What the PhysicsWallah order tells you about DPDP and children's data
India's consumer regulator moved first. But the same facts describe a Digital Personal Data Protection Act exposure that most platforms have never actually assessed: free sign-ups, a young user base, consent bundled into onboarding.
Key takeaways
- The Central Consumer Protection Authority, India's consumer regulator rather than California's privacy agency, has initiated proceedings against PhysicsWallah over conduct tied to free services.
- The DPDP Act does not care whether a service is paid. Section 3 turns on processing digital personal data in India, so free tiers and trial sign-ups carry the same consent obligations.
- Where the user base is predominantly children, Section 9 requires verifiable parental consent, and the penalty ceiling for children's-data failures is ₹200 crore.
- Consent obtained through a bundled or manipulative flow is not valid consent, which makes everything processed downstream of it unlawful rather than merely undocumented.
- The practical question is not whether you have a policy. It is whether you can produce a reasoned, signed position on which obligations apply to you, and the evidence that closes each one.
Two regulators can look at the same sign-up screen and see two different problems.
India’s Central Consumer Protection Authority has initiated proceedings against the edtech platform PhysicsWallah over conduct connected to its free offerings. Read as a consumer-protection matter, that is a question about how an offer was presented. Read as a data-protection matter, it is a question about how consent was obtained, and that second reading is the one most platforms have never run against their own onboarding.
A quick disambiguation, because the acronym collides: CCPA here is the Central Consumer Protection Authority, constituted under the Consumer Protection Act, 2019. It is not the California Consumer Privacy Act. The regulator is Indian, and so is the exposure.
Why a consumer-protection order is also a privacy problem
The two statutes are separate, and an order under one does not create liability under the other. But they can rest on the same findings of fact.
Consumer-protection enforcement around dark patterns asks whether an interface pushed a user into a choice they did not freely make. The DPDP Act asks whether consent was free, specific, informed, unconditional, and unambiguous. Those are not the same test, but they run on the same evidence: the wording of the screen, the default states, what was bundled with what, and whether declining was a real option.
So when a consumer regulator characterises an onboarding flow as manipulative, it has also described the conditions under which consent may not have been validly obtained. The Data Protection Board of India can examine that conduct on its own account.
This is the part worth sitting with. A defect in consent is not a documentation gap you can paper over later. If consent was never valid, then every downstream act of processing that relied on it (the profile, the marketing list, the analytics, the model training set) was unlawful at the time it happened, and remains so.
Free does not mean exempt
Section 3 of the DPDP Act applies the law to the processing of digital personal data within India. There is no threshold for revenue, company size, or whether the user paid.
This catches a category of processing that tends to escape review precisely because nobody thinks of it as a transaction: the free tier, the trial, the webinar registration, the “download the sample paper” form, the referral competition. Each of these collects personal data digitally from data principals in India, and each therefore needs a lawful basis under Section 4: consent, or one of the legitimate uses in Section 7.
For platforms built on a free-to-paid funnel, the free end of the funnel is usually where the data volume is, where the flows were shipped fastest, and where the consent record is thinnest.
Section 9: the obligation that changes the maths
Where the users are children, the analysis shifts.
Section 9 requires a data fiduciary to obtain verifiable parental consent before processing a child’s personal data. It also prohibits tracking, behavioural monitoring, and targeted advertising directed at children. And the Act defines a child as anyone under eighteen, a wider population than several other regimes capture, and a decisive fact for any platform whose product is school or exam preparation.
Two consequences follow, and they are different in kind.
The first is operational. “Verifiable” is doing real work in that sentence. A checkbox asserting that a parent agrees is not a verification mechanism. Building one that is proportionate, that does not itself collect excessive data, and that survives a regulator asking how it works, is an engineering project with a lead time.
The second is financial. The Act sets a penalty ceiling of ₹200 crore for breaches of the children’s-data obligations, against ₹250 crore for a failure to take reasonable security safeguards. Penalties are set by the Board on the facts, so a ceiling is not a forecast. But it establishes the order of magnitude that a board of directors has to carry as a contingent liability, and it is not an order of magnitude that is comfortably absorbed.
Bundled consent, and what Rule 3 now expects
The most common defect we see is not a missing privacy policy. It is a single acceptance doing several jobs at once.
One tick enrols the user, accepts the terms, permits marketing, and authorises analytics. That is efficient, it converts well, and under the DPDP Act it fails: consent has to be specific to a stated purpose and limited to the data necessary for it, and it cannot be made a condition of a service the user came for.
The Digital Personal Data Protection Rules, 2025 sharpen the notice side of this. Rule 3 requires the notice to stand on its own and to itemise, in plain language, an account of the personal data being collected and the specific purpose of processing, described clearly enough that a person can act on it, along with the means to withdraw consent and to complain to the Board. The Act’s Eighth Schedule languages sit behind this: a notice a user cannot read is not a notice that informs.
The engineering consequence is usually understated in board papers. Granular consent is not a copy change. It means consent state has to be stored per purpose, honoured across every downstream system, and withdrawn everywhere when a user changes their mind. If marketing data and operational data live in one table with no per-purpose consent log, there is no way to answer the Board’s first question, which will be: show me what this user agreed to, and when.
What this actually asks of you in the next quarter
Not a tooling decision. A scoping decision, in this order.
Establish what applies to you, in writing. Which obligations under the Act and the Rules attach to your processing, which do not, and on what reasoning. The exclusions matter as much as the inclusions: “scoped out” is a defensible position only if someone competent reasoned it and put their name to it.
Find where children’s data actually is. Not where you intended to collect it. Age-gates fail, family accounts blur, and a platform can hold children’s data without ever having designed to. This is a discovery exercise across systems, not a policy question.
Reconstruct your consent record. For each purpose, what was the user shown, what did they affirmatively do, and can you produce that for a specific user on a specific date? If the answer is no, you have a lawfulness problem rather than a records problem.
Separate the purposes in the data model. Consent per purpose, propagated to every system that acts on it, and withdrawable end to end.
Rewrite notices to Rule 3, in the languages your users read. Itemised, standalone, plain, and with the withdrawal and complaint routes actually working.
Where a signed position matters more than a dashboard
There is a reason so much compliance tooling stops short of the question you actually need answered.
Software can tell you that a field is unmapped, that a policy is past its review date, or that a new vendor appeared in your expense feed. It cannot tell you whether your parental-consent mechanism is verifiable within the meaning of Section 9, or whether a particular processing activity survives as a legitimate use under Section 7. Those are legal judgements, and a platform that renders them as a score is quietly asking you to rely on something it has disclaimed in its own terms.
That gap is the reason Sentinel by Vettam runs the programme differently. Sentinel does the discovery, the drafting, the register, and the continuous monitoring; the legal positions that come out of it are reviewed and signed by an independent lawyer, on their letterhead, attributed to whoever signed and dated. When a regulator asks why you concluded that an obligation did not apply to you, the answer is a document with a name on it, not a dashboard reading.
For an edtech or D2C platform with a young user base, that assessment is the cheapest work in the sequence and the only work that makes the rest of it defensible. It is also, at this point, time-bound: full compliance is required by 13 May 2027, and discovery alone takes most organisations a quarter.
If you want to know which of the obligations above actually attach to your processing, that is exactly what an applicability assessment produces, and it is worth doing before a regulator asks rather than after. Platforms in edtech, D2C and consumer categories are where the gap between intent and evidence tends to be widest.
This article is general information about Indian data protection law and is not legal advice. Sentinel is a product of Rylematic Technologies Private Limited; Vettam is a technology company and does not provide legal services. Legal opinions referenced on this site are issued by independent lawyers empanelled with Sentinel. The proceedings described here are ongoing and no findings referred to are final.
Frequently asked questions
- Does the DPDP Act apply to a free service?
- Yes. Section 3 applies to the processing of digital personal data within India. Nothing in it turns on whether money changed hands, so a free tier, a trial, or a promotional sign-up carries the same consent obligations as a paid transaction.
- What does the DPDP Act require for children's data?
- Section 9 requires verifiable parental consent before processing a child's personal data, and prohibits tracking, behavioural monitoring, and targeted advertising directed at children. The Act treats anyone under 18 as a child, which is a wider group than several other jurisdictions define.
- Can marketing consent be bundled into sign-up or checkout terms?
- No. Consent under the DPDP Act must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action and limited to the data necessary for the stated purpose. A single acceptance that also enrols the user into marketing does not meet that standard.
- What is the penalty exposure for children's-data failures?
- The Act sets a penalty ceiling of ₹200 crore for breaches of the additional obligations relating to children. Penalties are determined by the Data Protection Board of India on the facts of each case, so the ceiling is not a prediction of outcome.
- Does a consumer-protection order create a data-protection liability?
- Not automatically: they are separate statutes and separate regulators. But findings about how a sign-up flow was designed are findings about how consent was obtained, and the Data Protection Board can look at the same conduct under the DPDP Act.
Sources
Skip the pitch.
Give us an hour. We'll run a live applicability review on your actual processing and show you the register we'd build — before you commit to anything.
Book a scoping call