Xshala All resources Talk to a consultant
Explainer 7 min read

What the DPDP Act 2023 actually asks of a school

Consent, notice, purpose limitation and retention, translated into the forms your office already fills. Most of the work is writing down what you already do, then stopping the two or three things you should not.

This is a practical summary written for school and college administrators. It is not legal advice. Confirm your own obligations with counsel before changing policy.

A school is an unusual data fiduciary. Almost every person in your records is a child, which means the strictest parts of the Digital Personal Data Protection Act apply to your ordinary Tuesday. You also hold data you never asked for: a medical note handed in at the gate, a caste certificate required by a scholarship, a photograph a parent sent on WhatsApp.

The Act asks four things of that situation. Each one maps onto a form or a register your office already maintains.

The lifecycle of one piece of student data
01 Notice Plain language, itemised 02 Consent Guardian, per purpose 03 Collection Only what the purpose needs 04 Use No quiet second use 05 Retention Defined period 06 Erasure Or lawful archive A guardian may ask at any stage: show, correct, erase

The four obligations, in office terms

{{ d.i }} {{ d.n }}

{{ d.d }}

Where it lands in your office

{{ d.office }}

Children change the defaults

For a school this is the whole difference. Consent comes from the guardian, not the student, and two ordinary practices become risky.

Two things to stop
Behavioural tracking and profiling of students. Engagement scores that follow a child around, or targeted content chosen by past behaviour, sit badly with the Act. Report attainment, not inferred character.
Marketing to families from school records. An admission enquiry list is not a mailing list. Vendor offers, coaching tie-ups and photography packages need their own consent or they need to stop.

Age verification also cuts both ways. When a student turns eighteen mid-course, consent transfers to them. Your system should know the birth date it already holds and move the consent record accordingly, rather than leaving a guardian in control of an adult's data.

A retention schedule you can defend

Purpose limitation is meaningless without a stated period. Schools keep almost everything forever, usually because nobody decided otherwise. Deciding is most of the compliance.

Record Keep because Then
{{ r.k }} {{ r.why }} {{ r.then }}

Periods above are illustrative. Set your own against the statutory and board requirements that bind your institution.

Where to start this week

None of this requires a project. It requires four decisions and a place to write them down.

{{ s.i }} {{ s.t }}

A school that can show its notice, its consent register, its retention schedule and its erasure log is in a far better position than one with a policy document nobody has read. Start with the register, not the policy.

See the consent register on your own admission form.

A consultant walks your notice, consent and retention setup against the data you already collect at admission.