The DPDP Act and schools' data responsibilities
Schools hold more sensitive data about minors than almost any other institution. The DPDP Act does not ask for perfection, but it does ask for purpose, restraint and a plan for when things go wrong.
Schools hold more sensitive data about minors than almost any other institution. The DPDP Act does not ask for perfection, but it does ask for purpose, restraint and a plan for when things go wrong.
A school quietly holds one of the most sensitive data sets in any community: names, dates of birth, addresses, parent contact details, photographs, health notes, fee history, biometric attendance records and, increasingly, the live location of school buses. Nearly all of it belongs to children.
India's Digital Personal Data Protection (DPDP) Act, 2023, and the DPDP Rules notified in November 2025, set out how that kind of data must be handled. This guide explains what matters for a school administrator, in plain language, and what to do about it now.
This article is general information, not legal advice. Have your institution's counsel confirm how the law applies to you.
Under the Act, the organisation that decides why and how personal data is used is called a Data Fiduciary. For student and parent data, that is the school or college. A vendor that stores or processes the data on the institution's behalf, such as an ERP provider, is a processor.
The key point: outsourcing the software does not outsource the responsibility. If a vendor mishandles student data, the institution remains answerable to families and to the regulator.
The Act treats anyone under 18 as a child. As a general rule it requires verifiable consent from a parent or lawful guardian before a child's data is processed, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children.
The Rules phase in most obligations over a staggered timeline of up to 18 months from notification. Because dates and details can be refined, confirm the current schedule with your counsel rather than relying on a summary.
The Rules recognise that schools cannot run without processing student data. Educational institutions are exempt from the parental-consent requirement and the tracking restriction, but only where processing is limited to the institution's educational activities or the safety of enrolled students.
In practice, the core work of an ERP sits inside that boundary: admissions, attendance, timetables, marks, report cards and safety-related transport tracking.
The exemption is narrow. It does not stretch to:
For these optional uses, plan on collecting specific, verifiable parental consent that can be withdrawn.
Even where consent is not required, a school still has to:
Compliance with a data protection law is less a one-time project than a habit: know what you hold, use it for stated purposes, protect it, and be ready to explain both. Institutions that already run structured, permission-controlled records will find that habit far easier to build than those relying on scattered spreadsheets and chat groups.
Curious how a connected student record supports this? See how the Student Information System keeps records in one controlled place.
Explore the matching module or book a guided ERP demo for your school, college, or institution group.