PROTECTION OF MINORS
India is going through an overhaul as far as digital offerings targeted at minors (i.e., users below the age of 18) are concerned. The Digital Personal Data Protection Act 2023 (DPDP Act), which is due to be fully enforced from May 2027, carries direct obligations for data fiduciaries (i.e., entities deciding the purpose and means of processing) when they on-board minors or track their behaviour. While other existing laws such as the Promotion and Regulation of Online Gaming Act 2025 (PROG Act), the Information Technology Act 2000 and the Consumer Protection Act 2019 (CPA) do not explicitly have minor-specific safeguards, the obligations therein around game monetisation, content moderation, deceptive design and dark patterns, among others, need to be tempered for games accessible by minors. The need for such calibration is also compounded by the growing policy push in India towards child safety and protecting minors from inappropriate offerings. With the DPDP Act coming into full enforcement in May 2027, developers and publishers may benefit from operating their games with certain considerations in mind. Amongst these, we have identified three key themes below, which may take centre stage in the run up to the DPDP Act’s enforcement and are bound to reinforce the obligations already present in laws such as the PROG Act and the CPA. Verifiable Parental Consent before processing minors’ personal data As is true in many jurisdictions, most games offered in India today verify the age of the user through an affirmative opt-in box or by stating in the T&Cs that if the user is a minor, the parent or the lawful guardian “consents to the minor’s use and engagement with the game”. The current practice relies on the minor’s “opt-in” (which could be a misdeclaration) or
Introduction From simple static pixels to hyper-realistic virtual environments, minors have access to all types of games today. While global certifications categorise games as per their appropriateness for a particular age-group, they sometimes do little to ensure that a user only accesses a game fit for their age. Rockstar Games’ blockbuster Grand Theft Auto (GTA) video game, for example, is rated 18+ by almost all popular ratings like the Entertainment Software Rating Board (ESRB), Pan- European Game Information (PEGI), and the British Board of Film Classification (BBFC). Yet, a survey of British GTA players found that 71 percent of them had their first experience of the game before they turned 18, with 20 percent of them having played the game before the age of 11. 1 A separate Norwegian survey also found that GTA is the second most-played game among the sampled boys in the 13-14 age group, right behind Fortnite 2 . Games have become the new “social media” and an activity on which minors spend the most time. Ofcom, the UK regulator for communication services, now tracks games like Call of Duty, Minecraft, and Roblox in its updated 2026 tracker for online safety 3 . This trend is amplified with games shifting to ‘free-to-play’ and freemium models, and mobile-first markets enabling seamless distribution via app stores. As a practical consequence, minors are routinely exposed to games that were neither designed with them in mind, nor calibrated to account for their unique vulnerabilities. For global game developers, publishers and distributors offering or planning their game launches in India, the dilemma above is not simply ethical, but is fraught with legal and policy considerations.
1 Christien Phelby, ‘Seven in ten British GTA gamers first played when they were underage’ (YouGov, 5 December 2023) 2 ‘Report on most played video games among boys aged 13-14 years’ (Statista, 2020) 3 Ofcom, ‘Children’s Online Experiences’ (21 May 2026)
IMGL MAGAZINE | SEPTEMBER 2026
PAGE 23
Made with FlippingBook flipbook maker