What DPDP Act 2023 obligations apply to educational institutions? Educational institutions — schools, colleges, universities, and EdTech platforms — process personal data of students, parents, and staff, often including sensitive data such as academic performance, health records, and financial information. Under the DPDP Act 2023, they must obtain parental consent for processing children's data (students under 18), maintain a clear privacy notice, enable data principals to access or correct their records, and sign DPAs with third-party platforms used for learning management or communication. EdTech platforms with large child user bases may be designated Significant Data Fiduciaries.
Schools, universities, and EdTech platforms collect student data from millions of learners — including minors. Here's exactly what DPDP requires you to do.
Most students are under 18. DPDP Section 9's strictest rules — including verifiable parental consent — apply automatically. Processing student data without meeting this standard is a direct violation, regardless of whether you believed users were adults.
Up to ₹200 Cr penaltyPerformance data, learning disabilities, attendance records, and behavioural assessments all qualify as personal data under DPDP requiring specific consent. Many institutions treat these as internal records — but they are regulated data under the Act.
Requires explicit consentMost institutions use 5–10 platforms — LMS, video conferencing, assessment tools, payment gateways, analytics. Each is a data processor requiring a written Data Processing Agreement (DPA). Without DPAs, every integration is a compliance gap.
DPA required per vendor"Users self-declare age" is NOT verifiable parental consent under Section 9. A sign-up checkbox or date-of-birth field that the minor fills out does not satisfy the parental consent requirement. If a minor lies about their age, the obligation still rests with you.
Strict liability applies| Obligation | DPDP Section | Max Penalty | Typical Compliance Gap |
|---|---|---|---|
| Parental consent for student data All data collected from students under 18 |
S.9 | ₹200 Cr | Common gap: Implicit consent assumed from admission form. Admission forms collect data but do not constitute verifiable parental consent under DPDP. |
| Staff employment data handling HR, payroll, attendance, performance records |
S.6 | ₹50 Cr | Common gap: No DPDP privacy notice issued to employees. Most schools issue employment contracts but not a separate data processing notice. |
| Third-party vendor DPAs LMS, library software, transport tracking, CCTV vendors |
S.9 | ₹200 Cr | Common gap: No written DPAs with technology vendors. Verbal agreements or purchase orders do not substitute for a DPDP-compliant DPA. |
| CCTV footage as personal data Video surveillance of students and staff |
S.6 | ₹50 Cr | Common gap: CCTV footage not subject to a consent or retention policy. Footage kept indefinitely without a disclosed retention period. |
| Alumni data retention Records of past students kept after graduation |
S.8(7) | ₹50 Cr | Common gap: Alumni data retained indefinitely with no retention schedule. DPDP requires data to be deleted once the purpose is served. |
| Obligation | DPDP Section | Max Penalty | Typical Compliance Gap |
|---|---|---|---|
| Age verification before account creation Before any personal data is collected |
S.9 | ₹200 Cr | Common gap: Date-of-birth field at sign-up without any verification. A minor can enter a false DOB and create an account — this does not discharge the parental consent obligation. |
| Parental consent for under-18 users Verifiable consent before account activation |
S.9 | ₹200 Cr | Common gap: T&C checkbox accepted from the minor user. Section 9 requires consent from the parent or guardian — not from the child. |
| Behavioural targeting of student users Retargeting, ad personalisation, social pixels |
S.9 | ₹200 Cr | Common gap: Facebook Pixel, Google Ads retargeting, or remarketing lists that include student users. DPDP S.9(3) explicitly prohibits this for under-18 users. |
| Learning analytics and profiling Performance scoring, learning style classification, AI tutors |
S.9 | ₹200 Cr | Common gap: AI-based learning analytics that infer student potential, aptitude, or learning difficulties without a separate, specific consent disclosing the profiling. |
| Payment data from parents Fee collection, subscription billing, EMI |
S.6 | ₹50 Cr | Common gap: No separate consent notice for payment processing. The fee payment page must disclose the payment processor, purpose, and data sharing — separate from the general privacy policy. |
| Obligation | DPDP Section | Max Penalty | Typical Compliance Gap |
|---|---|---|---|
| Candidate identity document storage Aadhaar, PAN, passport uploaded at registration |
S.4 | ₹200 Cr | Common gap: Aadhaar or government ID collected and stored without explicit consent specifying: why it is needed, how long it will be retained, and who can access it. |
| Biometric attendance Fingerprint or face recognition at exam centres |
S.4 | ₹200 Cr | Common gap: Biometric data collected under the assumption that exam registration implies consent. DPDP requires explicit, specific consent for biometric data — separate from general T&C. |
| Result data sharing with universities Score reports sent to admissions portals |
S.9 | ₹200 Cr | Common gap: No DPA with university portals and admissions platforms. Sharing candidate result data with a third-party portal requires both consent from the candidate and a signed DPA with the receiving entity. |
| Hall ticket photo storage Candidate photos stored for verification |
S.6 | ₹50 Cr | Common gap: No defined retention or deletion policy for hall ticket photographs. Photos stored indefinitely in exam databases without any deletion schedule violate DPDP's data minimisation and retention obligations. |
Section 9 carries the highest penalty in the entire DPDP Act — up to ₹200 Crore per violation. This is 4x higher than most other sections. For an EdTech platform serving 1 lakh students, a single consent mechanism failure — such as allowing a minor to self-register without parental consent — could trigger this penalty. The Data Protection Board, once constituted, can investigate on the basis of a single complaint and can impose penalties that are not capped per complainant but per violation category. With millions of student accounts, the exposure is not theoretical.
3-step online assessment of your Section 9 posture. Instant compliance score + top violations. Full report with consent templates, training checklist, and penalty exposure calculation.
Full-scope DPDP compliance assessment for EdTech platforms. Covers Section 9 obligations, data inventory, vendor DPAs, privacy notices, grievance officer setup, and enforcement readiness.
Live or recorded training workshop for education institutions and EdTech teams. Covers all Section 9 obligations, consent standards, parental rights, and breach response — specific to the education sector.
Tell us about your institution and we'll map your exact DPDP obligations — covering Section 9, vendor DPAs, parental consent mechanisms, and your enforcement timeline.
Yes. DPDP applies to any entity processing personal data of Indian citizens in digital form, including government educational institutions. However, the central government may notify certain exemptions for state or government bodies through rules — these have not been notified yet.
No. Admission forms collect data for the purpose of admission processing. They do not constitute DPDP-compliant consent because they do not: (a) itemise each category of data and its purpose, (b) allow parents to consent selectively, (c) describe data retention periods, or (d) explain parents' rights to access, correct, or delete data.
DPDP does not have a grandfather clause for existing users. Platforms must re-obtain verifiable parental consent for all existing minor users, or stop processing their data. This is one of the most operationally complex aspects of Section 9 compliance for established EdTech platforms.
The DPDP Act 2023 is in force. The Data Protection Board of India is expected to become operational in 2026, with active enforcement from May 2027. However, violations occurring today can be investigated once the Board is constituted — building compliance now protects against retrospective liability.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.