What the DPDP Act 2023 actually asks of a school
Consent, notice, purpose limitation and retention, translated into the forms your office already fills. Most of the work is writing down what you already do, then stopping the two or three things you should not.
This is a practical summary written for school and college administrators. It is not legal advice. Confirm your own obligations with counsel before changing policy.
A school is an unusual data fiduciary. Almost every person in your records is a child, which means the strictest parts of the Digital Personal Data Protection Act apply to your ordinary Tuesday. You also hold data you never asked for: a medical note handed in at the gate, a caste certificate required by a scholarship, a photograph a parent sent on WhatsApp.
The Act asks four things of that situation. Each one maps onto a form or a register your office already maintains.
The four obligations, in office terms
{{ d.d }}
{{ d.office }}
Children change the defaults
For a school this is the whole difference. Consent comes from the guardian, not the student, and two ordinary practices become risky.
Age verification also cuts both ways. When a student turns eighteen mid-course, consent transfers to them. Your system should know the birth date it already holds and move the consent record accordingly, rather than leaving a guardian in control of an adult's data.
A retention schedule you can defend
Purpose limitation is meaningless without a stated period. Schools keep almost everything forever, usually because nobody decided otherwise. Deciding is most of the compliance.
| Record | Keep because | Then |
|---|---|---|
| {{ r.k }} | {{ r.why }} | {{ r.then }} |
Periods above are illustrative. Set your own against the statutory and board requirements that bind your institution.
Where to start this week
None of this requires a project. It requires four decisions and a place to write them down.
A school that can show its notice, its consent register, its retention schedule and its erasure log is in a far better position than one with a policy document nobody has read. Start with the register, not the policy.
See the consent register on your own admission form.
A consultant walks your notice, consent and retention setup against the data you already collect at admission.