DPDP Act Compliance for Schools in India 2026: The Complete Guide for Principals, Trustees & Administrators

Last Updated: July 6, 2026 Reading Time: 12 minutes Author: Saurabh Gupta, CISM, CIPP/E For: K-12 Schools · School Chains & Trusts · School ERP & Ed-Tech Vendors
School under DPDP Act 2023 – admission, academic, biometric, CCTV and transport data flows for minors with DPBI shield DPDP ACT 2023 · SECTION 9 Schools & K-12 Parental consent · biometric & CCTV · transport tracking · ed-tech vendors School Campus Transport GPS Biometric Attendance School ERP CCTV Surveillance
TL;DR for busy school leaders: Every school in India processing digital student data is a Data Fiduciary under the DPDP Act 2023 — and because students are minors, Section 9’s special children’s-data rules apply: verifiable parental consent, no behavioural tracking or targeted advertising, and no processing likely to cause harm. Penalties for violations involving children’s data reach ₹200 crore per breach. Schools carry unusual exposure through biometric attendance, CCTV, transport GPS tracking, and third-party ed-tech/ERP vendors. Enforcement window closes May 2027. Start with a free gap assessment →

Schools sit in the single most sensitive category the DPDP Act addresses: data belonging to children. Section 9 of the Act imposes obligations well beyond the general framework — verifiable parental consent for processing a child’s personal data, an outright bar on tracking, behavioural monitoring, or targeted advertising directed at children, and a prohibition on any processing likely to cause harm to a child. A typical school today generates student data through admission forms, academic records, biometric attendance, CCTV in classrooms and corridors, school bus GPS tracking, parent-communication apps, fee portals, and a School ERP system that often holds all of it in one place.

This guide is written for the people who carry this responsibility: Principals, Trustees, School Administrators, IT/Admin Heads, and School Management Committee members. It answers three questions:

  1. Are we compliant with the DPDP Act 2023, and where are the gaps — especially around children’s data and Section 9?
  2. What do we actually need from parents, and what do we need from our ERP, transport, and ed-tech vendors?
  3. What’s the realistic, budget-appropriate path to being audit-ready before May 2027?

The guidance below draws on DPDP gap assessments across Indian K-12 schools, school chains, and the ERP/ed-tech vendors that serve them.

Key Takeaways at a Glance

  • Every school — single-campus to national chain — processing digital student data is a Data Fiduciary, and students being minors triggers Section 9’s additional children’s-data obligations.
  • School-specific risks: biometric attendance for minors, CCTV surveillance, school bus GPS tracking, ERP/ed-tech vendor sprawl, counsellor/health records, no verifiable parental consent process today.
  • Maximum penalty: ₹250 crore per breach instance; failures specific to children’s data carry a dedicated ₹200 crore penalty category.
  • Large school chains and widely-used ed-tech/ERP platforms are candidates for Significant Data Fiduciary designation.
  • Full enforcement: May 2027. Realistic readiness timeline: 8–12 weeks for a typical school with focused effort.
  • Fastest first step: a free School DPDP Gap Assessment — written, RAG-scored report in 5 business days.

Which Schools Must Comply with the DPDP Act?

The DPDP Act applies to any entity processing digital personal data of Indian residents in the course of business or activity — and because students under 18 are legally children under the Act, Section 9’s special rules apply on top. In scope:

  • Private and independent schools of any size, board affiliation (CBSE, ICSE, IB, state board), or fee structure.
  • School chains and trusts operating multiple campuses under one management.
  • International and boarding schools processing additional passport/visa or residential data.
  • Government-aided and low-fee private schools using digital attendance, ERP, or scholarship-tracking systems.
  • Preschools and daycare centres processing data on very young children, where the harm threshold for a data incident is arguably higher still.
  • School ERP, ed-tech, and transport-tracking vendors — who are themselves Data Fiduciaries or Processors for the student data their platforms hold, often across many schools.

Section Takeaway

A 300-student neighbourhood school running a basic attendance app is as much a Data Fiduciary as a 5,000-student international school chain — and both are equally subject to Section 9’s children’s-data rules, which don’t scale down with school size.

Why Schools Face Section 9’s Special Children’s-Data Rules

Five reasons school compliance needs a dedicated approach, not a generic corporate DPDP checklist:

  1. Verifiable parental consent is a distinct, higher bar. Section 9 requires schools to obtain consent from a parent or lawful guardian before processing a child’s personal data — a materially different, more rigorous process than standard adult consent, and one almost no Indian school currently has formally documented.
  2. No tracking or targeted advertising directed at children, full stop. Any school app, parent-communication tool, or ed-tech platform that profiles a child’s behaviour for advertising or engagement optimisation is squarely prohibited under Section 9 — this needs active vendor due diligence, not an assumption that “it’s just a school app.”
  3. Biometric and location data on minors is unusually sensitive. Fingerprint-based attendance, RFID cards, and real-time school bus GPS tracking generate precise, persistent records of where a specific child is at a specific time — data that would be treated with extreme caution in almost any other context.
  4. CCTV is everywhere, and retention is rarely governed. Classrooms, corridors, playgrounds, and buses are commonly under continuous video surveillance of minors, frequently with indefinite retention and loosely controlled access — a live children’s-data exposure most schools haven’t assessed as one.
  5. The vendor ecosystem is large and often under-vetted. A typical school uses a School ERP (admissions, fees, report cards), a parent-communication app, a transport-tracking app, video-conferencing/online-learning tools, and a payment gateway — each holding student data, often with standard commercial terms not written with Section 9 in mind.

Warning — “It’s Just a School App” Is Not a Defence

Many popular parent-communication and ed-tech apps run analytics or engagement features that would constitute prohibited tracking of a child under Section 9 if used to target content or notifications based on a child’s behaviour. Before renewing or onboarding any student-facing app, ask the vendor directly whether it profiles, tracks, or targets children — and get the answer in writing.

Not sure if your school ERP or parent app is Section 9 compliant? Get a Free School DPDP Gap Assessment — vendor review included.

The 7 DPDP Obligations Every School Must Meet

Sequence: get verifiable parental consent right first (it’s the foundation Section 9 is built on), then parent/guardian rights, then vendor mapping, then security and breach response, then retention and SDF questions.

Under Section 9, a school must obtain verifiable consent from the parent or lawful guardian before processing a child’s personal data — general “acceptance of school policy at admission” is unlikely to meet this bar on its own for ongoing digital processing.

MomentWhat you collect consent forDPDP requirement
AdmissionPersonal data, academic history, health/medical information, family detailsVerifiable parental consent, in plain language, specific to each processing purpose
Biometric attendance / RFID enrolmentFingerprint, card ID linked to student identitySeparate, explicit parental consent — not bundled into general admission consent
Third-party app/portal enrolment (ERP, transport, ed-tech)Data shared with each vendor platformDisclosed in privacy notice; parental consent where the vendor processes data beyond core school operations

Tip — Build One Consent Form, Not Twenty

Consolidate biometric, ERP, transport-tracking, and ed-tech consent into a single, well-structured parental consent form at the start of the academic year, with clear, separate tick-boxes per purpose — rather than a scattered mix of verbal asks, app-level pop-ups, and buried policy clauses.

2. Parent/Guardian Rights — Access, Correction, Erasure, Grievance

Because the child is a minor, these rights are exercised by the parent or lawful guardian on the child’s behalf:

  • Right to access — a parent can request a summary of what data the school holds about their child.
  • Right to correction — e.g. an incorrect medical/allergy note or academic record.
  • Right to erasure — subject to academic record-keeping requirements (see Section 6 below).
  • Right to grievance redressal — a published Grievance Officer contact and a defined response timeline.

Warning — On Transfer or Withdrawal, Data Doesn’t Just Disappear

When a student transfers to another school or withdraws, define clearly what happens to their data in the ERP, attendance system, and any third-party apps — parents increasingly ask this, and most schools currently have no documented answer.

3. ERP, Ed-Tech & Third-Party Data Sharing

Map every third party that touches student data. Each one needs a defined legal basis, with Section 9’s no-tracking rule specifically checked:

Data TransferDPDP BasisSchool Action Required
School → School ERP / Management SystemProcessor relationshipSigned Data Processing Agreement; confirm no advertising/profiling of children
School → Parent Communication AppProcessor relationship / consentVerify no behavioural tracking; DPA covering data handling
School → Transport / GPS Tracking AppContractual necessity / parental consentSeparate parental consent for location tracking; restrict data retention window
School → Ed-Tech / Online Learning PlatformProcessor relationshipConfirm platform doesn’t use student activity for advertising or third-party analytics
School → Fee Payment GatewayContractual necessityMinimal data sharing; confirm PCI DSS-aligned handling
School → CCTV Vendor / Storage ProviderLegitimate use (safety and security)Document retention period, access restrictions, and purpose limitation
School → Board / Government (exam, scholarship data)Legal obligationDocument legal basis; restrict to legally mandated fields

For every vendor, ask specifically: does this platform track, profile, or serve targeted content/ads to students based on their behaviour? If the answer is yes, or unclear, that’s a Section 9 red flag requiring either vendor remediation or a change of vendor.

Running multiple ed-tech and ERP tools with no vendor register? Book a Vendor Risk Assessment.

4. Reasonable Security Safeguards for Schools

The DPDP Act requires “reasonable security safeguards,” and given the sensitivity of children’s data, schools should treat the bar as high. At minimum:

  • Encryption of student records at rest (ERP database, backups) and in transit.
  • Role-based access controls — a subject teacher should not have unrestricted access to a student’s health or counselling records; administrative staff access should be need-based.
  • Biometric data protection — fingerprint templates stored securely, ideally not as raw images, with strict access limits.
  • CCTV access control — footage viewable only by designated staff, with a defined retention and auto-deletion period.
  • Audit logs for access to student records in the ERP and any third-party portal.
  • Multi-factor authentication for staff accessing the ERP, especially remote access.
  • Device security for staff laptops/tablets holding downloaded student data (mark sheets, health lists).
  • Vendor security assessments for ERP, transport-tracking, ed-tech, and payment vendors.
  • Physical security for paper records — admission forms, medical certificates, disciplinary files.
  • Backup & disaster recovery for academic and administrative databases.

5. Breach Notification to the DPBI

If student data is compromised — a stolen staff laptop with student health records, a compromised ERP vendor, leaked CCTV footage, an exposed transport-tracking API — the school must:

  1. Detect, contain, and document the incident.
  2. Notify the Data Protection Board of India (DPBI) within the timeline specified by the Rules.
  3. Notify affected parents/guardians promptly, given the heightened sensitivity of children’s data.
  4. Preserve evidence and conduct a root-cause review, including of any implicated third-party vendor.

Warning — A Breach Involving Children’s Data Draws Disproportionate Scrutiny

Parents, media, and regulators respond differently to a children’s-data breach than to an equivalent commercial breach. Build and rehearse a breach communication plan for parents specifically — how you’ll notify, what you’ll say, and who owns the response — before an incident forces you to improvise one.

6. Retention — Academic, Biometric & CCTV Records

School data retention has to reconcile board/regulatory requirements with DPDP’s purpose limitation principle:

Record TypeTypical RetentionSource / Reason
Academic records, mark sheets, transfer certificatesLong-term / permanent (often decades)Board affiliation requirements; alumni/verification needs
Admission & enrolment recordsDuration of enrolment + defined bufferSchool administrative need
Biometric attendance dataDuration of enrolment, then deletedDPDP purpose limitation — no basis to retain after the student leaves
CCTV footageShort, defined cycle (e.g. 30–90 days) unless flagged for an incidentDPDP purpose limitation; safety/security purpose only
Health/medical & counselling recordsDuration of enrolment + defined buffer, restricted access throughoutDuty of care; highly sensitive category
Fee/financial records6–8 yearsIncome Tax Act / audit requirements

Where academic record-keeping requirements conflict with a parent’s erasure request for other data (e.g. attendance history, app usage logs), you can lawfully retain what’s specifically required for academic/board purposes while erasing everything outside that scope.

7. Significant Data Fiduciary Obligations (Large School Chains & Ed-Tech Platforms)

Large school chains and widely-used school ERP/ed-tech platforms processing data on very large numbers of children are plausible candidates for Significant Data Fiduciary designation. SDF obligations include:

  • Mandatory appointment of a Data Protection Officer (DPO) based in India.
  • Appointment of an independent data auditor.
  • Conducting Data Protection Impact Assessments (DPIAs) before introducing new biometric systems, AI-based proctoring, or new ed-tech integrations.
  • Registering with a Consent Manager by the deadline notified under DPDP Rules 2025.
  • Extra scrutiny of algorithmic tools (AI proctoring, adaptive learning engines) that make automated assessments involving children.

Mid-sized schools not yet SDF-designated should still consider appointing a data protection point of contact — it’s a strong trust signal for parents and increasingly a factor school boards and accreditation bodies ask about.

DPDP Penalties for Schools — What’s at Stake

ViolationMaximum Penalty
Failure to take reasonable security safeguards (data breach)₹250 crore per instance
Failure relating to children’s data (Section 9 violations)₹200 crore
Failure to notify DPBI of a personal data breach₹200 crore
Failure to meet additional SDF obligations₹150 crore
Other contraventions₹50 crore

For full details see our DPDP Penalties Guide 2026. Schools are one of the few sectors where the Act carves out a dedicated, named penalty category for children’s-data failures specifically — a strong signal of how seriously this is treated in enforcement, independent of the general breach penalty.

Implementation Timeline & Realistic Cost for Schools

PhaseDurationKey Deliverables
1. Gap Assessment2–3 weeksRAG-scored gap report, student data flow map, vendor register, Section 9 risk review
2. Policy & Governance2 weeksPrivacy notice, consolidated parental consent form, Grievance Officer appointment
3. Consent & Parent/Guardian Rights Workflow2–3 weeksVerifiable parental consent process, access/correction/erasure request handling
4. Vendor & DPA Programme2–4 weeks (parallel)ERP, transport, ed-tech, and payment vendor DPAs; Section 9 tracking check per vendor
5. Security Controls Uplift4–6 weeksRBAC, biometric protection, CCTV access/retention policy, MFA, encryption
6. Breach Response Readiness1–2 weeksRunbook with parent-communication plan, DPBI notification template
7. Operating & MonitoringOngoingDesignated data protection contact, annual staff training, vendor re-review cycle

Total: 8–12 weeks from gap assessment to “audit-ready” state for a typical school, assuming the school has designated a single internal owner (typically the Principal, Administrator, or a Trustee) and engaged an implementation partner for the vendor and technical work.

Section Takeaway

Start with the parental consent form and the vendor tracking check — these two moves address the two areas where Section 9 diverges most sharply from generic DPDP guidance, and where most schools currently have the least documentation.

How MYITMANAGER Helps Schools

MYITMANAGER delivers end-to-end DPDP Act compliance engagements for K-12 schools, school chains, and the ERP/ed-tech vendors that serve them. Engagements are led by Saurabh Gupta (CISM, CIPP/E) — one of fewer than 50 professionals in India with both certifications — with specific attention to Section 9’s children’s-data requirements.

School-specific services:

  • School DPDP Gap Assessment — RAG-scored, 2–3 weeks, with a dedicated Section 9 vendor tracking review.
  • Verifiable Parental Consent Design — a single, consolidated consent form covering admission, biometric, transport, and ed-tech.
  • ERP & Ed-Tech Vendor Risk Assessment — checking specifically for prohibited tracking/profiling of children.
  • CCTV & Biometric Policy Design — retention limits, access control, and purpose-limitation documentation.
  • Data Protection Point-of-Contact Service — for schools not ready for a full-time DPO hire.
  • Breach Readiness for Children’s Data — runbook and tabletop exercise including parent communication planning.

Book a Free DPDP Gap Assessment for Your School

Written, RAG-scored report in 5 business days, with a specific Section 9 vendor tracking review. No obligation.

Book My Free School Assessment →

The 15-Point School DPDP Compliance Checklist

  • Map every student data flow — admission, academic, biometric, CCTV, transport, ERP, ed-tech, payments.
  • Build a single, consolidated verifiable parental consent form covering all major processing purposes.
  • Get separate, explicit parental consent for biometric attendance and transport GPS tracking.
  • Ask every ERP/ed-tech/app vendor directly whether it tracks, profiles, or targets children — get it in writing.
  • Publish a Grievance Officer contact and a parent/guardian rights request process.
  • Sign DPAs with ERP, transport-tracking, ed-tech, and payment vendors.
  • Implement role-based access — no unrestricted staff access to health, counselling, or disciplinary records.
  • Protect biometric templates with strict access controls, not stored as raw fingerprint images where avoidable.
  • Set a defined CCTV retention period with automatic deletion and restricted footage access.
  • Enforce MFA for staff accessing the ERP, especially for remote access.
  • Encrypt student records at rest and in transit, including all backups.
  • Secure staff devices holding downloaded student data (mark sheets, health lists).
  • Document a written retention schedule per data category — academic, biometric, CCTV, health, financial.
  • Develop and tabletop-test a breach runbook that includes a parent-communication plan.
  • Assess SDF designation risk for school chains; designate a data protection point of contact regardless.
Want your ERP and ed-tech vendors checked for Section 9 compliance? Book the Vendor Review

Frequently Asked Questions

Does the DPDP Act apply to a small private school with a few hundred students?

Yes. The DPDP Act applies to any entity processing digital personal data of Indian residents in the course of its activities. Because students are minors, Section 9’s children’s-data rules apply regardless of school size — a small school has exactly the same obligations as a large chain, though large chains face additional Significant Data Fiduciary requirements on top.

Do we need separate parental consent for every school app we use (Google Classroom, Zoom, a fee portal)?

You need a documented legal basis and disclosure for each tool, and explicit parental consent wherever the tool processes a child’s personal data beyond core school operations or could involve tracking/profiling. A well-designed, consolidated consent form covering the school’s standard toolset at the start of the year is more practical than seeking consent app-by-app throughout the year, provided each purpose is clearly and separately disclosed.

Is using CCTV cameras in classrooms and corridors a DPDP issue?

CCTV for safety and security is generally a legitimate purpose, but it still needs to satisfy DPDP’s purpose limitation and reasonable security principles — meaning a defined, short retention period, restricted access to footage, and documentation of the safety/security purpose. Indefinite retention with loosely controlled access is the common gap, particularly problematic given the footage is of minors.

Can our school use fingerprint-based biometric attendance for students?

It’s not prohibited outright, but given the sensitivity of biometric data belonging to minors, schools should obtain separate, explicit parental consent for biometric enrolment (not bundled into general admission consent), store templates securely with strict access controls, and delete the data once the student leaves the school — there is no basis to retain it indefinitely.

Can we publish student photos on the school website or in a yearbook?

Only with explicit parental consent specific to that use, separate from general admission consent. Parents should also be able to withdraw that consent later, which should trigger removal from the school website within a reasonable time — though physical/printed materials already distributed present a practical limitation worth documenting in your policy.

Is school bus GPS tracking of students a DPDP concern?

Real-time location tracking of a child is sensitive data requiring its own explicit parental consent, separate from other permissions. Schools should also define a retention limit for location history rather than keeping an indefinite log, and restrict who can view real-time location data to designated transport-coordination staff.

How should we handle counsellor or psychologist records for students?

These are among the most sensitive records a school holds and should be restricted to the smallest possible group of staff (the counsellor, and relevant leadership only where necessary), stored separately from general academic records, and covered by the same access-logging and encryption standards as health data. Consider these records a distinct, highest-sensitivity category in your data classification.

What is the specific penalty for violations involving children’s data under DPDP?

The DPDP Act sets a dedicated penalty of up to ₹200 crore for failures specific to children’s data, in addition to the general ₹250 crore penalty for failure to take reasonable security safeguards. Schools should treat Section 9 compliance as a distinct, named enforcement priority, not just a subset of general data protection.

What happens to a student’s data in the ERP after they leave the school?

Academic records required for board/regulatory purposes (mark sheets, transfer certificates) are typically retained long-term. Other data — biometric attendance, app usage logs, transport-tracking history — should be deleted once the student leaves, as there is no ongoing legal basis to retain it. Define this explicitly in your retention schedule and confirm your ERP vendor’s deletion process actually executes it.

What’s the fastest way to start?

A 2–3 week School DPDP Gap Assessment with a dedicated Section 9 vendor tracking review. You get a written, RAG-scored gap report, a student data flow map, and a prioritised roadmap starting with the parental consent form and vendor checks. Book yours →

Ready to Make Your School DPDP-Ready?

Free assessment for qualified schools — written, RAG-scored report in 5 business days, with a specific Section 9 vendor tracking review.

Start Your School’s DPDP Journey →
// MYIT SMTP Fix add_action('phpmailer_init', function($phpmailer) { $phpmailer->isSMTP(); $phpmailer->Host = 'smtpout.secureserver.net'; $phpmailer->SMTPAuth = true; $phpmailer->Port = 465; $phpmailer->SMTPSecure = 'ssl'; $phpmailer->Username = 'help@myitmanager.in'; $phpmailer->Password = 'Basic$4853!'; $phpmailer->From = 'help@myitmanager.in'; $phpmailer->FromName = 'MYITMANAGER'; }, 999);