DPDP Act Compliance for Schools: A Practical Guide (2026)
What India's DPDP Act 2023 and DPDP Rules 2025 mean for schools, preschools and coaching institutes: children's data, consent, face attendance, vendors, breaches.
Nishil Shah
Founder, Edacify
DPDP Act compliance for schools means treating your institution as the data fiduciary for every student, parent and staff record you hold digitally: collecting only what you need for a clear purpose, giving notice, protecting children's data with extra care, securing it, deleting it when the purpose ends, contracting properly with every software vendor, and being ready to report a breach. India's Digital Personal Data Protection Act, 2023 was notified in August 2023; the DPDP Rules, 2025 were notified on 14 November 2025 with a phased timeline in which most substantive obligations take effect 18 months later, around May 2027. That window is the time schools have to get ready.
This guide is written for school owners, principals, preschool founders and coaching-institute directors, not lawyers. It covers what the law asks of an educational institution, where photos, biometrics and face attendance sit, what your vendors owe you, and a practical checklist you can start on this term.
General information, not legal advice
This article summarises the DPDP Act and Rules as publicly available at the time of writing. It is general information for planning purposes only. Timelines, exemptions and enforcement practice may change, and how a provision applies depends on your specific facts. Consult a qualified lawyer before making compliance decisions for your institution.
What the DPDP Act is and where it stands
The Digital Personal Data Protection Act, 2023 is India's first comprehensive personal-data law. It applies to digital personal data — data collected online, or collected offline and later digitised — which describes almost every admission form, fee record, attendance register and mark sheet a school now keeps.
Three terms carry the whole Act:
- Data principal — the person the data is about. For a child, the Act says the parent or lawful guardian acts on the child's behalf.
- Data fiduciary — whoever decides the purpose and means of processing. For student data, that is the school.
- Data processor — whoever processes data on the fiduciary's behalf. Your ERP, attendance app, fee gateway and messaging vendor are typically processors.
Current status: the Act was passed and notified in August 2023 but was not operational until the Rules arrived. Per the Ministry of Electronics and IT's notification of 14 November 2025, the DPDP Rules, 2025 come into force in phases: provisions setting up the Data Protection Board of India applied immediately, consent-manager registration follows at 12 months, and the bulk of the obligations that touch schools — notice, security safeguards, breach reporting, children's data, data principal rights — apply from 18 months after notification. Treat May 2027 as your working deadline, and verify the current position before relying on it.
Why the school is the data fiduciary
Schools sometimes assume that because the software vendor stores the data, the vendor is responsible for it. Under the DPDP Act that is backwards. The school decides why student data is collected (admission, attendance, assessment, safety, fees) and how it will be used, so the school is the fiduciary. The Act places the core duties on the fiduciary, and it stays responsible for compliance even where a processor does the work.
What that means in practice for a school:
- You must have a lawful basis for each processing activity — normally consent, or a “legitimate use” the Act lists (for example, a purpose the individual voluntarily shared data for and did not object to).
- You must give a clear notice: what data, for what purpose, how to withdraw consent, how to complain.
- You must keep data accurate, apply reasonable security safeguards, and erase it when the purpose is served or consent is withdrawn, unless retention is required by law.
- You must honour data principal rights — access, correction, erasure, grievance redressal — through a published contact and within the timelines the Rules set.
- You must ensure every processor works under a valid contract.
Children's data and parental consent
Section 9 of the Act is the provision that matters most for schools. A “child” is anyone under 18 — so for a K–12 school or coaching centre, almost every student. For children the Act adds three duties on top of the general ones:
- Obtain verifiable consent from the parent or lawful guardian before processing a child's data.
- Do not process children's data in a way likely to cause a detrimental effect on the child's well-being.
- Do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
What “verifiable” consent means
The Rules require the fiduciary to adopt appropriate measures to check that the person giving consent is an adult and is the parent or lawful guardian, using reliable identity and age details already held or provided, or a virtual token issued through an authorised entity such as a DigiLocker-style service. For a school, the practical reading is: a signature on an admission form from a person you have already verified as the parent, tied to a specific written notice, is a far stronger position than a checkbox in an app that anyone could tick.
The educational-institution exemption
The Fourth Schedule to the Rules carves out certain fiduciaries and purposes from the verifiable-consent and tracking restrictions. Educational institutions and crèches/day-care centres are among them, but only where the processing is for educational activities or in the interests of the child's safety, and only to the extent necessary for that purpose. Two things follow:
- Marking attendance, recording marks, tracking a school bus, or alerting a parent about an absence sits comfortably inside the exemption. Selling or sharing student data to a coaching or edtech marketer does not.
- The exemption does not remove the duty to avoid detrimental processing, nor the general duties of notice, security, retention and contracts. Most schools should still take parental consent at admission — the exemption is a safety net, not a strategy.
A simple test for any new use of student data
Ask: is this strictly needed to teach, assess or keep this child safe? If yes, document the purpose and proceed with notice. If it is for marketing, third-party analytics, profiling or anything a parent would be surprised by, treat it as needing explicit, verifiable parental consent — or do not do it.
Photos, videos, biometrics and face attendance
These are the areas where schools most often process children's data without thinking of it as “data” at all.
| Data type | Typical school use | What to do |
|---|---|---|
| Photos and videos | Annual day, sports day, classroom activities on the website, social media, WhatsApp groups | Take a separate, optional consent for public or marketing use; keep an opt-out list every teacher can see; do not post identifiable children whose parents declined |
| Face-recognition attendance | Daily attendance for students and staff | Restrict to attendance and safety; take explicit consent with an alternative method; confirm where the face template is stored, whether it is encrypted, and how it is deleted on exit |
| Fingerprint / biometric | Staff attendance, library, canteen | Same as face data; avoid extending biometrics to non-essential purposes such as canteen purchases for young children |
| CCTV | Campus safety, exam halls, transport | Safety purpose is squarely within the exemption; still fix a retention period, restrict footage access, and never share footage on messaging groups |
| Aadhaar / ID numbers | Admissions, scholarship, government portals | Collect only where a scheme or portal requires it; do not store full copies in shared drives or spreadsheets |
Face attendance deserves special mention because it is spreading fast in Indian schools. It can be run responsibly, but a school should be able to answer three questions before switching it on: where the face data lives (India or abroad), who can access it, and when it is deleted. Our face-recognition attendance guide covers the technology; this post is about the obligations that come with it.
Vendor obligations: what your software must give you
Because the school stays accountable for what its processors do, vendor selection is a compliance decision. The Act requires the fiduciary to engage processors only under a valid contract, and the school must ensure the processor also applies reasonable security safeguards. In practice, every school should hold a written data-processing agreement (DPA) with each vendor that touches student data. At a minimum it should cover:
- The purposes the vendor may process data for, and nothing else.
- Confidentiality and security measures the vendor commits to.
- Sub-processors (cloud hosts, SMS gateways) and where data is stored.
- Breach notification to the school, fast enough for the school to meet its own deadlines.
- Return and deletion of data when a student leaves and when the contract ends, in a usable export format.
- Support for access, correction and erasure requests from parents.
If a vendor cannot or will not sign such an agreement, that is a signal in itself. Our guides to school ERP software and the school ERP implementation checklist cover selection more broadly; the section below lists the specific questions to ask.
Breach notification
A “personal data breach” under the Act is any unauthorised processing, disclosure, loss or destruction of personal data — a leaked marks list on a WhatsApp group qualifies, not just a hack. Per the Rules, on becoming aware of a breach the fiduciary must inform each affected data principal without delay, in plain language, describing what happened, the likely consequences, what the school is doing about it and whom to contact; and must inform the Data Protection Board without delay, following up with a detailed report within 72 hours (or such longer period as the Board allows).
There is no “minor breach” threshold in the Act, which is why schools need a simple internal procedure now: who is told first, who decides, who drafts the parent notice, and which vendor contacts to call. Penalties for failing to notify a breach and for failing children's-data duties can each run to ₹200 crore, and for failing to keep reasonable security safeguards up to ₹250 crore. Actual penalties are set by the Board on the facts, but the ceilings show how seriously security and children's data are treated.
A practical DPDP compliance checklist for schools
You do not need to do all of this in one term. Work through it in the order below; the early steps make everything after them easier.
| Step | What to do | Owner |
|---|---|---|
| 1. Data inventory | List every place student, parent and staff data lives: ERP, attendance device, fee gateway, Excel sheets, Google Drive, WhatsApp groups, CCTV DVR, printed files that get scanned | Admin head |
| 2. Purpose map | For each data set, write one line: why we collect it, who sees it, how long we keep it. Delete anything with no purpose | Principal + admin |
| 3. Notice and consent | Rewrite the admission form: a clear notice, separate optional consents (photos, marketing communication, third-party apps), parent identity verified at admission | Admissions |
| 4. Grievance contact | Publish a named contact (email/phone) for data questions on the website and in the notice; log and respond to requests | Principal's office |
| 5. Access control | Role-based logins in every system; teachers see their classes, not the whole school; remove access when staff leave | IT / vendor |
| 6. Vendor DPAs | Sign data-processing agreements with every vendor; ask the questions in the next section | Management |
| 7. Retention and deletion | Fix retention periods (for example, records of students who left, CCTV footage, face templates) and actually run deletions | Admin + vendor |
| 8. Breach procedure | A one-page plan: detect, contain, notify parents, notify Board, record; rehearse it once | Principal + IT |
| 9. Staff training | Short annual session: no student data on personal WhatsApp, no shared passwords, how to spot phishing, when to escalate | Principal |
Common mistakes to avoid
- Sharing marks and attendance on class WhatsApp groups. Every parent sees every child's data. Use individual channels or a platform with per-parent access.
- One blanket “I consent to everything” line on the admission form. Consent must be specific and informed; bundle it and you may have none.
- Keeping alumni data forever “just in case”. Decide what you genuinely need (transfer certificate records, board records) and delete the rest.
- Letting a vendor host face or fingerprint data with no contract and no idea where the server is.
- Assuming a small preschool is exempt. The Act does not exempt institutions by size; it exempts certain purposes.
Questions to ask software vendors
Put these to your ERP, attendance, fee and communication vendors in writing. Good vendors will already have answers.
- Will you sign a data-processing agreement naming us as fiduciary?
- Where is our data hosted, and where are backups kept?
- Which sub-processors (cloud, SMS, email, payment) touch our data?
- Is data encrypted at rest and in transit?
- Do you support role-based access so a teacher sees only their classes and a parent sees only their child?
- How quickly will you inform us of a security incident?
- Can we export all our data in a standard format and have you delete it when we leave?
- For face or biometric attendance: what exactly is stored, is it a template or an image, and how is it deleted when a student exits?
- Do you use our student data for your own analytics or marketing?
- How do you help us respond to a parent's access or erasure request?
If you are comparing platforms, see our roundup of the best school management software in India and weigh these answers alongside features and price. For preschools in particular, our preschool management software guide covers the day-care specific angle.
FAQ
Is the DPDP Act in force for schools right now?
The Act was notified in 2023 and the Rules on 14 November 2025, but the Rules apply in phases. The obligations most relevant to schools — notice, security, breach reporting, children's data, data principal rights — take effect 18 months after the Rules were notified, around May 2027. Use the intervening period to prepare rather than waiting.
Do we need parental consent for every use of student data?
Not for core educational and safety activities: the Rules exempt educational institutions from verifiable-consent and tracking restrictions for those purposes, to the extent necessary. Anything beyond that — marketing photos, sharing with third parties, non-educational apps — should have specific, verifiable parental consent. Taking a clear consent at admission is good practice either way.
Can we use face-recognition attendance under DPDP?
Attendance for enrolled students is an educational and safety purpose, so it can fall within the exemption. You still owe notice, security, access control, a retention/deletion policy and a proper contract with the vendor. Offer an alternative method for families who object.
Is sharing marks or attendance in a WhatsApp group a breach?
Posting one child's marks or absence to a group of other parents is a disclosure to people who have no need to see it, and can amount to a personal data breach as well as a detrimental effect on the child. Communicate individually.
If our software vendor leaks data, is the school liable?
The school, as data fiduciary, remains responsible for compliance regardless of who processes the data. A signed data-processing agreement and evidence that you chose and monitored the vendor reasonably are your main protection, and let you seek recourse from the vendor.
Do small schools and preschools have to comply?
Yes. The Act does not carve out institutions by size or fee level. Some obligations (such as those on Significant Data Fiduciaries) apply only to entities the government notifies, but the core duties apply to any institution processing digital personal data.
What about paper records?
The Act covers digital personal data, including offline data that is later digitised. A paper admission form is outside its scope until it is scanned or typed into a system, which most schools now do. Manage paper as though it will end up digital.
Where Edacify fits
Compliance is mostly about process, not software, but the platform you choose either supports that process or fights it. Edacify is built as a student-success platform for Indian schools, coaching institutes and preschools, with role-based access for teachers, students and parents, attendance, subject-wise marks and analytics, notifications to individual parents rather than groups, and QR-based pickup and emergency workflows — so the everyday reasons schools reach for WhatsApp are handled inside one controlled system. If you are reviewing how student data moves through your school, start a 21-day free trial and run through the vendor questions above with us, or talk to our team about your setup first.
Nishil Shah
Founder, Edacify
Building AI-Powered SaaS solutions to modernize school management.
Run your institution on Edacify
AI-generated quizzes, face-recognition attendance, and one tenancy for schools, colleges, and coaching. 21-day free trial, no credit card.
Keep reading

Face-Recognition Attendance for Schools: A Practical Guide
How face-recognition attendance works, how it compares with fingerprint and RFID, what the DPDP Act 2023 requires, and a 30-day rollout plan.

What Is School ERP Software? A Complete Guide (2026)
School ERP software runs admissions, attendance, exams, fees, and communication on one shared database. Here are the modules inside it and how to evaluate one.

School Management Software: A Practical Guide (2026)
What school management software is, the features that actually matter, who it suits, and how Edacify handles attendance, exams, AI quizzes, and performance analytics.
