Industry · Schools

DPDPA Compliance for Schools in India

Schools hold more children's data than almost any other institution: admission forms, medical notes, transport GPS, CCTV, fee records, exam results, WhatsApp groups. Under the DPDP Act 2023, students under 18 are children for Section 9 — so admission, medical and most processing need verifiable parental consent, while Rule 12 keeps a narrow safety carve-out for things like bus GPS and campus CCTV. The compliance date is 13 May 2027, and Section 9 failures carry penalties up to ₹200 crore.

Last reviewed: 30 July 2026

What DPDPA compliance risks do schools face?

The exposure starts at the admission form. One signature bundling academics, transport, medical, fee financing, photography and marketing is not itemised consent — and for anyone under 18 it must come from a parent, verified. Rule 10 requires genuine due diligence that the consenting adult is identifiable, not a tick-box declaration. Section 9(3) then bars behavioural tracking and targeted advertising directed at children, which catches ed-tech plug-ins, analytics pixels and school social media handles that almost no management has audited.

What should schools prepare first for DPDPA compliance?

  • Split the admission form — one purpose, one parental choice (academics, transport, medical, photos, marketing).
  • Document Rule 10 guardian verification (identity already on file or Digital Locker–style token).
  • Audit ed-tech, website pixels, and social channels for Section 9(3) tracking and ads directed at children.
  • Put vendor DPAs in place for LMS, transport, fee gateway, biometrics, and photographers.
  • Rehearse dual-clock breach response: CERT-In 6 hours + parent intimation without delay + DPB within 72 hours.

Frequently asked questions

What actually counts as "verifiable parental consent"? Is a signature on the admission form enough?

No. Section 9(1) requires verifiable consent from the parent or lawful guardian before processing any student's data, and Rule 10 puts the due-diligence burden on you: you must take reasonable steps to confirm that the person consenting is an identifiable adult who genuinely is that child's parent or guardian. That means either identity details you already reliably hold, or a virtual token issued against verified identity by an entrusted entity. A tick-box, an unverified email link, or a signature with no identity trail will not survive scrutiny. Consent must also be itemised by purpose under Section 6 — academics, transport, medical, photography and marketing are separate asks, not one bundle. Note that a "child" is anyone under 18, so this covers your Class 12 students too; the day a student turns 18, consent shifts to them.

Does Section 9(3) mean we have to switch off bus GPS and CCTV?

No — but the exemption is narrower than most schools assume. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 12 read with the Fourth Schedule Part A(3) provides a limited carve-out for the educational institution, and Part A(5) covers a school-engaged transport provider, so tracking strictly necessary for the safety of the child — transport monitoring, campus premises security — remains permissible to that extent. The carve-out lifts Section 9(1) as well as 9(3) for that safety-restricted processing — not for marketing. What is not covered: analytics and advertising pixels on your website and app, engagement scoring inside ed-tech tools, remarketing lists built from enquiry data, admission campaigns aimed at students rather than parents, and posting identifiable student photographs to build the school's social media reach. Safety is a defence. Marketing is not.

Our ed-tech apps, photographers and transport contractors handle student data. Who is liable?

You are. The school is the Data Fiduciary; your LMS vendor, fee gateway, biometric attendance provider, yearbook photographer and bus operator are Data Processors acting on your instructions. Liability for their processing stays with you and cannot be contracted away — you need written contracts, purpose limits, deletion obligations on exit, and a list of who holds what. Two things schools commonly get wrong here: assuming medical records and biometrics fall under a stricter separate regime (DPDPA has no "sensitive personal data" category — one standard applies to everything), and leaving alumni databases and rejected-applicant files sitting in a vendor's cloud years after the purpose ended.

If our fee portal or student database is breached, what do we report — and what does it cost?

Two clocks start together and both must be met. CERT-In requires reporting of covered cyber incidents within 6 hours of detection. Separately under DPDPA, you must intimate affected parents and students without delay (Rule 7(1)), give the Board an initial description without delay (Rule 7(2)(a)), and file detailed particulars within 72 hours (Rule 7(2)(b)). On penalties: failure to observe the Section 9 obligations for children's data attracts up to ₹200 crore; failure to give the required breach intimation under Section 8(6) is assessed separately at up to ₹200 crore; and failure to maintain reasonable security safeguards attracts up to ₹250 crore — one incident can expose you under more than one head. One relief: the heavier Rule 13 obligations — annual DPIA, independent data audit, algorithmic due diligence, appointing an India-based Data Protection Officer — apply only to Significant Data Fiduciaries, which is a status the Central Government confers by notification. It is not automatic on student count. Every school still owes the baseline duties regardless.

Official sources

Free DPDPA gap scan for schools — and a badge for your website

Answer 20 questions about your admission form, your ed-tech vendors, your CCTV and transport tracking, and how you store student records. You get a written gap report scored against Section 9, Rule 10 and the security safeguards duty — no cost, no call required. Schools that clear the baseline get a DPDPA Ready badge to display for parents and at admissions.

Run the free gap scan Talk to us

Takes 10 minutes. Report emailed to your Principal or Correspondent. Nothing published without your permission.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.