Share 💬 💼
DPDP

DPDPA for Schools, Colleges & Private Institutions — Complete Compliance Guide 2025

📅 Mar 08, 2026
👤 Adv. Deepak Kumar
⏱️ 17 min read
📂 DPDP
DPDPA for Schools, Colleges & Private Institutions — Complete Compliance Guide 2025
Schools, colleges, coaching centres, and ed-tech platforms are among India's most data-intensive institutions — yet almost none are DPDPA-compliant. This guide covers Section 9 children's data obligations, consent architecture for admissions, vendor DPAs for ERP and school software, biometric data rules, staff data compliance, and a step-by-step academic-year compliance roadmap.
DPDP Act 2023 + DPDP Rules 2025 — Complete Guide for Educational Institutions

Schools, colleges, coaching centres, ed-tech platforms, universities, and private training institutes all share one thing: they collect, store, and use massive volumes of highly sensitive personal data — about students who are often minors, about parents, about staff, and about applicants. The Digital Personal Data Protection Act, 2023 applies to every one of these institutions in full. This guide explains what the law requires from the education sector, why the obligations are more stringent than most sectors, and what every institution must do before May 2027.

⚠️ Children's Data — Highest Risk Category

Schools and institutions serving students under 18 face the most stringent obligations under the DPDP Act. Section 9 imposes heightened requirements for processing children's data — including verifiable parental consent, a complete ban on behavioural tracking and targeted advertising, and strict limits on what data can be collected. These obligations carry penalties up to ₹200 crore and are subject to the lowest tolerance from the Data Protection Board. If your institution serves students under 18, read this guide in full before your next academic session.

Nov 2025
DPDP Rules notified — Board active
Nov 2026
Consent Manager registration opens
May 2027
All obligations enforceable — DEADLINE
📋 What This Guide Covers
  1. Does DPDPA apply to your institution?
  2. The data education institutions collect — and the risks attached
  3. Which institutions face which obligations
  4. Children's data — the highest-risk obligation in education
  5. Consent — what schools, colleges, and ed-tech must do differently
  6. The 8 core obligations every educational institution must meet
  7. Staff and employee data — a second compliance stream
  8. Ed-tech platforms — why online education carries extra risk
  9. The most common DPDPA violations in the education sector
  10. Practical compliance roadmap — academic year planning

1. Does DPDPA Apply to Your Institution?

The short answer: yes, without exception. The DPDP Act applies to every entity that processes digital personal data — there is no carve-out for educational bodies, government-aided institutions, non-profit trusts, or registered societies.

🏫 Primary and secondary schools — government, private, CBSE, ICSE, state board. All covered.
🎓 Colleges and universities — affiliated, deemed, autonomous. All covered.
📚 Coaching centres and test-prep institutes — JEE, NEET, UPSC, CA, and all others. All covered.
💻 Ed-tech platforms — online learning, LMS providers, skill development apps. All covered.
🏢 Corporate training and professional development institutes — all covered.
🏛️ Government-aided and trust-run institutions — the Act's public institution exemptions are narrow and do not cover most educational bodies. All covered.

The key test: Does your institution collect any digital personal data about students, parents, staff, or applicants? If yes — and every institution does — the DPDP Act applies in full. The Act does not distinguish between a ten-student coaching centre and a fifty-thousand-student university. Both are Data Fiduciaries with identical core obligations.

2. The Data Educational Institutions Collect — and the Risks Attached

Educational institutions are among the largest collectors of personal data in India — and much of it is sensitive. Consider the full scope of what a typical school or college holds:

Data Category Examples Who It Belongs To Sensitivity Level
Identity Data Name, DOB, Aadhaar number, passport, photograph Students, Staff, Parents HIGH
Contact Data Phone number, email, home address, emergency contacts Students, Staff, Parents MEDIUM
Academic Records Exam results, grades, attendance, progress reports, disciplinary records Students HIGH
Health & Medical Data Medical history, disability status, vaccination records, mental health notes Students, Staff VERY HIGH
Financial Data Fee payment records, bank details, scholarship eligibility, income certificates Students, Parents HIGH
Biometric Data Fingerprint attendance, face recognition entry systems, iris scans Students, Staff VERY HIGH
Behavioural & Learning Data Platform usage patterns, time-on-task, quiz responses, video watch time (ed-tech) Students HIGH
HR and Payroll Data Staff PAN, salary, leave records, performance appraisals, contract terms Staff MEDIUM–HIGH
CCTV & Surveillance Data Campus surveillance footage capturing identifiable students, staff, and visitors Students, Staff, Visitors HIGH

Why education is uniquely high-risk under DPDPA: Educational institutions hold data that spans nearly every sensitive category in the Act — identity, health, financial, and biometric — about individuals who are frequently minors. A single breach at a school could expose medical conditions, family income, disciplinary history, and home addresses of hundreds of children. The Data Protection Board will scrutinise the education sector closely.

3. Which Institutions Face Which Obligations

🏫
Schools (Classes 1–12) — Highest Obligation Tier
Primary, middle, secondary, senior secondary — all boards
CRITICAL RISK
Schools face the full weight of Section 9 (children's data obligations) for every student. This means verifiable parental consent before collecting any student data, an absolute ban on behavioural tracking and profiling, and strict data minimisation. Additionally, schools must manage data of parents/guardians and all teaching and non-teaching staff — making them one of the most compliance-intensive institution types under the Act.
🎓
Colleges and Universities — High Obligation Tier
Undergraduate, postgraduate, research institutions
HIGH RISK
Most college students are adults — so Section 9 applies only to students under 18 (first-year students who may be 17). However, colleges hold large volumes of sensitive data — financial records, health information, academic performance — and must meet all 8 core obligations. Large universities processing data of lakhs of students may also qualify as Significant Data Fiduciaries, attracting additional obligations including a Data Protection Officer and annual audits.
📚
Coaching Centres and Test-Prep Institutes — Medium–High Tier
JEE / NEET / CA / UPSC / language and skill coaching
MEDIUM–HIGH
Coaching centres often serve students between 15 and 20 — a mixed cohort of minors and adults. Section 9 applies to every student under 18. Coaching centres also commonly send marketing messages to student WhatsApp numbers and email IDs — an activity that requires explicit, prior, specific consent. Many also use third-party CRMs and SMS/WhatsApp platforms, making vendor compliance a critical additional obligation.
💻
Ed-Tech Platforms — Medium Tier (but scaling risk)
Online learning, LMS, tutoring apps, e-assessment platforms
SCALING RISK
Ed-tech platforms that serve large user bases — particularly those with lakhs of learners — are prime candidates for Significant Data Fiduciary designation. They collect behavioural and learning data at scale, often process it algorithmically, and frequently serve minors. Section 9's ban on behavioural tracking is especially relevant for ed-tech, as learning analytics and personalisation features may fall within its scope.

4. Children's Data — The Highest-Risk Obligation in Education

Section 9 of the DPDP Act creates a separate, elevated compliance layer for any institution that processes personal data of individuals under 18. For schools, this means every student. For coaching centres, this may mean the majority of students. For colleges, it means first-year students who have not yet turned 18.

Section 9 — The Four Hard Rules for Children's Data
① Verifiable Parental Consent
Before collecting any data from a child, you must obtain verifiable consent from a parent or legal guardian. A simple form signature is not sufficient — the consent must be genuinely verifiable.
② No Behavioural Tracking
You cannot monitor, profile, or track the behaviour of children for commercial purposes. This includes learning analytics used for advertising, personalisation algorithms, and any profiling that builds a behavioural profile of a child.
③ No Targeted Advertising
Targeted or interest-based advertising directed at children is absolutely prohibited. Any advertising shown to children on your platform must be generic and not based on their personal data or usage patterns.
④ Data Minimisation
Collect only the minimum data necessary for educational service delivery. Collecting a child's social media handle, consumer preferences, or siblings' data cannot be justified on educational grounds.

Practical implication for schools: Every admission form, every digital platform used by students, every app the school deploys — from the ERP system to the parent communication app — must be reviewed for Section 9 compliance. If any of these platforms tracks student behaviour, serves advertisements, or collects more data than necessary for education, it is a direct violation. The school, as Data Fiduciary, is liable — not the platform provider.

5. Consent — What Schools, Colleges, and Ed-Tech Must Do Differently

Consent in education is more complex than in most sectors because it involves multiple parties — the student, the parent (if the student is a minor), and sometimes the institution itself acting as both a Data Fiduciary and a Data Processor for the government. Here is how consent must work across institution types:

🏫 For Schools — Parental Consent Architecture
  • Consent must be obtained from a parent or legal guardian — not the child — for all data collected at admission and throughout enrollment
  • The consent notice must be in plain language, listing every data type collected, why it is collected, who it is shared with (including any ERP vendor, payment gateway, or parent-communication app), and how long it is retained
  • Separate consent is required for any data use beyond core education delivery — such as publishing a student's photograph on the school website, sharing academic records with third-party scholarship bodies, or using the student's data for the school's alumni database
  • If the school uses a platform that collects biometric data (fingerprint attendance, face recognition), specific explicit consent with a clear explanation of the technology must be obtained — and parents must be given an equivalent non-biometric option
  • Parents have the right to withdraw consent and access, correct, or request deletion of their child's data. The school must have a process to receive and respond to these requests
🎓 For Colleges — Adult Student Consent with Minor Carve-Outs
  • For students who are 18 or over, consent is obtained directly from the student — parental consent is not required
  • For students under 18 (typically first-year students in June–August), parental consent applies — colleges must have a system to identify and handle minor students separately
  • The admission form must not bundle consent for educational services with consent for marketing communications — these must be separate, specific opt-ins
  • Colleges that share student data with placement agencies, research partners, alumni networks, or corporate recruiters must obtain separate consent for each category of sharing
  • Students must be informed of their rights and provided with a Grievance Officer contact at the time of admission
💻 For Ed-Tech — Platform-Level Consent at Scale
  • The sign-up flow must present a compliant consent notice — not just a "by signing up you agree to our terms" checkbox buried in the flow
  • If the platform is accessible to users under 18, age-gating or parental consent mechanisms must be implemented before any data is collected
  • Any learning analytics or personalisation features that build a behavioural profile of a user must be disclosed at consent — and for users under 18, are subject to the Section 9 prohibition
  • If the platform serves institutional clients (schools, colleges), a Data Processing Agreement must be in place with each institution specifying what data is processed and on whose behalf
  • Cookie consent and tracking consent must be granular and purpose-specific — not an all-or-nothing banner

6. The 8 Core Obligations Every Educational Institution Must Meet

Regardless of institution type, every Data Fiduciary in the education sector must fulfil these eight obligations under the DPDP Act:

# Obligation Education-Specific Meaning Legal Ref Priority
1 Lawful Basis for All Processing Every data type collected must have a documented basis — parental consent for children, student consent for adults, or a legitimate use ground for statutory compliance (attendance registers, government reporting) S.4, S.6, S.7 🔴 MUST
2 Privacy Notice A comprehensive, plain-language privacy notice must be provided at admission — covering all data types, purposes, vendors, retention periods, rights, and the Grievance Officer's contact details S.5 🔴 MUST
3 Children's Data Safeguards For all students under 18: verifiable parental consent, no behavioural tracking or profiling, no targeted advertising, and strict data minimisation — before any data is collected S.9 🔴 MUST
4 Data Principal Rights Students and parents have rights of access, correction, erasure, and grievance redressal. The institution must have a functional process to receive and respond to each rights request within prescribed timelines S.11–S.14 🔴 MUST
5 Grievance Officer A named Grievance Officer — typically the Data Protection Officer or a senior administrator — must be appointed, with their contact details published in the institution's privacy notice and website S.13 🔴 MUST
6 Data Security Safeguards Technical and organisational measures appropriate to the sensitivity and volume of data held — encryption of academic records, access controls on student databases, secure HR systems, and CCTV footage management policies S.8(5) 🔴 MUST
7 Breach Notification Any breach of student, parent, or staff data must be reported to the Data Protection Board and to affected individuals. Institutions must have a documented breach response plan with clear internal escalation paths S.8(6), R.6 🔴 MUST
8 Vendor / Processor Management Every third-party system that processes student or staff data — ERP, LMS, payment gateway, parent communication app, cloud storage, CCTV analytics — must have a Data Processing Agreement with the institution S.9 🔴 MUST

7. Staff and Employee Data — A Second Compliance Stream

While student data often dominates attention, educational institutions are also employers — and must comply with DPDPA in respect of all staff data. This is a second, parallel compliance stream that many institutions overlook.

📋 Staff Data Compliance Obligations
  • Privacy notice given to all employees at appointment — covering HR, payroll, and performance data
  • Consent or legitimate use basis documented for every category of staff data processed
  • Staff have rights of access, correction, and erasure — even for performance appraisal records
  • Vendor DPAs in place with HR software, payroll processors, and background-check agencies
  • Ex-staff data deleted or anonymised within documented retention periods after departure
  • Grievance Officer accessible to staff — not just to students and parents
⚠️ Common Staff Data Violations in Education
  • Sharing staff salary and appraisal data with management committees without proper access controls
  • Retaining records of former employees for years without any legal basis or deletion schedule
  • No DPA with background verification agencies conducting checks on teaching staff
  • Biometric attendance data of staff stored without explicit consent or proper security
  • Staff WhatsApp groups used to share sensitive administrative or disciplinary information
  • No policy on access to staff HR files — multiple administrators can read any file

8. Ed-Tech Platforms — Why Online Education Carries Extra Risk

Ed-tech platforms face a unique combination of risks under DPDPA that offline institutions do not — primarily because they collect behavioural and learning data at scale, often from minors, and use it for algorithmic personalisation and commercial purposes.

📊
Learning Analytics and Personalisation
Features that track how long a student spends on each topic, which videos they re-watch, and where they drop off constitute behavioural profiling. For students under 18, this is prohibited under Section 9(3) unless genuinely necessary for educational service delivery — and even then, cannot be used for any commercial purpose. Platforms must audit every analytics feature against this standard.
🎯
Targeted Advertising to Students
Any advertising served to students under 18 based on their usage data, learning profile, or inferred interests is a hard prohibition under Section 9. Platforms that monetise through advertising — or that allow third-party retargeting pixels from their student-facing pages — are in direct violation if those students are minors.
🤝
B2B2C Data Flows
When an ed-tech platform sells to an institution (school or college) which then uses the platform with students, both the platform and the institution are Data Fiduciaries — for different aspects of the data flow. The platform is also a Data Processor for the institution. This dual role requires clear contractual delineation and DPAs between the parties, specifying exactly what data each party controls and for what purpose.
🌏
Cross-Border Data Transfers
Ed-tech platforms using cloud infrastructure outside India — AWS, Google Cloud, Azure, or servers in Singapore or the US — are potentially transferring personal data of Indian students across borders. Once the Data Protection Board notifies restricted countries under Section 16, such transfers may require additional authorisation. Platforms must map their data flows and prepare for this requirement.

9. The Most Common DPDPA Violations in the Education Sector

These violations are happening in schools, colleges, and coaching centres across India right now — before a single enforcement action has been taken:

# Violation Prevalence Max Penalty
1 Admission forms collecting Aadhaar, biometric, or medical data without a compliant privacy notice or consent mechanism ~95% of schools ₹50–200 Cr
2 Student photographs published on school website or social media without specific parental consent for that purpose ~80% of schools ₹50 Cr
3 No Data Processing Agreement with ERP vendor, school management software, or parent communication app despite these systems holding full student databases ~98% of schools ₹50 Cr
4 Coaching centres sending marketing WhatsApp messages and emails to students and parents without prior explicit consent for marketing communications ~90% of coaching centres ₹50 Cr
5 Sharing student academic records with placement agencies, scholarship bodies, or alumni networks without specific consent from the student ~70% of colleges ₹50 Cr
6 Biometric attendance systems deployed for students without explicit, informed consent and no alternative non-biometric option provided ~60% of biometric users ₹200 Cr
7 Ed-tech platforms using Facebook Pixel, Google Ads remarketing, or other tracking tools on student-facing pages — profiling minor users for advertising ~75% of ed-tech ₹200+ Cr
8 No named Grievance Officer and no accessible process for parents or students to exercise their data rights ~99% of institutions ₹50 Cr

10. Practical Compliance Roadmap — Academic Year Planning

The best time for an educational institution to implement DPDPA compliance is before a new academic year begins — when admission processes, data collection forms, and communications systems are being set up fresh. Here is the recommended sequence:

1
Data Audit — Map Every Data Flow (Month 1)
List every data type the institution collects — from admission forms to CCTV to payroll. For each: what is it, why is it collected, who can access it, where is it stored, which third-party systems process it, and how long is it kept. This data register is the foundation of every other compliance step and is itself a requirement under DPDPA.
2
Draft Core Legal Documents (Month 1–2)
Privacy Policy for the institution's website. Admission-time privacy notice for parents and students. Staff privacy notice for employees. Separate consent forms for biometric data, photography/video, marketing communications, and third-party sharing. These documents must be customised to your institution's actual data practices — generic templates will not withstand Board scrutiny.
3
Vendor DPAs — Cover Every System (Month 2–3)
Identify every third-party vendor that processes student or staff data: ERP provider, school management software, payment gateway, parent app, LMS, cloud storage, CCTV analytics platform, HR software, and any background-check agency. A Data Processing Agreement must be in place with each before the next academic year's data begins flowing to them.
4
Governance Setup — Officer, Process, Training (Month 3)
Appoint and formally designate a Grievance Officer. Build a rights-request intake process — a dedicated email or form accessible on the website. Draft an internal data breach response plan. Train administrative, IT, and HR staff on DPDPA obligations and data handling procedures. Document all of this in writing.
5
Admission Season Launch — Compliant From Day One (Before New Session)
Before the first admission form is issued or the first inquiry is received, every document must be finalised, every vendor DPA must be signed, and every consent process must be live. The goal is that from the first day of the new academic year, every data touchpoint — enquiry, registration, admission, orientation — is DPDPA-compliant. This is the standard that protects the institution from liability from the moment enforcement begins in May 2027.
📊 Education Sector DPDPA — At a Glance
₹200Cr
Max penalty for breach of
children's data safeguards
Section 9
Applies to every student
under 18 — no exceptions
8
Core obligations that apply
to every institution
5 Steps
Academic-year compliance
roadmap — start now
May 2027
Final enforcement deadline
— one academic year away

Make Your Institution DPDPA-Compliant Before the Next Admission Season

The May 2027 enforcement deadline is less than one full academic year away. Every institution that begins the next admission season without DPDPA-compliant admission forms, privacy notices, vendor agreements, and a Grievance Officer is operating in direct violation of Indian law — with penalties that start at ₹50 crore and rise to ₹200 crore for children's data failures.

We offer a dedicated Education Institution DPDPA Compliance Package — customised for schools, colleges, coaching centres, and ed-tech platforms. This includes a full data audit, DPDPA-compliant privacy notices and admission-form consent language, vendor DPA templates for your ERP and other platforms, Grievance Officer setup, a breach response plan, and staff training materials — all delivered before your next academic year begins.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp