Student data
The DPDP Act and Student Data: What Coaching Institutes Should Prepare Before May 2027
What India’s Digital Personal Data Protection Act and the DPDP Rules 2025 mean for coaching institutes: parental consent for students under 18, the education exemption, breach reporting, penalties, and a preparation checklist.
By Grawity · · 5 min read
Key takeaways
- The DPDP Rules were notified in November 2025. Most obligations — notices, security safeguards, breach reporting, and children’s consent — apply 18 months later, in May 2027.
- Under the Act anyone below 18 is a child, which covers many coaching students. Processing a child’s data generally needs verifiable parental consent.
- Educational institutions get a narrow exemption limited to tracking and behavioural monitoring for educational activities or student safety. It does not remove the other duties.
- Penalties go up to ₹250 crore for failing to keep reasonable security safeguards, and up to ₹200 crore for breach-notification or children’s data violations.
A coaching institute holds a lot of personal information: student names, dates of birth, mobile numbers, parents’ details, addresses, school records, photographs, attendance, test scores, and payment history. Most of it now lives in spreadsheets, WhatsApp groups, and software rather than paper registers.
India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 set out how organisations must handle that kind of data. The main obligations take effect in May 2027, which gives institutes time to prepare — if they start now.
The timeline
- August 2023 — Parliament enacts the Digital Personal Data Protection Act.
- November 2025 — the Government notifies the DPDP Rules, 2025. Rules establishing the Data Protection Board take effect immediately.
- November 2026 — the rule on Consent Managers takes effect, one year after notification.
- May 2027 — eighteen months after notification, the core obligations take effect: notices, security safeguards, breach intimation, data retention, contact details, and the rules on children’s data.
Does it apply to a coaching institute?
The Act applies to digital personal data, including data collected on paper and later digitised. An organisation that decides why and how personal data is processed is a Data Fiduciary. An institute that collects student and parent details for admissions, fees, attendance, and tests is making exactly those decisions, so in practice most coaching institutes should plan as Data Fiduciaries. Software providers who process that data on the institute’s behalf act as Data Processors.
Students under 18 and parental consent
Under the Act, a child is anyone who has not completed 18 years of age — which includes many students preparing for board, JEE, NEET, and similar exams. For a child, the Act treats the parent or lawful guardian as the person the data relates to for consent purposes.
Rule 10 requires a Data Fiduciary to take appropriate technical and organisational measures to obtain verifiable consent of the parent before processing a child’s personal data, and to check that the person identifying as the parent is an identifiable adult. The Rules allow this check to use reliable identity and age details already available to the organisation, or details or a virtual token issued by an authorised entity such as a DigiLocker service provider.
The education exemption — and its limits
Rule 12 and Part A of the Fourth Schedule exempt certain organisations from the verifiable-consent requirement and the ban on tracking and behavioural monitoring of children. One listed class is “a Data Fiduciary who is an educational institution”, defined as an institution of learning that imparts education, including vocational education.
The exemption is narrow. For educational institutions, processing is restricted to tracking and behavioural monitoring for the educational activities of the institution, or in the interests of the safety of enrolled children. Two cautions follow:
- Whether a particular coaching centre counts as an “educational institution” for this purpose is not spelled out for coaching specifically. Take legal advice rather than assuming the exemption applies to you.
- The exemption relieves specific requirements for specific purposes. It does not remove duties such as giving a clear notice, keeping data secure, reporting breaches, or responding to requests from students and parents.
Obligations to prepare for
- Notice: a separate, clear notice explaining what personal data you collect and the specific purposes you use it for.
- Security: reasonable security safeguards to prevent a personal data breach — the obligation with the highest penalty under the Act.
- Breach reporting: affected individuals must be informed without delay, in plain language. The Data Protection Board must be informed without delay, with a detailed report within 72 hours of becoming aware of the breach.
- Contact point: prominently publish the contact details of a person who can answer questions about how you process personal data.
- Rights requests: respond to requests to access, correct, update, or erase personal data within ninety days.
- Logs: retain personal data, traffic data, and logs of processing for at least one year from the date of processing, unless another law requires longer.
Penalties
The Act sets penalties of up to ₹250 crore for failing to take reasonable security safeguards; up to ₹200 crore each for failing to notify the Board or affected individuals of a breach, and for violating obligations relating to children; and up to ₹50 crore for other violations. Actual amounts are decided by the Data Protection Board case by case, but the scale shows how seriously student data is treated.
A preparation checklist for institutes
- 1List the personal data you collect at admission and afterwards, where it is stored, and who can see it.
- 2Stop collecting what you don’t need. For example, you rarely need a full Aadhaar number for coaching — the last four digits are usually enough to tell records apart.
- 3Update your admission form with a clear notice for students and parents, and a parental consent step for students under 18.
- 4Give staff access based on their role. A teacher needs their own batches, not the whole institute’s fee and contact data.
- 5Remove access immediately when a staff member leaves, and change shared passwords.
- 6Move student records out of personal phones, pen drives, and large WhatsApp groups where you can’t control who sees them.
- 7Decide how long you keep records of students who have left, and archive or delete them on that schedule.
- 8Write a one-page breach plan: who decides, who informs parents, and who informs the Board.
- 9Name a contact person for data questions and publish their details on your website.
How GIMS approaches student data
Software alone does not make an institute compliant — much of the work is policy and practice. GIMS is built to support good habits: role-based access so owners, teachers, and students each see only what their role needs; only the last four digits of Aadhaar stored on the student profile; student portal access that the institute can revoke, immediately ending existing sessions; and archiving students instead of deleting them so their history stays intact.
This article is general information for institute owners, not legal advice. Rules differ by state and change over time — confirm what applies to your institute with a lawyer or your state education department before acting on it.
Sources
See how GIMS handles this day to day.