PROCESSING CHILDREN’S PERSONAL DATA 14. Processing personal data of children. – (1) Every data controller or data processor shall process a child's personal data in such a manner that protects the rights and interests of a child. (2) The data controller or a data processor shall, before processing any personal data relating to a child, verify his age and seek the consent of his parent or relevant person or authorised person having parental responsibility over the child to decide on his behalf. (3) The manner for age verification and parental consent under sub-section (2) shall be prescribed by Rules to process children's data, taking into consideration: (a) the volume of personal data processed; (b) the proportion of such personal data likely to be that of the child; (c) possibility of harm to the child arising out of the processing of personal data; and (d) such other factors as may be prescribed. (4) A data controller or a data processor shall not process any personal data of a child that is likely to cause him harm. (5) A data controller or a data processor shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children. (6) The provisions of sub-section (1) and (3) shall not apply to the processing of the personal data of a child for such purposes, as may be prescribed in this Act. CHAPTER IV ADDITIONAL REQUIREMENTS FOR PROCESSING SENSITIVE AND CRITICAL PERSONAL DATA 15. Processing of sensitive and critical personal data. – (1) Subject to sub-section (6) of section 6, a data controller shall not process any sensitive and critical personal data of a data subject except under the following conditions: (a) the data subject has given his explicit consent to the processing of the personal 18

Select target paragraph3