Is Your CRM DPDPA-Ready? 8 Checks for Sales and Marketing Teams
October 5, 2026
October 4, 2026
Schools, coaching centres and EdTech platforms process more children's personal data than almost any other sector: admission forms, attendance, marks, fee records, CCTV, learning app activity, and increasingly, data from immersive and AI-driven tools. The DPDP Act, 2023 treats this data with extra care, and the obligations are stricter than many institutions assume.
The Act defines a child as anyone who has not completed 18 years. There is no separate teenage tier: a Class 12 student is treated exactly like a Class 1 student. Unlike GDPR, which lets EU member states set the digital age of consent between 13 and 16, DPDPA uses one threshold.
Breaching these additional obligations for children carries penalties of up to ₹200 crore under the Act's Schedule. For context on how penalties stack, see the real cost of waiting.
Rule 10 of the DPDP Rules, 2025 requires Data Fiduciaries to adopt technical and organisational measures to ensure the person consenting is the child's parent and an identifiable adult. Verification can rely on:
A tick-box on a paper admission form that bundles every purpose together will not meet this standard. Consent must be specific to each purpose, informed by a clear notice, and withdrawable.
The Rules recognise that schools cannot function if every attendance entry needs fresh parental verification. The Fourth Schedule therefore exempts educational institutions from verifiable consent and the tracking prohibition where processing is restricted to the institution's educational activities or to the safety of children enrolled with it. A separate entry covers creating a student email account used only for email communication.
This is a narrow carve-out, not a blanket pass. It stops applying the moment student data is used outside education and safety, for example:
An EdTech company is not automatically an "educational institution" for exemption purposes. Two common arrangements lead to different obligations:
The children's data provisions in the Rules take effect on 13 May 2027 under the current phased schedule. MeitY has proposed shortening timelines, but that proposal has not been notified at the time of writing. Schools run on an academic calendar, so the 2027–28 admission cycle is the practical deadline for redesigned forms and consent flows.
Our Abhigyaan VR learning platform runs in 1,350 Maharashtra Zilla Parishad schools, so we know how school data actually flows, from admission registers to classroom devices. DAPro (Data Adhikaar), our DPDPA compliance platform, helps schools and EdTech providers manage consent and keep tamper-evident compliance records, with notices available in 22 languages. Talk to us about a readiness review.
This article is for general information and is not legal advice. Confirm obligations against the official text of the DPDP Act and Rules and consult qualified counsel for your institution.
Monthly insights on AI, VR and DPDPA compliance — straight from our team to your inbox.
Free 30-minute consultation with our team — or see our products in action.