Skip to main content

Guide

The DPDP Act 2023, explained for schools

Schools hold more personal data about children than almost any other organisation they deal with. The Digital Personal Data Protection Act, 2023 puts obligations on that. This is a plain-English summary — not legal advice.

9 min read Intrithm Technologies

This guide is general information, not legal advice. Rules under the Act continue to develop, and you should take professional advice on your school's specific obligations.

Your school is the data fiduciary

The Act uses "data fiduciary" for the organisation that decides why and how personal data is processed. For student and parent data, that is the school. It decides what to collect, how long to keep it, and who on staff may see it.

A software vendor that processes the data on the school's instructions is a data processor. That distinction matters in practice: if a parent asks to see or correct their child's data, the obligation sits with the school, not the vendor. A vendor cannot lawfully act on such a request on its own.

Children's data carries extra obligations

The Act treats anyone under 18 as a child, which covers essentially the entire student body of a school. Processing a child's personal data generally requires verifiable consent from a parent or lawful guardian.

It also restricts tracking, behavioural monitoring and targeted advertising directed at children. For a school this mostly means being careful about what third-party tools are introduced into student-facing processes, and what those tools do with the data they see.

  • Obtain and record parental consent for the data you collect
  • Collect what you actually need, not what a form template offers
  • Be deliberate about recording government identifiers such as Aadhaar
  • Avoid tools that profile or track students for advertising

Notice, and what it has to say

Consent has to be informed, which means telling parents what you collect, why, who it is shared with and how to withdraw. A single line on an admission form saying data may be used "for school purposes" does not meet that.

The notice does not need to be long. It needs to be specific: the categories of data, the purposes, the third parties involved, the retention period, and how to raise a request or a grievance.

Third parties are your responsibility to know about

If your school sends fee reminders over WhatsApp, the recipient's number and the message content reach a messaging provider and then Meta. If your records are hosted, they sit on a hosting provider's infrastructure. Parents are entitled to know that.

Ask any vendor for a written list of their sub-processors, what data each receives, and where it is held. A vendor who cannot produce that quickly has not thought about it — which is itself informative.

  • Get the sub-processor list in writing
  • Check what data leaves the system, not just that it is "secure"
  • Confirm where data is hosted
  • Establish what happens to your data when the contract ends

Rights you need to be able to honour

Individuals can ask for a summary of the data held about them, ask for corrections, ask for erasure where the data is no longer needed, nominate someone to act for them, and raise a grievance.

Practically, this means someone at the school must be able to find everything held about one student reasonably quickly. If the answer is spread across registers, spreadsheets, message groups and a filing cabinet, honouring a request becomes difficult — which is an operational argument for consolidating records, quite apart from the legal one.

Practical steps worth taking

None of this requires a compliance department. It requires knowing what you hold and being able to explain it.

  • Write down what student and staff data you collect, and why
  • Review who has access, and remove accounts when staff leave
  • Publish a privacy notice that names your actual third parties
  • Decide retention periods, including what happens after a student leaves
  • Name someone to handle grievances, and publish how to reach them
  • Keep documents somewhere access-controlled rather than a shared drive

Common questions

Is our school a data fiduciary or a data processor?

A school is the data fiduciary for its student, parent and staff data — it decides what is collected and why. A software vendor processing that data on the school's instructions is a processor.

Do we need parental consent to use school management software?

You need a lawful basis to process the data, and for children's data that generally means verifiable parental consent. The obligation is the school's, and the notice should cover the software and its sub-processors.

What should we ask a software vendor about data protection?

Ask for the sub-processor list in writing, exactly what data leaves their system, where it is hosted, what security controls actually exist, retention periods, and what happens to your data if you leave. Be wary of unevidenced certification claims.

See how SchoolerHub could work for your school.

Tell us how your school currently works, and we will show you the parts that make the biggest difference.

Or call +91 86374 88136