School Data and India's DPDP Act: A Plain-English Guide for School Owners
A school is one of the most data-rich organisations in any Indian town. Think about what your office holds: names, dates of birth, addresses, photographs, parent phone numbers and occupations, health conditions, marks, fee payment histories. Nearly all of it about minors. Most of it collected without anyone thinking of it as "personal data" at all — it is just the admission file.
The Digital Personal Data Protection Act, 2023 changes the legal weight of that filing cabinet. This guide explains what the Act asks of schools in plain English. One thing before we start: this is orientation, not legal advice. The Act's supporting Rules were notified in late 2025 and obligations phase in over time — the specifics of what applies to your school and when are exactly what your own legal advisor should confirm.
The vocabulary, translated
The Act uses three terms worth learning, because everything else hangs off them:
| The Act says | In school terms |
|---|---|
| Data principal | The person the data is about — the student (represented by a parent, since students are minors) and the parent themselves |
| Data fiduciary | The one who decides why and how data is used — your school |
| Data processor | Anyone processing data on the school's behalf — your software vendor, your SMS gateway |
The important word is fiduciary. The school carries the duties — not the vendor, not the software. You can hire help with the work; you cannot outsource the responsibility.
The core obligations, in plain English
Consent and notice. Before collecting personal data, tell people what you are collecting and why, and get consent. For children — anyone under 18, which is nearly your entire student body — that consent must come verifiably from a parent or lawful guardian. In practice this pushes schools towards clearer admission-form language: not a vague "information may be used for school purposes" but a plain statement of what is collected and what it is used for.
Purpose limitation. Data collected for one purpose should not quietly be used for another. Phone numbers collected to send absence alerts are for absence alerts and school communication — not for selling to a coaching centre, and not for the school's own unrelated ventures. The uncomfortable question for many schools is the informal version: the class-teacher's personal phone full of parent numbers, the WhatsApp group exported who-knows-where.
Children's data gets extra protection. The Act specifically prohibits tracking, behavioural monitoring and targeted advertising directed at children. Schools should look hard at any free app or service that monetises attention, and ask what it does with student data.
Accuracy and erasure. Data should be correct and kept only while needed. Parents can ask for corrections — and a school should be able to make them in one place, not across five registers that disagree with each other.
Security safeguards and breach duty. The school must take reasonable security measures, and if personal data is breached, report it to the Data Protection Board of India and to affected people. The penalty provisions for failing to maintain safeguards are severe at the top end — scaled to seriousness, but framed in crores, not lakhs.
What this looks like on a Monday morning
Legal text is abstract; office practice is not. A few translations:
- The almirah question. Who can open the cabinet with the student files? On paper, effectively anyone in the office. "Reasonable safeguards" starts with knowing — and limiting — who can access what. Digital systems with role-based access are stricter here than paper ever was: the accountant sees fee ledgers, not health records; a teacher sees her own classes, not the whole school. (Our tour of what a student information system stores covers this in detail.)
- The spreadsheet-on-a-pen-drive question. Every export of student data that leaves the building on a USB stick or a personal laptop is a copy you no longer control. Fewer copies, in fewer places, is the single cheapest security improvement available.
- The departing-staff question. When a teacher or clerk leaves, is their access actually switched off? With registers there is nothing to switch off — which is the problem. With software, disabling a user account should be a routine part of exit.
- The vendor question. Ask your software vendor where data is stored, who at the vendor can access it, whether access is logged, and what their breach process is. A vendor who cannot answer crisply is telling you something.
What software can and cannot do for you
Be clear-eyed about the division of labour. Software cannot decide your purposes, write your consent language, or answer a parent's question about why you collected something — those are school decisions. Software can make the technical duties tractable: access control instead of an open almirah, audit logs instead of guesswork, encrypted connections instead of plain ones, and backups so data survives a failed hard disk.
A sensible sequence for a school owner: (1) map what personal data you hold and where; (2) tighten who can access it; (3) fix your admission-form notice and consent language with your advisor; (4) agree a simple written plan for what you would do on discovering a breach; (5) put your vendor's answers to the questions above in writing.
How Edutris approaches this
Edutris practises DPDP-aligned data handling — a deliberate phrase. It means the engineering choices line up with the Act's direction of travel: each school's data is tenant-isolated so no other school can reach it; access is role-based and per-user accounts can be disabled the day someone leaves; sensitive actions — fee changes, grade publishing, record deletions, settings changes — are written to an audit log; connections are encrypted; and automated database backups guard against loss. Parents see only their own child's information, on the web portal and the parent mobile app alike.
What it does not mean: a certification, or a guarantee of your school's legal compliance — no honest vendor can promise that, because compliance depends on your school's own practices and on advice we are not qualified to give. Read the specifics on our security page, and take the legal questions to your own advisor. The combination — sound practices on your side, sound engineering on ours — is what the Act is actually asking for.
Written by the Edutris team — led by Manjunath Shedabal, Founder
Every product claim traces to verified capability; unshipped features live on the roadmap. Read our editorial policy.Free: The School Digitalisation Checklist
25 checkpoints across records, attendance, fees, communication, and compliance — score your school in 5 minutes and see exactly where time and fee revenue leak.
How Edutris gives school owners real-time control

Frequently Asked Questions
Does the DPDP Act apply to schools?
Yes. The Digital Personal Data Protection Act, 2023 applies to anyone processing digital personal data in India, and schools hold a great deal of it — student names, dates of birth, addresses, parent phone numbers, health information and fee records. Under the Act, the school is a 'data fiduciary': the entity that decides why and how the data is used, and therefore the one carrying the legal duties. Because almost all students are minors, schools also sit in the Act's stricter children's-data territory. How the obligations apply to your specific school is a question for your legal advisor, but 'this doesn't apply to us' is not a safe assumption.
Do schools need parental consent to store student data under the DPDP Act?
The Act requires verifiable consent from a parent or lawful guardian before processing the personal data of a child (anyone under 18). For schools this largely formalises what admission forms already do, but the consent must be informed — parents should be told what data is collected and what it is used for — and records of that consent matter. The Act also prohibits tracking, behavioural monitoring and targeted advertising directed at children. Exactly how verifiable consent must be captured is detailed in the Rules under the Act, so take your advisor's view on the mechanics.
What happens if a school's data is leaked or breached?
The Act creates a duty to maintain reasonable security safeguards and to report personal data breaches to the Data Protection Board of India and to the affected individuals. Penalties for failing to maintain safeguards can be very significant — the Act provides for penalties running into hundreds of crores at the top end, scaled to the seriousness of the breach. For a school, the practical takeaway is less about the maximum fine and more about the duty itself: know where your student data lives, who can access it, and what you would do in the first 72 hours after discovering a problem.
Does using school management software make a school DPDP-compliant?
No software makes you compliant by itself, and you should be sceptical of any vendor who claims otherwise. Compliance is a property of the school's overall practices — what you collect, why, who you share it with, how you handle consent and requests from parents. What good software does is make the technical side of those practices achievable: access control, audit trails, encryption in transit, tenant isolation and backups. Edutris practises DPDP-aligned data handling in this sense, but your school's compliance position is something to establish with your own legal advisor.