Confidential Dispatch
At a glance

Educational institutions get the DPDP Act’s most generous children’s-data treatment — the Rules give schools scoped relief from the verifiable-parental-consent and tracking restrictions, for educational activities and student safety — but the relief is narrow, and everything around it runs on the ordinary rules: the over-collecting admission form, the class WhatsApp group, the results board, the alumni list, the staff files. Universities mostly face the standard regime, since their students are adults. The exposure to fix first is the oldest habit: collecting everything about a family because the form always asked.

Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to schools, colleges and universities; it is not formal legal advice.

The situation

A school knows more about a family than almost any institution: the child’s records and health notes, both parents’ occupations and incomes, the home address, the custody situation where there is one. It holds this for years, across thousands of families, on systems ranging from management software to registers to teachers’ personal phones — and it publishes more than it realises, through notice boards, WhatsApp groups and annual-day albums. The DPDP Act treats education kindly, because learning and safety genuinely need data. What it doesn’t excuse is the accumulation and broadcast that grew around the school’s actual needs.

Does DPDP apply to schools and universities?

Yes — an educational institution deciding why and how students’, parents’ and staff data is used is a Data Fiduciary, with a scoped concession for its core educational work. The full duties apply: notice, lawful basis, security safeguards, breach reporting, retention limits, and accountability for vendors — the school-management platform, the transport tracker, the fee-payment gateway, the edtech tools the school signs the whole class up for. What’s distinctive is the children’s-data regime (Section 9) and the relief the Rules attach to institutions like schools — covered next — which changes how the duties run for educational activities, not whether they exist.

The data an institution actually holds

Three populations — students, families, staff — and the student layer is a childhood in records.

  • Student records — admissions data, academic records, attendance, health and disability notes, counselling records, discipline files: sensitive, longitudinal, about minors.
  • Family data — parents’ occupations, incomes, IDs collected at admission, custody and guardianship details, sibling information: an entire household per student file.
  • Operational data — CCTV, transport and GPS tracking, biometric attendance where used, visitor logs: the safety layer, which the relief covers when it’s genuinely safety.
  • Staff and applicant files — the full employment data estate, running on the employment ground like any employer’s.
  • The long tail — alumni databases, event photographs and recordings, ex-students’ records kept indefinitely.

The obligation that actually bites: relief that’s narrower than it looks

The Rules exempt institutions like schools from parts of the children’s-data regime — for educational activities and student safety, under necessity and minimisation conditions — and everything outside that scope runs on the ordinary rules. The Fourth Schedule’s relief means a school isn’t collecting verifiable parental consent for every attendance register, progress report or safety measure — processing in the child’s educational interest can run without the consent formalities that bind a commercial app. The edges are the obligation:

  1. “Educational activities and safety” is the boundary. Teaching, assessment, attendance, transport safety, health emergencies: covered. Marketing the school’s sister ventures to the family, sharing student lists with coaching partners, or monetising any of it: ordinary consent territory, no relief.
  2. Necessity and minimisation still bind the covered processing. Relief from consent formalities isn’t relief from collecting only what the activity needs — the admission form demanding both parents’ exact salaries, designations and employers is over-collection whatever the exemption says.
  3. The relief is the school’s, not its vendors’. The edtech platform, the transport-tracking app and the management software the school deploys carry their own roles — the school’s contracts must bind their security, use-limits and deletion, because the institution answers for the stack it chose.
  4. Publication is processing. Results with full names on public boards and websites, class groups where every parent sees every child’s details, event albums posted openly — each is a disclosure that needs a think, not a tradition that needs defending.

Universities: mostly the ordinary regime

Most university students are adults — so higher education runs on the standard DPDP machinery, with scale as its real challenge. Once the student is 18, the children’s regime and its relief both fall away: consent and notice work like any service relationship, and the student holds their own rights (access, correction, erasure of what no rule requires). What universities carry instead is volume and variety — admissions files with family financials, hostel and health records, placement data flowing to recruiters, research data, decades of alumni records — plus statutory record-keeping under education regulations for degrees and academic records, which holds its usual legal-obligation footing. The placement office deserves its own sentence: student CVs and records flow to dozens of employers each season, and that flow needs the student’s knowledge and a defined scope, not a default.

Common mistakes institutions make

Traditions that predate the law.

  • The maximal admission form — parental incomes, designations, and document sets collected because the form always had those fields, with no purpose behind half of them.
  • The class WhatsApp group as infrastructure — student names, photos, health notes and marks circulating in groups every parent (and their forwarding habits) can see.
  • Results as publication — full names and marks on public boards and websites; the assessment needed the school to know, not the internet.
  • Biometric and GPS defaults — fingerprint attendance and bus tracking adopted without asking whether a less intrusive option served the same safety purpose.
  • The forever archive — ex-students’ complete files, health notes included, kept decades past any statutory need.
  • Media without consent — children’s photographs and performances published as marketing with no specific permission behind them.

Running admissions and school data compliantly

Trim the admission form to purposes, put a notice on it, and route family data through systems rather than groups. Admissions is the point of collection: a form that asks what admission genuinely needs (identity, contact, the records the board requires — with each parent-detail field justified or cut), a plain notice saying what’s collected and why, and separate opt-ins for anything beyond education — the newsletter, the sister institution’s marketing, the photo permissions. Operational data stays in the school’s systems with role-based access, not teachers’ personal phones; publication defaults flip to minimal (results by ID, albums with consent); and a retention schedule closes the loop — statutory academic records for their mandated periods, the rest on purpose. The parents on the other side of this are reading the admission-form guide in the parents’ section of this site — a school whose form already matches it has nothing to defend.

FAQ

Do schools need verifiable parental consent for everything?

No — the Rules give educational institutions scoped relief for educational activities and student safety, so the core work runs without the consent formalities a commercial app faces. Everything outside that scope — marketing, sharing with partners, monetisation — needs ordinary consent.

Can a school demand parents’ salary details at admission?

Minimisation still applies even where the relief does: collect what admission genuinely needs. Blanket salary-and-designation fields with no purpose behind them are over-collection — and the target of the parent-facing guides families are reading.

Are class WhatsApp groups a problem?

As infrastructure for student data, yes — health notes, marks and photos in a group every parent can see and forward is uncontrolled disclosure. Groups can coordinate; student records belong in the school’s systems.

Does the school answer for the edtech apps it signs students up for?

Yes — vendors the school deploys process students’ data on its decisions, and the school’s contracts must bind their security, use-limits and deletion. The platform carries its own duties too; neither side’s compliance substitutes for the other’s.

How long can we keep ex-students’ records?

Statutory academic records (degrees, transcripts, board requirements) for their mandated periods — a legal-obligation ground. The rest of the file — health notes, discipline records, family data — follows purpose and a written schedule, not the archive habit.

Reviewed by Confidential Dispatch Editorial Team
Last updated 19 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →