DPDP compliance for edtech companies

DPDP compliance for edtech companies
EdTech

DPDP compliance for edtech companies

Edtech platforms handle student data, children's data, and parental information — some of the most sensitive categories under the DPDP Act. Here is the compliance picture.

Quick Answer: Edtech companies are Data Fiduciaries under the DPDP Act for the personal data of students, parents, and teachers. Where the platform is used by anyone under 18, verifiable parental consent is required before processing the child's data, and the platform cannot use children's data for targeted advertising or behavioural profiling. Student data — learning history, assessment scores, engagement analytics — is personal data. Consent for marketing must be separate from consent for the educational service. Platform analytics must be designed to avoid identifying individual minors without consent. Enforcement deadline: May 2027.

Why are edtech platforms considered high-risk under the DPDP Act?

Edtech platforms occupy a uniquely sensitive position: they process children's data at scale, they know a great deal about individual learners — strengths, weaknesses, learning pace, engagement — and they often have access to a family's full contact and payment details. This combination of volume, sensitivity, and child-data exposure makes edtech one of the sectors regulators are most likely to scrutinise under DPDP.

How do edtech platforms implement verifiable parental consent at scale?

For any edtech platform used by under-18 students, verifiable parental consent is required before processing the child's personal data. This must happen before the student starts using the platform, not buried in terms accepted by the student themselves. At scale — for platforms with millions of students — this requires a robust, automated consent verification flow: parent registers separately, identity is verified through OTP or digital ID, and the consent is linked to the student's account in your ledger.

Does DPDP apply to student learning analytics data?

Learning analytics — tracking which concepts students struggle with, how long they spend on each module, which content leads to better outcomes — is valuable for product improvement. But it is personal data, and using it to profile individual students requires consent. Use anonymised or aggregated analytics for product decisions wherever possible; where individual-level analytics are necessary, ensure you have consent that covers this use and that students (or parents) can access their analytics profile.

Do edtech companies need separate consent for marketing communications?

Parents who enrol their child on an edtech platform have not automatically consented to receive marketing for other products, promotional offers, or third-party advertisements. Marketing communications require separate, specific consent. Many edtech companies conflate the educational service consent with a broad marketing consent — this will not withstand scrutiny under DPDP. Audit your consent forms and split service consent from marketing consent clearly.

Does the DPDP Act apply to teacher and tutor data on edtech platforms?

Edtech platforms also hold data on teachers, tutors, and content creators — employment or contractor records, performance data, earnings, and in some cases video recordings of teaching sessions. These individuals have the same DPDP rights as students and parents. Ensure your privacy notice covers teacher data, and that your platform's data management tools allow teachers to access and correct their records.

Do edtech companies need Data Processing Agreements with schools and universities?

Many edtech platforms sell to schools, universities, or corporate training departments (B2B). In this model, the institution is the Data Fiduciary for its students or employees, and the edtech platform is the Data Processor. Update your institutional contracts to function as DPAs. Specify what you can do with the institution's data, prohibit use for your own product analytics without their consent, and build data export and deletion features so institutions can exercise their fiduciary responsibilities.

Frequently asked questions

A student accepted our terms at registration. Is that enough for DPDP consent?

No. If the student is under 18, terms accepted by the student themselves — even if they claim to be 18 — are not verifiable parental consent. You need a separate, verified consent from the parent or lawful guardian before processing the child's data. The verification must be reliable enough to confirm the adult is genuinely a parent or guardian, not just another minor lying about their age.

Can we use student learning data to train our AI tutoring model?

Using identifiable student data to train an AI model is a secondary processing activity that requires consent beyond the educational service consent. Either obtain explicit consent for model training (covering what data is used, how, and for how long), or anonymise the data before using it for training. Given the sensitivity of children's learning data, the latter is strongly recommended. Document your anonymisation approach carefully.

Do we need a DPA with the schools we sell to?

Yes. If a school or university sends you student personal data to manage on their platform, they are the Data Fiduciary and you are the Data Processor. Your institutional contract must function as a DPA — specifying processing scope, security requirements, breach notification, and deletion at contract end. This is increasingly expected by school procurement officers and IT departments anyway, so updating your contracts benefits both compliance and sales.

Assess your edtech DPDP compliance

Niti Bharat's DPDP Readiness Assessment covers edtech platforms — verifiable parental consent, student data analytics, institutional DPAs, and marketing consent — in a structured engagement.

Start EdTech DPDP Assessment
Previous Post Next Post

Get Free DPDP Checklist