DPDP Act for Schools and EdTech: Handling Children's Data
Verifiable parental consent, the ban on tracking and targeted ads, and the exemptions for educational institutions. What schools and edtech products must change.

Under the DPDP Act a child is anyone under 18. That makes almost every user of a school ERP or a K-12 learning app a child, and brings in the strictest part of the law: verifiable parental consent before processing, and a ban on tracking, behavioural monitoring and targeted advertising directed at children.
The three rules for children's data
Section 9 of the Act sets three obligations, and breaching them can attract a penalty of up to ₹200 crore.
How to verify a parent
The Rules require technical and organisational measures to make sure the person giving consent is an identifiable adult. They describe checking against reliable identity and age details the business already holds, details the parent voluntarily provides, or a virtual token issued by an authorised entity such as a Digital Locker service provider.
An OTP to a phone number proves someone has a phone. It does not prove they are the parent.
The exemptions for education
The Fourth Schedule to the Rules exempts certain bodies and purposes from the parental consent and no-tracking rules, within limits. An educational institution is exempt for tracking and behavioural monitoring that is for the child's educational activities or in the interest of the child's safety. Crèches and day care centres, and transport engaged by these institutions for location tracking during travel, have similar limited exemptions.
What edtech products should change
Consumer learning apps carry the most risk because their growth tools often rely on behaviour data.
What schools should change
Schools are Data Fiduciaries for student and parent data, and their ERP, app and transport vendors are processors. Review admission forms as notices, list the purposes, and sign processor agreements with every vendor. Limit photographs and public posts of students to what parents have agreed to, restrict staff access by role, and set a retention period for records of students who have left.
Timeline
These obligations apply from 13 May 2027. The practical work, particularly parent verification and removing tracking from child-facing products, takes months, so start with a data inventory and a review of every SDK in the app.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





