DPDPA Compliance for Schools and Higher Education Institutions
A practical, sourced guide to what the Digital Personal Data Protection Act 2023 actually requires of Indian schools and universities today, and what changes when the remaining provisions come into force on 14 May 2027.
Schools Are Data Fiduciaries Under the DPDPA
Every Indian school and higher education institution now sits inside a specific legal category, whether it chose to or not. The Digital Personal Data Protection Act (DPDPA) 2023, which received presidential assent on 11 August 2023 (Source: Ministry of Electronics and Information Technology (MeitY), Gazette of India, 11 Aug 2023), defines a "Data Fiduciary" as any person who, alone or with others, determines the purpose and means of processing personal data. A school deciding what to collect on an admission form, how long to retain exam records, or which vendor runs its learning management system is making exactly those determinations. That makes the institution itself, not its software vendor, the Data Fiduciary responsible under the Act.
The data at stake is broader than most administrators assume. A typical K-12 school holds admission-form data, Aadhaar copies, photographs, biometric attendance records, health and medical information, disciplinary files, closed-circuit television (CCTV) footage, transport records, and parents' payment details. A university adds National Assessment and Accreditation Council (NAAC) and National Institutional Ranking Framework (NIRF) self-study submission data, faculty personnel files, research participant data, hostel and disciplinary records, and, for institutions with international intake, passport and visa details of foreign students. Every one of these is personal data under the Act, and once it sits in an enterprise resource planning (ERP) system, a biometric device, or a third-party learning app, it falls inside the DPDPA's scope.
Research compilation, not legal advice. This guide is drawn from the DPDPA 2023, the DPDP Rules 2025, and publicly available regulatory notifications and legal commentary current as of August 2026. It is for orientation purposes only and does not constitute legal advice. Schools and universities should engage qualified legal counsel before finalising consent workflows, vendor contracts, or breach-response procedures.
This guide focuses on the DPDPA alone. For the other 30-plus statutes a school must satisfy alongside data privacy, see RAYSolute's Complete Compliance Framework for Schools, which covers DPDPA compliance as one item among 17 regulatory domains. This article goes deeper into that one law: what it means for the data already sitting in your ERP, and what actually changes on the date that matters.
The DPDPA Compliance Timeline for Schools
Most published guidance on the DPDPA reads as though every one of its obligations is already legally binding. That is not the current position. Section 1(2) of the Act lets the Central Government bring different provisions into force on different dates, and it has used that power deliberately. The DPDP Rules 2025 were notified by MeitY on 14 November 2025 (Source: MeitY, Gazette Notification, 14 Nov 2025; Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP rules", 2025-26), setting an 18-month, three-stage commencement schedule rather than switching the whole Act on at once.
(Source: Gazette Notification, DPDP Rules 2025, 14 Nov 2025, section-commencement schedule; corroborated independently by India Briefing, "India's DPDP Timeline: Critical Compliance Deadlines for 2026-27", 2026, and Shardul Amarchand Mangaldas & Co, 2025-26.)
What still applies right now. Section 44(2) of the DPDPA, which repeals the old Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 ("SPDI Rules"), does not itself commence until 14 May 2027. Until then, the SPDI Rules under Section 43A of the Information Technology Act 2000 continue to apply in parallel to any school or university that processes sensitive personal data electronically, including health and financial information. Schools are not in a regulatory vacuum today; they are operating under the older IT Act regime while the DPDPA's own machinery is switched on in stages.
For a school or university, this matters practically. The runway between today and 14 May 2027 is exactly the time to build a verifiable-consent workflow, renegotiate vendor contracts, and rehearse a breach response, before the Data Protection Board's penalty powers activate. Institutions that wait until the enforcement date to start are choosing to build under time pressure what could be built calmly now.
Verifiable Parental Consent Requirements Explained
Section 9 of the DPDPA is the provision most directly aimed at institutions like schools. It requires a Data Fiduciary to obtain verifiable consent from a parent or lawful guardian before processing the personal data of a "child", defined under Section 2(f) as anyone who has not completed eighteen years of age (Source: DPDPA 2023, Sections 2(f) and 9). That threshold is stricter than comparable regimes elsewhere: the European Union's General Data Protection Regulation (GDPR) sets 16 (member states may lower it to 13), and the United States' Children's Online Privacy Protection Act (COPPA) applies only under 13. India's flat 18-year line means every K-12 student, and depending on the programme, some university-entry-age students, falls under Section 9's protection.
Section 9 also carries standing prohibitions that apply regardless of consent: no tracking or behavioural monitoring of a child for targeted advertising, no advertising directed at children built on their processed data, and no processing detrimental to a child's wellbeing (Source: DPDPA 2023, Section 9).
What Counts as "Verifiable" (Rule 10)
Consent is not a checkbox on an admission form. Rule 10 of the DPDP Rules 2025 recognises three specific mechanisms for verifying that the person granting consent really is the child's parent or lawful guardian (Source: DPDP Rules 2025, Rule 10):
Reliable identity and age details the school already holds, typically captured and verified at the point of admission.
Identity and age information the parent supplies directly at the point consent is sought.
Mapped to identity and age, issued by an authorised entity: a government body, an entity it appoints, or a Digital Locker (DigiLocker) service provider notified under the Information Technology Act 2000.
The Fourth Schedule Exemption Schools Should Know
| Schedule 4 Entry | What It Exempts |
|---|---|
| Part A, Entry 3 | No verifiable consent required where a school's processing of a child's data is restricted to the institution's own educational activities, or to the safety of children enrolled with it. |
| Part B, Entry 3 | No verifiable consent required to create a student email account, so long as its use stays limited to communication by email. |
(Source: DPDP Rules 2025, Fourth Schedule, Parts A and B.)
This is a narrow carve-out, not a blanket exemption. The moment a school's use of student data moves outside "educational activities" or "child safety", sharing it with a marketing vendor, or feeding it to a third-party analytics tool that profiles students, Section 9's full verifiable-consent requirement applies again. Treat the exemption as covering core academic and safety systems, and verify consent for everything else.
EdTech Vendor Data Processing Agreements
Almost every Indian school now runs on someone else's software: an ERP for admissions and fees, a learning management system, a biometric attendance device, a proctoring tool for online tests. Under the DPDPA, each of these vendors is typically a "Data Processor" acting on the school's instructions, while the school itself remains the Data Fiduciary. Section 8(2) requires that a Data Fiduciary may engage a Data Processor "only under a valid contract" (Source: DPDPA 2023, Section 8(2)).
The point most schools miss is Section 8(1): a Data Fiduciary "shall, irrespective of any agreement to the contrary," remain responsible for complying with the Act in respect of any processing a Data Processor does on its behalf (Source: DPDPA 2023, Section 8(1)). A well-drafted vendor contract gives the school contractual recourse against a vendor that mishandles data; it does not transfer the school's own statutory liability. If an EdTech vendor exposes student records, the Data Protection Board's penalty exposure lands on the school.
What a School's Vendor Contract Should Cover
The DPDPA itself mandates only "a valid contract" (Section 8(2)) without dictating clause-by-clause content. The items below are recommended contracting practice, not independent statutory requirements.
The contract states plainly that the school owns the data and the vendor may not sell, license, or otherwise exploit it independently.
The exact categories of student and parent data shared, why, and for how long they may be retained.
Every downstream vendor the EdTech company itself uses, disclosed and subject to the school's approval before a new one is added.
Encryption in transit and at rest, access controls, and, where the vendor's scale warrants it, an independent security certification.
The vendor must notify the school fast enough for the school to meet its own Rule 7 timeline, not the vendor's own convenience.
An explicit bar on using student data to train the vendor's own machine-learning or AI models.
A defined, certified deletion timeline once the contract ends or the vendor relationship is terminated.
Your Data Breach Notification Duties
Section 8(6) of the DPDPA requires a Data Fiduciary to intimate both the Data Protection Board and each affected Data Principal, the student, or the parent where the data belongs to a minor, of a personal data breach (Source: DPDPA 2023, Section 8(6)). Rule 7 of the DPDP Rules 2025 sets out how, in two stages: the school must inform the Board without delay once a breach is confirmed, describing its nature, extent, timing, and likely impact, then, within 72 hours of becoming aware of the breach, file a fuller report covering the circumstances, remedial steps taken, and, where known, who caused it (Source: DPDP Rules 2025, Rule 7). The Board can grant more time on a written request, but the clock starts the moment the school becomes aware, not once an investigation concludes.
The penalty exposure, once Sections 27-34 come into force on 14 May 2027, is real. The Act's Schedule under Section 33 sets a ceiling of up to Rs 250 crore for a failure to implement reasonable security safeguards, and up to Rs 200 crore each for a failure to notify a breach as required and for non-compliance with the children's-data obligations under Section 9 (Source: DPDPA 2023, Section 33 and Schedule). The Board weighs several statutory factors before setting the actual amount, and may double a penalty for a repeat or particularly serious breach.
Section 8(9) additionally requires every Data Fiduciary, schools included, to publish the business contact details of a Data Protection Officer, if it has one, or a person able to answer a Data Principal's questions about their data (Source: DPDPA 2023, Section 8(9)). A Data Protection Officer becomes mandatory only for a Significant Data Fiduciary under Section 10, a threshold the government is yet to notify for the education sector; a named, published contact person is the baseline every institution should have regardless.
Your DPDPA Compliance Roadmap
Schools and universities do not need to build everything by 14 May 2027 in one push. A sequenced runway gets there without disrupting term-time operations.
ERP, biometric attendance, learning management system, canteen point-of-sale, transport tracker, CCTV, exactly what each collects and where it lives.
Under Section 8(9), someone parents and students can reach with questions about their data, even before a formal Data Protection Officer is required.
Using one of Rule 10's three mechanisms, and separately map which systems fall inside the Fourth Schedule's educational-activity exemption and which do not.
Against Section 8(2) and the checklist above; renegotiate any contract missing a valid data-processing clause.
One that can meet Rule 7's "without delay" first report and its 72-hour detailed follow-up.
How long each data category is kept, and what specifically triggers its deletion.
Get a DPDPA Compliance Diagnostic for Your Institution
RAYSolute's School Compliance Diagnostic includes a dedicated DPDPA module: a data map of every system touching personal data, a gap assessment against Sections 8 and 9, a review of your EdTech vendor contracts, and a practical roadmap to 14 May 2027.
Frequently Asked Questions
More from RAYSolute
Explore our case studies, reports, and thought leadership