DPDP Act and Rules 2025 — What Every Indian School Needs to Know Before the Compliance Deadline
The Digital Personal Data Protection Rules, 2025 were finally notified on 14 November 2025, after a public consultation that drew 6,915 inputs. For schools, this is the moment the conversation moves from "there's a privacy law coming" to "there's a privacy law in force, with a clock running." It's worth reading what it actually says, rather than relying on the version that's been simplified in a vendor's sales deck — including, frankly, our own past posts, which I'd encourage you to re-check against the points below.
What happened, and when
The DPDP Act itself was passed back in 2023, but a law without operational rules is hard for anyone to actually comply with in practice. The Rules notified on 14 November 2025 are what make the Act enforceable. Based on current public reporting of the phased timeline, most substantive obligations — notices, consent mechanics, security safeguards, breach reporting, retention — are expected to apply roughly 18 months after notification, putting the practical deadline in mid-2027, with Consent Manager provisions arriving sooner, around November 2026. These are the figures being reported at the time of writing — please confirm the exact dates against the Gazette notification itself before relying on them for planning, since implementation timelines have shifted during the drafting process before.
Where a school sits under this law
A school that collects a student's name, date of birth, address, attendance record, academic history, or photograph is what the Act calls a Data Fiduciary — the party responsible for deciding why and how that data gets processed. That responsibility doesn't transfer to a software vendor just because the vendor built the system being used. If a vendor mishandles student data, the school remains the party the law holds accountable for that processing relationship.
The part most online explainers get wrong
This is worth being precise about, because getting it wrong in either direction causes real problems — either needless parental consent paperwork for things that don't require it, or, worse, assuming an exemption covers more than it does.
The Rules require verifiable consent from a parent or guardian before processing a child's personal data — but with specific, named exceptions. The government's own explainer states plainly that this consent requirement does not apply where the processing relates to essential services such as healthcare, education, or real-time safety.
In practical terms: a school generally doesn't need to run a parental consent flow just to take attendance or record academic progress — that sits within the educational-purpose exemption. What it does not cover is everything else a school app might also be doing — behavioural profiling for targeted notifications, sharing data with unrelated third-party advertisers, or using student data for anything outside the educational or safety purpose it was collected for. The exemption is purpose-bound, not a blanket pass. Treating it as blanket permission is the mistake likely to cause a school trouble later — not the absence of a consent form for ordinary attendance tracking.
What applies regardless of the exemption
Separate from the consent question, the Rules set baseline obligations for any Data Fiduciary, schools included: clear, itemised notices explaining what's collected and why; defined retention periods rather than indefinite storage; reasonable security safeguards; and a fixed window for reporting breaches once identified.
A starting checklist, not a compliance guarantee
- Map exactly what student and parent data your school collects, across every app and vendor — not just the attendance system.
- Separate "educational purpose" processing from anything else — marketing, behavioural tracking, third-party data sharing — since the exemption doesn't extend to the latter.
- Designate a clear point of contact parents can actually reach for data-related queries.
- Get it in writing from every vendor: how long they retain student data, and what happens to it when a student leaves or the contract ends.
Sources
This article is for general awareness and does not constitute legal advice. Compliance timelines and obligations should be confirmed with the official Gazette text and a qualified legal advisor before a school acts on them.