What does DPDP require from edtech platforms?
Children's data is the strictest regime. Here's what edtech platforms must do.
Parental consent and age-gating
If your platform admits students under 18, you must obtain verifiable parental consent (not just a checkbox from the student claiming to be old enough). A consent mechanism verified by email, SMS or parent login is the baseline. Age-gating — confirming the student's age at signup — is mandatory. Collecting only age range or cohort is risky; get the birth date and verify.
No behavioural ads to minors
Serving targeted ads to children based on their learning behaviour or interests is prohibited. You can run contextual ads (safe, non-targeted), but algorithmic personalisation that trains on student data is out of bounds. This includes not selling or sharing student data for advertising purposes.
Purpose and retention strictness
Student data collected for learning analytics can only be used for learning. Selling anonymised cohort insights for research is allowed if consent covers it. Retention is tighter too — once a student graduates or leaves, most data must be deleted within a short period unless the student or parent consents to longer retention.
Frequently asked questions
Can I use student data for research?
Only if you have explicit parental consent for research use and the data is truly anonymised. Pseudonymised data linked to a student is still personal data.
What is verifiable parental consent?
A checkbox on a form is not enough. Verifiable means the platform confirms the parent's identity, often via email verification, SMS code or a parent portal login.
How do I handle student data after graduation?
Delete it unless the student or parent has consented to longer retention for records (e.g., transcript archival) or unless a law requires retention.
Check your student-consent flows
Use the DPDP for EdTech guide to verify parental consent, age-gating and purpose limits.
DPDP for EdTech