Cybersecurity
DPDP Order 2026: Child Consent and Data Audit Changes
Affix Center · · 5 min read

In short: On 5 October 2026 the Ministry of Electronics and Information Technology (MeitY) issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026. It corrects wording in Section 9 on consent for children and persons with disability, and in Section 10 on audits by Significant Data Fiduciaries. It adds no new duty, but your consent flows and audit plans should match it.
If your business has an app, a website form, a school or coaching portal, a hospital system or any service that people under 18 may use, this week's DPDP news concerns you. The change is small in words, but it removes two doubts that compliance teams had about how the law should be read.
What Happened
MeitY issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026, dated 5 October 2026. According to India Briefing (7 October 2026) and the law firm King Stubb & Kasiva (8 October 2026), the Order was made under Section 43(1) of the Digital Personal Data Protection Act, 2023, which allows the central government to remove difficulties in giving effect to the Act. The law firm Fox Mandal (7 October 2026) reports the notification number as S.O. 5458(E).
The Order came into force on its publication in the Official Gazette. The reports we read do not agree on that date: one gives 6 October 2026 and another gives 7 October 2026. Please check the Gazette copy on egazette.gov.in or the MeitY website for the exact date.
The Order makes two wording corrections:
| Provision | Earlier wording | Corrected wording | Effect, as reported |
|---|---|---|---|
| Section 9(1), consent | "child or a person with disability" | "child or of a person with disability" | Makes clear that verifiable consent of the parent or lawful guardian applies to both groups separately |
| Section 10(2)(c)(ii), Significant Data Fiduciaries | "audit" | "data audit" | Makes clear that the periodic audit is a data protection audit, in line with the other audit reference in Section 10 |
All three reports describe these as clarifications. King Stubb & Kasiva states that the Order does not add new substantive obligations.
Who Is Affected
- Any organisation that processes personal data of children. Under the DPDP Act a child is a person below 18 years. This covers schools, colleges, ed-tech and coaching platforms, gaming and entertainment apps, hospitals, sports academies, and any consumer app or website that minors can sign up for.
- Organisations that process data of persons with disability who have a lawful guardian. Examples are hospitals, rehabilitation centres, welfare departments and NGOs.
- Significant Data Fiduciaries (SDFs). These are data fiduciaries that the central government notifies based on factors such as the volume and sensitivity of data they handle. Large platforms, financial firms and big data holders should assume they may be notified.
- Government departments and their software vendors that run scholarship, welfare, health or education systems holding data of children.
What It Means for an Indian Business or Department
First, there is no new deadline. Under the phased timeline of the DPDP Rules, 2025, the main obligations on data fiduciaries, including those in Sections 9 and 10, are due to apply from May 2027. The Order only corrects the text you will have to follow.
Second, the Section 9 correction closes a possible argument that the guardian consent rule was meant for only one of the two groups. If your consent design treated data of persons with disability more loosely than data of children, review it.
Third, the Section 10 correction tells likely SDFs what kind of audit to plan for: a data audit of how personal data is collected, used, stored, shared and deleted. A general IT audit or a financial audit will not meet that purpose. Our DPDP Act compliance checklist explains the wider list of duties and the timeline.
This article is general information and not legal advice. Please confirm how the Order applies to your organisation with your legal adviser.
What to Do Now
- Read the Order and note the wording. Download the Gazette copy, share it with your legal, compliance and IT heads, and update any internal DPDP notes that quote the old text of Sections 9 and 10.
- Find where you collect data of children. List every form, app screen, admission system and database that can hold data of a person under 18. Include data collected through schools, agents or partners on your behalf.
- Find where you hold data of persons with disability who have a guardian. Mark these records and check how guardian details and consent are captured today.
- Design verifiable guardian consent. Work with your software team on age checks, a parent or guardian consent step, a record of that consent and a simple way to withdraw it. Build it into the product, not into a paper form.
- Plan a data audit if you may be an SDF. Prepare a data inventory, data flow maps, access logs and retention rules now, so an independent data auditor can test them later without a rush.
- Ask your vendors what they have changed. Write to your software, cloud and marketing vendors and ask how their products will support guardian consent and data audit evidence before May 2027.
A sound data governance framework makes steps 2, 3 and 5 much easier, because you already know what data you hold and who owns it.
Frequently Asked Questions
Does the DPDP Order 2026 create new compliance duties?
According to the published reports, no. It corrects wording in Sections 9(1) and 10(2)(c)(ii) of the DPDP Act so that the provisions read as intended. The duties themselves come from the Act and the DPDP Rules, 2025.
When do the child consent and data audit rules start to apply?
Under the phased timeline of the DPDP Rules, 2025, the core obligations of data fiduciaries are due to apply from May 2027. Confirm the exact date for each provision with your legal adviser, as the government can issue further notifications.
Is a data audit the same as a VAPT or an ISO 27001 audit?
No. A security test checks for technical weaknesses, and ISO 27001 checks your security management system. A data audit under Section 10 looks at how personal data is handled against the DPDP Act. Security evidence helps, but it does not replace a data audit.
How Affix Center Can Help
Affix Center is a Mumbai-based IT company. We help organisations map personal data across their applications, build consent and age-check flows into websites, portals and apps, and prepare the logs and records a data audit needs. Our cybersecurity team handles security safeguards and assessments, and our enterprise advisory team helps you plan DPDP readiness in phases. We work alongside your legal adviser; we do not give legal opinions.
To review your consent flows or plan DPDP readiness for your systems, talk to our team.
Sources: India Briefing, "DPDP Order 2026 Clarifies Consent and Data Audit Requirements in India" (7 October 2026); Fox Mandal, "MeitY Issues Order Correcting Sections 9 and 10 of the DPDP Act" (7 October 2026); King Stubb & Kasiva, "DPDP Removal of Difficulties Order 2026: What Changed" (8 October 2026).