By: Chintan Shah, Founder, DPDPGaurd.ai
Walk into any Indian school today, and you will find far more than classrooms and playgrounds. You will find biometric attendance systems, fee-payment portals linked to bank details, learning-management platforms tracking every quiz a child takes, CCTV feeds, medical and immunisation records, Aadhaar-linked admission forms, and increasingly, AI-based proctoring tools that watch students during exams. Few institutions in the country hold as dense and as sensitive a concentration of personal data — most of it belonging to minors — as schools do. Yet, as India moves into the operational phase of the Digital Personal Data Protection Act, 2023 (DPDP Act), a striking number of schools have not yet built even a basic compliance roadmap. That gap between the data schools already hold and the governance maturity to protect it is fast becoming one of India’s most under-discussed digital risks — and one of its clearest opportunities for institutions willing to act early.
A law built around the child — with real nuance
The DPDP Act, together with the DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology (MeitY) on November 13, 2025, gives India its first comprehensive, citizen-centred data protection framework. Section 9 prohibits processing of children’s personal data that could harm their well-being and restricts tracking, behavioural monitoring and targeted advertising directed at children. However, these restrictions are not absolute, as the Act allows prescribed exemptions for certain Data Fiduciaries, purposes and conditions.
The courts are already shaping how this plays out
In December 2025, the Orissa High Court, in Rohit Anand Das & Anr. v. State of Odisha & Ors., directed the Union government to amend the model consent form for the Automated Permanent Academic Account Registry (APAAR) — the lifelong student ID scheme run under the National Education Policy 2020 — to give parents an explicit option to refuse or opt out, holding that the absence of such an option undermined the government’s claim that the scheme was voluntary and raised genuine privacy concerns. In August 2026, hearing a separate challenge to APAAR’s Aadhaar linkage, a Supreme Court bench led by Chief Justice Surya Kant indicated it would direct the CBSE to implement the Orissa High Court’s ruling on a pan-India basis, since the Centre had not appealed it, and flagged that CBSE circulars remain subject to the DPDP Act rather than overriding it. For schools and boards handling large-scale student ID and consent workflows, this signals that courts are actively testing whether consent mechanisms are genuinely free, informed and revocable — not just present on paper.
Real-world risk, not a hypothetical one
The consequences of weak data governance are already playing out in Indian courtrooms. In June 2026, the Bombay High Court granted an ex parte injunction restraining a hacking group from publishing sensitive student data allegedly stolen from schools run by a Mumbai-based charitable trust, after the group demanded a ransom of USD 750,000. The compromised data reportedly included children’s medical and mental-health details, daily travel patterns, and their parents’ income and occupation — information the court found could pose a grave risk to the children’s safety if released. This sits alongside a broader pattern: a nine-month pilot study by the CyberPeace Foundation, released with government and academic backing in August 2025, recorded over two lakh cyberattacks and nearly four lakh data-breach attempts against Indian educational institutions, with weak passwords and unmonitored admin accounts among the most common failure points.
The cost of getting it wrong is now precise
The DPDP Act’s Schedule sets out fixed monetary penalties by category of violation, and schools should understand exactly what applies to them. The Data Protection Board of India may impose a penalty of up to ₹250 crore per instance for failing to implement reasonable security safeguards to prevent a personal data breach — the single largest penalty slab in the Act. If the Data Protection Board of India and the concerned data principals are not notified about the breach, and there is non-compliance with the provisions for children’s data, then the maximum penalty will be ₹200 crore for both offences.
From risk to readiness: what schools actually need to do
Turning this into a workable plan does not require an overwhelming overhaul. It requires working through six things in sequence: a clear-eyed data map of exactly what personal data is collected, from whom, through which system, and why; consent and notice workflows that are genuinely verifiable for parents, written in plain language, and built to reflect the narrow, purpose-specific exemptions rather than a one-size-fits-all form; a defined process for handling children’s rights — including a real opt-out, not a post-facto withdrawal option, as the Orissa High Court insisted on; vendor governance covering the ed-tech platforms, biometric systems, transport apps, and payment gateways that schools rely on daily, each backed by a proper data-processing contract; access controls that limit who inside and outside the institution can see sensitive records; and breach-readiness and retention policies that define how long data is kept and how the institution will detect, contain and report an incident within regulatory timelines.
The path forward
India’s data protection journey has moved from legislative intent to judicial and regulatory reality faster than many institutions expected, and schools sit at its most sensitive intersection — holding vast amounts of children’s data while still building the governance muscle to protect it. The Orissa High Court’s intervention on APAAR consent, the Supreme Court’s move to apply it nationwide, the Bombay High Court’s response to an actual student-data breach, and a penalty structure that now runs into hundreds of crores are not abstract signals. They are a clear indication that the window for schools to treat DPDP compliance as optional is closing. The institutions that map their data, fix their consent processes and build breach-readiness now will not just avoid the consequences — they will build the kind of trust that parents, regulators and courts are increasingly going to expect as a baseline. This is also an area where DPDPGuard.ai can come to the rescue by allowing schools to structure their processes for privacy and compliance in line with their DPDP readiness program.
