Children's Data, Adult Negligence: Why Schools Are DPDPA's Biggest Blind Spot

Article by

Children's Data

Introduction 

Educational institutions start collecting a child's personal information during the admission process. This information typically includes the child's name, date of birth, address, identity documents and contact details. As the child continues their education, schools collect additional information such as attendance records, academic performance, health records, photographs, videos and details of participation in extracurricular activities. 

With the increasing use of digital platforms for teaching and school administration, educational institutions now possess large volumes of student data. As schools routinely collect and process personal data, they are classified as Data Fiduciaries and are subject to the obligations under the DPDP Act. Therefore, it becomes their duty to implement robust data protection practices and educating students about their privacy rights 

Why Schools Are DPDPA's Biggest Blind Spot 

The DPDP Act is set to come into effect from May 2027. Although the transition period has been provided to allow institutions time to comply with its requirements, schools continue to operate without complete regulatory guidance during this period. 

Institutional awareness and capacity to manage consent, verification, and grievance redressal remain limited. Further, many parents lack the awareness and technical understanding needed to make informed privacy choices. Moreover, in the absence of sector-specific guidance from the Data Protection Board and effective coordination between the Ministry of Electronics and Information Technology (MeitY) and the Ministry of Education (MoE), as well as limited capacity-building and child-specific compliance standards, the protection of learner data continues to depend largely on the discretion of individual institutions rather than effective regulatory oversight.  

Risks Associated with Inadequate Data Protection in Schools 

Educational institutions have become frequent targets of ransomware and cyberattacks because they hold large volumes of student data while often having limited cybersecurity resources. Once attackers compromise a vendor's systems, they may gain access to school networks and sensitive information, including student records, financial information, healthcare data and employee records. Some risks associated are mentioned below:  

  • Risk of Unauthorised Access and Data Misuse: Schools process large volumes of personal data relating to students, parents, staff and alumni. Inadequate data protection measures may result in unauthorised access, disclosure, loss or misuse of sensitive information. 


  • Risk of Cyber Attacks: Schools are increasingly vulnerable to cyber threats such as malware, phishing, ransomware, identity theft and data breaches. Such incidents can compromise personal data and disrupt educational and administrative functions. 


  • Reputational Risk: A data breach can erode the trust of students, parents and the wider community. Loss or misuse of personal information may negatively affect the institution's credibility and public image. 


  • Regulatory and Compliance Risk: As data protection laws continue to evolve, schools may face legal and regulatory consequences for failing to comply with applicable obligations relating to the collection, use and protection of personal data. 


  • Operational Risk: Cyber incidents and data breaches can disrupt teaching, administration and other essential school functions, affecting the continuity and effectiveness of educational services. 


  • Risk Associated with Third-Party Data Sharing: Schools often share student personal data with third-party service providers such as transport providers, canteen operators, learning management systems and technology vendors. Such data sharing may create compliance risks if adequate contractual safeguards are not in place with the service providers. 

Processing of Children's Personal Data under the DPDP Act and Rules. 

Under the Digital Personal Data Protection Act, 2023, a Data Principal is the individual to whom the personal data relates. In the case of a child, the term also includes the child's parent or lawful guardian. Section 9 of the Act imposes additional obligations on Data Fiduciaries when processing the personal data of children. These include: 

  • Verifiable Parental Consent: Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian in the prescribed manner. 


  • Protection of the Child's Well-being: A Data Fiduciary must not process a child's personal data in a manner that is likely to have a detrimental effect on the child's well-being. 


  • Prohibition on Tracking and Targeted Advertising: A Data Fiduciary is prohibited from undertaking tracking or behavioural monitoring of children or directing targeted advertisements at them. 


  • Liability: Failure to comply with these additional obligations under Section 9 may attract a financial penalty of up to ₹200 crore

Furthermore, Rule 10 of the Digital Personal Data Protection Rules requires a Data Fiduciary to implement appropriate technical and organisational measures to ensure that verifiable parental consent is obtained before processing the personal data of a child. To verify such consent, the Data Fiduciary must exercise due diligence to confirm that the individual claiming to be the child's parent is an adult and can be identified. This verification may be carried out using: 

  • Reliable identity and age information already available with the Data Fiduciary; or 


  • Identity and age details voluntarily provided by the individual, either directly by the individual; or through a virtual token linked to such identity issued by an authorised entity. 

Key Cybersecurity Considerations for Schools 

Implementing appropriate cybersecurity measures is essential to protect school systems, safeguard personal information and ensure the continuity of educational services. Below are some key technical and organisational measures that a school must implement: 

  • User Security Practices: Encourage students, parents, teachers and staff to follow good cybersecurity practices, such as using strong passwords, securing devices, keeping software updated and protecting personal information. 


  • Providing Stronger Safeguards: Children require additional protection when their personal data is collected and processed. Data protection frameworks recognise their specific rights, such as greater control over their personal information and enhanced safeguards for online services. Organisations are encouraged to present privacy notices, consent requests and terms of service in a clear, simple and age-appropriate manner so that children can understand how their data is being used. 


  • Promoting Awareness and Education: Creating awareness among children, parents and educators is a key aspect of protecting children's privacy. Educational programmes, workshops and guidance materials can help children understand online safety, the importance of protecting personal information and safe digital practices. Parents and teachers also benefit from resources that support them in guiding children on the responsible use of digital technologies. 


  • Embedding Privacy by Design: Digital services intended for children should incorporate privacy and data protection measures from the design stage. Age-appropriate interfaces, simple privacy controls and transparent data practices enable children to make informed choices and exercise their rights more effectively. Integrating privacy into the development of digital products helps create a safer online environment for young users. 


  • Secure Network Infrastructure: Schools should use secure and password-protected networks to reduce the risk of unauthorised access, network intrusions and other cyber threats. Where appropriate, secure technologies such as Virtual Private Networks (VPNs) may be used to protect data transmissions. 


  • Data Backup: Schools should regularly back up important data and ensure that backups are securely stored to enable recovery in the event of data loss or a cyber incident. 


  • Protection Against Malware: Appropriate measures should be implemented to protect school systems from malware and other malicious software, including maintaining updated software and restricting the installation of unapproved applications. 


  • Device Security: School-owned devices should be protected through appropriate security measures, including authentication mechanisms, regular software updates and remote management capabilities to reduce the risk of unauthorised access or data loss. 


  • Cybersecurity Awareness: Schools should promote cybersecurity awareness among students, parents, teachers and staff by guiding on common cyber threats, safe online behaviour and the secure use of digital learning platforms. 


  • Cyber Incident Response: Schools should establish clear procedures for responding to cybersecurity incidents, including reporting mechanisms, incident containment, communication with relevant authorities and affected individuals, and post-incident reviews to address vulnerabilities and strengthen future preparedness. 

Conclusion 

Schools hold large amounts of sensitive information about children. This makes them prime targets for cyber threats and data breaches. To address these risks, schools must look beyond basic legal requirements. They need to secure their digital networks and build strong data privacy practices protects young learners from digital harm. This, in turn, helps schools build long-term trust with parents and the wider community and ensure a secure digital environment for student learning.  

Want to stay ahead?     

Secure your communications today with a tailored privacy and compliance strategy from GoTrust.