For CBSE, ICSE, state board and international schools
DPDP compliance for schools
Almost every student in your school is a child under the DPDP Act, so the parent is the person you answer to. ConsentKit records verified parental consent for everything beyond teaching and safety, from annual-day photos to the school app, and keeps the proof ready.
- Students under 18
- Every one of them
- Parent verification
- Required beyond the exemption
- Full compliance
- 13 May 2027
Student registration
Where the DPDP Act touches a school year
Schools collect data from admission day to the transfer certificate. Pick a stage to see what you hold and whether the education exemption covers it.
What changes for your school on 13 May 2027
The Act applies to every private school that holds data digitally, including the school app and WhatsApp groups. These are the gaps we see most.
Parents must verify, not just tick a boxSection 9 and Rule 10
Outside education and safety, a parent’s consent has to be verifiable: you need reasonable proof it really came from the parent or guardian.
OTP or DigiLocker verification, or a match against details you already hold, saved with every consent.
Photos need a clear choiceSections 6 and 9
Sharing students’ photos on social media, in brochures or in ads is not an educational activity. Each family needs to say yes or no.
A per-child photo preference your social media team can check before posting.
No tracking or targeted ads at childrenSection 9(3)
Behavioural monitoring and targeted advertising aimed at children are prohibited, except where the exemption for education and safety applies.
An app and vendor register that flags tools which track or advertise to students.
Parents can ask what you holdSections 11 to 14
Parents can request access, correction and erasure on their child’s behalf, and raise grievances you must answer in time.
A parent request portal with identity checks and deadline tracking.
Vendors are your responsibilitySection 8 and Rule 6
ERP, app, transport, canteen and uniform vendors all touch student data. The school answers for all of them.
Processor contract checklist and a register of every vendor and what they hold.
Breaches go to parents tooRule 7
If a teacher’s phone with a class list is stolen, or the school app leaks, you must tell the Board and the affected families.
A 72-hour breach workflow with parent notices drafted in plain language.
What the school exemption covers
The DPDP Rules let educational institutions process children’s data without verified parental consent, and monitor behaviour, only as far as needed for educational activities and the safety of the children in their care. The Rules give school transport a similar carve-out for tracking location for safety.
This is general guidance, not legal advice. Confirm how it applies to you with your counsel.
A plan that fits the school calendar
The new session starts in April, just before enforcement. Get parent consent collected with admissions and re-registration, not after.
Audit apps and vendors
List the school app, ERP, learning apps, transport and every WhatsApp group that holds student data.
Build the parent flow
Set up notices in English and your regional language, and the parent verification step.
Collect consent at re-registration
Ask every family for their choices as part of the new-session paperwork.
Train staff and go live
Brief teachers on photos, apps and WhatsApp, and publish a contact for grievances.
For every kind of school
Templates come set up for your board and structure.
Single schools
One campus, one admin, set up in a day.
School chains
Central policy with per-branch notices and admins.
International schools
Families abroad and cross-border transfer of records.
Boarding schools
Hostel, health and weekend-leave records.
Pre-schools and daycare
Very young children, CCTV and pickup authorisations.
Special schools
Therapy and disability records handled with extra care.
DPDP compliance for schools near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions schools are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Does the DPDP Act apply to schools?
Yes. Any school that holds students’, parents’ or staff personal data digitally, including in an ERP, a school app or on staff phones, is a data fiduciary. Full obligations apply from 13 May 2027.
Do schools need parental consent for everything?
No. The Rules exempt educational institutions from verifiable parental consent for processing needed for educational activities and the safety of children. Anything beyond that, such as photos on social media or sharing with partners, needs a parent’s verified consent.
Can we post students’ photos on social media?
Only with each parent’s consent for that purpose. Record the choice per child and remove photos if a parent withdraws.
Are WhatsApp class groups covered?
Yes. Class lists, phone numbers and photos shared in groups are personal data the school is processing. Set rules for what staff can share and who can join.
How do we verify that a parent is really the parent?
Rule 10 accepts reliable identity details you already hold, or verification through an authorised service such as DigiLocker. ConsentKit supports both and records how each consent was verified.
Get parent consent sorted before the new session
The readiness check takes about ten minutes and gives you a gap report built for schools, whether or not you use ConsentKit.