Skip to content

NewQuiz library, gamification & bus tracking.What's new in the release notes

Compliance & data

The DPDP Act, 2023: what schools should know

A plain-language introduction to India's Digital Personal Data Protection Act for school leaders — children's data, consent, security and practical first steps. Not legal advice.

CampusConnect TeamIQLEXA Technologies Private Limited 5 min read

India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) sets out how organisations must handle personal data in digital form. Schools hold a great deal of personal data — about children, parents and staff — so the Act is directly relevant to them.

This article is a plain-language introduction for school leaders. It is not legal advice. The Act is supported by rules that set out details and timelines; consult the official text, the current rules and a legal adviser before making decisions.

The key ideas, in plain language

  • Personal data is any data about an individual who can be identified by or in relation to that data. Student names, dates of birth, marks, attendance, photos, parents’ phone numbers and staff salary details are all personal data.
  • Data principal is the person the data is about. For a child, the Act involves the parent or lawful guardian.
  • Data fiduciary is the organisation that decides why and how personal data is processed. For student records, that is usually the school.
  • Data processor is an organisation that processes data on behalf of a data fiduciary — for example, a software provider that hosts the school’s records under a contract.

Children’s data gets extra protection

The Act treats a child as anyone under 18 and gives children’s data additional protection. In broad terms, it requires verifiable consent of a parent or lawful guardian before processing a child’s personal data, and it restricts processing that is likely to harm a child’s well-being, as well as tracking, behavioural monitoring and targeted advertising directed at children. The rules made under the Act describe how these requirements apply, including certain exemptions; schools should look at those details carefully.

For a school, this is a good moment to look at what children’s data you collect, why, and with whom it is shared.

Core obligations, broadly

Without going into legal detail, the Act expects data fiduciaries to:

  1. Have a lawful basis — usually consent, or certain specified legitimate uses — for processing personal data.
  2. Give clear notice of what data is collected and why.
  3. Collect only what is needed for the stated purpose, and keep it accurate.
  4. Protect the data with reasonable security safeguards to prevent breaches.
  5. Notify the Data Protection Board and affected individuals in the event of a personal data breach, as the rules require.
  6. Respect individuals’ rights — such as access to information about their data, correction and erasure, and grievance redressal.
  7. Delete data when it is no longer needed for its purpose, unless the law requires it to be kept.
  8. Ensure processors protect data, through contracts with vendors that handle data for the school.

Practical first steps for a school

Map your data. List what personal data you collect (admission forms, attendance, marks, health records, photos, fee details, staff HR data), where it is kept (registers, spreadsheets, software, WhatsApp groups) and who can see it.

Reduce what you don’t need. Admission forms often ask for more than the school uses. Each field you remove is one less thing to protect.

Review consent and notices. Make sure parents are told clearly, at admission, what data the school collects and how it is used. Review consent for things like publishing photos on social media.

Tighten access. Not every staff member needs every record. Role-based access — teachers see their classes, accountants see fees — is one of the most effective safeguards.

Move data out of informal channels. Class WhatsApp groups and personal phones are hard to control. Moving communication and records into school-controlled systems makes protection and deletion possible.

Check your vendors. Ask your software providers how they protect data: encryption in transit, how passwords are stored, how one school’s data is kept separate from another’s, what logs exist, and how they would notify you of a breach. Put the answers in your contract.

Plan for incidents. Decide who is responsible if data is lost or exposed, how you would find out, and whom you would inform.

Appoint a point of contact for privacy questions and grievances, and publish how to reach them.

What this means for school software

Software can’t make a school compliant on its own — compliance depends on the school’s own policies and practices — but the right tools make good practice easier. Look for role-based access, an audit log of important actions, encryption in transit, strong password storage, clear separation of each school’s data, and a vendor that does not sell data or show ads.

Questions school leaders often ask

Is the school or the software company responsible? For student records, the school usually decides why and how data is processed, which makes it the data fiduciary. A software provider that hosts the records on the school’s instructions acts as a processor. Both have responsibilities; your contract with the vendor should say what the vendor will do.

Do we need consent for everything? Not necessarily — the Act provides for consent as well as certain legitimate uses, and the rules provide details, including for children’s data. Work out the basis for each purpose with your legal adviser rather than assuming one answer fits all.

How CampusConnect approaches this

CampusConnect is designed with the DPDP Act in mind. Schools own and control their data, and we process it on their behalf. Access is role-based for admins, staff, students, parents and drivers; passwords are stored only as bcrypt hashes; connections use HTTPS; each school’s data is kept separate, with automated tests for that isolation; important actions are recorded in an audit log; and we never sell data or show ads. You can read the details in our trust centre.

If you are reviewing how your school handles data, book a free demo and we’ll walk your team through it.

Compliance & data5 min read

UDISE+ basics for school administrators

A plain-language overview of UDISE+, the national school data system: what it collects, why accurate records matter, and how good everyday record-keeping makes submissions easier.

· CampusConnect Team

Get started

See CampusConnect with your own school's workflow

Get a free, personalised demo. We'll show you the modules that matter to you and plan a smooth switch with your team.

  • Personalised demo, at a time that suits you
  • Help importing your data from Excel
  • Training for admins, accountants and teachers
  • +91 95382 22239WhatsApp support
Book a free demo