Checklist · School Principal

DPDPA Checklist for School Principals

The substantive DPDPA obligations land on 13 May 2027, and in a school the accountable head is you. Most of this is not an IT project — it's your admission form, your vendor contracts, and who you have named to answer a parent. Ten things to own personally, in order.

Last reviewed: 30 July 2026

What must a school principal do for DPDPA compliance?

  1. Rebuild the admission form into itemised purposes. Pull your current form and count how many purposes hide behind one signature. Split academics, transport, infirmary/medical, fee financing, ed-tech accounts, photography, and marketing into separate choices. Rule 3 requires an itemised description of the personal data and each specified purpose in plain language. Critical: consent must be unconditional, so admission cannot be made contingent on consenting to yearbook photos or promotional use. Owner: you + Admissions Head. Artefact: versioned consent form, with the version number logged against each admission.
  2. Pick and document your Rule 10 guardian-verification method. Rule 10 requires due diligence that the person identifying as the parent is an adult (completed 18 years) who is identifiable, by reference to one of exactly three routes: reliable identity and age details the school already holds; details voluntarily provided by that individual; or a virtual token mapped to such details issued by an authorised entity, which includes a Digital Locker service provider. Decide which route you use for existing families versus new admissions, write it down, and record which method was used for each consent. A tick-box saying "I am the parent" verifies nothing.
  3. Build the 18th-birthday trigger. A "child" is anyone under 18, so Section 9 covers your Class 12 cohort — and the day a student turns 18, consent transfers from the guardian to the student. Your ERP needs a date-of-birth trigger that flags these students for re-consent in their own name. Almost no school has this, and it is the easiest gap for a parent or an ex-student to point at.
  4. Handle Rule 11 separately — students with disability who have a lawful guardian. Rule 11 is a different test from Rule 10 and applies regardless of the student's age. You must verify the guardian was appointed by a court, by a designated authority under s.15 of the Rights of Persons with Disabilities Act 2016, or by a local level committee under s.13 of the National Trust Act 1999. Do not run these students through your ordinary parental-consent flow. Owner: you + Special Educator.
  5. Run the Section 5(2) notice exercise across your existing roll. Where consent was obtained before the Act commenced, Section 5(2) requires you to give those Data Principals the required notice as soon as reasonably practicable. That means a one-time notice to the guardians of every currently enrolled student, not just new admissions. It is the single largest task on this list and the cleanest one to start with — do it in an admissions off-season, not in May 2027.
  6. Separate safety tracking from marketing surveillance — then kill the second one. Section 9(3) prohibits tracking, behavioural monitoring, and targeted advertising directed at children. Rule 12 read with Fourth Schedule Part A(3) disapplies s.9(1) and s.9(3) for an educational institution where processing is restricted to tracking and behavioural monitoring for the institution's educational activities or in the interests of the safety of enrolled children; Part A(5) covers a transport provider you engage, restricted to tracking location during travel to and from school; Part B(4) covers real-time location determination in the interest of a child's safety. Bus GPS and campus security survive. What does not: analytics and ad pixels on your website and app, remarketing lists built from admission enquiries, engagement scoring inside ed-tech dashboards, and posting identifiable student photographs to grow the school's social reach. Have someone open your site in an inspector this week and list every third-party tag. Note the carve-out covers tracking and monitoring only — it does not remove the need for verifiable parental consent for admission, medical, or photography processing.
  7. Get written Data Processor contracts on every vendor holding student data. The school is the Data Fiduciary and liability for your processors stays with you — it cannot be contracted away. Make a one-page inventory: ERP/LMS, fee gateway, biometric attendance, transport operator and its GPS app, yearbook photographer, counselling software, cloud host, WhatsApp-based communication tools. Each needs purpose limits, an explicit bar on repurposing child data for the vendor's own profiling or advertising, deletion on contract exit, and an obligation to notify you of any incident within hours, not "promptly." Rule 6(1)(f) requires appropriate security provisions in the processor contract. Owner: you + Correspondent/Trust.
  8. Name the contact person and publish the grievance route. Rule 9 requires every Data Fiduciary to prominently publish on its website or app the business contact information of the person able to answer questions about processing — and to repeat it in every response to a rights request. Rule 14(3) requires a grievance redressal system that responds within a period not exceeding ninety days. Name a real person with a real inbox, publish it on the site and on the admission form, and put the 90-day ceiling in your internal SOP so it is not discovered during a complaint. A DPO is not required (see FAQ 1) — this contact person is.
  9. Write a retention and erasure schedule, with the one-year floor in it. Decide and document how long you hold: rejected-applicant files, records of students who left or transferred, alumni databases, counselling and infirmary records, CCTV footage, and copies sitting in vendor clouds. Erase once the purpose and any statutory retention period end. But note the floor — Rule 6(1)(e) requires retaining access logs and personal data for one year as a security safeguard, and Rule 8(3) sets a one-year minimum for personal data, traffic data and processing logs. "Delete everything on request" is wrong; so is keeping 2016 enquiry lists.
  10. Rehearse the breach drill once, on paper, before it's law. Simulate the fee portal leaking on a Saturday. Four obligations run in parallel, and they are cumulative: CERT-In within 6 hours of noticing; Rule 7(1) intimation to each affected parent and student without delay; Rule 7(2)(a) initial intimation to the Data Protection Board without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. Name the incident owner and their alternate, pre-draft the parent notice, and time every phase. If your team is drafting notification text at hour four, the plan has already failed.

Frequently asked questions

Do we need a Data Protection Officer and an annual data audit?

Almost certainly not. The heavier obligations — an annual Data Protection Impact Assessment and independent audit, algorithmic due diligence, and an India-based Data Protection Officer reporting to the board — sit in Rule 13 and bind Significant Data Fiduciaries only. SDF status is conferred by Central Government notification under Section 10; it is not triggered automatically by student count, fee revenue, or number of branches. What you do owe regardless: a named contact person published under Rule 9, a grievance mechanism answering within ninety days under Rule 14(3), valid consent, purpose limitation, security safeguards, and breach notification. One related myth to retire — DPDPA has no separate "sensitive personal data" tier. Your infirmary records, disability disclosures, biometric attendance data and a parent's mobile number all sit under one legal standard. The difference is the harm, not the rule.

Do we have to switch off the school buses' GPS and the campus CCTV?

No. Rule 12 with Fourth Schedule Part A(3) and A(5), and Part B(4), permit tracking and behavioural monitoring for the institution's educational activities, in the interests of enrolled children's safety, and for determining a child's real-time location for their safety — which covers transport monitoring during the journey and campus premises security. Two cautions. The carve-out is purpose-bound, so it protects the safety use and nothing bolted onto it: if the same transport app also builds parent marketing profiles, that part is outside the exemption. And the exemption is from tracking and monitoring only — it does not excuse you from obtaining verifiable parental consent for admission, medical, academic or photographic processing. Safety is a defence. Reach is not.

If our fee portal or ERP is breached, what does it actually cost us?

Three separate penalty heads under the Schedule, and one incident can trigger more than one. Failure to observe the additional obligations for children's data under Section 9 attracts up to ₹200 crore. Failure to maintain reasonable security safeguards under Section 8(5) attracts up to ₹250 crore. Failure to give the required breach intimation under Section 8(6) attracts a further up to ₹200 crore. These are statutory ceilings, not expected fines — the Board sets actual quantum on the facts, weighing the nature and gravity of the breach, the harm caused, and your conduct, which is precisely why documented safeguards and a rehearsed notification are worth more than any policy document. Note also that ransomware locking your ERP is a personal data breach even if nothing was exfiltrated, because loss of access counts; "nothing was stolen" is not an exemption from notifying.

Official sources

Free DPDPA gap scan for schools — and a badge for your website

Answer 20 questions about your admission form, your ed-tech vendors, your CCTV and transport tracking, and how you store student records. You get a written gap report scored against Section 9, Rule 10 and the security safeguards duty — no cost, no call required. Schools that clear the baseline get a DPDPA Ready badge to display for parents and at admissions.

Run the free gap scan Talk to us

Takes 10 minutes. Report emailed to your Principal or Correspondent. Nothing published without your permission.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.