Children's data under DPDP: parental consent for schools and edtech
· 5 min read
Reviewed by Adv. Mahir Gupta, Advocate, Delhi High Court ·

Most Indian schools, coaching centres and learning apps hold a great deal of data about minors: names, photographs, marks, attendance, parents' phone numbers, device identifiers and, in many apps, detailed records of how a child studies. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 place specific duties on exactly this kind of data. This explainer sets out what those duties are, where the exemptions stop, and what an institution can start changing now.
Who counts as a child. Under the Act, a child is any individual who has not completed eighteen years of age. This is higher than the age used by many other privacy laws, and it applies to every service regardless of how it classifies users elsewhere. A coaching app for Class 11 and 12 students therefore deals with many children, and so does a school portal. The same protection extends to a person with a disability who has a lawful guardian.
The timeline. The Rules were notified on 14 November 2025 and provide an eighteen-month phased period for compliance, ending in May 2027. Published analyses differ on whether the end date is 13 or 14 May 2027, so institutions should plan for the earlier date. The period is not a reason to wait: consent flows, vendor contracts and analytics tools take months to change.
What S. 9 requires. DPDP Act S. 9 has three core rules. First, a Data Fiduciary must obtain verifiable consent of the parent or lawful guardian before processing any personal data of a child. Second, it must not process data in a way likely to cause a detrimental effect on the child's well-being. Third, it must not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children. The third rule is a separate prohibition: S. 9(3) is not made subject to parental consent, and the only relief is through the exemptions described below, which S. 9(4) allows the Rules to prescribe.
What 'verifiable' means in the Rules. Rule 10 requires appropriate technical and organisational measures to be sure that the person giving consent is the child's parent and is an identifiable adult, meaning someone who has completed eighteen years. The Rules allow this to be done through reliable identity and age details the organisation already holds, through details the person voluntarily provides, or through a virtual token issued by an authorised entity, which includes a Digital Locker service provider. Advisers also stress documenting how each parent was verified and keeping the consent record, while collecting no more parental data than the check needs.
A practical point for schools: if admission records already hold verified parent details, those may count as reliable details already held. An app that only ever receives a child's own sign-up has no such record and will need a parent-side step, for example a parent-created account or a token-based check. This is our reading of Rule 10, not legal advice.
The tracking ban and its exemptions. Under Rule 12, the Fourth Schedule to the Rules exempts certain classes of Data Fiduciary, and certain purposes, from S. 9(1) and S. 9(3). An educational institution is exempt only for tracking and behavioural monitoring done for educational activities or in the interests of the safety of enrolled children. A crèche or day-care operator is exempt for safety monitoring, and a transport provider for tracking a child's location during travel, in the interests of safety. Health establishments are exempt to the extent necessary to protect the child's health. The exemptions are tied to the class of organisation and the stated purpose, and they are limited to what is necessary.
The Schedule also lists purposes that are exempt for any fiduciary, for example creating a child's user account used only for email, real-time location tracking in the interest of the child's safety, preventing access to harmful content, and confirming that a user is not a child as part of the Rule 10 due diligence. Law-firm commentary (for example Legal 500 and MHCO) stresses that exemptions are purpose-specific and conditional: being a school does not make every form of processing exempt.
What this means for edtech. The exemption is written for educational institutions. A commercial learning app or test-prep platform is not clearly an educational institution (the Rules do not define the term), so it should not assume it can use engagement tracking, behavioural profiling or advertising-driven analytics on minors. A sensible approach is to separate data needed to deliver a lesson from profiling used for marketing, and to switch off targeted advertising for child accounts entirely.
The penalty. The Schedule to the Act provides for a penalty of up to ₹200 crore for breach of the additional obligations relating to children (S. 9). Failure to take reasonable security safeguards (S. 8(5)) carries up to ₹250 crore. These are ceilings set by the Act; the Data Protection Board decides the amount in each case.
What to change now. First, map every place a minor's data enters: admission forms, fee portals, attendance and biometric systems, CCTV, learning apps, WhatsApp groups and third-party SDKs. Second, tag which records belong to under-18s. Third, decide for each use whether it is delivery of education, safety, or something else, because only the first two can rely on the school exemption. Fourth, design a parental verification step and a consent record that can be produced later. Fifth, remove advertising and analytics trackers from child-facing screens and check vendor contracts for what they collect. Sixth, tighten security, since the larger penalty attaches to weak safeguards.
How Codesnag helps. Codesnag works on the cyber security side of this: finding which tools and trackers actually run on a school or app, checking whether student records are exposed on the open internet, and helping an institution respond if a student database is leaked. Whether a particular practice is lawful under the Rules is a question for the institution's own counsel.
If a student's data has been leaked or misused, the first hour matters. Preserve screenshots and messages, change passwords on affected accounts, and report cyber fraud on the national helpline 1930 and at cybercrime.gov.in. Offences involving a minor's images or identity may also engage the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, and the police can register the complaint.
Sources
- DPDPA.com: Section 9, Processing of personal data of children
- DPDPA.com: Rule 10, Verifiable consent for processing children's personal data
- Privacy Law Hub: Fourth Schedule, DPDP Rules 2025
- Legal 500: Data privacy laws for businesses handling children's personal data in India
- MHCO: Children's data protection under India's DPDP Act
- ELP Law: Processing of children's personal data under the DPDP Act
- India Briefing: India's DPDP timeline, compliance deadlines for 2026-27
First published on codesnag.ai

