Skip to main content
Home » Education Technology » DPDPA for Schools and EdTech: Children’s Data and Verifiable Parental Consent

DPDPA for Schools and EdTech: Children’s Data and Verifiable Parental Consent

Hemlata Kalsha

October 4, 2026

Blog features image

Schools, coaching centres and EdTech platforms process more children's personal data than almost any other sector: admission forms, attendance, marks, fee records, CCTV, learning app activity, and increasingly, data from immersive and AI-driven tools. The DPDP Act, 2023 treats this data with extra care, and the obligations are stricter than many institutions assume.

Every student under 18 is a child

The Act defines a child as anyone who has not completed 18 years. There is no separate teenage tier: a Class 12 student is treated exactly like a Class 1 student. Unlike GDPR, which lets EU member states set the digital age of consent between 13 and 16, DPDPA uses one threshold.

The three core obligations

  • Verifiable parental consent before processing a child's personal data (Section 9(1)).
  • No processing likely to cause a detrimental effect on a child's well-being (Section 9(2)).
  • No tracking, behavioural monitoring or targeted advertising directed at children (Section 9(3)).

Breaching these additional obligations for children carries penalties of up to ₹200 crore under the Act's Schedule. For context on how penalties stack, see the real cost of waiting.

What makes consent "verifiable"?

Rule 10 of the DPDP Rules, 2025 requires Data Fiduciaries to adopt technical and organisational measures to ensure the person consenting is the child's parent and an identifiable adult. Verification can rely on:

  • Reliable identity and age details the institution already holds, such as parent records verified at admission;
  • Identity and age details voluntarily provided by the parent; or
  • A virtual token mapped to identity and age, issued by an authorised entity, which can include a DigiLocker service provider.

A tick-box on a paper admission form that bundles every purpose together will not meet this standard. Consent must be specific to each purpose, informed by a clear notice, and withdrawable.

The Fourth Schedule exemption, and its limits

The Rules recognise that schools cannot function if every attendance entry needs fresh parental verification. The Fourth Schedule therefore exempts educational institutions from verifiable consent and the tracking prohibition where processing is restricted to the institution's educational activities or to the safety of children enrolled with it. A separate entry covers creating a student email account used only for email communication.

This is a narrow carve-out, not a blanket pass. It stops applying the moment student data is used outside education and safety, for example:

  • Sharing contact details with a coaching partner or uniform vendor for marketing;
  • Feeding learning-app activity into third-party analytics that profiles students;
  • Using student photos or videos in promotional campaigns;
  • Running retargeting ads based on a child's browsing of your website.

Where EdTech platforms stand

An EdTech company is not automatically an "educational institution" for exemption purposes. Two common arrangements lead to different obligations:

  • Platform deployed by a school: the school is usually the Data Fiduciary and the EdTech vendor acts as its Data Processor. A written contract should limit the vendor to the school's instructions, and the vendor must not reuse student data for its own purposes.
  • Direct-to-consumer app: the EdTech company is the Data Fiduciary and must obtain verifiable parental consent itself, and must not run behavioural tracking or targeted ads aimed at children.

A practical checklist for schools

  1. Inventory every system holding student and parent data, including WhatsApp groups and teachers' personal devices.
  2. Classify each use as educational, safety-related, or something else.
  3. Redesign admission forms with purpose-wise consent for anything outside the exemption.
  4. Review every EdTech, transport and CCTV vendor contract for processor clauses.
  5. Remove tracking pixels and retargeting from pages children are likely to visit.
  6. Set retention periods for alumni and applicant data, and delete what you no longer need.
  7. Publish a contact for parents' data questions and a grievance process.

Timeline

The children's data provisions in the Rules take effect on 13 May 2027 under the current phased schedule. MeitY has proposed shortening timelines, but that proposal has not been notified at the time of writing. Schools run on an academic calendar, so the 2027–28 admission cycle is the practical deadline for redesigned forms and consent flows.

How Qodequay can help

Our Abhigyaan VR learning platform runs in 1,350 Maharashtra Zilla Parishad schools, so we know how school data actually flows, from admission registers to classroom devices. DAPro (Data Adhikaar), our DPDPA compliance platform, helps schools and EdTech providers manage consent and keep tamper-evident compliance records, with notices available in 22 languages. Talk to us about a readiness review.

This article is for general information and is not legal advice. Confirm obligations against the official text of the DPDP Act and Rules and consult qualified counsel for your institution.

Author profile image

Hemlata Kalsha

I am a founder director at Qodequay Technologies Pvt. Ltd., a leading digital transformation consulting firm that helps clients across industries to innovate, optimize, and grow their businesses. I have over two decades of experience in the digital domain, spanning product development, e-commerce, user experience, design thinking, web and app development, and business leadership. My core competencies include developing and executing digital transformation strategies, building teams globally, roadmaps, and solutions that leverage data, insights, and emerging technologies such as artificial intelligence, augmented reality, blockchain, and immersive experience. I also have expertise in digital commerce, supply chain integration, and product management, having worked with both B2B and B2C brands in various sectors. My mission is to create value for customers and stakeholders by delivering impactful and engaging digital experiences that drive growth and innovation.

Never miss an update

Monthly insights on AI, VR and DPDPA compliance — straight from our team to your inbox.

Have a project in mind?

Free 30-minute consultation with our team — or see our products in action.

Book a 30-min Consultation