Compliance & Regulation

DPDP Act for Schools and EdTech: Handling Children's Data

Verifiable parental consent, the ban on tracking and targeted ads, and the exemptions for educational institutions. What schools and edtech products must change.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
8 min read
Students learning with laptops

Under the DPDP Act a child is anyone under 18. That makes almost every user of a school ERP or a K-12 learning app a child, and brings in the strictest part of the law: verifiable parental consent before processing, and a ban on tracking, behavioural monitoring and targeted advertising directed at children.

01

The three rules for children's data

Section 9 of the Act sets three obligations, and breaching them can attract a penalty of up to ₹200 crore.

Verifiable parental consentBefore processing any personal data of a child
No detrimental processingNothing likely to harm the child's well-being
No tracking or targeted advertisingNo behavioural monitoring of children or advertising directed at them
02

How to verify a parent

The Rules require technical and organisational measures to make sure the person giving consent is an identifiable adult. They describe checking against reliable identity and age details the business already holds, details the parent voluntarily provides, or a virtual token issued by an authorised entity such as a Digital Locker service provider.

An OTP to a phone number proves someone has a phone. It does not prove they are the parent.

Parent already a verified userUse the identity and age details you hold
Parent is newVerify through DigiLocker-based or similar token, or details issued by a government-authorised entity
School-mediatedThe school, which has admission records of parents, collects and records consent
Record itWhich parent, which child, how verified, when, and for which purposes
03

The exemptions for education

The Fourth Schedule to the Rules exempts certain bodies and purposes from the parental consent and no-tracking rules, within limits. An educational institution is exempt for tracking and behavioural monitoring that is for the child's educational activities or in the interest of the child's safety. Crèches and day care centres, and transport engaged by these institutions for location tracking during travel, have similar limited exemptions.

Likely coveredAttendance, learning progress, classroom behaviour records, bus location, campus safety
Not coveredAdvertising, selling data, profiling for upsell, sharing with unrelated third parties
Who is exemptThe educational institution, for those purposes. A private edtech app sold directly to families should not assume it qualifies
04

What edtech products should change

Consumer learning apps carry the most risk because their growth tools often rely on behaviour data.

Age gate at sign-upParent account linked to childRemove ad SDKs from child experiencesDisable behavioural ad profilingAnalytics limited to learning purposesNo third-party trackersSales calls only to verified parents
05

What schools should change

Schools are Data Fiduciaries for student and parent data, and their ERP, app and transport vendors are processors. Review admission forms as notices, list the purposes, and sign processor agreements with every vendor. Limit photographs and public posts of students to what parents have agreed to, restrict staff access by role, and set a retention period for records of students who have left.

06

Timeline

These obligations apply from 13 May 2027. The practical work, particularly parent verification and removing tracking from child-facing products, takes months, so start with a data inventory and a review of every SDK in the app.

Under 18
The definition of a child
₹200 crore
Maximum penalty for breaching child data obligations
13 May 2027
Obligations apply
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact