Introduction

The European Commission issued preliminary findings indicating that TikTok may have breached the Digital Services Act (“DSA”) in relation to the protection of minors. The Commission’s concerns include the accessibility of public account content, the ease with which younger users can change their account settings, and the recommendation of minors’ content through the platform’s For You Feed. In particular, the Commission examined whether TikTok’s default account settings and related design choices adequately mitigate risks to minors, including unwanted contact and exposure to harmful interactions. TikTok has an opportunity to exercise its right of defence before the Commission determines the next steps. Under the DSA, specified non-compliance may attract a fine of up to 6% of a provider’s total worldwide annual turnover, subject to the applicable legal requirements.

For India, the regulatory developments provide a timely basis for examining the child-data protections under the Digital Personal Data Protection Act, 2023 (“DPDPA”), and the institutional readiness of the Data Protection Board of India (“DPBI”). Section 9 of the DPDPA establishes specific obligations concerning the processing of children’s personal data, while the phased commencement of the Act and the DPDP Rules, 2025 raises questions about when and how these safeguards will become operationally enforceable. The comparison is therefore not simply between two regulatory frameworks, but between statutory protection, platform-level implementation and the institutional capacity to hold digital services accountable.

Section 9 and the DPDP Rules, 2025

India’s DPDPA anticipates this exact kind of harm, and in some aspects, it is stricter than the DSA. Section 2(f) defines a child as anyone who has not completed 18 years, a bright-line considerably wider than the GDPR’s flexible 13 to 16 band. Section 9 places the Act’s most stringent obligations on any Data Fiduciary processing a child’s personal data. Verifiable parental consent is required before processing under Section 9(1). Processing that is likely to cause any detrimental effect on a child’s well-being is prohibited under Section 9(2). Most relevant to a TikTok-style default visibility problem, tracking, behavioural monitoring and targeted advertising directed at children are absolutely barred under Section 9(3).

The DPDP Rules, 2025 operationalise these provisions. Rule 10 sets out the verifiable consent mechanisms a Data Fiduciary must use before processing a child’s data, including reliable identity or age proof, a voluntarily furnished token, or a DigiLocker authenticated credential. If a platform’s default settings exposed a minor’s account to the public internet in the manner the Commission found with TikTok, that conduct would fall squarely within what Section 9(2) and 9(3) are meant to prevent. India has already legislated for this exact problem. The penalty exposure is also not small. The Schedule to the DPDPA caps penalties for a Section 9 violation at ₹200 crore, placing children’s data breaches near the top of the Act’s penalty hierarchy, just below the ₹250 crore ceiling for failures of reasonable security safeguards under Section 8(5).

The Institutional Gap

The difficulty is not the statute. It is the absence, so far, of a regulator equipped to apply it the way the European Commission just applied the DSA. The DPBI was established as a body corporate under Section 18, effective 13 November 2025, along with the provisions needed for its constitution. That establishment is real and formal. As of public reporting in April 2026, however, the Chairperson and Members envisaged under the Act and the Rules had not all been appointed and had not all taken office. The selection committees required to make those appointments had themselves faced delay. A Board that is not fully staffed cannot conduct the kind of proactive, evidence-based inquiry that produced the finding against TikTok. At present it can, at best, receive and log complaints while it awaits its own completion.

The DPDPA’s phased rollout widens this gap further. The DPBI’s constitutive provisions took effect immediately in November 2025. The consent manager provisions phase in only by 13 November 2026. The Commission, by contrast, is applying a regulation that is already fully in force, backed by a Board with a prior finding against this same platform and a demonstrated record of using its penalty powers. India has the statute. It does not yet have the regulator to test a platform’s default account state against it, and on the current timeline it will not have the enforceable obligation in force for close to another year.

Where the Framework Falls Short

A candid assessment should not stop at the appointments delay. Even once fully staffed, the DPBI’s independence rests on a different footing than the Commission’s. Its Chairperson and Members are appointed by the Central Government rather than through a process insulated from executive control, a structural difference likely to shape how assertively it can act against powerful or politically sensitive platforms. Verifiable parental consent at the scale Rule 10 contemplates, across India’s linguistic diversity and uneven parental digital literacy, remains its own unresolved operational challenge, separate from institutional readiness. The enforcement lag also carries a real cost. Platforms operating in India today face no equivalent of the finding TikTok just received, even though comparable conduct, such as a minor’s account defaulting to public visibility, would likely fall within Section 9 once the substantive obligations take effect in 2027.

AMLEGALS Remarks

The EU’s TikTok proceedings highlight the importance of embedding children’s data protection into platform design and default settings. India’s DPDPA, 2023 establishes specific safeguards for children’s personal data under Section 9, including verifiable parental consent and restrictions on tracking and targeted advertising, while the DPBI’s establishment and the phased commencement of substantive obligations remain central to the framework’s implementation. For Data Fiduciaries, the priority should be to proactively assess privacy-by-design measures, default settings and consent mechanisms, ensuring that compliance is reflected in actual data processing practices rather than limited to written policies.

For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com

Leave a Reply

Your email address will not be published. Required fields are marked *

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.