Legal Register
Control Workpaper
OBL-25 Section 9(2) ACT-9

OBL-25: Child Detrimental Processing Prohibition (Section 9(2))

Prohibits any processing of child personal data that is likely to cause harm to child well-being.

Statutory scope: Section 9(2) · Assigned to Product / guardian assurance · Systems: Separate CASE-101 fixture; not Company child lending

Operational Interface Requirement

Recommended interface: Supply a valid parent token for prohibited targeting without an established applicable exception; expected outcome is deny. Verify each claimed exception separately.

Expected Audit Assertion / Test Result

Supply a valid parent token for prohibited targeting without an established applicable exception; expected outcome is deny. Verify each claimed exception separately.

Governance & Architecture

Recommended Activity Owner
Product / guardian assurance
Target Systems & Interfaces
Separate CASE-101 fixturenot Company child lending

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-25

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/remediation/Q04/child-controls.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

ACT-9 Lines 386–403
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Data Fiduciary; Central Government for notifications

Trigger Context

Child data or covered disability/guardian processing

Statutory Conditions

Verifiable parent/guardian consent before processing; no detrimental child effect; no tracking/behavioural monitoring/targeted child advertising.

Statutory Exceptions

s9(4) prescribed classes/purposes/conditions and s9(5) notified verifiably safe processing relax only (1)/(3), not (2).