In a recent LinkedIn post, Chirag Goswami highlights the significant implications of the Digital Personal Data Protection Act (DPDP) on how companies handle user consent, particularly for minors. Goswami uses a humorous meme to pivot to the serious regulatory changes that now require more than a simple “I agree” from users under 18.
Goswami emphasizes the shift from a lenient past to a stringent present, stating:
“For years, platforms accepted a simple “I agree.” That assumption doesn’t work anymore.”
The core of Goswami’s argument centers on the necessity for businesses to implement robust age verification and obtain verifiable parental consent for underage users. This moves beyond mere administrative tasks, fundamentally altering the design and user experience of applications and onboarding processes.
The New Standard for Consent Under DPDP
Chirag Goswami argues that the DPDP Act necessitates a fundamental re-evaluation of how data privacy is integrated into product development. The days of assuming a user’s age or accepting a self-declared agreement are over. Goswami points out the new requirements:
“Now companies must verify age, capture guardian consent, and prove it if questioned.”
This mandates a proactive approach to data collection, where the burden of proof lies with the company. Goswami clarifies that this is not simply about generating more paperwork but about embedding privacy considerations into the very architecture of digital services.
Beyond Paperwork: A Design Philosophy Shift
Goswami’s analysis suggests that compliance with DPDP is not a box-ticking exercise. Instead, it requires a deeper commitment to understanding user data provenance. As Goswami puts it:
“DPDP isn’t about forms. It’s about knowing exactly who you’re collecting data from.”
This perspective underscores the principle of ‘Privacy by Design,’ urging companies to build systems that inherently protect user data and respect consent, especially for vulnerable populations like minors. The implications extend to user interface design, data storage policies, and internal data handling protocols. Companies must demonstrate a clear chain of custody for consent, ensuring that every data point collected is done so with explicit, verifiable permission.
The Broader Impact on Digital Platforms
The insights shared by Chirag Goswami on LinkedIn suggest a future where user onboarding will be more complex but also more trustworthy. The requirement for verifiable parental consent, according to Goswami, forces platforms to engage with users, and their guardians, in a more meaningful and transparent way. This could lead to increased user trust and a more responsible digital ecosystem. The emphasis on verification means that the technical and operational challenges are significant, requiring investment in new technologies and processes to meet the DPDP Act’s mandates effectively.
In conclusion, Chirag Goswami’s post serves as a critical alert to businesses operating under the DPDP Act, highlighting that robust, verifiable consent mechanisms, particularly for minors, are no longer optional but a foundational requirement for compliant and ethical data handling.
📝 About This Content
This article is based on insights shared by Chirag Goswami on LinkedIn.
📅 Originally posted on March 3, 2026 | View original post on LinkedIn →