Click the Play button to listen to article

On June 1, 2026, the Central Consumer Protection Authority (CCPA) penalised PhysicsWallah Limited with ₹5 lakh for deployment of dark patterns on its platform. The order narrates that PhysicsWallah maintained a pre-ticked “Donate for PW Foundation” checkbox which added ₹10 to the final checkout bill unless the user affirmatively unchecks it. The order also found that the “free courses” that PhysicsWallah offered were inaccessible unless every user affirmatively surrenders their phone number and email address to the platform. The CCPA, upon independent investigation, identified that the registration wall, which included collection of phone number and email address of its users, did not demonstrate to serve any function to merit its conditioning for the users. PhysicsWallah was held liable by CCPA under Sections 2(9), 2(28) and 2(47) of the Consumer Protection Act, 2019 read with Consumer Protection (E- Commerce) Rules, 2020 and Guidelines for Prevention and Regulation of Dark Patterns 2023.

The CCPA proceeding, however, surfaces a separate question, one which the CCPA was never designed to address. Even if the consumer-protection violation is maintained, was PhysicsWallah's collection and processing of users' personal data itself lawful? This article examines this inquiry under the light of India's data protection law, the Digital Personal Data Protection Act, 2023 (DPDPA).

The limits of the Fourth Schedule exemption

Section 9(1) of the DPDPA mandates a Data Fiduciary to obtain verifiable parental consent before processing the personal data of a user under the age of eighteen. Section 9(3) prohibits tracking, behavioural monitoring or targeted advertising directed at children. The provision stands independent of consent, meaning even by consent the prohibition cannot be bypassed. Additionally, Rule 12 of the Digital Personal Data Protection Rules, 2025 read with Part A of the Fourth Schedule creates a narrow possibility of bypassing Section 9(1) and 9(3) for the following five specific classes of Data Fiduciary: 1) healthcare establishments 2) allied healthcare professionals 3) educational institutions 4) day-care providers and 5) child-transport operators engaged by such institutions.

Under Entry 3 of Part A, Fourth Schedule, a Data Fiduciary who is an educational institution is exempted to process children's data for the purpose of tracking and monitoring behaviour for a) educational activities of such institutions and b) ensuring safety of children enrolled with such institution. The Fourth Schedule defines an “educational institution” as “an institution of learning that imparts education, including vocational education”. However, being an educational institution does not suffice to enjoy the exemption under the law. The exemption may be unlocked only under select purposes of data processing i.e., when processing is purpose limited to educational activity or tracking associated with the child's safety.

Measures such as Anti-piracy, prevention of duplicate account, account integrity across devices and personalised learning raise further question i.e., when does data processing undertaken by an EdTech platform remain adequately connected to educational activity to fall within Entry 3? They are platform security measures common to commercial applications whose nexus with the educational purposes contemplated by Entry 3 is not self-evident. A teacher tracking whether a student has attempted her homework shows an obvious nexus with educational activity. However, obtaining a phone number to prevent duplicate account creation presents a less obvious connection with the purposes specified under Entry 3. Moreover, a substantial portion of any EdTech platform's target population is likely to fall within the statutory definition of a child. Whether such collection falls within the purposes protected under the Fourth Schedule would depend upon the nexus between the processing activity and the educational purposes specified in Entry 3.

Data minimisation beyond consumer protection

Even if we assume that the protection within Entry 3 includes platform security measures, the Rule 12 offers immunity against applicability of Section 9(1) i.e., verifiable parental consent and 9(3) i.e., behavioural tracking and targeted advertisement. Section 6 of the Act's purpose limitation and data minimisation would continue to remain applicable. The Data Fiduciary must ensure that the personal data obtained and processed by it is limited to the purpose for which the data was obtained. Further, Section 8(1) puts the responsibility to comply on the Data Fiduciary, “irrespective of any agreement to the contrary”.

CCPA's findings indicate that the registration wall did not demonstrate a functional necessity between the data collected and the corresponding service delivered. An examination of the foregoing under the DPDPA would require the Data Fiduciary to demonstrate that the personal data collected through such a data wall satisfies the statutory requirements governing processing. If the collection cannot be justified under those requirements, conditioning access to a service labelled as 'free' may raise a compliance question under the DPDPA

Children's well-being and manipulative interfaces

Then there remains Section 9(2), which the Fourth Schedule fails to exempt. Unlike sub-sections (1) and (3), sub-section (2) survives regardless of the Data Fiduciary type or purpose. It prohibits a Data Fiduciary from “such processing of personal data that is likely to cause any detrimental effect on the well-being of a child”. The CCPA characterising the interface to be psychologically manipulative raises a further question under Section 9(2), i.e., would an interface found to be manipulating consumers carry more significance where the affected user is a child? The Data Protection Board of India could also scrutinise it accordingly taking into account that children constitute a legally protected class under the DPDPA.

The regulatory gap this exposes

This discussion leads to two regulatory observations. Firstly, the CCPA observed that the pre-selected donation box remained active from 14th February 2024 to 24th December 2025, and during that period it collected about ₹2.47 crore from more than 21 lakh users. The difference in regulatory repercussions as well makes coordination necessary. A factual record developed in a CCPA proceeding may later become relevant to a Data Protection Board proceeding involving a distinct statutory and enforcement architecture.

Secondly, the regulatory design of compliance raises another concern. The CCPA has conducted its investigation over the allegations levelled on PhysicsWallah. It tested the personalisation claim, compared it with relevant platforms, and developed a repository of fact findings. Data Protection Board, being an independent regulatory body, cannot treat the CCPA's conclusions as conclusive proof of a DPDPA violation. The two authorities operate under distinct statutory mandates, legal tests and procedural safeguards.

India's EdTech platforms may increasingly discover that a conduct compliant with one statutory regime may raise question under another. The CCPA order exposes an issue beyond dark patterns. As digital activities increasingly fall within the jurisdiction of multiple regulatory authorities, India needs mechanisms for cross-regulatory coordination. Without mechanisms for coordination, regulators may develop duplicate factual inquiries that have already been undertaken elsewhere.

Author Shambhunath Yadiyapur is the Coordinator of the Centre for Applied Data Protection, Bengaluru. 

Tags: