WhatsApp Age Check: A screenshot circulating on X this week showed something unusual inside WhatsApp: a prompt asking users to add their date of birth, explaining that “upcoming laws in India require us to ask for
your age.”
WhatsApp has confirmed to independent journalist Aditi Agarwal that it’s testing what a spokesperson called “privacy-protective ways for people to confirm their age,” tied directly to India’s Digital Personal Data Protection Act. The Meta-owned company was clear that this is a limited test, not a rollout, that it won’t change how the app works day to day, and that age-related details won’t be shared with other users.
What’s actually interesting here isn’t the test itself, it’s how early it is. WhatsApp isn’t legally required to do any of this yet. The obligation this prompt is preparing for doesn’t actually kick in until 13 May 2027, more than nine months away. So why move now? The answer lies in how India’s data protection law is being rolled out in stages, and what happens once the clock actually starts.
The Law
The DPDP Act, 2023, deals with how platforms are allowed to handle children’s data under Section 9, and it defines a child simply as anyone who hasn’t yet turned 18. That’s the entire population WhatsApp’s new age prompt is trying to identify.
But the Act isn’t being switched on all at once. It’s arriving in three distinct phases, based on the implementation timeline the government notified on 13 November 2026:
- 13 November 2025: The Data Protection Board of India was formally set up, and a handful of foundational provisions took effect.
- 13 November 2026: Rules governing Consent Managers come into force.
- 13 May 2027: The Act’s major operative provisions activate, including Section 9 and everything it requires around children’s data.
That last date is the one that matters for WhatsApp’s current test. Right now, the company faces no legal consequence for how it handles a minor’s data on the platform. Once May 2027 arrives, that changes entirely, and the current age prompt looks a lot like a company getting its systems ready well before the deadline forces its hand, not reacting to a rule already in force.
What “Verifiable” Parental Consent Means
Section 9(1) of the Act spells out the core obligation platforms will face: “The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian, obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed.”
In practical terms, this means WhatsApp won’t be able to collect or use any data belonging to a user under 18 without first getting sign-off from that user’s parent or legal guardian, and simply clicking “I am a parent” won’t cut it. WhatsApp will need to actually confirm who the consenting adult is, and confirm that they’re genuinely the child’s parent or guardian, not just take their word for it.
How That Verification Is Supposed to Work
The rules of “verifiable” consent are laid out separately, in Rule 10 of the Digital Personal Data Protection Rules, 2025. The rule requires platforms to take reasonable technical and organisational steps to confirm three things before processing a child’s data: that the adult claiming to be the parent is actually at least 18 years old themselves, that their identity checks out, and that a record of this verification is kept for compliance purposes.
The rules point to two accepted routes for this. The first leans on a platform’s own existing user base, if the parent already has a verified WhatsApp account, that existing identity and age data can be used directly. The second route runs through DigiLocker, India’s government-backed digital identity platform, where a parent can verify themselves either by submitting a government-issued ID directly or through a virtual age token issued by an authorised body.
What Platforms Won’t Be Allowed to Do With Personal Data
Beyond consent, the Act draws a hard line around what happens to a child’s data once it’s collected. Two provisions matter most here:
Section 9(3) states plainly: “A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.”
Section 9(2) adds a broader restriction: “A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child.”
These two clauses rule out a fairly wide range of common platform practices when the user is a minor. No building a behavioural profile based on what a child does on the app. No serving personalised ads based on their data. No tracking their activity patterns for any commercial purpose. And more broadly, nothing that could reasonably be expected to harm the child’s wellbeing.
May 2027 Deadline
The DPDP Act is effectively asking WhatsApp to have four things working by the May 2027 deadline:
- A working technical system to identify whether a given user is under 18
- A verified parental consent flow that actually confirms who the consenting adult is
- A complete stop to tracking, behavioural profiling, or targeted ads aimed at users identified as children
- No data processing that could plausibly harm a child user’s wellbeing














