DPDP Act for Schools: What Indian Schools Must Do About Student Data
Under India's Digital Personal Data Protection Act 2023, a school is a "data fiduciary" for the personal data of students, parents and staff. Because everyone under 18 is a child under the Act, schools generally need verifiable consent from a parent or guardian to process a student's data, must not track or profile children beyond what education and safety require, must keep data secure, report breaches, and make sure their software vendors follow the same rules. The DPDP Rules notified in November 2025 phase in most obligations over the following 18 months.
This article is a general overview, not legal advice. Read the Act and the notified DPDP Rules, and take advice from a lawyer for your school's specific situation, particularly on exemptions.
Who the law applies to in a school
The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to anyone who processes digital personal data in India. In a school:
- The school (or its trust or society) is the data fiduciary: it decides why and how personal data is used.
- Students, parents and staff are data principals: the people the data is about.
- Software vendors — your school ERP, LMS, transport tracking, payment gateway, messaging providers — are usually data processors, acting on the school's instructions.
The school remains responsible for what its processors do with the data.
Students are children under the Act
The Act defines a child as anyone under 18. For children, it requires:
- Verifiable consent from a parent or lawful guardian before processing the child's personal data.
- No processing likely to harm the child's well-being.
- No tracking, behavioural monitoring or targeted advertising directed at children.
The DPDP Rules describe how a fiduciary can verify that the person consenting is really the parent, and provide exemptions for some processing by educational institutions — broadly, for educational activities and for the safety of children. The scope of these exemptions matters a great deal for schools, so check the notified text and document which of your activities rely on them.
Consent and notice
Consent must be free, specific, informed and unambiguous, and given for a stated purpose. In practice:
- A notice in plain language (English and the languages your families read) that explains what data you collect, why, and how to withdraw consent or complain.
- Separate purposes rather than one blanket clause in the admission form: running the school, sending photographs to a newspaper and sharing data with a coaching partner are different purposes.
- Withdrawal must be as easy as giving consent.
- Records of who consented, when and to what.
Rights of parents, students and staff
Data principals can ask what data you hold and how it is used, ask for corrections and updates, ask for erasure where the data is no longer needed, and nominate someone to act for them. Schools need a simple, published way to receive and answer these requests, and a grievance contact.
Security and breaches
The Act requires reasonable security safeguards. For a school, that means at least:
- Role-based access, so a transport coordinator cannot see health records and a class teacher sees only their classes.
- Two-factor sign-in for staff with access to sensitive data.
- An audit trail of who viewed or changed sensitive records.
- Encryption in transit and at rest, and backups.
- A breach response plan: the Act requires breaches to be reported to the Data Protection Board and to affected people.
Penalties under the Act are large, up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for breaching the obligations on children's data.
Retention
Keep personal data only as long as the purpose needs it. Schools have genuine long-term needs — transfer certificates, mark records, alumni verification — so set a retention schedule per type of record and delete what has no reason to be kept, such as old enquiry data from families who never joined.
Your vendors
Most student data now lives in vendor systems. Ask every vendor:
- Where is our data stored, and is it separated from other schools?
- Who at the vendor can access it, and is that access logged?
- Do you use our data for anything other than providing the service to us, including training AI models or advertising?
- How will you tell us about a breach, and how fast?
- How do we export and delete our data when we leave?
Put the answers in your contract as a data processing agreement.
A starting checklist for schools
- List every place student, parent and staff data is held, including spreadsheets and WhatsApp groups.
- Write down the purpose of each, and which rely on consent and which on an exemption.
- Rewrite admission forms with a clear notice and separate consents.
- Set up a way to verify parental consent and keep records.
- Review roles and access in your school software; remove access for staff who have left.
- Sign data processing agreements with vendors.
- Write a breach response plan and name who leads it.
- Publish a privacy notice and a grievance contact.
- Train staff, especially on sharing student data over personal phones.
How EduVizio approaches school data
In EduVizio every request is scoped to your school and campus, access is controlled by built-in and custom roles with per-user overrides, staff can use two-factor sign-in, and sensitive actions are logged with who did them, from where and what changed — including every role and permission change. Health records are visible only to the right roles. Read more on our security page.
Frequently asked questions
Does the DPDP Act apply to schools?
Yes. Schools process personal data of students, parents and staff, so they are data fiduciaries under the Act. Because students are under 18, the rules on children's data apply, subject to any exemptions for educational institutions in the DPDP Rules.
Do schools need parental consent for student data?
Generally, yes: the Act requires verifiable parental consent to process a child's personal data. The DPDP Rules exempt some processing by educational institutions for educational activities and safety; check the notified text and document which activities rely on an exemption.
When do the DPDP Rules come into force?
The DPDP Rules were notified in November 2025, with most obligations on data fiduciaries phased in over the following 18 months. Check the official notification for the exact dates that apply.