India’s Digital Personal Data Protection Act, 2023 applies to schools and colleges like any other organisation that holds personal data — and because most of the people in your records are children, it applies to you with extra weight. This is a plain-language read of what it means inside a school office.
The one idea that explains the rest
The Act splits everyone into two roles. The organisation that decides why and how personal data is processed is the Data Fiduciary. Anyone processing that data on its behalf is a Data Processor.
Your institution is the Data Fiduciary. You decide what goes on the admission form, why you keep it and who sees it. Your ERP vendor — us, or anyone else — is a processor acting on your instruction.
That has a consequence worth sitting with: you cannot outsource the responsibility. Buying good software helps you meet your obligations, but the obligations remain the institution’s. A vendor telling you that using their product makes you compliant is overselling.
Children’s data is treated differently
Most of the personal data a school holds belongs to people under eighteen, and the Act sets a higher bar for it. Three things stand out for institutions:
- Verifiable parental consent is required before processing a child’s personal data. For a school this mostly lives in your admission paperwork — but it needs to be a real, recorded consent for stated purposes, not a line in a prospectus.
- No behavioural tracking or targeted advertising directed at children. This one is squarely aimed at software: any tool you put in front of students or parents should not be profiling them or serving ads.
- Nothing detrimental to the child’s wellbeing. A broad standard, deliberately.
The practical filter: if a system you use monetises attention, it does not belong in front of your students.
Five things worth doing this term
1. Write down what you hold and why
Most institutions have never made this list, and it is the foundation of everything else. Walk through the admission form, the staff file, the transport register, the medical record, the CCTV, the WhatsApp groups. For each item: what is it, why do we have it, who can see it, how long do we keep it?
The list is usually uncomfortable. Schools routinely collect parents’ income, caste, medical details and photographs, keep them forever, and let more people see them than anyone intended.
2. Stop collecting what you do not use
The Act expects you to collect only what is necessary for the stated purpose. If a field on your admission form has never once been used in a decision, take it off the form. It is the cheapest compliance work available, and it reduces what you can possibly lose.
3. Fix your logins
This is where school data actually leaks — not through a breached server, but through a staffroom account that everyone knows the password to, and a teacher who left in 2023 whose login still works.
- One login per person. Never a shared one.
- Close accounts the day somebody leaves.
- Give each role the narrowest access that lets them do the job — a class teacher rarely needs the fee ledger.
Any competent ERP lets your own administrator do all three without calling the vendor. Ours does; check that yours does too.
4. Know who your processors are
Your ERP is one. So is your SMS gateway, your payment gateway, your email provider, your cloud storage, the photographer who holds student photographs, and the company that runs your bus tracking. Each of them processes personal data on your behalf.
You should have a written agreement with each covering what they may do with the data, that they will not use it for their own purposes, that they will secure it, and that they will tell you if something goes wrong. Ask for one. A serious vendor will already have a template.
5. Decide who answers when a parent asks
Parents have rights under the Act — to know what is held about their child, to have errors corrected, and to complain. Someone at your institution needs to be the person who handles that, with a published way to reach them.
It does not have to be a full-time role for a school of ordinary size. It does have to be a named person who knows the process, rather than a query that bounces around the office until it reaches whoever is least able to say no.
What good software should already be doing
You should not have to build these yourself. Any ERP handling student data in India ought to give you, as standard:
- Role-based access you control, and the ability to close an account instantly.
- Encryption in transit, and hosting that is not a machine under someone’s desk.
- Backups you could actually restore from.
- A record of who changed what — particularly for marks and money.
- A clean export of everything, on request, at no charge.
- No advertising and no third-party tracking in anything students or parents see.
- A willingness to sign a processing agreement and complete your security questionnaire.
If your current system cannot do most of that, the gap is not a paperwork problem. We have set out our own position in detail on our security page — use it as a checklist against whoever you are evaluating, including us.
The reframe that helps
It is tempting to treat this as another compliance burden landing on an already stretched office. But most of what the Act asks for is what a careful institution would want anyway: know what you hold, hold less of it, let fewer people see it, be able to answer a parent honestly, and be able to get it back.
Schools have always been trusted with more sensitive information about families than almost any other institution they deal with. The law has caught up with an obligation that was already there.