Under Section 9 of the DPDP Act 2023, EdTech platforms that process personal data of anyone under 18 must obtain verifiable parental consent before processing, and must not undertake behavioural tracking or targeted advertising directed at children. This applies to student names, academic records, attendance, biometric attendance data and parent contact details. This checklist scores your EdTech platform against the specific children's-data obligations in the DPDP Act.
Section 9 of the DPDP Act imposes some of the strictest rules in the law on any platform handling under-18 student data. Check your EdTech platform in 3 minutes.
The DPDP Act 2023 singles out children's data for the toughest treatment in the law. Section 9 requires verifiable parental consent before processing any personal data of a person under 18, and it flatly prohibits behavioural monitoring, tracking or targeted advertising directed at children — regardless of consent. For an EdTech company, this covers far more than login credentials: it includes attendance records, quiz and assessment scores, biometric attendance, video from live classes, and parent contact details captured at enrolment.
Penalties for failing children's-data obligations run up to Rs 200 crore per instance under the DPDP Act — among the highest penalty bands in the law, second only to security safeguard failures. For a school ERP or learning platform processing thousands of student records, an unverified consent flow or an ad-tech SDK collecting behavioural data is not a minor gap; it is the single biggest exposure on the platform.
A parent ticking a checkbox at signup does not meet the DPDP bar for verifiable consent. The DPDP Rules 2025 point toward identity-verification mechanisms — proof the person giving consent is genuinely the parent or lawful guardian, not just an email address. In practice this means EdTech platforms need a consent flow that can withstand a Data Protection Board inquiry: a record of who consented, when, to what specific processing purpose, and evidence the consenting adult was verified. Niti Bharat builds this consent architecture as part of a fixed-price EdTech DPDP Compliance Pack, alongside the privacy documentation and retention schedule schools and platforms need before the May 2027 enforcement deadline.
A one-page, print-ready checklist mapping every S.9 obligation to a specific control, so your team can self-audit before a school or investor asks for evidence.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.