Guide
The DPDP Act 2023, explained for schools
Schools hold more personal data about children than almost any other organisation they deal with. The Digital Personal Data Protection Act, 2023 puts obligations on that. This is a plain-English summary — not legal advice.
This guide is general information, not legal advice. Rules under the Act continue to develop, and you should take professional advice on your school's specific obligations.
Your school is the data fiduciary
The Act uses "data fiduciary" for the organisation that decides why and how personal data is processed. For student and parent data, that is the school. It decides what to collect, how long to keep it, and who on staff may see it.
A software vendor that processes the data on the school's instructions is a data processor. That distinction matters in practice: if a parent asks to see or correct their child's data, the obligation sits with the school, not the vendor. A vendor cannot lawfully act on such a request on its own.
Children's data carries extra obligations
The Act treats anyone under 18 as a child, which covers essentially the entire student body of a school. Processing a child's personal data generally requires verifiable consent from a parent or lawful guardian.
It also restricts tracking, behavioural monitoring and targeted advertising directed at children. For a school this mostly means being careful about what third-party tools are introduced into student-facing processes, and what those tools do with the data they see.
- Obtain and record parental consent for the data you collect
- Collect what you actually need, not what a form template offers
- Be deliberate about recording government identifiers such as Aadhaar
- Avoid tools that profile or track students for advertising
Notice, and what it has to say
Consent has to be informed, which means telling parents what you collect, why, who it is shared with and how to withdraw. A single line on an admission form saying data may be used "for school purposes" does not meet that.
The notice does not need to be long. It needs to be specific: the categories of data, the purposes, the third parties involved, the retention period, and how to raise a request or a grievance.
Third parties are your responsibility to know about
If your school sends fee reminders over WhatsApp, the recipient's number and the message content reach a messaging provider and then Meta. If your records are hosted, they sit on a hosting provider's infrastructure. Parents are entitled to know that.
Ask any vendor for a written list of their sub-processors, what data each receives, and where it is held. A vendor who cannot produce that quickly has not thought about it — which is itself informative.
- Get the sub-processor list in writing
- Check what data leaves the system, not just that it is "secure"
- Confirm where data is hosted
- Establish what happens to your data when the contract ends
Rights you need to be able to honour
Individuals can ask for a summary of the data held about them, ask for corrections, ask for erasure where the data is no longer needed, nominate someone to act for them, and raise a grievance.
Practically, this means someone at the school must be able to find everything held about one student reasonably quickly. If the answer is spread across registers, spreadsheets, message groups and a filing cabinet, honouring a request becomes difficult — which is an operational argument for consolidating records, quite apart from the legal one.
Practical steps worth taking
None of this requires a compliance department. It requires knowing what you hold and being able to explain it.
- Write down what student and staff data you collect, and why
- Review who has access, and remove accounts when staff leave
- Publish a privacy notice that names your actual third parties
- Decide retention periods, including what happens after a student leaves
- Name someone to handle grievances, and publish how to reach them
- Keep documents somewhere access-controlled rather than a shared drive