India's Digital Personal Data Protection Act treats anyone under 18 as a child. For a school, that means almost every record you hold — admission forms, fee ledgers, attendance, medical notes, bus routes, photos on the notice board — is a child's personal data.
The Act was passed in 2023. Its Rules were notified on 14 November 2025, with an eighteen-month runway. The main obligations apply from 14 May 2027. That's roughly eight months from now, which is about the time it takes a school to change its admission forms, its vendor contracts and its habits.
This is a practical guide, written by people who build and run school systems. It is not legal advice. Your exact obligations depend on your school's structure, your vendors and the data you hold, and you should get advice specific to your institution. What we can do is translate the law into the operational questions you'll need to answer.
The dates that matter
| Date | What comes into force |
|---|---|
| 14 November 2025 | The Rules are notified and the Data Protection Board is set up |
| 14 November 2026 | Registration of consent managers |
| 14 May 2027 | The substantive duties: notice and consent, verifiable parental consent for children, security safeguards, breach reporting, and the rights of individuals |
For schools, the third row is the one that matters. Everything in the rest of this article becomes enforceable on that date.
Who's who, in school terms
The law uses three words you'll keep seeing:
- Data fiduciary — whoever decides why and how personal data is used. That's your school or trust.
- Data processor — anyone processing data on your behalf. Your ERP vendor, payment gateway, bus-tracking provider and cloud storage all fall here.
- Data principal — the person the data is about. For a child, the law includes the parent or lawful guardian.
The important consequence: the duties sit with the school, not the vendor. If your transport app leaks student addresses, the law looks at you first. That's why vendor contracts and system design matter as much as policy documents.
The rules for children's data
Section 9 of the Act sets three rules for children:
- Verifiable parental consent before processing a child's personal data.
- No processing likely to cause a detrimental effect on a child's well-being.
- No tracking, behavioural monitoring, or targeted advertising directed at children.
The Rules explain what "verifiable" means in practice: the school should be able to confirm the person consenting is an identifiable adult, using reliable identity and age details it already has, details the parent provides, or a virtual token such as one issued through DigiLocker.
The school exemption is narrower than it sounds
The Rules include a schedule of exemptions, and educational institutions are on it. Headlines summarised this as "schools are exempt." Read the actual wording before you rely on that.
The Fourth Schedule lifts the consent requirement and the tracking ban for an educational institution only where:
"Processing is restricted to tracking and behavioural monitoring: for the educational activities of such institution; or in the interests of safety of children enrolled with such institution."
That covers a lot of what a school legitimately does: attendance, gate logs, knowing which students are on the bus, and monitoring for safety. It does not, on its face, say that everything else a school does with a child's data needs no consent.
So a sensible working assumption is this: for data collected at admission — names, addresses, guardian details, documents, health information, fee records — plan to give parents a clear notice and take their consent, and keep a record of it. The government's own explainer summarises the children's rule more broadly, so this is exactly the kind of question to put to your lawyer. But designing for consent now costs a line on the admission form. Discovering you needed it in 2027 costs a lot more.
What the exemption plainly doesn't allow: using student data for marketing, selling or sharing it for purposes unrelated to education and safety, or profiling students for anything that could harm them.
What the law expects from your systems
Rule 6 lists the "reasonable security safeguards" every data fiduciary must take. Translated into school software, they read like an ERP buyer's checklist:
| The Rule asks for | What it means in your school |
|---|---|
| Encryption, masking or tokenisation | Student data encrypted in storage and in transit; sensitive fields such as Aadhaar masked on screen |
| Access control | Every staff member has their own login and sees only what their role needs. No shared "office" password |
| Logs, monitoring and review | A record of who accessed or changed what, reviewed periodically |
| Logs kept for one year | Audit logs retained for at least a year, unless another law requires longer |
| Continuity if something is compromised | Backups you have actually tested restoring |
| Contracts with data processors | Written terms with every vendor that touches student data |
Rule 6 also expects appropriate technical and organisational measures to make all of this work. In plain terms: a policy on paper is not enough if the software lets everyone see everything.
When something goes wrong
A breach can be a hacked database, but it can just as easily be a mark sheet sent to the wrong parents' WhatsApp group or a laptop left in an auto-rickshaw.
Under Rule 7, when a breach happens the school must:
- Tell affected families without delay, in plain language: what happened, how it may affect them, what the school is doing, what they can do to protect themselves, and who to contact.
- Inform the Data Protection Board without delay, and send a detailed report within 72 hours of becoming aware of it, unless the Board allows longer.
The penalties set out in the Act are serious. According to the government's explainer, failing to maintain reasonable security safeguards can attract a penalty of up to ₹250 crore, while failing to report a breach and violating the obligations for children can each attract up to ₹200 crore. Other violations can attract up to ₹50 crore.
Nobody expects a school to be fined at the maximum. The point is that the law treats children's data and security as the two most serious categories, which is where schools live.
What parents can ask you for
Parents, as data principals for their children, can ask to access the data you hold, correct it, update it, or have it erased in certain situations. They can also nominate someone to act for them. Schools must respond within ninety days, and must display a contact person for data questions.
Operationally, that means someone must be able to find every copy of a child's data — in the ERP, in spreadsheets, in the transport vendor's app, in the WhatsApp groups — within three months of a request. Most schools can't do that today.
An eight-month plan
If you do nothing else before May 2027, do these ten things:
- Map where student data lives. The ERP, but also Google Sheets, personal phones, WhatsApp groups, the transport vendor, the coaching partner, the photographer.
- Rewrite the admission form with a clear notice of what you collect and why, and a consent step for parents that you record.
- End shared logins. Every person gets their own account and a role. This single change makes most of the other duties possible.
- Check your audit logs. Can you see who changed a mark or waived a fee, and is that record kept for at least a year?
- Put every vendor on paper. Written terms covering what they can do with the data, security, breach notification to you, and deletion when the contract ends.
- Stop pasting student data into public AI tools. We covered where AI helps and where it shouldn't decide in AI for Schools.
- Write a one-page breach plan with the 72-hour clock, who calls whom, and a draft message to parents.
- Name a contact for data questions and put their details on your website and admission form.
- Decide how long you keep what. Rejected applicants, withdrawn students and alumni records don't need to live forever.
- Test a parent request. Pick a student and try to find and export everything you hold about them. Time it.
Questions to put to your ERP vendor now
Your ERP will carry most of the load, so ask your vendor, in writing:
- How is our data separated from other schools on the same system?
- How many roles and permissions can we define, and is access checked on every action?
- Is every change logged with the person and time, and how long are logs kept?
- Where is our data hosted, and which of your staff can access it?
- If a parent asks for their child's data, how do we export it? If they ask for erasure, how do we do it?
- Will you notify us of a breach fast enough for us to meet the 72-hour deadline?
A vendor that answers "we're fully DPDP compliant" and nothing more has told you nothing. Compliance is the school's obligation. A good vendor tells you which parts of it the system handles, and which parts are still yours.
For what it's worth, this is how we built the school ERP we run: each institution's data is separated at the application layer and again in the database; access is governed by 15 roles and 92 permissions and checked on every request; every change is written to a searchable audit log; attendance can't be quietly rewritten after the day; and the school can take a full export of its data at any time. None of that makes a school compliant on its own. It makes compliance something the school can actually demonstrate.
Sources
- Press Information Bureau, explainer on the DPDP Act, 2023 and DPDP Rules, 2025 (penalties, 18-month phasing, 90-day response, children's consent)
- Ministry of Electronics and IT, Digital Personal Data Protection Rules, 2025
- Fourth Schedule text, as reproduced at dpdpa.com; Rule 6 on security safeguards; Rule 7 on breach intimation
- Shardul Amarchand Mangaldas, enforcement timeline of the DPDP Act and Rules
Not sure where your school's student data actually lives? That's the first thing our free audit maps. Book 30 minutes and we'll show you where the gaps are — including the ones no software fixes.