Protecting Children in the Digital Era: A Critical Analysis of India's Legal Framework from POCSO to the Digital Personal Data Protection Act, 2023

Main Article Content

Sakshi Bansal

Abstract

India's legal architecture for protecting children online has developed in disconnected layers rather than as a single, coherent scheme. The Protection of Children from Sexual Offences Act, 2012 was drafted for a world of physical proximity between offender and victim and had to be retrofitted through its 2019 amendment to reach the creation, storage and circulation of child sexual abuse material online. The Information Technology Act, 2000, principally through Sections 67, 67A and 67B and the Intermediary Guidelines of 2021, supplied the platform-facing obligations that POCSO itself does not impose. The Supreme Court's 2024 decision in Just Rights for Children Alliance v. S. Harish stitched these two statutes together for the first time in a single interpretive framework, while the constitutional recognition of privacy as a fundamental right in K.S. Puttaswamy v. Union of India supplied the doctrinal foundation for a data-protection statute that did not yet exist. That statute, the Digital Personal Data Protection Act, 2023, finally addresses a different but related harm: not the abuse of a child's image but the commercial exploitation of a child's data. This paper traces the four-stage evolution of criminal law, cyber law, constitutional law and data-protection law and argues that while each stage was individually necessary, their combined effect remains fragmented and supplements the analysis with primary survey evidence (N = 157) testing whether the gaps identified in the statutory text are also felt in practice. It argues that while each legislative stage was individually necessary, their combined effect remains fragmented. In conclusion the survey data corroborates from the perspective of parents, legal professionals, technologists and young people themselves. The paper concludes with recommendations for harmonizing enforcement across the Ministry of Home Affairs, the Ministry of Electronics and Information Technology and the forthcoming Data Protection Board of India. The notification of the Digital Personal Data Protection Rules, 2025 on 13 November 2025 operationalized for the first time statutory obligations on data fiduciaries regarding children's personal data, including a bar on behavioral tracking and targeted advertising directed at minors and a requirement of verifiable parental consent. However, the phased implementation timeline - extending key obligations to November 2026 and May 2027 - means that meaningful protection remains prospective rather than actual. This paper undertakes a doctrinal, empirical and comparative legal analysis of the legislative continuum from POCSO (2012) through the Information Technology Act, the Juvenile Justice Act, 2015, to the DPDP Act, 2023 and DPDP Rules, 2025. It identifies definitional inconsistencies, the practical infeasibility of verifiable age-and-consent architecture and jurisdictional fragmentation among enforcement bodies as the principal weaknesses of the current regime. Drawing on comparative frameworks - the U.S. Children's Online Privacy Protection Act, the UK Age-Appropriate Design Code and Australia's Online Safety Act - the paper argues that statutory completeness on paper has outpaced institutional capacity to protect children in practice and proposes a converged, child-centric enforcement architecture to close this gap.

Article Details

How to Cite
Sakshi Bansal. (2026). Protecting Children in the Digital Era: A Critical Analysis of India’s Legal Framework from POCSO to the Digital Personal Data Protection Act, 2023. International Journal of Special Education, 41(19s), 1286–1298. Retrieved from https://internationalsped.com/index.php/ijse/article/view/5899
Section
General