Skip to main content

The DPDP Act and schools' data responsibilities

Schools hold more sensitive data about minors than almost any other institution. The DPDP Act does not ask for perfection, but it does ask for purpose, restraint and a plan for when things go wrong.

Compliance & Security4 min readPublished

Key takeaways

  • Outsourcing student data to an ERP vendor does not outsource responsibility — the school remains the Data Fiduciary answerable to families and the regulator.
  • The school exemption covers core educational and safety activities only; publishing photos, marketing and third-party sharing fall outside it and need separate parental consent.
  • Clear notice, reasonable safeguards, breach response, retention limits and grievance handling apply whether or not consent is required.
  • A data inventory, purpose labelling and a rehearsed breach playbook turn compliance from a one-time project into a routine habit.

Who is responsible for what

A school quietly holds one of the most sensitive data sets in any community: names, dates of birth, addresses, parent contact details, photographs, health notes, fee history, biometric attendance records and, increasingly, the live location of school buses. Nearly all of it belongs to children.

India's Digital Personal Data Protection (DPDP) Act, 2023, and the DPDP Rules notified in November 2025, set out how that kind of data must be handled. This guide explains what matters for a school administrator, in plain language, and what to do about it now.

This article is general information, not legal advice. Have your institution's counsel confirm how the law applies to you.

Under the Act, the organisation that decides why and how personal data is used is called a Data Fiduciary. For student and parent data, that is the school or college. A vendor that stores or processes the data on the institution's behalf, such as an ERP provider, is a processor.

The key point: outsourcing the software does not outsource the responsibility. If a vendor mishandles student data, the institution remains answerable to families and to the regulator.

Why children's data gets extra attention

The Act treats anyone under 18 as a child. As a general rule it requires verifiable consent from a parent or lawful guardian before a child's data is processed, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children.

The Rules phase in most obligations over a staggered timeline of up to 18 months from notification. Because dates and details can be refined, confirm the current schedule with your counsel rather than relying on a summary.

What the school exemption does and does not cover

The Rules recognise that schools cannot run without processing student data. Educational institutions are exempt from the parental-consent requirement and the tracking restriction, but only where processing is limited to the institution's educational activities or the safety of enrolled students.

In practice, the core work of an ERP sits inside that boundary: admissions, attendance, timetables, marks, report cards and safety-related transport tracking.

The exemption is narrow. It does not stretch to:

  • Publishing student photographs or achievements on social media and marketing material
  • Sharing student details with third-party apps for non-educational purposes
  • Using parent or student data for promotions, or for fundraising outreach
  • Analytics or profiling that goes beyond the educational purpose

For these optional uses, plan on collecting specific, verifiable parental consent that can be withdrawn.

Duties that apply either way

Even where consent is not required, a school still has to:

  • Give clear notice describing what data is collected and why, in plain language
  • Protect the data with reasonable safeguards such as encryption, access controls, activity logs and backups
  • Respond to breaches by informing affected individuals and the Data Protection Board, with a detailed report to the Board within a short, fixed window
  • Limit retention by deleting data once its purpose ends, unless another law requires it to be kept
  • Honour rights and grievances such as access, correction and erasure requests, through a named contact

Six practical steps for a school

  1. Build a data inventory. List every place student and parent data lives: ERP, spreadsheets, biometric devices, WhatsApp groups, admission forms, CCTV, transport apps.
  2. Label each use by purpose. Mark whether it is core education or safety, or something optional such as marketing.
  3. Start a consent register for the optional uses, with a simple way for parents to withdraw.
  4. Tighten vendor contracts. Cover breach notification timelines, sub-processors, data location, deletion at exit and audit rights.
  5. Enforce role-based access and logging, so you can show who viewed or changed a record.
  6. Write and rehearse a breach playbook covering who decides, who informs families, and what the first 72 hours look like.

Questions to put to your ERP vendor

  • Where is our data stored, and is it encrypted at rest and in transit?
  • Who at your company can access our records, and is that access logged?
  • How quickly will you tell us about a suspected breach?
  • Can we export and permanently delete our data if we leave?
  • Do you use student data for anything beyond delivering the service?

The bottom line

Compliance with a data protection law is less a one-time project than a habit: know what you hold, use it for stated purposes, protect it, and be ready to explain both. Institutions that already run structured, permission-controlled records will find that habit far easier to build than those relying on scattered spreadsheets and chat groups.

Curious how a connected student record supports this? See how the Student Information System keeps records in one controlled place.

See this workflow in Pii Aura

Explore the matching module or book a guided ERP demo for your school, college, or institution group.

7989995014