Book Demo

DPDP Act for Schools - Complete Compliance Checklist 2026

What the DPDP Act and 2025 Rules mean for Indian schools - parental consent, student data security, breach reporting, deadlines and a 12-step checklist.

DPDP Act for Schools - Complete Compliance Checklist 2026

Every school in India holds sensitive personal data about children: names, dates of birth, Aadhaar numbers, addresses, parents' phone numbers, medical conditions, photographs, marks and fee records. Until recently, there was no single law setting out how that data must be handled.

That has changed. The Digital Personal Data Protection (DPDP) Act, 2023, together with the DPDP Rules, 2025, now applies to schools as much as to banks or e-commerce companies. Because nearly every student is under 18, schools face some of the strictest requirements in the law.

This guide explains what the DPDP Act for schools means in plain language: the key deadlines, what "verifiable parental consent" involves, the limited exemption for educational institutions, and a practical 12-step checklist your school can start on this term.

Disclaimer: This article is general information, not legal advice. The DPDP framework is new and its interpretation will develop over time. Consult a qualified legal professional for advice specific to your school.


What Is the DPDP Act?

The DPDP Act is India's first comprehensive law on digital personal data. It sets out:

  • Who is responsible: the organisation that decides why and how personal data is used, called a Data Fiduciary. A school is a Data Fiduciary for the data of its students, parents and staff.
  • Whose data is protected: the individual the data belongs to, called a Data Principal. For a child, the parent or lawful guardian acts on their behalf.
  • What is required: clear notice, valid consent, reasonable security, breach reporting, and respect for people's rights over their own data.

The DPDP Rules, 2025 turn the Act's principles into specific operational requirements.


Key Dates Every School Should Know

Date What happens
August 2023 The DPDP Act is passed by Parliament
13 November 2025 The DPDP Rules, 2025 are notified; the Data Protection Board provisions take effect
November 2026 Rules on registered Consent Managers take effect (12 months after notification)
May 2027 Main obligations take effect, including consent, security, breach reporting and penalties (18 months after notification)

Eighteen months can sound like plenty of time. It isn't much for a school, where changes to admission forms, parent communication and systems usually happen once a year, at the start of a new session. For most schools, the 2026–27 admission cycle is the last full cycle before the obligations apply.


Why Schools Are in a Special Position

The Act defines a child as anyone under 18 years of age. Almost every student in a school is therefore a child in the eyes of the law, which brings in extra protections:

  1. Verifiable parental consent is generally required before processing a child's personal data.
  2. Tracking, behavioural monitoring and targeted advertising directed at children are generally prohibited.
  3. Processing that is likely to harm a child's well-being is not allowed.

The law also recognises that schools cannot function without handling children's data, so it provides a specific, limited exemption, explained below.


The Educational Institution Exemption, and Its Limits

The Fourth Schedule of the DPDP Rules exempts an educational institution from the parental-consent and tracking restrictions only where processing is restricted to tracking and behavioural monitoring:

  • for the educational activities of the institution, or
  • in the interests of the safety of children enrolled with the institution.

A related entry covers tracking a child's location during travel to and from school, in the interests of their safety.

In practical terms, this means a school can generally:

  • Mark attendance and track academic progress
  • Monitor behaviour and discipline as part of education
  • Use transport tracking to keep children safe on the way to and from school

What the exemption does not clearly cover includes:

  • Posting students' photos or videos on social media or in marketing
  • Sharing student data with third-party apps, coaching partners or vendors for their own purposes
  • Using student data to promote other services to parents
  • Collecting data that is not needed for education or safety

For activities outside the exemption, schools should assume that the normal rules apply, including verifiable parental consent. The safest approach is to treat the exemption narrowly and seek legal advice on anything borderline.


Consent under the DPDP framework is much more than a signature at the bottom of an admission form. It must be:

  • Free: given willingly, not forced as a condition for something unrelated
  • Specific: tied to a clearly stated purpose
  • Informed: the parent understands what data is collected and why
  • Unambiguous: a clear, positive action, not a pre-ticked box
  • Withdrawable: as easy to withdraw as it was to give

The Rules also require the school to be reasonably sure that the person giving consent is actually the child's parent or lawful guardian and is an adult. Recognised ways to verify this include relying on identity details the school already holds reliably, details the parent provides, or a virtual token from an authorised entity (such as a DigiLocker-based service).

What this means in practice: replace the one-line "I agree to all terms" in your admission form with a clear notice and separate consent for each non-essential purpose, such as photos on the website, sharing data with an outside activity provider, or promotional messages.


What Schools Must Do: Core Obligations

1. Give a Clear Privacy Notice

Parents must be told, in clear and simple language, what data you collect, why you collect it, and how they can exercise their rights or withdraw consent. The notice should be understandable on its own, not buried in a long policy document. Offering it in the language parents actually read is good practice.

2. Collect Only What You Need

If a piece of information isn't needed for admission, education, safety or a legal requirement, don't collect it. Every extra field is extra risk.

3. Protect Data With Reasonable Security Safeguards

The Rules expect measures such as:

  • Encryption or similar protection for personal data
  • Access control, so only authorised people see data they need
  • Logs that record access to personal data and help detect misuse (generally kept for at least one year)
  • Backups and the ability to keep functioning after an incident
  • Contracts that require your vendors to follow the same standards

Failing to take reasonable security safeguards carries the highest penalty in the Act, up to ₹250 crore.

4. Report Data Breaches

If personal data is compromised through hacking, a lost device, a wrong email attachment or unauthorised access, the school must:

  • Inform the Data Protection Board without delay, with detailed information within 72 hours
  • Inform every affected parent or individual without delay, explaining what happened, the likely impact and what they can do

The Rules set no minimum size, so even a small breach may need to be reported.

5. Respect Parents' Rights

Parents (on behalf of their children) and staff have the right to:

  • Access a summary of the data held about them
  • Correct inaccurate or incomplete data
  • Erase data that is no longer needed, subject to legal retention requirements
  • Raise a grievance and receive a response
  • Nominate someone to act for them

Your school should publish a contact person for data questions and have a simple process for handling requests.

6. Don't Keep Data Forever

Personal data should not be kept once its purpose is complete, unless a law requires you to keep it (for example, certain academic, financial or board records). Set clear retention periods, such as how long CCTV footage, attendance photos or former students' contact details are kept, and follow them.


Penalties Under the DPDP Act

The Data Protection Board can impose significant financial penalties. The maximum amounts include:

Violation Maximum penalty
Failure to take reasonable security safeguards Up to ₹250 crore
Failure to notify the Board and individuals of a breach Up to ₹200 crore
Failure to meet obligations relating to children's data Up to ₹200 crore
Other breaches of the Act or Rules Up to ₹50 crore

The Board considers factors such as the nature, seriousness and duration of the breach, and whether steps were taken to reduce harm. In practice, a school that can show it made a genuine effort to comply is in a much stronger position than one that did nothing. For a school, reputational damage and loss of parents' trust can hurt as much as any fine.


DPDP Compliance Checklist for Schools: 12 Steps

Infographic: 12-step DPDP Act compliance checklist for schools

Understand your data

  1. Map your data. List every place student, parent and staff data lives: admission forms, registers, the school ERP, spreadsheets, WhatsApp groups, CCTV, email and third-party apps.
  2. Identify the purpose of each item. Mark whether it's needed for education, safety, a legal requirement or something else.
  3. Appoint a data contact person. Choose one named person to own data protection and handle parents' questions.

Update your documents

  1. Rewrite your privacy notice in clear, simple language.
  2. Revise admission and consent forms, with separate consent for photos, marketing and third-party sharing.
  3. Review vendor contracts, including your ERP, transport, online learning and payment providers.

Secure your systems

  1. Limit access by role. Teachers, accountants and office staff should each see only what their job requires.
  2. Encrypt sensitive data such as Aadhaar, bank details and medical records.
  3. Turn on activity logs and review them periodically.
  4. Stop using personal devices and chat groups for sensitive records. Move them into a secure, school-controlled system.

Be ready to respond

  1. Create a breach response plan covering who does what, whom to inform, and how to meet the 72-hour window.
  2. Train your staff. Most breaches start with human error: a wrong recipient, a shared password or a lost phone.

See how Amitrix encrypts, restricts and logs access to your student data.

Book a free demo →

Common DPDP Mistakes Schools Make

  • Treating the admission form as blanket consent. One signature cannot cover every purpose.
  • Keeping student records in WhatsApp groups and personal phones. These are hard to secure, audit or delete.
  • Posting student photos online without specific consent.
  • Giving every staff member access to everything. A shared admin login is a major risk.
  • Assuming the vendor handles compliance. Your software provider processes data for you, but the school remains the Data Fiduciary and stays responsible.
  • Waiting until 2027. Forms, systems and habits take at least one admission cycle to change.

Schools already preparing for board changes can pair this work with our guides to the CBSE 75% attendance rule and the Holistic Progress Card.


How School Management Software Supports DPDP Compliance

No software can make a school compliant on its own. Compliance also depends on your policies, notices, consent process and staff behaviour. The right school ERP makes the technical side much easier, and a weak one can put the school at risk.

When evaluating software, ask:

Question Why it matters
Which fields are encrypted? Aadhaar, bank and medical data need strong protection
Is access controlled by role, and enforced on the server? Hiding menus is not the same as restricting access
Is each school's data kept separate? Essential on shared cloud platforms
Are there audit logs of who changed what? Supports accountability and breach investigation
Can parents see only their own child's data? Prevents accidental exposure between families
How are photos and documents stored? Files should never be publicly accessible
Can you set retention periods? Helps you avoid keeping data forever
Where is data stored, and how is it backed up? Needed for your own records and vendor review

For a full guide to choosing a school ERP, see best school management software in India.


How Amitrix Helps Schools Protect Student Data

Amitrix is a school management platform built with data protection in mind from the start:

  • Encryption of sensitive fields: Aadhaar, PAN, bank details and similar data are encrypted at rest using AES-256.
  • Role-based access, enforced on the server: Admin, Principal, Teacher, Accountant, HR, Parent and Student each see only what their role allows.
  • Parents see only their own children. Access to another family's records is blocked at the server.
  • Separate data for each school, even on a shared platform.
  • Audit logs that record key actions across the system.
  • Secure file handling: uploaded files are checked for their real content type, and photos and documents are stored privately, not on public links.
  • Automatic retention for attendance photos: selfies are deleted after the period each school sets, while the attendance record is kept.
  • Controlled corrections: students can request changes to their profile through an approval workflow, supporting the right to correct data.
  • Short, secure login sessions that expire automatically.

Amitrix handles the technical safeguards. Your school's notices, consent process and staff practices complete the picture.

See how your student data is protected.

Book a free Amitrix demo →

Frequently Asked Questions

Does the DPDP Act apply to schools in India?

Yes. Schools collect and process personal data of students, parents and staff, which makes them Data Fiduciaries under the DPDP Act. Because most students are under 18, the stricter rules on children's data also apply.

When do schools need to comply with the DPDP Rules?

The DPDP Rules, 2025 were notified on 13 November 2025. Most obligations, including consent, security safeguards, breach reporting and penalties, take effect 18 months later, in May 2027.

Do schools need parental consent for all student data?

Not in every case. The Rules exempt educational institutions from the parental-consent and tracking restrictions where processing is limited to educational activities or the safety of enrolled children. Activities outside that scope, such as posting photos publicly or sharing data with third parties, will generally need verifiable parental consent.

What is the penalty for a school that violates the DPDP Act?

Penalties can reach up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to report a breach or to meet obligations relating to children's data. The actual amount depends on the seriousness of the violation.

What should a school do if student data is leaked?

Contain the breach, then inform the Data Protection Board without delay and provide detailed information within 72 hours. Affected parents or individuals must also be told what happened, the likely impact, and what they can do to protect themselves.

Does using a school ERP make my school DPDP compliant?

A good school ERP supports compliance with encryption, access control and audit logs, but it does not make a school compliant by itself. The school remains responsible for its privacy notices, consent process, vendor contracts and staff practices.


Conclusion

The DPDP Act for schools is not something to leave until 2027. Parents are already paying more attention to how their children's data is used, and the schools that act early will earn their trust.

Start with the basics this term: map your data, rewrite your notices and consent forms, limit access by role, and move sensitive records off personal phones and chat groups. Then build a breach plan and train your staff before the 2027 deadline.

Want to see how Amitrix keeps your student data secure? Book your free demo today.

Is paperwork eating into your week?

Amitrix EMS handles admissions, attendance, fees, exams and the parent app for one flat ₹12,000 a year, with no limit on students.

Book a free demoView pricing

Keep reading