India's DPDP Act and What It Means for Your School

India's DPDP Act and What It Means for Your School
← All posts

The DPDP Act is India's first comprehensive data protection law. For schools, which hold significant amounts of personal data — including children's data — the implications are real, even if many institutions haven't started the work.

What you\'re responsible for

Schools become "data fiduciaries" under DPDP. That means you have an obligation to:

  • Collect only the data you need (purpose limitation)
  • Get parental consent for processing children's data
  • Provide a clear privacy notice to parents
  • Allow data subjects to request access or deletion of their data
  • Notify the DPB and affected users of any breach

Children's data has stricter rules

DPDP defines a child as anyone under 18 and treats their data with elevated care. You can't process it for tracking, profiling, or behavioural advertising — and you need verifiable parental consent.

What your ERP needs to do

Most school ERPs are not DPDP-ready. They were built before this law existed. Things to check with your vendor:

  1. Can parents export all their child's data on request?
  2. Is there a hard delete (not just "archive") for data subject deletion requests?
  3. Does the system log who accessed what data and when (audit trails)?
  4. Are sub-processors (e.g. SMS gateways, payment processors, AI providers) named in your data processing agreement?
  5. Is data hosted in compliant data centres with documented security controls?

What we've built into Schoolo

Self-service data export, hard delete, audit logs on every access, named sub-processors in our DPA, and SOC-style controls in our cloud. Read more in our Privacy Policy.

Penalties, in plain numbers

The DPDP Act allows penalties up to ₹250 crore for significant data breaches involving children's data specifically — among the highest categories under the Act. Most schools will never see anything close to that, but it signals how seriously children's data is treated compared to general personal data, where penalties are lower.

A realistic compliance timeline for a school

  1. Month 1: Data mapping — list every system holding student or parent personal data, including spreadsheets, WhatsApp groups, and third-party apps.
  2. Month 2: Consent — issue a clear privacy notice to parents and capture verifiable consent for data processing, ideally at admission and re-confirmed annually.
  3. Month 3: Vendor review — ask every software vendor the five questions listed above; drop or renegotiate with anyone who can't answer them.

The most overlooked risk: WhatsApp groups

Class WhatsApp groups run by teachers or parent volunteers are rarely thought of as "the school's data processing," but they routinely contain phone numbers, photos of children, and sometimes health or behavioural information shared informally. Under DPDP, if the school is aware these groups exist and operate as an extension of school communication, that data still falls under the school's responsibility.

Payment data is personal data too — see how we handle it securely in our Razorpay setup guide.

This post is not legal advice — your school should still consult a qualified legal advisor on its specific obligations.