Your Data Is the Product: A Teen's Guide to Digital Privacy in India
Quick take
Nobody is charging you for the app because the app isn't the product. You are. India now has a real data protection law with specific rules for under-18s — here's what it says, and the twenty minutes of settings work nobody will do for you.
Explore this topic
Article body
Your Data Is the Product: A Teen's Guide to Digital Privacy in India
Count the apps on your phone you have never paid a rupee for. Photo editors, wallpaper apps, a game you installed for one bus ride, three different quiz apps, a flashlight app that somehow needed your contacts.
Building and running those apps costs real money — servers, engineers, storage. Somebody is paying for all of it. If it is not you, then you are not the customer. You are the inventory.
That is not a conspiracy theory, it is just the business model, and it has been the business model for twenty years. What has changed is that India now has an actual law about it — with specific rules for people under 18 — and almost nobody your age knows what it says.
The app is free. Something else is being paid for.
What actually gets collected
People imagine data collection as somebody reading their messages. It is duller and much wider than that.
A typical free app can see the model and make of your phone, your operating system version, your rough location from your IP address, your precise location if you granted it, which other apps you have installed in some cases, how long you spend on each screen, what you tap, what you scroll past quickly, when you open the app and when you close it, and an advertising ID that ties all of this to the same you across different apps.
None of that is your name. That is the point people miss — it does not need to be. A device that opens a JEE prep app at 6am, a specific school's location on weekdays, a Class 12 board result app in May, and a college admission site in June is a very identifiable person, and the profile is more valuable than the name.
The uncomfortable version: your data is not valuable because of who you are now. It is valuable because of what you are about to become — someone who will pick a college, take a loan, buy a first phone with their own money, and choose a bank. Advertisers are not bidding on your attention today. They are bidding on your next ten years.
Where it goes
Some of it stays with the app. Plenty of it does not.
Most free apps include third-party kits for advertising and analytics — small pieces of code from other companies bundled inside the app. When you use the app, those companies get their share of the data too. So "which app is collecting this?" often has more than one answer, and you agreed to all of them with a single tap on Accept.
From there, data can be sold or shared onward to brokers who combine it with other sources. Nobody sends you a receipt when that happens.
The average person spends about two seconds on this screen. That's the design, not an accident.
India actually has a law now — and it treats you differently
The Digital Personal Data Protection Act was passed in 2023, and the detailed rules under it were formally notified in November 2025. A Data Protection Board of India has been set up to enforce it. Most of the heavy compliance obligations on companies phase in over roughly the next year and a half rather than all at once, so this is a law you will watch arrive in real time.
Here is the part that concerns you directly. Under this law, anyone under 18 is a child — not 13, not 16, eighteen. And that comes with specific protections:
- Verifiable parental consent is required before a platform processes a child's personal data. Not a checkbox saying "I am over 18" — the platform is expected to actually verify that an adult consented, and that they are your parent or guardian.
- Tracking and behavioural monitoring of children is restricted, as is targeted advertising directed at them, unless a specific exemption applies.
- There is a narrow carve-out allowing real-time location processing where it is genuinely for a child's safety.
Two honest caveats. First, a law existing is not the same as a law being followed — enforcement takes years, and the gap between the rule and reality is where you actually live. Second, this only ever protects data you have not already handed over voluntarily. No law can un-send a screenshot.
The one line worth remembering
- The law makes companies responsible for how they take your data.
- It cannot make them responsible for what you post yourself.
- Those are two different problems and only one of them has a lawyer working on it.
The twenty-minute cleanup
None of this requires technical skill. It requires twenty minutes once, and about two minutes a month after that.
1. Audit permissions, not apps
On Android: Settings → Privacy → Permission manager. On iPhone: Settings → Privacy & Security. Go permission by permission rather than app by app. Look at everything that has Location, then everything with Microphone, then Contacts, then Camera. Ask one question per app: does this app need this to do its job? A photo editor needs storage. It does not need your contacts. A wallpaper app does not need your location.
Set location to "While using the app" wherever you keep it at all. Very few apps have any business knowing where you are while closed.
2. Reset your advertising ID
Android: Settings → Privacy → Ads, where you can delete or reset the advertising ID. iPhone: Settings → Privacy & Security → Tracking, and turn off "Allow Apps to Request to Track". This breaks the thread linking your behaviour across apps. Do it every few months.
3. Deal with the Aadhaar habit
Sending a photo of your Aadhaar card on WhatsApp to a coaching centre, a hostel, a gym, or a person selling a second-hand phone is extremely normal and genuinely risky, because that image now exists on their phone, their backup, and any group they forward it to.
Use a masked Aadhaar or a Virtual ID from the official UIDAI site instead — it hides most digits while still serving as valid proof. Where a document must be shared, share the minimum version that does the job. And treat an OTP the way you'd treat your house key: nobody legitimate ever needs it, including someone who says they are calling from your bank.
4. Stop using one password everywhere
When a random site gets breached — and they do, constantly — the leaked password is immediately tried on your email, because attackers assume reuse and are usually right. Your email is the master key: whoever holds it can reset everything else. Give your email a password used nowhere else, and turn on two-factor authentication on it today.
5. Be suspicious of the fun stuff
Personality quizzes, "which anime character are you", horoscope apps, apps that age your face, free ringtone apps, apps that promise to show who viewed your profile — this category is where the worst permission requests hide, because nobody reads a permission screen while they are entertained. That last one, "who viewed your profile", is essentially always a scam or a data grab. The platforms do not provide that information to anyone.
The most invasive permission requests almost always arrive attached to something fun.
A quick table you can act on
| Location, always-on | Change to "while using" — or off. Almost nothing needs it in the background. |
| Contacts access | Deny by default. This is how apps map your entire social circle without ever meeting them. |
| Microphone | Only for apps you actively speak into. Revoke everywhere else. |
| "Log in with Google" | Convenient and generally safer than a reused password — but review connected apps twice a year and remove what you no longer use. |
| Aadhaar photo in chat | Use masked Aadhaar or a Virtual ID instead. Delete old ones you've already sent where you can. |
| Public Wi-Fi | Fine for browsing. Not for banking, not for anything you'd hate to lose. |
Menu paths differ slightly by phone brand and Android version — search your exact model if an option isn't where described.
The part that isn't about settings
Every privacy guide ends with a settings checklist, and the checklist is genuinely useful, but it is the smaller half of the problem.
The bigger half is that a lot of what will follow you was volunteered. A story posted in anger. A group chat screenshot. A photo of somebody else you did not ask before posting. A username reused across ten platforms that ties an account you'd like to keep separate to your real name in about four seconds of searching.
Assume anything you send can be screenshotted, and anything screenshotted can resurface at the worst possible time — during an admission process, in front of a family member, in an argument two years from now with somebody who used to be a friend. That is not paranoia. It is just how the medium works.
A test that works: before you post, ask whether you'd be fine with it being read out by someone who dislikes you, to someone whose opinion of you matters. If the answer is no, that is your answer. It takes three seconds and it has saved more people than any privacy setting.
Why this is a skill and not a lecture
Data protection is now a growing professional field in India — the law created demand for people who understand consent, retention, and how systems are supposed to handle personal information. Compliance roles, security work, policy analysis. Some of the people who will do those jobs in ten years are in Class 11 right now and do not know the field exists.
But even if you never work in it: understanding how the economics of the internet actually function makes you very hard to manipulate. You stop being surprised that the app is free. You start noticing what it wants in return.
Twenty minutes. Today.
Open your permission manager and go through it once. You will find at least three things that make no sense — you always do. That's the whole first step.
Then tell one person to do the same.Comments 0
Keep reading
Similar blogs by topic
AI Agents Explained: The Tech That Will Do Your Homework and Your Job
A chatbot answers. An agent does. That one difference is quietly rewriting which jobs will exist by the time you finish college — and you can build one yourself this weekend for zero rupees.
I Asked 12 Seniors What They'd Do Differently in Class 11.
Twelve people who are already through it, one question each. Nobody said they should have studied more hours. Almost everybody said some version of the same three things.
Everyone in My Class Wants to Be an Engineer. I Asked Them Why.
Almost every hand went up. So I went around and asked each of them for their actual reason — and the answers fell into four groups, only one of which was really an answer.