ConsentKit DPDP

For CBSE, ICSE, state board and international schools

DPDP compliance for schools

Almost every student in your school is a child under the DPDP Act, so the parent is the person you answer to. ConsentKit records verified parental consent for everything beyond teaching and safety, from annual-day photos to the school app, and keeps the proof ready.

Students under 18
Every one of them
Parent verification
Required beyond the exemption
Full compliance
13 May 2027
admissions.yourschool.edu.inStep 1 of 4

Student registration

Change the date to see how ConsentKit routes the consent.
    Every step is saved to the consent log

    Where the DPDP Act touches a school year

    Schools collect data from admission day to the transfer certificate. Pick a stage to see what you hold and whether the education exemption covers it.

    What changes for your school on 13 May 2027

    The Act applies to every private school that holds data digitally, including the school app and WhatsApp groups. These are the gaps we see most.

    Parents must verify, not just tick a boxSection 9 and Rule 10

    Outside education and safety, a parent’s consent has to be verifiable: you need reasonable proof it really came from the parent or guardian.

    OTP or DigiLocker verification, or a match against details you already hold, saved with every consent.

    Photos need a clear choiceSections 6 and 9

    Sharing students’ photos on social media, in brochures or in ads is not an educational activity. Each family needs to say yes or no.

    A per-child photo preference your social media team can check before posting.

    No tracking or targeted ads at childrenSection 9(3)

    Behavioural monitoring and targeted advertising aimed at children are prohibited, except where the exemption for education and safety applies.

    An app and vendor register that flags tools which track or advertise to students.

    Parents can ask what you holdSections 11 to 14

    Parents can request access, correction and erasure on their child’s behalf, and raise grievances you must answer in time.

    A parent request portal with identity checks and deadline tracking.

    Vendors are your responsibilitySection 8 and Rule 6

    ERP, app, transport, canteen and uniform vendors all touch student data. The school answers for all of them.

    Processor contract checklist and a register of every vendor and what they hold.

    Breaches go to parents tooRule 7

    If a teacher’s phone with a class list is stolen, or the school app leaks, you must tell the Board and the affected families.

    A 72-hour breach workflow with parent notices drafted in plain language.

    What the school exemption covers

    The DPDP Rules let educational institutions process children’s data without verified parental consent, and monitor behaviour, only as far as needed for educational activities and the safety of the children in their care. The Rules give school transport a similar carve-out for tracking location for safety.

    Usually coveredAttendance, marks, report cards, CCTV on campus, bus location during school trips, health care on campus.
    Usually not coveredPhotos on social media, marketing, sharing with coaching or tuition partners, third-party apps that profile children.

    This is general guidance, not legal advice. Confirm how it applies to you with your counsel.

    A plan that fits the school calendar

    The new session starts in April, just before enforcement. Get parent consent collected with admissions and re-registration, not after.

    1. Audit apps and vendors

      List the school app, ERP, learning apps, transport and every WhatsApp group that holds student data.

    2. Build the parent flow

      Set up notices in English and your regional language, and the parent verification step.

    3. Collect consent at re-registration

      Ask every family for their choices as part of the new-session paperwork.

    4. Train staff and go live

      Brief teachers on photos, apps and WhatsApp, and publish a contact for grievances.

    For every kind of school

    Templates come set up for your board and structure.

    Single schools

    One campus, one admin, set up in a day.

    School chains

    Central policy with per-branch notices and admins.

    International schools

    Families abroad and cross-border transfer of records.

    Boarding schools

    Hostel, health and weekend-leave records.

    Pre-schools and daycare

    Very young children, CCTV and pickup authorisations.

    Special schools

    Therapy and disability records handled with extra care.

    Questions schools are asking

    For the full picture, read our DPDP Act guide or compliance checklist.

    Does the DPDP Act apply to schools?

    Yes. Any school that holds students’, parents’ or staff personal data digitally, including in an ERP, a school app or on staff phones, is a data fiduciary. Full obligations apply from 13 May 2027.

    Do schools need parental consent for everything?

    No. The Rules exempt educational institutions from verifiable parental consent for processing needed for educational activities and the safety of children. Anything beyond that, such as photos on social media or sharing with partners, needs a parent’s verified consent.

    Can we post students’ photos on social media?

    Only with each parent’s consent for that purpose. Record the choice per child and remove photos if a parent withdraws.

    Are WhatsApp class groups covered?

    Yes. Class lists, phone numbers and photos shared in groups are personal data the school is processing. Set rules for what staff can share and who can join.

    How do we verify that a parent is really the parent?

    Rule 10 accepts reliable identity details you already hold, or verification through an authorised service such as DigiLocker. ConsentKit supports both and records how each consent was verified.

    Get parent consent sorted before the new session

    The readiness check takes about ten minutes and gives you a gap report built for schools, whether or not you use ConsentKit.