Guide · 8 min read
What the DPDP Act actually means for your school
Anika · co-founder · 12 May 2026
A plain-English (and Hindi) explainer of India's data-protection law as it applies to K-12. With checklists.
India's Digital Personal Data Protection Act, 2023 is the country's first comprehensive privacy law. The Rules followed in November 2025. By the time you've finished reading this essay, you'll know enough to act - and that's the entire point.
We've spent the last six months getting Patashale to a place where a principal can sign a DPA with us and not have to re-read the Act every time procurement asks. Here's what we learned, in plain English, and then in Hindi if you scroll to /hi/blog/dpdp-for-schools.
The 30-second version
DPDP gives every individual ("Data Principal") a set of rights over data about them: knowing what's collected, having it corrected, having it erased, complaining when it's misused. For schools, the most important thing is that a minor's data requires verifiable parental consent. Not implied consent, not "the parent agreed when they enrolled their child", not "by using our app you accept" - actual, recorded, verifiable consent.
The law applies to every entity that processes personal data of people in India, regardless of where the entity is based. The penalty ceiling is ₹250 crore per violation. The Data Protection Board enforces it.
The act is not the threat. Pretending you've read it, is.
The schools that get this wrong are the ones who tried to read the Act for the first time when the procurement team forwarded the supplier audit. Read it now, while the only thing at stake is your weekend.
Consent for minors
Section 9 of the Act is the one you have to memorise.
A "Child" is anyone under 18 in India - older than the COPPA threshold of 13 in the US. Every operation that involves a minor's data - storing it, processing it, sending notifications about it, even displaying it - requires verifiable guardian consent. The guardian's consent has to be recorded with a timestamp and the purpose for which it was given.
This means:
- You cannot send a class-wide WhatsApp message containing a single student's marks if you don't have explicit per-parent consent for that purpose.
- You cannot use a student's photograph on your website or marketing collateral without recorded consent.
- You cannot share data with a third-party analytics service unless the parent has been informed and has agreed.
The Act doesn't define exactly what "verifiable" means - that's left to the Data Protection Board. The conservative interpretation, which most schools we've spoken to are adopting, is that OTP-verified consent over WhatsApp or SMS is sufficient. Phone numbers in India are heavily verified by KYC norms; this is the easiest defensible standard.
Data-fiduciary duties
If you're a school, you're a Data Fiduciary - the entity that decides why and how data is processed. Patashale is your Data Processor, acting on your instructions.
As a Data Fiduciary you must:
- Maintain a record of every data-processing activity ("Records of Processing Activities" or RoPA).
- Honour every Data Principal's request to access, correct, or erase their data within a reasonable time - we recommend 7 working days.
- Notify the Data Protection Board and every affected individual within 72 hours of a breach.
- Appoint a Data Protection Officer once you exceed a threshold of student count (the exact number is in the Rules - for most schools, the relevant trigger is ~5,000 students, but the Board can revise this).
- Publish a Privacy Notice in English and at least one Indian language, written so a parent can understand it.
Patashale makes the operational side of this manageable. Every consent is recorded. Every export, deletion, and correction is logged. The audit trail is exportable. We never use student data to train AI, and we never transfer it outside India.
The 72-hour clock
Notify the Data Protection Board and every affected individual within 72 hours of a breach. Document everything before that clock starts.
The 72-hour clock is the single highest-stakes obligation in the Act. The moment a material incident is detected, you have three days to draft and send a regulatory notification. This is genuinely fast - it's the same window as the EU GDPR.
In practice, the 72 hours starts when you "become aware" of the breach, not when it actually occurred. So the priority is detection. Patashale's intrusion-detection rules, anomaly alerts, and access-log monitoring exist to make sure the gap between "incident occurs" and "you become aware" is small.
If your current ERP can't tell you who accessed what, when, with which IP, you cannot honestly comply with this obligation. Audit logging is a hard prerequisite, not a nice-to-have.
A checklist
You can adopt this on a single afternoon:
- Inventory - list every place your school stores personal data (your ERP, Tally, Google Drive, Excel sheets, WhatsApp groups). DPDP applies to all of them.
- Consent flow - switch your admission form to a DPDP-style consent: list the purposes, record the timestamp, store the IP, give the parent a copy.
- Privacy Notice - publish a Hindi + English notice. Patashale includes a template in
/security/dpdp-template.pdf. - Audit trail - ensure every action involving student data is logged. If your current system can't do this, that's the strongest argument for switching.
- Breach playbook - write down, on one page, who decides whether something is a breach, who drafts the regulatory notification, who calls the parents, who calls the press. Practice it once.
- DPO - appoint someone, even informally, even if you're below the legal threshold. It clarifies responsibility. It also makes you legible to procurement.
- Vendor DPAs - sign a Data Processing Agreement with every vendor that touches student data. Patashale provides one, signed within 24 hours of request. Insist that other vendors do too.
If you do these seven things, you are ahead of 95% of Indian schools. You are also defensible.
We'll keep updating this post as the Rules are amended. The next big update is expected around the appointment of the Board's first chairperson, currently rumoured for early 2026.
SEE IT ON YOUR OWN DATA
A short walkthrough of Patashale running your school, no obligation.
