from a shared device, a data minimisation review of whatever identity source is used for verification, and a Data Protection Impact Assessment that treats the age and consent flow as a distinct processing activity rather than an extension of ordinary account creation. Putting this off until the Rules take their final shape leaves very little room to get it right once May 2027 arrives.
AMLEGALS Remarks
WhatsApp’s introduction of an age prompt may appear to be a minor interface update, but it reflects a much broader shift towards preparing for compliance with the DPDP Act. It signals that platforms catering to Indian users are already beginning to adapt their systems in anticipation of Section 9, even before the provision formally comes into force.
However, the real compliance challenge goes beyond displaying an age declaration. The key question for every Data Fiduciary is whether its systems can obtain and demonstrate verifiable parental consent when required. Organisations that invest in building these capabilities now will be far better positioned for the regulatory landscape ahead.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
