DPDP Act Compliance for Schools in India 2026: The Complete Guide for Principals, Trustees & Administrators
Schools sit in the single most sensitive category the DPDP Act addresses: data belonging to children. Section 9 of the Act imposes obligations well beyond the general framework — verifiable parental consent for processing a child’s personal data, an outright bar on tracking, behavioural monitoring, or targeted advertising directed at children, and a prohibition on any processing likely to cause harm to a child. A typical school today generates student data through admission forms, academic records, biometric attendance, CCTV in classrooms and corridors, school bus GPS tracking, parent-communication apps, fee portals, and a School ERP system that often holds all of it in one place.
This guide is written for the people who carry this responsibility: Principals, Trustees, School Administrators, IT/Admin Heads, and School Management Committee members. It answers three questions:
- Are we compliant with the DPDP Act 2023, and where are the gaps — especially around children’s data and Section 9?
- What do we actually need from parents, and what do we need from our ERP, transport, and ed-tech vendors?
- What’s the realistic, budget-appropriate path to being audit-ready before May 2027?
The guidance below draws on DPDP gap assessments across Indian K-12 schools, school chains, and the ERP/ed-tech vendors that serve them.
Key Takeaways at a Glance
- Every school — single-campus to national chain — processing digital student data is a Data Fiduciary, and students being minors triggers Section 9’s additional children’s-data obligations.
- School-specific risks: biometric attendance for minors, CCTV surveillance, school bus GPS tracking, ERP/ed-tech vendor sprawl, counsellor/health records, no verifiable parental consent process today.
- Maximum penalty: ₹250 crore per breach instance; failures specific to children’s data carry a dedicated ₹200 crore penalty category.
- Large school chains and widely-used ed-tech/ERP platforms are candidates for Significant Data Fiduciary designation.
- Full enforcement: May 2027. Realistic readiness timeline: 8–12 weeks for a typical school with focused effort.
- Fastest first step: a free School DPDP Gap Assessment — written, RAG-scored report in 5 business days.
Which Schools Must Comply with the DPDP Act?
The DPDP Act applies to any entity processing digital personal data of Indian residents in the course of business or activity — and because students under 18 are legally children under the Act, Section 9’s special rules apply on top. In scope:
- Private and independent schools of any size, board affiliation (CBSE, ICSE, IB, state board), or fee structure.
- School chains and trusts operating multiple campuses under one management.
- International and boarding schools processing additional passport/visa or residential data.
- Government-aided and low-fee private schools using digital attendance, ERP, or scholarship-tracking systems.
- Preschools and daycare centres processing data on very young children, where the harm threshold for a data incident is arguably higher still.
- School ERP, ed-tech, and transport-tracking vendors — who are themselves Data Fiduciaries or Processors for the student data their platforms hold, often across many schools.
Section Takeaway
A 300-student neighbourhood school running a basic attendance app is as much a Data Fiduciary as a 5,000-student international school chain — and both are equally subject to Section 9’s children’s-data rules, which don’t scale down with school size.
Why Schools Face Section 9’s Special Children’s-Data Rules
Five reasons school compliance needs a dedicated approach, not a generic corporate DPDP checklist:
- Verifiable parental consent is a distinct, higher bar. Section 9 requires schools to obtain consent from a parent or lawful guardian before processing a child’s personal data — a materially different, more rigorous process than standard adult consent, and one almost no Indian school currently has formally documented.
- No tracking or targeted advertising directed at children, full stop. Any school app, parent-communication tool, or ed-tech platform that profiles a child’s behaviour for advertising or engagement optimisation is squarely prohibited under Section 9 — this needs active vendor due diligence, not an assumption that “it’s just a school app.”
- Biometric and location data on minors is unusually sensitive. Fingerprint-based attendance, RFID cards, and real-time school bus GPS tracking generate precise, persistent records of where a specific child is at a specific time — data that would be treated with extreme caution in almost any other context.
- CCTV is everywhere, and retention is rarely governed. Classrooms, corridors, playgrounds, and buses are commonly under continuous video surveillance of minors, frequently with indefinite retention and loosely controlled access — a live children’s-data exposure most schools haven’t assessed as one.
- The vendor ecosystem is large and often under-vetted. A typical school uses a School ERP (admissions, fees, report cards), a parent-communication app, a transport-tracking app, video-conferencing/online-learning tools, and a payment gateway — each holding student data, often with standard commercial terms not written with Section 9 in mind.
Warning — “It’s Just a School App” Is Not a Defence
Many popular parent-communication and ed-tech apps run analytics or engagement features that would constitute prohibited tracking of a child under Section 9 if used to target content or notifications based on a child’s behaviour. Before renewing or onboarding any student-facing app, ask the vendor directly whether it profiles, tracks, or targets children — and get the answer in writing.
The 7 DPDP Obligations Every School Must Meet
Sequence: get verifiable parental consent right first (it’s the foundation Section 9 is built on), then parent/guardian rights, then vendor mapping, then security and breach response, then retention and SDF questions.
1. Verifiable Parental Consent
Under Section 9, a school must obtain verifiable consent from the parent or lawful guardian before processing a child’s personal data — general “acceptance of school policy at admission” is unlikely to meet this bar on its own for ongoing digital processing.
| Moment | What you collect consent for | DPDP requirement |
|---|---|---|
| Admission | Personal data, academic history, health/medical information, family details | Verifiable parental consent, in plain language, specific to each processing purpose |
| Biometric attendance / RFID enrolment | Fingerprint, card ID linked to student identity | Separate, explicit parental consent — not bundled into general admission consent |
| Third-party app/portal enrolment (ERP, transport, ed-tech) | Data shared with each vendor platform | Disclosed in privacy notice; parental consent where the vendor processes data beyond core school operations |
Tip — Build One Consent Form, Not Twenty
Consolidate biometric, ERP, transport-tracking, and ed-tech consent into a single, well-structured parental consent form at the start of the academic year, with clear, separate tick-boxes per purpose — rather than a scattered mix of verbal asks, app-level pop-ups, and buried policy clauses.
2. Parent/Guardian Rights — Access, Correction, Erasure, Grievance
Because the child is a minor, these rights are exercised by the parent or lawful guardian on the child’s behalf:
- Right to access — a parent can request a summary of what data the school holds about their child.
- Right to correction — e.g. an incorrect medical/allergy note or academic record.
- Right to erasure — subject to academic record-keeping requirements (see Section 6 below).
- Right to grievance redressal — a published Grievance Officer contact and a defined response timeline.
Warning — On Transfer or Withdrawal, Data Doesn’t Just Disappear
When a student transfers to another school or withdraws, define clearly what happens to their data in the ERP, attendance system, and any third-party apps — parents increasingly ask this, and most schools currently have no documented answer.
3. ERP, Ed-Tech & Third-Party Data Sharing
Map every third party that touches student data. Each one needs a defined legal basis, with Section 9’s no-tracking rule specifically checked:
| Data Transfer | DPDP Basis | School Action Required |
|---|---|---|
| School → School ERP / Management System | Processor relationship | Signed Data Processing Agreement; confirm no advertising/profiling of children |
| School → Parent Communication App | Processor relationship / consent | Verify no behavioural tracking; DPA covering data handling |
| School → Transport / GPS Tracking App | Contractual necessity / parental consent | Separate parental consent for location tracking; restrict data retention window |
| School → Ed-Tech / Online Learning Platform | Processor relationship | Confirm platform doesn’t use student activity for advertising or third-party analytics |
| School → Fee Payment Gateway | Contractual necessity | Minimal data sharing; confirm PCI DSS-aligned handling |
| School → CCTV Vendor / Storage Provider | Legitimate use (safety and security) | Document retention period, access restrictions, and purpose limitation |
| School → Board / Government (exam, scholarship data) | Legal obligation | Document legal basis; restrict to legally mandated fields |
For every vendor, ask specifically: does this platform track, profile, or serve targeted content/ads to students based on their behaviour? If the answer is yes, or unclear, that’s a Section 9 red flag requiring either vendor remediation or a change of vendor.
4. Reasonable Security Safeguards for Schools
The DPDP Act requires “reasonable security safeguards,” and given the sensitivity of children’s data, schools should treat the bar as high. At minimum:
- Encryption of student records at rest (ERP database, backups) and in transit.
- Role-based access controls — a subject teacher should not have unrestricted access to a student’s health or counselling records; administrative staff access should be need-based.
- Biometric data protection — fingerprint templates stored securely, ideally not as raw images, with strict access limits.
- CCTV access control — footage viewable only by designated staff, with a defined retention and auto-deletion period.
- Audit logs for access to student records in the ERP and any third-party portal.
- Multi-factor authentication for staff accessing the ERP, especially remote access.
- Device security for staff laptops/tablets holding downloaded student data (mark sheets, health lists).
- Vendor security assessments for ERP, transport-tracking, ed-tech, and payment vendors.
- Physical security for paper records — admission forms, medical certificates, disciplinary files.
- Backup & disaster recovery for academic and administrative databases.
5. Breach Notification to the DPBI
If student data is compromised — a stolen staff laptop with student health records, a compromised ERP vendor, leaked CCTV footage, an exposed transport-tracking API — the school must:
- Detect, contain, and document the incident.
- Notify the Data Protection Board of India (DPBI) within the timeline specified by the Rules.
- Notify affected parents/guardians promptly, given the heightened sensitivity of children’s data.
- Preserve evidence and conduct a root-cause review, including of any implicated third-party vendor.
Warning — A Breach Involving Children’s Data Draws Disproportionate Scrutiny
Parents, media, and regulators respond differently to a children’s-data breach than to an equivalent commercial breach. Build and rehearse a breach communication plan for parents specifically — how you’ll notify, what you’ll say, and who owns the response — before an incident forces you to improvise one.
6. Retention — Academic, Biometric & CCTV Records
School data retention has to reconcile board/regulatory requirements with DPDP’s purpose limitation principle:
| Record Type | Typical Retention | Source / Reason |
|---|---|---|
| Academic records, mark sheets, transfer certificates | Long-term / permanent (often decades) | Board affiliation requirements; alumni/verification needs |
| Admission & enrolment records | Duration of enrolment + defined buffer | School administrative need |
| Biometric attendance data | Duration of enrolment, then deleted | DPDP purpose limitation — no basis to retain after the student leaves |
| CCTV footage | Short, defined cycle (e.g. 30–90 days) unless flagged for an incident | DPDP purpose limitation; safety/security purpose only |
| Health/medical & counselling records | Duration of enrolment + defined buffer, restricted access throughout | Duty of care; highly sensitive category |
| Fee/financial records | 6–8 years | Income Tax Act / audit requirements |
Where academic record-keeping requirements conflict with a parent’s erasure request for other data (e.g. attendance history, app usage logs), you can lawfully retain what’s specifically required for academic/board purposes while erasing everything outside that scope.
7. Significant Data Fiduciary Obligations (Large School Chains & Ed-Tech Platforms)
Large school chains and widely-used school ERP/ed-tech platforms processing data on very large numbers of children are plausible candidates for Significant Data Fiduciary designation. SDF obligations include:
- Mandatory appointment of a Data Protection Officer (DPO) based in India.
- Appointment of an independent data auditor.
- Conducting Data Protection Impact Assessments (DPIAs) before introducing new biometric systems, AI-based proctoring, or new ed-tech integrations.
- Registering with a Consent Manager by the deadline notified under DPDP Rules 2025.
- Extra scrutiny of algorithmic tools (AI proctoring, adaptive learning engines) that make automated assessments involving children.
Mid-sized schools not yet SDF-designated should still consider appointing a data protection point of contact — it’s a strong trust signal for parents and increasingly a factor school boards and accreditation bodies ask about.
DPDP Penalties for Schools — What’s at Stake
| Violation | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards (data breach) | ₹250 crore per instance |
| Failure relating to children’s data (Section 9 violations) | ₹200 crore |
| Failure to notify DPBI of a personal data breach | ₹200 crore |
| Failure to meet additional SDF obligations | ₹150 crore |
| Other contraventions | ₹50 crore |
For full details see our DPDP Penalties Guide 2026. Schools are one of the few sectors where the Act carves out a dedicated, named penalty category for children’s-data failures specifically — a strong signal of how seriously this is treated in enforcement, independent of the general breach penalty.
Implementation Timeline & Realistic Cost for Schools
| Phase | Duration | Key Deliverables |
|---|---|---|
| 1. Gap Assessment | 2–3 weeks | RAG-scored gap report, student data flow map, vendor register, Section 9 risk review |
| 2. Policy & Governance | 2 weeks | Privacy notice, consolidated parental consent form, Grievance Officer appointment |
| 3. Consent & Parent/Guardian Rights Workflow | 2–3 weeks | Verifiable parental consent process, access/correction/erasure request handling |
| 4. Vendor & DPA Programme | 2–4 weeks (parallel) | ERP, transport, ed-tech, and payment vendor DPAs; Section 9 tracking check per vendor |
| 5. Security Controls Uplift | 4–6 weeks | RBAC, biometric protection, CCTV access/retention policy, MFA, encryption |
| 6. Breach Response Readiness | 1–2 weeks | Runbook with parent-communication plan, DPBI notification template |
| 7. Operating & Monitoring | Ongoing | Designated data protection contact, annual staff training, vendor re-review cycle |
Total: 8–12 weeks from gap assessment to “audit-ready” state for a typical school, assuming the school has designated a single internal owner (typically the Principal, Administrator, or a Trustee) and engaged an implementation partner for the vendor and technical work.
Section Takeaway
Start with the parental consent form and the vendor tracking check — these two moves address the two areas where Section 9 diverges most sharply from generic DPDP guidance, and where most schools currently have the least documentation.
How MYITMANAGER Helps Schools
MYITMANAGER delivers end-to-end DPDP Act compliance engagements for K-12 schools, school chains, and the ERP/ed-tech vendors that serve them. Engagements are led by Saurabh Gupta (CISM, CIPP/E) — one of fewer than 50 professionals in India with both certifications — with specific attention to Section 9’s children’s-data requirements.
School-specific services:
- School DPDP Gap Assessment — RAG-scored, 2–3 weeks, with a dedicated Section 9 vendor tracking review.
- Verifiable Parental Consent Design — a single, consolidated consent form covering admission, biometric, transport, and ed-tech.
- ERP & Ed-Tech Vendor Risk Assessment — checking specifically for prohibited tracking/profiling of children.
- CCTV & Biometric Policy Design — retention limits, access control, and purpose-limitation documentation.
- Data Protection Point-of-Contact Service — for schools not ready for a full-time DPO hire.
- Breach Readiness for Children’s Data — runbook and tabletop exercise including parent communication planning.
Book a Free DPDP Gap Assessment for Your School
Written, RAG-scored report in 5 business days, with a specific Section 9 vendor tracking review. No obligation.
Book My Free School Assessment →The 15-Point School DPDP Compliance Checklist
- Map every student data flow — admission, academic, biometric, CCTV, transport, ERP, ed-tech, payments.
- Build a single, consolidated verifiable parental consent form covering all major processing purposes.
- Get separate, explicit parental consent for biometric attendance and transport GPS tracking.
- Ask every ERP/ed-tech/app vendor directly whether it tracks, profiles, or targets children — get it in writing.
- Publish a Grievance Officer contact and a parent/guardian rights request process.
- Sign DPAs with ERP, transport-tracking, ed-tech, and payment vendors.
- Implement role-based access — no unrestricted staff access to health, counselling, or disciplinary records.
- Protect biometric templates with strict access controls, not stored as raw fingerprint images where avoidable.
- Set a defined CCTV retention period with automatic deletion and restricted footage access.
- Enforce MFA for staff accessing the ERP, especially for remote access.
- Encrypt student records at rest and in transit, including all backups.
- Secure staff devices holding downloaded student data (mark sheets, health lists).
- Document a written retention schedule per data category — academic, biometric, CCTV, health, financial.
- Develop and tabletop-test a breach runbook that includes a parent-communication plan.
- Assess SDF designation risk for school chains; designate a data protection point of contact regardless.
Frequently Asked Questions
Does the DPDP Act apply to a small private school with a few hundred students?
Yes. The DPDP Act applies to any entity processing digital personal data of Indian residents in the course of its activities. Because students are minors, Section 9’s children’s-data rules apply regardless of school size — a small school has exactly the same obligations as a large chain, though large chains face additional Significant Data Fiduciary requirements on top.
Do we need separate parental consent for every school app we use (Google Classroom, Zoom, a fee portal)?
You need a documented legal basis and disclosure for each tool, and explicit parental consent wherever the tool processes a child’s personal data beyond core school operations or could involve tracking/profiling. A well-designed, consolidated consent form covering the school’s standard toolset at the start of the year is more practical than seeking consent app-by-app throughout the year, provided each purpose is clearly and separately disclosed.
Is using CCTV cameras in classrooms and corridors a DPDP issue?
CCTV for safety and security is generally a legitimate purpose, but it still needs to satisfy DPDP’s purpose limitation and reasonable security principles — meaning a defined, short retention period, restricted access to footage, and documentation of the safety/security purpose. Indefinite retention with loosely controlled access is the common gap, particularly problematic given the footage is of minors.
Can our school use fingerprint-based biometric attendance for students?
It’s not prohibited outright, but given the sensitivity of biometric data belonging to minors, schools should obtain separate, explicit parental consent for biometric enrolment (not bundled into general admission consent), store templates securely with strict access controls, and delete the data once the student leaves the school — there is no basis to retain it indefinitely.
Can we publish student photos on the school website or in a yearbook?
Only with explicit parental consent specific to that use, separate from general admission consent. Parents should also be able to withdraw that consent later, which should trigger removal from the school website within a reasonable time — though physical/printed materials already distributed present a practical limitation worth documenting in your policy.
Is school bus GPS tracking of students a DPDP concern?
Real-time location tracking of a child is sensitive data requiring its own explicit parental consent, separate from other permissions. Schools should also define a retention limit for location history rather than keeping an indefinite log, and restrict who can view real-time location data to designated transport-coordination staff.
How should we handle counsellor or psychologist records for students?
These are among the most sensitive records a school holds and should be restricted to the smallest possible group of staff (the counsellor, and relevant leadership only where necessary), stored separately from general academic records, and covered by the same access-logging and encryption standards as health data. Consider these records a distinct, highest-sensitivity category in your data classification.
What is the specific penalty for violations involving children’s data under DPDP?
The DPDP Act sets a dedicated penalty of up to ₹200 crore for failures specific to children’s data, in addition to the general ₹250 crore penalty for failure to take reasonable security safeguards. Schools should treat Section 9 compliance as a distinct, named enforcement priority, not just a subset of general data protection.
What happens to a student’s data in the ERP after they leave the school?
Academic records required for board/regulatory purposes (mark sheets, transfer certificates) are typically retained long-term. Other data — biometric attendance, app usage logs, transport-tracking history — should be deleted once the student leaves, as there is no ongoing legal basis to retain it. Define this explicitly in your retention schedule and confirm your ERP vendor’s deletion process actually executes it.
What’s the fastest way to start?
A 2–3 week School DPDP Gap Assessment with a dedicated Section 9 vendor tracking review. You get a written, RAG-scored gap report, a student data flow map, and a prioritised roadmap starting with the parental consent form and vendor checks. Book yours →
Ready to Make Your School DPDP-Ready?
Free assessment for qualified schools — written, RAG-scored report in 5 business days, with a specific Section 9 vendor tracking review.
Start Your School’s DPDP Journey →Related Resources for Schools
- DPDP Act Compliance Checklist India 2026
- DPDP Breach Notification — Timelines & Templates
- DPIA Under DPDP Act — When & How
- Consent Manager India — DPDP Rules 2025
- DPDP Act Penalties India 2026
- Data Processing Agreement Under DPDP Act
- DPDP Act Compliance Services
- DPDP for NGOs India
- DPDP for Hospitals India
- Virtual CISO (vCISO) Services India