Skip to content
Vidyom
← All resources

Compliance · 3 Aug 2026 · 7 min read

DPDP consent for schools: a practical 2027 guide

Under the DPDP Act, a school must get verifiable parental consent before it processes a child’s data. Here’s what that means in practice — and how to be ready before 2027.

India’s Digital Personal Data Protection Act, 2023 (DPDP) treats every student under 18 as a child, and children’s data as a special category. Before a school processes it, the Act requires verifiable consent from a parent or lawful guardian. For most schools that single word — verifiable — is the whole challenge, and it is worth getting right well before the 2027 enforcement window closes.

Start with what consent actually has to be. Under DPDP it must be free, specific, informed, unambiguous, and given by a clear affirmative action — a pre-ticked box or a blanket line in the admission form does not qualify. Each purpose you use a child’s data for (fee processing, academics, transport, communication, health) should be described in plain language, and the parent should be able to agree to them knowingly rather than by default.

Verifiable adds a second requirement on top: the school must be able to show, later, that the consenting adult was genuinely the child’s parent or lawful guardian, and that they actually consented. In practice that means capturing who consented, when, and for which purposes, and retaining the parent-child link as evidence — not just a tick, but a record you could produce if the Data Protection Board ever asked.

This is where school reality bites. Admissions happen on paper, over WhatsApp, at a counter, in the parent’s language, often with a guardian who is not the biological parent. A consent system that only works for tech-savvy parents on a good connection will leave gaps — and a gap in children’s-data consent is exactly what the Act penalises.

The practical model that holds up is a consent register: for every child, a durable record of each consent event — the purpose, the version of the notice shown, the identity of the consenting adult, the timestamp, and the channel. When a parent later withdraws consent for a purpose, that too is an event, and processing for that purpose stops from that point. Because it is a log rather than a single flag, you can always answer a simple question: what were we allowed to do, and when?

Notice is the other half of consent. Parents must be told, before or at the time of collection, what data you take and why, in a form they can actually read. For Indian schools that means the notice should be available in the languages your parents speak, and written without legal jargon. Consent obtained against an unreadable notice is not informed consent.

Guardianship needs explicit handling. The Act allows a lawful guardian to consent for a child, so your system has to record which adult holds that right for each student, and handle the messy cases — separated parents, a grandparent as guardian, a change of guardian mid-year — without losing the audit trail. Tying consent to a specific, identified guardian is what makes it verifiable rather than assumed.

Withdrawal and rights complete the picture. A parent can withdraw consent, and can ask to access, correct, or erase their child’s data. When they do, the school must honour it within DPDP’s timelines, and erasure has to reach every place the record lives — not just the primary screen, but reports, exports, and backups. If consent for a purpose is withdrawn, continued processing for that purpose is a fresh violation.

A common mistake is to treat consent as a one-time admission-form event. Purposes change over the years — a new transport route, a health programme, a photo for the website — and each genuinely new purpose needs its own consent, layered onto the record rather than bundled retroactively into the original tick. The register model makes this natural; a single form field does not.

None of this has to slow a school down if the software carries the weight. The job of a school ERP here is to make the compliant path the easy path: show the right notice in the parent’s language, capture consent as a first-class event tied to an identified guardian, keep the register, and make withdrawal and erasure real actions rather than promises.

This is how Vidyom is built. Consent for a child is recorded as a verifiable event — the guardian identified, the purpose and notice version stored, the parent-child link retained as evidence — and withdrawal, access, correction and erasure are wired through to every system that holds the record. The aim is that a school is ready for DPDP before the deadline, not reconstructing consent after it.

The 2027 clock is not far off, and children’s-data obligations are the part regulators will look at first. A school that can produce, for any student, a clear record of who consented to what and when is not just compliant — it has turned a legal risk into ordinary, provable operations.

Get started

See it on your own school’s data

Register or book a demo. We set you up and migrate your data, with nothing lost.

Register your schoolBook a demo