Nipun Schools — free guides for parents, students & schools, plus school softwareISO 9001:2015 CertifiedMSME UDYAM-TS-12-0026878Startup India DIPP04274CIN U85490TS2025PTC194629 · Ministry of Corporate AffairsNGO Darpan TS/2025/0538233NAPS E03253600001 · NCS S20C56-1711396313889Free demo for principals & correspondents — Call +91 94917 00810
For Schools & Teachers

Student Data Privacy for Schools: DPDP Act Basics

Parental consent, children's data, security, breach handling, retention and a practical checklist for school offices.

Key points

  • Schools hold a large amount of personal data about children, parents and staff, and most of it sits in registers, WhatsApp chats, Excel files and software.
  • India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to digital personal data, and treats everyone under 18 as a child.
  • The DPDP Rules, 2025 were notified in November 2025 with a phased start. Most day-to-day obligations begin about 18 months after notification, so schools have time to prepare, but should start now.
  • Key ideas for schools: clear notice and consent, verifiable parental consent for children's data, using data only for stated purposes, reasonable security, breach handling and deleting data that is no longer needed.
  • This is a general overview, not legal advice. For your school's specific situation, consult a qualified lawyer.

A typical school office knows more about a family than almost anyone else: the child's date of birth, Aadhaar number, caste and religion for official forms, health conditions, parents' phone numbers and income details, and years of marks. Teachers share photos in WhatsApp groups. Marks lists are pinned on notice boards. Former staff still have logins to the fee software. Most of this happens without bad intent, but it creates real risk for children and for the school.

India now has a dedicated law on digital personal data. This guide explains the basics of the Digital Personal Data Protection Act, 2023 as they relate to schools, the current status of the Rules, and a practical checklist your office can start using today.

What personal data does a school hold?

CategoryExamples
Student identityName, date of birth, photo, Aadhaar, birth certificate, transfer certificate, admission number
Family detailsParents' names, phone numbers, address, occupation, income certificate
Sensitive in practiceCaste and religion (for official records), health conditions, disability, allergies, counselling notes
Academic recordsMarks, report cards, attendance, disciplinary records, teacher remarks
Financial recordsFee payments, concessions, dues, bank or UPI references
Location and imagesBus tracking data, CCTV footage, event photos and videos
Staff dataQualifications, salary, bank details, ID documents, attendance

The DPDP Act covers personal data in digital form, and data collected on paper that is later digitised. In practice, almost every school now has digital data: scanned admission forms, spreadsheets, phone contacts and software records.

DPDP Act basics in plain language

The Act uses a few terms you should know:

  • Data Principal: the person the data is about. For a child, the Act treats the parent or lawful guardian as acting for the child.
  • Data Fiduciary: the organisation that decides why and how data is processed. A school is a Data Fiduciary for its students' and staff data.
  • Data Processor: someone who processes data on the school's behalf, such as a software vendor, a bus tracking provider or a payroll service.
  • Child: anyone who has not completed 18 years of age. This covers nearly every school student, including Class 11 and 12.

Notice and consent

Where processing is based on consent, the Act requires a clear notice that tells people what personal data is collected and why, how they can withdraw consent, and how they can complain. Consent must be free, specific, informed and unambiguous, and it should be as easy to withdraw as to give. The Act also allows some processing without consent for certain "legitimate uses", for example to comply with a law. Which basis applies to which school activity is exactly the kind of question to check with a lawyer.

Children's data and verifiable parental consent

For children, the Act requires the verifiable consent of the parent or lawful guardian before processing their personal data. It also says organisations must not process children's data in a way likely to harm their well-being, and must not do tracking, behavioural monitoring or targeted advertising directed at children.

The DPDP Rules, 2025 describe how verifiable parental consent can be obtained, and they list certain exemptions. Published legal commentary on the Rules notes an exemption for educational institutions that is limited to processing for their educational activities and for the safety of enrolled children. That exemption is narrow. Using student data for marketing, sharing it with unrelated third parties, or profiling students through analytics tools would generally fall outside it. Read the exact wording in the official Rules, or ask a lawyer, before relying on any exemption.

Purpose limitation

Use data only for the purpose it was collected for. Phone numbers collected for school communication should not be handed to a tuition centre, a uniform shop or a political campaign. Admission data should not be reused for unrelated promotions without proper consent.

Security safeguards

The Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The Rules describe measures such as access control, encryption or masking where appropriate, monitoring of access, and keeping logs. The Act's schedule sets out penalties that can run into crores of rupees for failures, including failure to take reasonable security safeguards. The Data Protection Board decides penalties case by case.

Breach handling

If personal data is leaked, lost or accessed without authority, the Act requires the organisation to inform the Data Protection Board and each affected person. The Rules describe what the intimation should contain and set timelines for reporting. Examples in a school include a lost laptop with student records, a marks spreadsheet sent to the wrong WhatsApp group, or a hacked software account.

Data retention and erasure

Personal data should be erased when the purpose is served and it is no longer needed, unless a law requires the school to keep it. Schools do need to keep some records for long periods, such as admission registers and transfer certificate records, under education department rules. The point is to keep what you must, delete what you no longer need, and know which is which.

Rights of parents and students

Data Principals can ask for a summary of their data, ask for corrections and erasure in certain cases, and raise grievances. The organisation must provide a way to respond, such as a named contact person.

Current status of the DPDP Rules

The Digital Personal Data Protection Rules, 2025 were notified by the Government of India in November 2025. According to published summaries of the notification, they take effect in phases:

  • provisions relating to the Data Protection Board took effect on publication;
  • provisions on Consent Managers apply after about one year;
  • most substantive obligations, including notice, security safeguards, breach intimation and children's data, apply about 18 months after publication.

Legal commentators read the 18-month phase as running to around mid-2027. Timelines can be amended, so check the latest official notification on the Ministry of Electronics and Information Technology (MeitY) website or in the Gazette of India before planning around any date.

Tip: Do not wait for the deadline. Most of the work, such as cleaning up WhatsApp groups, removing old staff logins and writing a simple consent form, costs little and reduces risk immediately.

Practical checklist for school offices

AreaCommon practiceSafer practice
Class WhatsApp groupsAll parents see every other parent's number; teachers post marks and remarks in groupsUse broadcast lists or an app that hides numbers; send individual marks and remarks privately; set group rules
Photos on social mediaEvent photos with children's faces and names posted publiclyTake written parental consent for photos; allow opt-out; avoid pairing faces with full names
Marks lists on notice boardsFull class marks displayed in corridors or posted onlineShare marks with each family individually; if a list must be displayed, limit it to what is required
Admission formsCollecting every possible detail "just in case"Collect only what is needed, with a short notice of why; store paper forms in a locked cupboard
Staff accessShared passwords; former staff still have loginsIndividual logins with role-based access; remove access on the day a staff member leaves
DevicesOffice computers without passwords; data on personal pen drivesPassword-protected devices, screen locks, regular backups; avoid personal pen drives
Vendor contractsNo written terms with software, bus tracking or photography vendorsWritten agreement covering data use, security, breach reporting and deletion at contract end
Old recordsYears of unused spreadsheets and printouts lying aroundA retention schedule: what to keep, for how long, and how to destroy it safely
BreachesNo plan; staff hide mistakesA named person to report to, a simple incident log, and a plan to inform affected families and authorities as required
CCTV and bus trackingFootage and location shared freelyLimit who can view; keep footage only as long as needed; share location only with the child's own parents

Online safety for students is a related but separate topic. See our child online safety guide. For safer parent messaging habits, our guide to parent communication for schools also helps.

A simple starting plan

  1. Appoint a responsible person in the office for data protection questions and complaints.
  2. List your data: what you collect, where it is stored, who can access it and who you share it with.
  3. Remove what you do not need, including old staff logins, stale spreadsheets and unnecessary form fields.
  4. Update your admission form with a clear notice and parental consent for optional uses such as photos.
  5. Train staff once a term on WhatsApp habits, passwords and what to do if something goes wrong.
  6. Review vendor agreements and ask each vendor how they protect data.
Tip: Ask any software vendor (including us) how they protect data: where it is stored, who can access it, whether it is backed up, and what happens to it if you stop using the service. You can raise these questions during a demo.

This article is general information for school staff and is not legal advice. Laws and rules change, and their application depends on facts. For specific questions, such as drafting consent forms or vendor contracts, consult a qualified lawyer.

Frequently asked questions

Does the DPDP Act apply to small private schools?

The Act applies to organisations processing digital personal data in India, and it does not exempt schools based on size. Some exemptions exist for specific purposes, so check the official text or take legal advice for your situation.

Is a Class 11 or 12 student a child under the Act?

Yes. The Act defines a child as a person who has not completed 18 years, so almost all school students are children for this purpose.

Can we still use WhatsApp to communicate with parents?

The Act does not ban any app. The concern is what you share and with whom. Avoid exposing parents' numbers to everyone, and send individual marks, fee dues or health matters privately.

Can we post children's photos on the school's social media?

Take written parental consent first, allow parents to opt out, and avoid combining faces with full names and other identifying details. Remove photos when asked.

When do the DPDP Rules fully apply?

The Rules were notified in November 2025 with phased timelines, and most obligations apply about 18 months after publication. Check the latest official notification from MeitY for current dates.

For Schools & Teachers

Government & Quality Recognitions

Our Valued Partners

Registered and aligned with national excellence and quality certification standards.

WhatsApp Call