Verifiable consent for persons with disability under DPDP (Rule 11)
- Before processing personal data of a person with disability who has a lawful guardian, a Data Fiduciary must obtain verifiable consent of that guardian (section 9(1)).
- Rule 11 requires due diligence that the guardian was appointed by a court, a designated authority, or a local level committee under the applicable guardianship law.
- The applicable law is the Rights of Persons with Disabilities Act, 2016 or the National Trust Act, 1999, depending on the person's condition (Rule 11(2)(b)).
- The children-only restrictions in section 9(2) and 9(3), and the Rule 12 exemptions, are about children; Rule 11 is a separate verification duty.
- Section 9 and Rule 11 apply from eighteen months after 13 November 2025.
The DPDP Act extends its parental consent rule beyond children. Where an adult with disability has a lawful guardian, the guardian gives consent on her behalf, and the business must check the guardian is genuine. This guide explains section 9(1), Rule 11 and how to build a workable guardian verification flow.
Who counts as a person with disability here
Rule 11(2)(d) defines a person with disability as either:
- an individual with a long-term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society equally with others, and who, despite adequate and appropriate support, is unable to take legally binding decisions; or
- an individual with autism, cerebral palsy, mental retardation (the term used in the Rules) or a combination of two or more of these, including severe multiple disability, who, despite adequate and appropriate support, is unable to take legally binding decisions.
The key element in both limbs is inability to take legally binding decisions despite support. Disability alone does not trigger guardian consent; many persons with disability give their own consent under section 6 like anyone else.
Who the guardian is, and how to verify
Under section 2(j)(ii), the “Data Principal” for a person with disability includes her lawful guardian acting on her behalf. Rule 11(1) says that when an individual identifies herself as the lawful guardian, the Data Fiduciary must observe due diligence to verify that the guardian was appointed by one of:
- a court of law;
- a designated authority, meaning an authority designated under section 15 of the Rights of Persons with Disabilities Act, 2016 to support persons with disabilities in exercising legal capacity (Rule 11(2)(a)); or
- a local level committee constituted under section 13 of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 (Rule 11(2)(c)).
The appointment must be under the “law applicable to guardianship”: the Rights of Persons with Disabilities Act, 2016 for the first category of person above, and the National Trust Act, 1999 for the second (Rule 11(2)(b)).
Rule 11 does not prescribe a particular document or technology. Unlike Rule 10 for children, which refers to identity and age details and virtual tokens, Rule 11 focuses on verifying the appointment itself. In practice, that usually means seeing the appointing order or certificate and recording that you checked it.
How this differs from the children's rules
| Topic | Children | Persons with disability with a lawful guardian |
|---|---|---|
| Who consents | Parent (including lawful guardian) (section 9(1)) | Lawful guardian (section 9(1)) |
| Verification rule | Rule 10: parent is an identifiable adult | Rule 11: guardian appointed by court, designated authority or local level committee |
| No detrimental processing, no tracking or targeted ads | Applies (section 9(2) and 9(3)) | Not stated in section 9(2) or 9(3), which refer only to children |
| Fourth Schedule exemptions | Available (Rule 12) | Rule 12 refers only to children |
For the child-specific rules, see children's data rules under DPDP.
A practical guardian consent flow
- Offer a guardian route. At sign-up and in support, let someone say they are acting as a lawful guardian. Do not rely on a tick-box alone.
- Give the notice to the guardian. The consent request must still be preceded or accompanied by a notice meeting section 5 and Rule 3, in clear language, with the option of English or an Eighth Schedule language (sections 5(3) and 6(3)).
- Check the appointment. Ask for the order or certificate showing appointment by a court, designated authority or local level committee, and check it names the guardian and the person (Rule 11(1)).
- Record the diligence. Keep a note of what you saw, who checked it and when. If consent is questioned in a proceeding, the Data Fiduciary must prove notice and consent (section 6(10)). See consent logs and recordkeeping.
- Minimise what you keep. Collect only what is necessary to verify; consent is limited to data necessary for the specified purpose (section 6(1)).
- Route rights through the guardian. Because the guardian is included in “Data Principal”, access, correction, erasure and grievance requests can come from the guardian (sections 11 to 13). Train support teams accordingly.
- Plan for change. Guardianship can end or change. Have a way to update who may act, and to handle withdrawal of consent (section 6(4)).
Note that a nominee under section 14 is different: a nominee acts on death or incapacity of the Data Principal, while a lawful guardian acts for a person who already has one. See right to nominate.
Penalties
Item 3 of the Schedule covers breach of “additional obligations in relation to children under section 9”, with a penalty that may extend to two hundred crore rupees. The Schedule does not separately name the guardian-consent duty for persons with disability. Whether a lapse falls under item 3 or under item 7 (any other provision, up to fifty crore rupees) is not settled by the text itself; take advice if it matters to you. See DPDP penalties explained.
Who should prioritise this
Any business whose users may include adults under guardianship: health and care services, insurance, banking and payments, government-facing services and assisted-living or support platforms. Healthtech teams can continue with DPDP for healthtech.
Frequently asked questions
Does the DPDP Act require guardian consent for persons with disability?
Yes, where the person has a lawful guardian. Section 9(1) requires a Data Fiduciary to obtain verifiable consent of the lawful guardian before processing personal data of a person with disability who has a lawful guardian.
How do I verify a lawful guardian under Rule 11?
Rule 11(1) requires due diligence to verify that the guardian was appointed by a court of law, a designated authority under section 15 of the Rights of Persons with Disabilities Act, 2016, or a local level committee under section 13 of the National Trust Act, 1999. The Rules do not prescribe a specific document.
Does every person with a disability need a guardian to consent?
No. Rule 11(2)(d) covers individuals who, despite adequate and appropriate support, are unable to take legally binding decisions, and section 9(1) applies only where the person has a lawful guardian. Others give their own consent.
Does the ban on tracking and targeted advertising apply to persons with disability?
Section 9(2) and 9(3) refer only to children. The Act does not extend those specific restrictions to persons with disability, though all general obligations, such as consent standards and security, still apply.
When does Rule 11 come into force?
Rule 11 and section 9 come into force eighteen months after 13 November 2025 (Rule 1(4) and the commencement notification noted at section 1(2)).
Practical next step
Add a guardian path to your onboarding and support scripts: what evidence you accept, who checks it, where the record is stored, and how a guardian then exercises rights.