What does an EdTech platform need for DPDP compliance around children's data? An EdTech platform serving users under 18 must implement a verifiable parental consent workflow before processing a child's personal data, avoid any behavioural tracking or targeted advertising directed at children under DPDP Section 9, publish a student data policy explaining what is collected and why, and issue clear notices to both parents and teachers/schools where relevant. This pack builds the consent workflow, the Section 9 compliance framework, the student data policy, and vendor clauses for any ed-tech tooling that touches student data.
Build a verifiable parental consent workflow, a DPDP Section 9 compliance framework, and a full student data policy — for platforms with users under 18.
What 'verifiable' requires: DPDP Section 9 requires that consent for processing a child's (under-18) personal data be given by a parent or lawful guardian, and that the consent be verifiable — not a self-declared checkbox by the child themselves, and not an unverified parental email click-through alone. Acceptable verification approaches for an EdTech platform typically combine: parent-provided contact details validated via OTP, a parent-account layer that gates the child's profile creation, and a re-verification trigger if account details later change.
Design decisions this framework covers: Where in the signup funnel age is captured (before or after account creation — before is required), how the platform routes a self-registering under-18 user into the parental-consent flow rather than allowing standalone signup, and what happens if parental consent is not completed within a defined window (account should not activate).
The two hard prohibitions: Section 9 of the DPDP Act prohibits (a) processing of a child's personal data in any manner likely to cause detrimental effect on their wellbeing, and (b) tracking or behavioural monitoring of children, or targeted advertising directed at children. For an EdTech platform this means learning-analytics features that build behavioural profiles for ad-targeting purposes — as opposed to pure pedagogical progress tracking used only to serve the child's own learning — sit in a legally risky zone that needs explicit review.
What the checklist flags based on your inputs: If you indicated in-platform advertising, this is flagged as a likely Section 9 violation for your under-18 user segment and must be scoped out or made strictly non-targeted/contextual. If you indicated behavioural analytics, the checklist distinguishes permitted 'learning progress tracking' from prohibited 'behavioural profiling for engagement/ad purposes' and tells you which category each of your current features falls into.
Documents selected for your compliance pack:
The DPDP Act sets its steepest penalty tier — up to ₹200 crore — specifically for violations involving children's personal data, alongside breach-notification failures. EdTech platforms, by the nature of their user base, are structurally more likely to process children's data than almost any other sector, which makes Section 9 compliance a first-order legal risk rather than a secondary consideration. A platform that has strong general privacy practices but no verifiable parental consent mechanism is still fully exposed under this highest penalty tier.
As DPDP Rules 2025 implementation guidance matures ahead of full enforcement around May 2027, the expectation on 'verifiable' consent is tightening — self-declared age gates without any parental verification step are increasingly seen as non-compliant. Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) for EdTech platforms building this consent and governance layer — contact hello@nitibharat.com.
Many EdTech platforms use learning analytics — time-on-task, quiz performance trends, engagement scoring — to personalise instruction and flag students who need support. This is generally distinguishable from the behavioural tracking and targeted advertising DPDP Section 9 prohibits, provided the analytics serve the child's own learning outcome and are not repurposed to build an ad-targeting profile or sold/shared with third-party advertisers. The line is purpose: analytics used to help a specific child learn better sit outside Section 9's prohibition; the same data repurposed for engagement-maximisation or advertising does not.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.