Edition 32: WhatsApp tests age self-declaration in India
The company is testing an optional age-declaration feature to comply with the pending provisions related to processing of children's data in the Digital Personal Data Protection Act, 2023,
Please note that my commentary has been italicised and bracketed (like this).
WhatsApp is testing an age self-declaration feature for users with Indian numbers in anticipation of the implementation of provisions related to processing of children’s data in the Digital Personal Data Protection Act, 2023, a spokesperson for WhatsApp confirmed to The Tech Trace.
Users on at least two subreddits (here and here) shared screenshots that asked WhatsApp users to add their date of birth as “upcoming laws in India require us to ask for your age”. One of the screenshots, titled “When were you born?”, allowed users to ignore the age declaration prompt by clicking on “Not now”. The Tech Trace has not personally received any such prompts in the app but the WhatsApp spokesperson confirmed the veracity of these screenshots.
“To comply with upcoming laws in India like the Digital Personal Data Protection Act (DPDP), we are testing privacy-protective ways for people to confirm their age. This doesn’t change how WhatsApp works or your experience. We understand that information about someone’s age is private and it won’t be shared with other WhatsApp users,” the spokesperson said.


To be sure, nothing in the DPDP Act or the Rules requires data fiduciaries such as WhatsApp to collect or verify minors’ ages.
Instead, they require data fiduciaries to obtain “verifiable consent” of parents or lawful guardians before processing the personal data of any child, and observe “due diligence” to establish the adult as the minor’s parents.
Rule 10 provides for the DF to observe “due diligence” to check the identity and age of the adult in question only if the adult voluntarily provides this information or when an authorised entity (such as a digital locker service provider) issues a token mapping “such details” (that is, identity and age of the adult).
Thus, for verifiable parental consent to work in its entirety, a DF has to check for three things:
Are you a child?
First, establish whether a user is a minor or not. This can be done either through self-declaration (where kids can lie) or by forcing everybody in the country to declare their age online by tying it to a government ID (data maximisation leading to greater risks of data leaks and breaches). Tautologically, if the DF processes the kid’s government ID before getting verifiable consent from parent/guardian, the DF would technically be in violation of Section 9(1) of the DPDP Act.
***After this article was published, Aparna Gaur, partner at Trace Law Partners, flagged that Part B of the Fourth Schedule of the DPDP Rules allows DFs to process a child’s data before obtaining verifiable personal consent to “confirm” that the data principal “is not a child”. This schedule lists the purposes for which Sections 9(1) (verifiable parental consent) and 9(3) (prohibition on tracking/behavioural monitoring of children and targeting advertisements at them) will not apply.
That is a fair point.
On the face of it, this creates an exemption for such data processing but what is interesting is that the Fourth Schedule provides an exemption to fulfil an aim — that is, prove that a user is an adult — that is not mandated in Rule 10 or Section 9 (explained below).
Arguably, the first exemption of Part B of the Fourth Schedule — that exempts processing of children’s data to “exercise any power, performance of any function or discharge of any duties in the interests of a child, under any law for the time being in force in India” — could also be used to exempt WhatsApp’s age verification feature that could, in future, rely on the kid’s government ID.
(The framing of this law reminds me of drowsy philosophy classes in college that focussed on formal logic/reasoning establishing cogence between subject and object across propositions. I have wasted so much paper trying to link the subject/object from the Act to the Rules to the Schedules that now, I can set up my own version of a Sisyphean exercise where I roll up the giant paper boulder up a hill.)***
Are you an adult?
Second, for every minor account (self-declared or otherwise), find an adult to claim it and ensure that the adult in question is indeed an adult. As per Rule 10, “due diligence” needs to be done by the DF to establish the individual claiming to be an adult as an adult (and all readers of this newsletter understand the expansive meaning of “due diligence” in legalese *wink, wink, nudge, nudge*).Are you the adult linked to the child?
Third, establish the link between the kid and the adult as a relationship between that of a parent/guardian and a child so that the consent obtained from the adult is actually verified.
Of these three steps, there is a soft obligation for step 2 via Rule 10 and hard obligation for step 3 via Section 9 and Rule 10. Step 1, which is crucial to the process, has not been envisioned at all.
Moreover, while different state governments in India are rolling out their versions of family IDs, they do not envision kinship relationships outside those of a parent-child.
(For instance, if I am babysitting a minor nibling and the kid wants to play on Roblox, do I call my nibling’s parents or can I — a fully functioning adult with a familial relationship with the child in question who has been entrusted to care for the child by its parents — give consent? How will such a relationship, which is not established through any government issued documents, be verified for the purposes of “verified consent”? What if I am looking after a friend’s kid where I do not have a familial bond so I cannot prove the relationship even through a million government documents?)
WhatsApp, for the time being, is resorting to self-declaration where users can easily fib.
As I have reported earlier, Meta analyses public posts on Instagram (such as birthday posts) for age-related signals to see whether Instagram users might have lied about their age, as per Antigone Davis, Meta’s global head of safety.
Could this extend to an analysis of WhatsApp profile photos, group photos, group composition, group subject, and group descriptions, all of which are unencrypted, as per WhatsApp’s pending traceability lawsuit in the Delhi High Court? If Meta concludes that a phone number linked to a minor’s Instagram account is also linked to a WhatsApp account, will it also conclude that the WhatsApp account is a minor’s and thus impose age-related restrictions?
As per WhatsApp’s FAQs on how the company uses age information, if people opt to connect their WhatsApp account to “Meta Account” (also called “Accounts Centre”) or opt to use Meta AI within WhatsApp, the user’s WhatsApp account information (which includes the user’s number and age amongst other things) can be shared with Meta to, for instance, “determine whether [they] are eligible to access certain features or to ensure consistency across your accounts”.
Who knows? (Everybody does.)
The provisions related to verifiable parental consent will come into effect in May 2027 as per the gazette notification dated November 13, 2025.
Read more:
Push to protect children online faces basic challenges: Experts (Hindustan Times, January 5, 2025)
Govt may not define specific steps for parental control measures (Hindustan Times, July 19, 2024)
“The End”
Update (August 3, 1:40 pm IST): Added the section bracketed between *** and ***.

