Contact Us
2026 Regulatory Guide

DPDPA Compliance for Schools and Higher Education Institutions

A practical, sourced guide to what the Digital Personal Data Protection Act 2023 actually requires of Indian schools and universities today, and what changes when the remaining provisions come into force on 14 May 2027.

11 Aug 23
DPDPA Enacted
14 Nov 25
Rules Notified
14 May 27
Full Enforcement
INR 250 Cr
Max Penalty (Sec 33)

Schools Are Data Fiduciaries Under the DPDPA

Every Indian school and higher education institution now sits inside a specific legal category, whether it chose to or not. The Digital Personal Data Protection Act (DPDPA) 2023, which received presidential assent on 11 August 2023 (Source: Ministry of Electronics and Information Technology (MeitY), Gazette of India, 11 Aug 2023), defines a "Data Fiduciary" as any person who, alone or with others, determines the purpose and means of processing personal data. A school deciding what to collect on an admission form, how long to retain exam records, or which vendor runs its learning management system is making exactly those determinations. That makes the institution itself, not its software vendor, the Data Fiduciary responsible under the Act.

The data at stake is broader than most administrators assume. A typical K-12 school holds admission-form data, Aadhaar copies, photographs, biometric attendance records, health and medical information, disciplinary files, closed-circuit television (CCTV) footage, transport records, and parents' payment details. A university adds National Assessment and Accreditation Council (NAAC) and National Institutional Ranking Framework (NIRF) self-study submission data, faculty personnel files, research participant data, hostel and disciplinary records, and, for institutions with international intake, passport and visa details of foreign students. Every one of these is personal data under the Act, and once it sits in an enterprise resource planning (ERP) system, a biometric device, or a third-party learning app, it falls inside the DPDPA's scope.

This guide applies equally to K-12 schools and higher education institutions. The Act's obligations (Data Fiduciary duties, vendor-contract rules, breach notification) apply identically to both. The one provision that differs is Section 9's verifiable-parental-consent requirement, which applies wherever the institution processes the data of a person under 18: nearly every K-12 student, and a smaller share of university-level and foundation-year students.

Research compilation, not legal advice. This guide is drawn from the DPDPA 2023, the DPDP Rules 2025, and publicly available regulatory notifications and legal commentary current as of August 2026. It is for orientation purposes only and does not constitute legal advice. Schools and universities should engage qualified legal counsel before finalising consent workflows, vendor contracts, or breach-response procedures.

This guide focuses on the DPDPA alone. For the other 30-plus statutes a school must satisfy alongside data privacy, see RAYSolute's Complete Compliance Framework for Schools, which covers DPDPA compliance as one item among 17 regulatory domains. This article goes deeper into that one law: what it means for the data already sitting in your ERP, and what actually changes on the date that matters.

The DPDPA Compliance Timeline for Schools

Most published guidance on the DPDPA reads as though every one of its obligations is already legally binding. That is not the current position. Section 1(2) of the Act lets the Central Government bring different provisions into force on different dates, and it has used that power deliberately. The DPDP Rules 2025 were notified by MeitY on 14 November 2025 (Source: MeitY, Gazette Notification, 14 Nov 2025; Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP rules", 2025-26), setting an 18-month, three-stage commencement schedule rather than switching the whole Act on at once.

14 November 2025 · Immediate
The Board is constituted
Sections 18-26 (the Data Protection Board of India), Section 2 (definitions), and procedural sections 35 and 38-43 came into force. The Board exists and can receive complaints, but it cannot yet adjudicate DPDPA breaches or impose penalties.
14 November 2026 · 12 Months
Consent Managers go live
Section 6(9) and Section 27(1)(d) commence, opening registration for Consent Managers, the interoperable consent-management platforms the Rules introduce for Data Principals to manage consent across services.
14 May 2027 · 18 Months, Full Enforcement
Every substantive obligation switches on
Sections 3-17 (data fiduciary duties under Section 8, children's data under Section 9, Significant Data Fiduciary duties under Section 10), Sections 27-34 (penalty and adjudication powers), and Sections 36-37 come into force together. This is the date every operative obligation in this guide, consent, vendor contracts, breach notification, and the Rs 250 crore/Rs 200 crore penalty exposure, becomes enforceable.

(Source: Gazette Notification, DPDP Rules 2025, 14 Nov 2025, section-commencement schedule; corroborated independently by India Briefing, "India's DPDP Timeline: Critical Compliance Deadlines for 2026-27", 2026, and Shardul Amarchand Mangaldas & Co, 2025-26.)

What still applies right now. Section 44(2) of the DPDPA, which repeals the old Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 ("SPDI Rules"), does not itself commence until 14 May 2027. Until then, the SPDI Rules under Section 43A of the Information Technology Act 2000 continue to apply in parallel to any school or university that processes sensitive personal data electronically, including health and financial information. Schools are not in a regulatory vacuum today; they are operating under the older IT Act regime while the DPDPA's own machinery is switched on in stages.

For a school or university, this matters practically. The runway between today and 14 May 2027 is exactly the time to build a verifiable-consent workflow, renegotiate vendor contracts, and rehearse a breach response, before the Data Protection Board's penalty powers activate. Institutions that wait until the enforcement date to start are choosing to build under time pressure what could be built calmly now.

Section 9 of the DPDPA is the provision most directly aimed at institutions like schools. It requires a Data Fiduciary to obtain verifiable consent from a parent or lawful guardian before processing the personal data of a "child", defined under Section 2(f) as anyone who has not completed eighteen years of age (Source: DPDPA 2023, Sections 2(f) and 9). That threshold is stricter than comparable regimes elsewhere: the European Union's General Data Protection Regulation (GDPR) sets 16 (member states may lower it to 13), and the United States' Children's Online Privacy Protection Act (COPPA) applies only under 13. India's flat 18-year line means every K-12 student, and depending on the programme, some university-entry-age students, falls under Section 9's protection.

Section 9 also carries standing prohibitions that apply regardless of consent: no tracking or behavioural monitoring of a child for targeted advertising, no advertising directed at children built on their processed data, and no processing detrimental to a child's wellbeing (Source: DPDPA 2023, Section 9).

What Counts as "Verifiable" (Rule 10)

Consent is not a checkbox on an admission form. Rule 10 of the DPDP Rules 2025 recognises three specific mechanisms for verifying that the person granting consent really is the child's parent or lawful guardian (Source: DPDP Rules 2025, Rule 10):

1
Existing verified records

Reliable identity and age details the school already holds, typically captured and verified at the point of admission.

2
Voluntarily provided details

Identity and age information the parent supplies directly at the point consent is sought.

3
A virtual token

Mapped to identity and age, issued by an authorised entity: a government body, an entity it appoints, or a Digital Locker (DigiLocker) service provider notified under the Information Technology Act 2000.

The Fourth Schedule Exemption Schools Should Know

Schedule 4 EntryWhat It Exempts
Part A, Entry 3No verifiable consent required where a school's processing of a child's data is restricted to the institution's own educational activities, or to the safety of children enrolled with it.
Part B, Entry 3No verifiable consent required to create a student email account, so long as its use stays limited to communication by email.

(Source: DPDP Rules 2025, Fourth Schedule, Parts A and B.)

This is a narrow carve-out, not a blanket exemption. The moment a school's use of student data moves outside "educational activities" or "child safety", sharing it with a marketing vendor, or feeding it to a third-party analytics tool that profiles students, Section 9's full verifiable-consent requirement applies again. Treat the exemption as covering core academic and safety systems, and verify consent for everything else.

EdTech Vendor Data Processing Agreements

Almost every Indian school now runs on someone else's software: an ERP for admissions and fees, a learning management system, a biometric attendance device, a proctoring tool for online tests. Under the DPDPA, each of these vendors is typically a "Data Processor" acting on the school's instructions, while the school itself remains the Data Fiduciary. Section 8(2) requires that a Data Fiduciary may engage a Data Processor "only under a valid contract" (Source: DPDPA 2023, Section 8(2)).

The point most schools miss is Section 8(1): a Data Fiduciary "shall, irrespective of any agreement to the contrary," remain responsible for complying with the Act in respect of any processing a Data Processor does on its behalf (Source: DPDPA 2023, Section 8(1)). A well-drafted vendor contract gives the school contractual recourse against a vendor that mishandles data; it does not transfer the school's own statutory liability. If an EdTech vendor exposes student records, the Data Protection Board's penalty exposure lands on the school.

What a School's Vendor Contract Should Cover

The DPDPA itself mandates only "a valid contract" (Section 8(2)) without dictating clause-by-clause content. The items below are recommended contracting practice, not independent statutory requirements.

Data ownership

The contract states plainly that the school owns the data and the vendor may not sell, license, or otherwise exploit it independently.

Purpose limitation

The exact categories of student and parent data shared, why, and for how long they may be retained.

Sub-processor transparency

Every downstream vendor the EdTech company itself uses, disclosed and subject to the school's approval before a new one is added.

Security standards

Encryption in transit and at rest, access controls, and, where the vendor's scale warrants it, an independent security certification.

Breach-notification flow-down

The vendor must notify the school fast enough for the school to meet its own Rule 7 timeline, not the vendor's own convenience.

No AI-training use

An explicit bar on using student data to train the vendor's own machine-learning or AI models.

Data destruction on exit

A defined, certified deletion timeline once the contract ends or the vendor relationship is terminated.

Your Data Breach Notification Duties

Section 8(6) of the DPDPA requires a Data Fiduciary to intimate both the Data Protection Board and each affected Data Principal, the student, or the parent where the data belongs to a minor, of a personal data breach (Source: DPDPA 2023, Section 8(6)). Rule 7 of the DPDP Rules 2025 sets out how, in two stages: the school must inform the Board without delay once a breach is confirmed, describing its nature, extent, timing, and likely impact, then, within 72 hours of becoming aware of the breach, file a fuller report covering the circumstances, remedial steps taken, and, where known, who caused it (Source: DPDP Rules 2025, Rule 7). The Board can grant more time on a written request, but the clock starts the moment the school becomes aware, not once an investigation concludes.

The penalty exposure, once Sections 27-34 come into force on 14 May 2027, is real. The Act's Schedule under Section 33 sets a ceiling of up to Rs 250 crore for a failure to implement reasonable security safeguards, and up to Rs 200 crore each for a failure to notify a breach as required and for non-compliance with the children's-data obligations under Section 9 (Source: DPDPA 2023, Section 33 and Schedule). The Board weighs several statutory factors before setting the actual amount, and may double a penalty for a repeat or particularly serious breach.

Section 8(9) additionally requires every Data Fiduciary, schools included, to publish the business contact details of a Data Protection Officer, if it has one, or a person able to answer a Data Principal's questions about their data (Source: DPDPA 2023, Section 8(9)). A Data Protection Officer becomes mandatory only for a Significant Data Fiduciary under Section 10, a threshold the government is yet to notify for the education sector; a named, published contact person is the baseline every institution should have regardless.

Your DPDPA Compliance Roadmap

Schools and universities do not need to build everything by 14 May 2027 in one push. A sequenced runway gets there without disrupting term-time operations.

1
Map every system that touches personal data

ERP, biometric attendance, learning management system, canteen point-of-sale, transport tracker, CCTV, exactly what each collects and where it lives.

2
Publish a named contact person

Under Section 8(9), someone parents and students can reach with questions about their data, even before a formal Data Protection Officer is required.

3
Design a verifiable-consent workflow

Using one of Rule 10's three mechanisms, and separately map which systems fall inside the Fourth Schedule's educational-activity exemption and which do not.

4
Audit every EdTech and ERP vendor contract

Against Section 8(2) and the checklist above; renegotiate any contract missing a valid data-processing clause.

5
Write and rehearse a breach-response plan

One that can meet Rule 7's "without delay" first report and its 72-hour detailed follow-up.

6
Draft a retention and deletion policy

How long each data category is kept, and what specifically triggers its deletion.

Get a DPDPA Compliance Diagnostic for Your Institution

RAYSolute's School Compliance Diagnostic includes a dedicated DPDPA module: a data map of every system touching personal data, a gap assessment against Sections 8 and 9, a review of your EdTech vendor contracts, and a practical roadmap to 14 May 2027.

1
Data Mapping (Week 1-2)Every system touching personal data, catalogued against the DPDPA
2
Consent & Vendor Gap Report (Week 3)Section 8/9 gaps, exemption mapping, and vendor-contract review
3
Remediation Roadmap (Week 4-6)A sequenced plan to close every gap before enforcement begins
4
Breach-Response Rehearsal (Week 7-8)A tested, documented response that meets Rule 7's timelines
No obligation. No spam. Just a clear picture of your DPDPA exposure.
AS

Aurobindo Saxena

Founder & CEO, RAYSolute Consultants

CMA, CS, MBA (E-Commerce). Forbes India contributor; author of 90+ published articles and 30+ industry reports on Indian education across Forbes India, Medium and raysolute.com. He brings 23+ years in institutional consulting across K-12, higher education, and EdTech. RAYSolute is one of the first education consultancies to offer Generative Engine Optimization (GEO) for educational institutions.

aurobindo@raysolute.com · www.raysolute.com

Frequently Asked Questions

Yes. A Data Fiduciary is any person who determines the purpose and means of processing personal data. A school or university deciding what to collect at admission, how long to keep records, and which vendor runs its systems is making exactly that determination, which makes the institution itself, not its software vendor, the Data Fiduciary responsible under the Act for that data.
No. The DPDP Rules 2025 were notified on 14 November 2025 with an 18-month, three-stage commencement schedule. The Data Protection Board was constituted immediately in November 2025, Consent Manager registration opens in November 2026, and the substantive obligations, including Sections 8 and 9 on data fiduciary and children's data duties and Sections 27 to 34 on penalties, come into force together on 14 May 2027. Until then, the older IT Act 2000 Sensitive Personal Data or Information (SPDI) Rules continue to apply in parallel.
Not for every use. Section 9 requires verifiable parental consent before processing a child's personal data, but the DPDP Rules' Fourth Schedule gives educational institutions a narrow exemption: no consent is required where processing is restricted to the institution's own educational activities or to the safety of enrolled children. The moment data is used for anything outside that scope, such as sharing it with a marketing vendor, full verifiable consent under Section 9 applies again.
Section 8(2) requires that a Data Fiduciary may engage a Data Processor only under a valid contract. Beyond that statutory minimum, a well-drafted school vendor contract should cover data ownership, purpose limitation, sub-processor transparency, security standards, a breach-notification flow-down timed to the school's own 72-hour duty, a bar on using student data to train the vendor's AI models, and a defined data-destruction timeline on contract exit. Section 8(1) means the contract does not transfer the school's own statutory liability.
Section 8(6) requires the school to intimate both the Data Protection Board and each affected Data Principal, or the parent where the data belongs to a minor. Rule 7 sets a two-stage process: an initial report to the Board without delay, then a detailed report within 72 hours of becoming aware of the breach. Once Sections 27 to 34 are in force from 14 May 2027, penalties can reach Rs 250 crore for a failure of security safeguards and up to Rs 200 crore each for a breach-notification failure or for non-compliance with the children's-data provisions.
The Compliance Framework for Schools article maps the DPDPA as one of 17 domains across 30-plus Indian statutes a school must satisfy. This guide is a dedicated deep-dive into that one law: the actual enforcement timeline, the parental-consent mechanics, the vendor-contract requirements, and the breach-notification duties, in the depth a school actually needs before 14 May 2027.

More from RAYSolute

Explore our case studies, reports, and thought leadership

All Articles & Media