Young Indian boy playing computer games

September 17, 2026

  • Ranjana Adhikari, Partner, Shardul Amarchand Mangaldas & Co
  • Sarthak Doshi, Senior Associate, Shardul Amarchand Mangaldas & Co
  • Prateek Joinwal, Associate, Shardul Amarchand Mangaldas & Co

Minor players, major stakes: a guide for developers offering their games in the Indian market

VIDEO GAME DEVELOPERS WILL NEED TO ADAPT TO A NEW FOCUS ON THE PROTECTION OF MINORS WHICH MAY FOLLOW A DIFFERENT APPROACH FROM ELSEWHERE

From simple static pixels to hyper-realistic virtual environments, minors have access to all types of games today. While global certifications categorise games as per their appropriateness for a particular age-group, they sometimes do little to ensure that a user only accesses a game fit for their age. Now three laws going through the Indian Parliament will change the way computer games are offered to minors resulting in game developers having to make significant product changes compared to other markets.

Rockstar Games’ blockbuster Grand Theft Auto (GTA) video game, for example, is rated 18+ by almost all popular ratings like the Entertainment Software Rating Board (ESRB), Pan-European Game Information (PEGI), and the British Board of Film Classification (BBFC). Yet, a survey of British GTA players found that 71 percent of them had their first experience of the game before they turned 18, with 20 percent of them having played the game before the age of 11.[i] A separate Norwegian survey also found that GTA is the second most-played game among the sampled boys in the 13-14 age group, right behind Fortnite.[ii]

Games have become the new “social media” and an activity on which minors spend the most time. Ofcom, the UK regulator for communication services, now tracks games like Call of Duty, Minecraft, and Roblox in its updated 2026 tracker for online safety.[iii] This trend is amplified with games shifting to ‘free-to-play’ and freemium models, and mobile-first markets enabling seamless distribution via app stores. As a practical consequence, minors are routinely exposed to games that were neither designed with them in mind, nor calibrated to account for their unique vulnerabilities.

For global game developers, publishers and distributors offering or planning their game launches in India, the dilemma above is not simply ethical, but is fraught with legal and policy considerations.

India is going through an overhaul as far as digital offerings targeted at minors (i.e., users below the age of 18) are concerned. The Digital Personal Data Protection Act 2023 (DPDP Act), which is due to be fully enforced from May 2027, carries direct obligations for data fiduciaries (i.e., entities deciding the purpose and means of processing) when they on-board minors or track their behaviour. While other existing laws such as the Promotion and Regulation of Online Gaming Act 2025 (PROG Act), the Information Technology Act 2000 and the Consumer Protection Act 2019 (CPA) do not explicitly have minor-specific safeguards, the obligations therein around game monetisation, content moderation, deceptive design and dark patterns, among others, need to be tempered for games accessible by minors. The need for such calibration is also compounded by the growing policy push in India towards child safety and protecting minors from inappropriate offerings.

With the DPDP Act coming into full enforcement in May 2027, developers and publishers may benefit from operating their games with certain considerations in mind. Amongst these, we have identified three key themes below, which may take centre stage in the run up to the DPDP Act’s enforcement and are bound to reinforce the obligations already present in laws such as the PROG Act and the CPA.

Verifiable Parental Consent before processing minors’ personal data

As is true in many jurisdictions, most games offered in India today verify the age of the user through an affirmative opt-in box or by stating in the T&Cs that if the user is a minor, the parent or the lawful guardian “consents to the minor’s use and engagement with the game”. The current practice relies on the minor’s “opt-in” (which could be a misdeclaration) or by deeming that the parent or lawful guardian has consented to the minor’s access and engagement with the game (even in cases where they had not).

The DPDP Act moves away from the deemed consent model and obligates all data fiduciaries to obtain verifiable parental consent (VPC) before processing any personal data of minors.[iv]. Game publishers (or the relevant data fiduciary) have two key obligations: first, to ensure that the person identifying as the parent / guardian are themselves an adult and second, that the person is identifiable against the details submitted by the person.[v] The standard under Indian laws may differ from what publishers are accustomed to in other jurisdictions. For example, the EU’s General Data Protection Regulation (GDPR) obligates data controllers offering information society services to minors to “verify” that the consent is provided by the parent and make “reasonable efforts to verify” that the parent or guardian did indeed give consent,[vi] whereas the DPDP Act expects that consent is also “verifiable” or “identifiable” against a document or secondary source.[vii]

Mechanisms to achieve VPC are not codified currently under the DPDP Act. The Data Protection Board of India may provide guidance closer to the DPDP Act’s full enforcement in May 2027. Until then, publishers may benefit from establishing internal processes that demonstrate an effort to verify the identity of the parent / lawful guardian against the requirements of the DPDP Act. A good starting point is to rely on existing KYC solutions (e.g., DigiLocker, e-KYC, real-time video-based verification, etc.) that verify identity documents against certain markers or government databases. Zero-knowledge proofs,[1] maintaining auditable consent logs, and features disabling minors from changing privacy choices are some good practices that the industry is exploring.[viii] Stakeholders may also seek guidance from measures such as providing a form for the parent to complete and mail back, maintaining a toll-free number for parents to call in their consent etc.,[ix] that are acknowledged for compliance with the Children’s Online Privacy Protection Act (COPPA) in the US. In any case, with no codified standard under the DPDP Act, the obligation rests with the data fiduciary to demonstrate the sufficiency of the technological and organisational measures and ensure that their data processors follow suit.

Like the COPPA or the GDPR, the DPDP Act provides certain exemptions. The VPC obligation is inapplicable when processing is undertaken by educational institutions, healthcare professionals, creche service providers, etc. or for purposes where processing is in the child’s interest or for their safety.[x] Publishers of educational games may thus experience an easier compliance journey if they process data within the statutory limits and with due regard to the applicability of the exemptions.

Behavioural analytics and tracking of minors

Behavioural analytics are routinely employed in online games to foster engagement.[xi] Tracking and amassing multiple in-game datasets serves several purposes.[xii] A study on digital profiling in online gaming revealed that even limited engagement led to over 2000 data transmissions to multiple third-parties, with operators recording over 180 attributes for each player.[xiii]

In India, children are usually exposed to the same tracking and behavioural analytics tools as any other user, although restrictions under Indian law may nudge publishers to change the current approach. The DPDP Act imposes two key prohibitions: first, against behaviourally monitoring, tracking, or issuance of targeted ads to minors; and second, against undertaking any processing likely to cause any determinantal effect on a minor’s well-being. No prescriptive guidance has currently been provided on either of these. While certain exemptions linked to the processing-purposes are present, these remain narrow and an abundance of caution is recommended before invoking them.

Notably, the DPDP Act specifies stricter obligations than comparative data privacy legislations. For example, while GDPR specifies that children’s personal data merits greater protection,[xiv] it merely grants them a right to not be subjected to a decision based exclusively on their profiling.[xv] It does not codify other restrictions vis-à-vis behavioural monitoring for minors, as confirmed by Article 29 Data Protection Working Party.[xvi] Even the Information Commissioner’s Office clarified that the UK GDPR does not bar profiling of minors insofar as the obligations thereunder are satisfied.[xvii] Restrictions against tracking and profiling of minors may therefore be a unique challenge for game developers and publishers offering their products in India, one they have not already encountered elsewhere.

Stakeholders could consider a couple approaches to navigate this situation. First, they can adopt ‘privacy-by-design’ in early stages of game development and analytics by assessing the risks associated with the processing of players’ data and by undertaking routine Data Protection Impact Assessments (DPIAs). This is likely to aid in the identification of risks posed to minors, especially on aspects such as their behavioural monitoring and tracking, both of which remain expressly prohibited under the DPDP Act. Second, once a player is identified to be a minor, features or aspects that are either prohibited under Indian laws or those that endanger their safety should be automatically disabled. For example, the profiling of in-game datasets (e.g., gameplay patterns, session duration, spending history etc.) for minors should be isolated from any analytics engines furthering personalisation or ad-targeting algorithms. Third, developers should assess the feasibility of neutral advertising frameworks as opposed to those that direct behavioural or interest-based ads to minors. Contextual ads tailored to the nature of content rather than players’ behavioural profile or datasets fed in ad-selection algorithms present a fair argument against non-compliance with the DPDP Act.

Building child safety into game design

Games generally come with age-appropriateness ratings. While regulated ratings like the International Age Rating Coalition (IARC) certify games with 3+, 7+, 12+, 16+, and 18+ ratings, the game version available to all eligible users is usually the same. A 13-year-old is hence exposed to the same UI, gameplay, mechanics, and monetisation models as an adult user, inviting rightful concerns around child safety and privacy. Loot boxes draw a fair share of regulatory and policy scrutiny in this regard. Today, more than 80 percent of games offered via app stores have a loot box.[xviii] Most countries (excluding Germany and Australia)[xix] do not consider the presence of loot boxes when determining the age rating of a game, underplaying the effect a loot box offering has on a minor. Perhaps more concerningly, loot boxes are also infamous in certain jurisdictions for their deceptive and addictive design and for circumventing parental controls vis-à-vis monetary transactions being undertaken by children.

In India, while loot boxes are not specifically regulated, the extant subject-matter laws create a reasonable governance framework. Under gambling laws for example, they remain arguably excluded from the definition of “gambling”, subject to an inherent inability to transfer or trade loot box items for monetary value. Even under India’s recently enacted federal law on gaming i.e., PROG Act, games monetising through loot boxes are likely to face scrutiny only for being in the prohibited class of “online money games” or considered for mandatory certification as an “online social game” by the government. Traditional consumer protection principles against misleading declarations, dark patterns and unfair trade practices, also obligate publishers to keep their game design non-deceptive and transparent.

The legality of loot boxes and allied monetisation mechanics under Indian laws depends on multiple factors including the presence of deposits, the nature or real-world value of the rewards, etc. Although, now more than ever, their offering and the overall game design is likely to face greater scrutiny from the government, especially when they are being offered to minors. Global best practices like disclosing the probability of receiving a reward, displaying prices in Indian Rupees (and not in-game currencies), and providing transparent information about the rewards will help publishers to demonstrate their bona fides. With the growing policy push towards child-safety in the country, stakeholders should consider the creation of separate child-specific versions of their game or adopt an age-neutral game design for its entire userbase. Both approaches are going to be arduous tasks and should be considered with due regard to their effectiveness and protection against non-compliance of regulatory requirements.

Conclusion

With India’s position as one of the largest global gaming markets, developers and studios intending to offer their titles in India must strive to adapt them to the distinct regulatory expectations flagged above. On many fronts such as procuring VPC and restrictions on behavioural monitoring, the Indian framework appears to be stricter than global regimes. Thus, offerings otherwise compliant with global frameworks would need to be re-assessed for their compliance posture under Indian laws. For global game developers, studios, and publishers assessing India as a market, the path to compliance is not merely a legal checkbox but a product-design imperative. On this front, the measures outlined in this article are intended to serve as a practical starting point for stakeholders to align their offerings with India’s evolving regulatory expectations, whilst continuing to deliver engaging and responsible gaming experiences.

[1] A term coined for privacy-preserving verification measures that allow a platform to confirm a specific attribute about a user (e.g., age), without requiring the user to disclose the underlying personal data used to establish that attribute.

[i] Christien Phelby, ‘Seven in ten British GTA gamers first played when they were underage’ (YouGov, 5 December 2023) available here.

[ii] ‘Report on most played video games among boys aged 13-14 years’ (Statista, 2020) available here.

[iii] Ofcom, ‘Children’s Online Experiences’ (21 May 2026) available here.

[iv] Section 9(1) of the DPDP Act.

[v] Rules 10(1) and 10(2) of the Digital Personal Data Protection Rules 2025.

[vi] Article 8 of GDPR.

[vii] Section 9 of the DPDP Act read with Rule 10 of the Digital Personal Data Protection Rules 2025.

[viii] Martin Sas et al., ‘Informing Children about Privacy: A Review and Assessment of Age-Appropriate Information Designs in Kids-Oriented F2P Video Games’ (ACM Digital Library, 2023).

[ix] Id., Section 312.5(b).

[x] Rule 12 of the Digital Personal Data Protection Rules 2025 read with its Fourth Schedule.

[xi] Leon Xiao, ‘Failing to protect the Online Consumer: Poor Compliance with Dutch loot box and Video Game Consumer Protection Guidelines’ (2025) International Journal of Law and Information Technology 33.

[xii] Id.

[xiii] Jack McCarrigle et al., ‘Consent Banners, Dark Patterns, and GDPR Infringements in Online Gambling: Evidence from a Systematic Audit and Online Experiment’ (SSRN, 2026).

[xiv] Recital 38 of GDPR.

[xv] Article 22 of GDPR.

[xvi] Article 29 Data Protection Working Party. ‘Guidelines on Automated Individual Decision-Making and Profiling for the Purposes of Regulation 2016/679’.

[xvii] Information Commissioner’s Office. “Children and the UK GDPR”.

[xviii]  Leon Xiao, supra n(xi).

[xix] Jugendschutzgesetz (JuSchG) [Protection of Young Persons Act] (Germany), s 10b(3); Guidelines for the Classification of Computer Games 2023 (Cth) (Australia).

Read more articles on gaming and gambling in India

More on: