DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

What DPDP Act 2023 obligations apply to educational institutions? Educational institutions — schools, colleges, universities, and EdTech platforms — process personal data of students, parents, and staff, often including sensitive data such as academic performance, health records, and financial information. Under the DPDP Act 2023, they must obtain parental consent for processing children's data (students under 18), maintain a clear privacy notice, enable data principals to access or correct their records, and sign DPAs with third-party platforms used for learning management or communication. EdTech platforms with large child user bases may be designated Significant Data Fiduciaries.

Free Guide · Education Sector · DPDP Act 2023

DPDP Compliance for Educational Institutions — Students & Children's Data

Schools, universities, and EdTech platforms collect student data from millions of learners — including minors. Here's exactly what DPDP requires you to do.

Section 9 obligations EdTech-specific rules Penalty framework Free instant checklist
Why Education is a High-Risk Sector Under DPDP
Four structural reasons the education sector faces the most severe DPDP exposure of any industry in India.
1

Student Data = Children's Data

Most students are under 18. DPDP Section 9's strictest rules — including verifiable parental consent — apply automatically. Processing student data without meeting this standard is a direct violation, regardless of whether you believed users were adults.

Up to ₹200 Cr penalty
2

Academic Records Are Sensitive Personal Data

Performance data, learning disabilities, attendance records, and behavioural assessments all qualify as personal data under DPDP requiring specific consent. Many institutions treat these as internal records — but they are regulated data under the Act.

Requires explicit consent
3

Third-Party EdTech Stack = Multiple Data Processors

Most institutions use 5–10 platforms — LMS, video conferencing, assessment tools, payment gateways, analytics. Each is a data processor requiring a written Data Processing Agreement (DPA). Without DPAs, every integration is a compliance gap.

DPA required per vendor
DPDP Obligations for Education — By Sub-Sector
Select your sector to see specific obligations, applicable DPDP sections, penalty levels, and the most common compliance gaps.
Obligation DPDP Section Max Penalty Typical Compliance Gap
Parental consent for student data
All data collected from students under 18
S.9 ₹200 Cr Common gap: Implicit consent assumed from admission form. Admission forms collect data but do not constitute verifiable parental consent under DPDP.
Staff employment data handling
HR, payroll, attendance, performance records
S.6 ₹50 Cr Common gap: No DPDP privacy notice issued to employees. Most schools issue employment contracts but not a separate data processing notice.
Third-party vendor DPAs
LMS, library software, transport tracking, CCTV vendors
S.9 ₹200 Cr Common gap: No written DPAs with technology vendors. Verbal agreements or purchase orders do not substitute for a DPDP-compliant DPA.
CCTV footage as personal data
Video surveillance of students and staff
S.6 ₹50 Cr Common gap: CCTV footage not subject to a consent or retention policy. Footage kept indefinitely without a disclosed retention period.
Alumni data retention
Records of past students kept after graduation
S.8(7) ₹50 Cr Common gap: Alumni data retained indefinitely with no retention schedule. DPDP requires data to be deleted once the purpose is served.
Obligation DPDP Section Max Penalty Typical Compliance Gap
Age verification before account creation
Before any personal data is collected
S.9 ₹200 Cr Common gap: Date-of-birth field at sign-up without any verification. A minor can enter a false DOB and create an account — this does not discharge the parental consent obligation.
Parental consent for under-18 users
Verifiable consent before account activation
S.9 ₹200 Cr Common gap: T&C checkbox accepted from the minor user. Section 9 requires consent from the parent or guardian — not from the child.
Behavioural targeting of student users
Retargeting, ad personalisation, social pixels
S.9 ₹200 Cr Common gap: Facebook Pixel, Google Ads retargeting, or remarketing lists that include student users. DPDP S.9(3) explicitly prohibits this for under-18 users.
Learning analytics and profiling
Performance scoring, learning style classification, AI tutors
S.9 ₹200 Cr Common gap: AI-based learning analytics that infer student potential, aptitude, or learning difficulties without a separate, specific consent disclosing the profiling.
Payment data from parents
Fee collection, subscription billing, EMI
S.6 ₹50 Cr Common gap: No separate consent notice for payment processing. The fee payment page must disclose the payment processor, purpose, and data sharing — separate from the general privacy policy.
Obligation DPDP Section Max Penalty Typical Compliance Gap
Candidate identity document storage
Aadhaar, PAN, passport uploaded at registration
S.4 ₹200 Cr Common gap: Aadhaar or government ID collected and stored without explicit consent specifying: why it is needed, how long it will be retained, and who can access it.
Biometric attendance
Fingerprint or face recognition at exam centres
S.4 ₹200 Cr Common gap: Biometric data collected under the assumption that exam registration implies consent. DPDP requires explicit, specific consent for biometric data — separate from general T&C.
Result data sharing with universities
Score reports sent to admissions portals
S.9 ₹200 Cr Common gap: No DPA with university portals and admissions platforms. Sharing candidate result data with a third-party portal requires both consent from the candidate and a signed DPA with the receiving entity.
Hall ticket photo storage
Candidate photos stored for verification
S.6 ₹50 Cr Common gap: No defined retention or deletion policy for hall ticket photographs. Photos stored indefinitely in exam databases without any deletion schedule violate DPDP's data minimisation and retention obligations.
Quick Self-Assessment — 6 Questions
Answer honestly. You'll get an instant readiness verdict for your organisation.
1Do you verify age before collecting student data, and obtain verifiable parental consent for under-18 users before activating their account?
2Do you have written Data Processing Agreements (DPAs) with all EdTech vendors you use — including LMS, video platform, and payment gateway?
3Do you have a children's privacy notice written in simple, parent-friendly language — separate from your main privacy policy?
4Do you explicitly prohibit behavioural advertising, psychological profiling, and tracking of student users under 18?
5Do you have a documented process to delete a student's data within 30 days of a parental deletion request?
6Have your staff and product teams received DPDP training specifically covering children's data obligations under Section 9?

Highest Penalty in the Entire DPDP Act

The Section 9 Penalty Reality for EdTech

₹200 Crore per violation — 4x higher than most other DPDP sections

Section 9 carries the highest penalty in the entire DPDP Act — up to ₹200 Crore per violation. This is 4x higher than most other sections. For an EdTech platform serving 1 lakh students, a single consent mechanism failure — such as allowing a minor to self-register without parental consent — could trigger this penalty. The Data Protection Board, once constituted, can investigate on the basis of a single complaint and can impose penalties that are not capped per complainant but per violation category. With millions of student accounts, the exposure is not theoretical.

What Niti Bharat Does for Education
From quick online assessments to full compliance engagements — structured around the education sector's specific DPDP risks.
🛡️

Children's Data Compliance Assessment

3-step online assessment of your Section 9 posture. Instant compliance score + top violations. Full report with consent templates, training checklist, and penalty exposure calculation.

₹999
Start Free Assessment →
📋

DPDP Readiness Assessment for EdTech

Full-scope DPDP compliance assessment for EdTech platforms. Covers Section 9 obligations, data inventory, vendor DPAs, privacy notices, grievance officer setup, and enforcement readiness.

₹75,000
Request Proposal →

Talk to a DPDP Expert — Free 30-Minute Call

Tell us about your institution and we'll map your exact DPDP obligations — covering Section 9, vendor DPAs, parental consent mechanisms, and your enforcement timeline.

✓ No obligation ✓ 30-minute call ✓ DPDP Act 2023 specialists ✓ Education sector focus

Frequently Asked Questions — DPDP for Education

Does the DPDP Act apply to government schools?

Yes. DPDP applies to any entity processing personal data of Indian citizens in digital form, including government educational institutions. However, the central government may notify certain exemptions for state or government bodies through rules — these have not been notified yet.

Is the admission form consent sufficient for DPDP compliance?

No. Admission forms collect data for the purpose of admission processing. They do not constitute DPDP-compliant consent because they do not: (a) itemise each category of data and its purpose, (b) allow parents to consent selectively, (c) describe data retention periods, or (d) explain parents' rights to access, correct, or delete data.

What happens to EdTech platforms that already have millions of minor users signed up?

DPDP does not have a grandfather clause for existing users. Platforms must re-obtain verifiable parental consent for all existing minor users, or stop processing their data. This is one of the most operationally complex aspects of Section 9 compliance for established EdTech platforms.

When does DPDP enforcement start?

The DPDP Act 2023 is in force. The Data Protection Board of India is expected to become operational in 2026, with active enforcement from May 2027. However, violations occurring today can be investigated once the Board is constituted — building compliance now protects against retrospective liability.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Act 2023 for Fintech CompaniesDPDP Act 2023 for Manufacturing Companies: What Yo…DPDP Act Compliance Checklist for BPO & KPO Compan…Privacy by Design Checker for EngineeringSee all By Sector tools →📝 DPDP Apply Payment Data Fintech📝 DPDP for Saas Companies