Key points
- Schools hold a large amount of personal data about children, parents and staff, and most of it sits in registers, WhatsApp chats, Excel files and software.
- India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to digital personal data, and treats everyone under 18 as a child.
- The DPDP Rules, 2025 were notified in November 2025 with a phased start. Most day-to-day obligations begin about 18 months after notification, so schools have time to prepare, but should start now.
- Key ideas for schools: clear notice and consent, verifiable parental consent for children's data, using data only for stated purposes, reasonable security, breach handling and deleting data that is no longer needed.
- This is a general overview, not legal advice. For your school's specific situation, consult a qualified lawyer.
A typical school office knows more about a family than almost anyone else: the child's date of birth, Aadhaar number, caste and religion for official forms, health conditions, parents' phone numbers and income details, and years of marks. Teachers share photos in WhatsApp groups. Marks lists are pinned on notice boards. Former staff still have logins to the fee software. Most of this happens without bad intent, but it creates real risk for children and for the school.
India now has a dedicated law on digital personal data. This guide explains the basics of the Digital Personal Data Protection Act, 2023 as they relate to schools, the current status of the Rules, and a practical checklist your office can start using today.
What personal data does a school hold?
| Category | Examples |
|---|---|
| Student identity | Name, date of birth, photo, Aadhaar, birth certificate, transfer certificate, admission number |
| Family details | Parents' names, phone numbers, address, occupation, income certificate |
| Sensitive in practice | Caste and religion (for official records), health conditions, disability, allergies, counselling notes |
| Academic records | Marks, report cards, attendance, disciplinary records, teacher remarks |
| Financial records | Fee payments, concessions, dues, bank or UPI references |
| Location and images | Bus tracking data, CCTV footage, event photos and videos |
| Staff data | Qualifications, salary, bank details, ID documents, attendance |
The DPDP Act covers personal data in digital form, and data collected on paper that is later digitised. In practice, almost every school now has digital data: scanned admission forms, spreadsheets, phone contacts and software records.
DPDP Act basics in plain language
The Act uses a few terms you should know:
- Data Principal: the person the data is about. For a child, the Act treats the parent or lawful guardian as acting for the child.
- Data Fiduciary: the organisation that decides why and how data is processed. A school is a Data Fiduciary for its students' and staff data.
- Data Processor: someone who processes data on the school's behalf, such as a software vendor, a bus tracking provider or a payroll service.
- Child: anyone who has not completed 18 years of age. This covers nearly every school student, including Class 11 and 12.
Notice and consent
Where processing is based on consent, the Act requires a clear notice that tells people what personal data is collected and why, how they can withdraw consent, and how they can complain. Consent must be free, specific, informed and unambiguous, and it should be as easy to withdraw as to give. The Act also allows some processing without consent for certain "legitimate uses", for example to comply with a law. Which basis applies to which school activity is exactly the kind of question to check with a lawyer.
Children's data and verifiable parental consent
For children, the Act requires the verifiable consent of the parent or lawful guardian before processing their personal data. It also says organisations must not process children's data in a way likely to harm their well-being, and must not do tracking, behavioural monitoring or targeted advertising directed at children.
The DPDP Rules, 2025 describe how verifiable parental consent can be obtained, and they list certain exemptions. Published legal commentary on the Rules notes an exemption for educational institutions that is limited to processing for their educational activities and for the safety of enrolled children. That exemption is narrow. Using student data for marketing, sharing it with unrelated third parties, or profiling students through analytics tools would generally fall outside it. Read the exact wording in the official Rules, or ask a lawyer, before relying on any exemption.
Purpose limitation
Use data only for the purpose it was collected for. Phone numbers collected for school communication should not be handed to a tuition centre, a uniform shop or a political campaign. Admission data should not be reused for unrelated promotions without proper consent.
Security safeguards
The Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The Rules describe measures such as access control, encryption or masking where appropriate, monitoring of access, and keeping logs. The Act's schedule sets out penalties that can run into crores of rupees for failures, including failure to take reasonable security safeguards. The Data Protection Board decides penalties case by case.
Breach handling
If personal data is leaked, lost or accessed without authority, the Act requires the organisation to inform the Data Protection Board and each affected person. The Rules describe what the intimation should contain and set timelines for reporting. Examples in a school include a lost laptop with student records, a marks spreadsheet sent to the wrong WhatsApp group, or a hacked software account.
Data retention and erasure
Personal data should be erased when the purpose is served and it is no longer needed, unless a law requires the school to keep it. Schools do need to keep some records for long periods, such as admission registers and transfer certificate records, under education department rules. The point is to keep what you must, delete what you no longer need, and know which is which.
Rights of parents and students
Data Principals can ask for a summary of their data, ask for corrections and erasure in certain cases, and raise grievances. The organisation must provide a way to respond, such as a named contact person.
Current status of the DPDP Rules
The Digital Personal Data Protection Rules, 2025 were notified by the Government of India in November 2025. According to published summaries of the notification, they take effect in phases:
- provisions relating to the Data Protection Board took effect on publication;
- provisions on Consent Managers apply after about one year;
- most substantive obligations, including notice, security safeguards, breach intimation and children's data, apply about 18 months after publication.
Legal commentators read the 18-month phase as running to around mid-2027. Timelines can be amended, so check the latest official notification on the Ministry of Electronics and Information Technology (MeitY) website or in the Gazette of India before planning around any date.
Practical checklist for school offices
| Area | Common practice | Safer practice |
|---|---|---|
| Class WhatsApp groups | All parents see every other parent's number; teachers post marks and remarks in groups | Use broadcast lists or an app that hides numbers; send individual marks and remarks privately; set group rules |
| Photos on social media | Event photos with children's faces and names posted publicly | Take written parental consent for photos; allow opt-out; avoid pairing faces with full names |
| Marks lists on notice boards | Full class marks displayed in corridors or posted online | Share marks with each family individually; if a list must be displayed, limit it to what is required |
| Admission forms | Collecting every possible detail "just in case" | Collect only what is needed, with a short notice of why; store paper forms in a locked cupboard |
| Staff access | Shared passwords; former staff still have logins | Individual logins with role-based access; remove access on the day a staff member leaves |
| Devices | Office computers without passwords; data on personal pen drives | Password-protected devices, screen locks, regular backups; avoid personal pen drives |
| Vendor contracts | No written terms with software, bus tracking or photography vendors | Written agreement covering data use, security, breach reporting and deletion at contract end |
| Old records | Years of unused spreadsheets and printouts lying around | A retention schedule: what to keep, for how long, and how to destroy it safely |
| Breaches | No plan; staff hide mistakes | A named person to report to, a simple incident log, and a plan to inform affected families and authorities as required |
| CCTV and bus tracking | Footage and location shared freely | Limit who can view; keep footage only as long as needed; share location only with the child's own parents |
Online safety for students is a related but separate topic. See our child online safety guide. For safer parent messaging habits, our guide to parent communication for schools also helps.
A simple starting plan
- Appoint a responsible person in the office for data protection questions and complaints.
- List your data: what you collect, where it is stored, who can access it and who you share it with.
- Remove what you do not need, including old staff logins, stale spreadsheets and unnecessary form fields.
- Update your admission form with a clear notice and parental consent for optional uses such as photos.
- Train staff once a term on WhatsApp habits, passwords and what to do if something goes wrong.
- Review vendor agreements and ask each vendor how they protect data.
This article is general information for school staff and is not legal advice. Laws and rules change, and their application depends on facts. For specific questions, such as drafting consent forms or vendor contracts, consult a qualified lawyer.
Frequently asked questions
Does the DPDP Act apply to small private schools?
The Act applies to organisations processing digital personal data in India, and it does not exempt schools based on size. Some exemptions exist for specific purposes, so check the official text or take legal advice for your situation.
Is a Class 11 or 12 student a child under the Act?
Yes. The Act defines a child as a person who has not completed 18 years, so almost all school students are children for this purpose.
Can we still use WhatsApp to communicate with parents?
The Act does not ban any app. The concern is what you share and with whom. Avoid exposing parents' numbers to everyone, and send individual marks, fee dues or health matters privately.
Can we post children's photos on the school's social media?
Take written parental consent first, allow parents to opt out, and avoid combining faces with full names and other identifying details. Remove photos when asked.
When do the DPDP Rules fully apply?
The Rules were notified in November 2025 with phased timelines, and most obligations apply about 18 months after publication. Check the latest official notification from MeitY for current dates.