Children's Data Under DPDP: What the Education Provisions Do and Do Not Cover

Rule 12 and the Fourth Schedule are often summarised as an exemption for schools. The disapplication is narrower than that summary suggests: it names two of the three children's provisions in section 9, operates only within a stated condition, and leaves section 9(2) untouched.

MJ
Mihir Jana
·10 September 2026·19 min read
⚡ Quick answer

A school is not outside the DPDP Rules. Rule 12(1), read with Part A of the Fourth Schedule, disapplies two of the three children's provisions in section 9 of the Act for educational institutions: section 9(1), the verifiable consent of a parent or lawful guardian, and section 9(3), which prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. That disapplication is not general. It operates only within the condition recorded against the education entry, which is written in terms of tracking and behavioural monitoring for the educational activities of the institution or the safety of children enrolled with it. On the wording of that condition, targeted advertising directed at children appears to sit outside both limbs. Section 9(2), which prohibits processing likely to cause a detrimental effect on a child's wellbeing, is not disapplied for anyone. These provisions commence on the expiry of eighteen months from the publication of the Rules on 13 November 2025, which falls in mid-May 2027.

This is general information, not legal advice.

DPDP obligations depend on the facts of your organisation and how it processes personal data. The Rules are phased and some provisions have not yet commenced. Before you act on anything here, take advice from a qualified professional on your own circumstances.

Where the material in this post comes from

Everything in this post is drawn from publicly available documents: the Digital Personal Data Protection Act, 2023 as published, and the Digital Personal Data Protection Rules, 2025, notified in the Official Gazette on 13 November 2025 by notification G.S.R. 846(E). Where the post describes a provision, it is describing that published text, and the wording is quoted wherever the exact words carry the argument. No confidential, client or unpublished material is used anywhere in this post, and no organisation, institution or individual is named as an example. The provisions relied on are listed with links at the end.

Key takeaways

  • Under the Act a child is anyone who has not completed eighteen years of age. In a school, that is almost every learner.
  • Section 9 carries three separate duties: verifiable consent of a parent or lawful guardian under 9(1), no processing likely to cause a detrimental effect on a child's wellbeing under 9(2), and no tracking or behavioural monitoring of children and no targeted advertising directed at children under 9(3).
  • Rule 12(1) disapplies sub-sections (1) and (3) only, for the classes listed in Part A of the Fourth Schedule, and only subject to the conditions specified in that Part. Educational institutions are entry 3 in Part A.
  • Section 9(2) is not among the provisions disapplied. On the text it continues to apply to every Data Fiduciary, including those listed in the Fourth Schedule.
  • The condition recorded against the education entry is written in terms of tracking and behavioural monitoring for the institution's educational activities or the safety of enrolled children. How far that condition reaches is not settled by the text, and this post does not settle it either.
  • Section 9(1) also covers a person with disability who has a lawful guardian. Rule 12 disapplies section 9(1) for processing of the personal data of a child; it is not worded to reach that second category, and Rule 11 sets out separate due diligence on a lawful guardian's appointment.
  • The children's provisions and the rest of the substantive Rules commence together, on the expiry of eighteen months from the publication of the Rules on 13 November 2025, which falls in mid-May 2027.

Start with what section 9 actually says

Most summaries of DPDP and schools begin with the exemption. It is easier to follow if you begin with the duties the exemption acts on, because there are three of them and they are not interchangeable.

Under the Digital Personal Data Protection Act, 2023, a child is an individual who has not completed eighteen years of age. In a school that is almost every learner on the roll. In a college it is a shrinking but real part of the first-year intake. Section 9 then sets out three separate duties.

  • Section 9(1) — before processing the personal data of a child, or of a person with disability who has a lawful guardian, a Data Fiduciary is to obtain the verifiable consent of the parent or of that lawful guardian. The second category matters and is easy to miss; we come back to it below.
  • Section 9(2) — a Data Fiduciary is not to undertake processing that is likely to cause any detrimental effect on the wellbeing of a child.
  • Section 9(3) — a Data Fiduciary is not to undertake tracking or behavioural monitoring of children, or targeted advertising directed at children.

Three duties, three different subjects. One is about permission. One is about harm. One is about a category of activity. Keeping them apart is the whole exercise, because the exemption does not treat them the same way.

What Rule 12 lifts, and for whom

Rule 12 of the Digital Personal Data Protection Rules, 2025 has two sub-rules, and they are worded almost identically. Sub-rule (1) provides that the provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child by such class of Data Fiduciaries as are specified in Part A of the Fourth Schedule, subject to such conditions as are specified in the said Part. Sub-rule (2) does the same thing for the purposes listed in Part B.

Three things are worth noticing before going any further.

Only sub-sections (1) and (3) are named. Sub-section (2) — the prohibition on processing likely to cause a detrimental effect on a child's wellbeing — appears in neither sub-rule. On the text it is not lifted for schools, for hospitals, for those caring for children in a crèche, or for anyone else in the Fourth Schedule.

The exemption is conditional, not general. The phrase subject to such conditions as are specified in the said Part is not decoration. Each entry in the Fourth Schedule has a condition written against it, and the disapplication operates within that condition.

Rule 12(1) is worded for a child. It speaks of processing of personal data of a child. Section 9(1) reaches further than that, and we return to the difference below.

The entry for educational institutions

Educational institutions are entry 3 in Part A of the Fourth Schedule. The condition recorded against that entry is that “processing is restricted to tracking and behavioural monitoring — (a) for the educational activities of such institution; or (b) in the interests of safety of children enrolled with such institution”.

The neighbouring entries are worth reading alongside it, because they show how tightly these conditions are drawn. Entry 4 names the individual in whose care infants and children in a crèche or child day-care centre are entrusted, and restricts processing to tracking and behavioural monitoring “in the interests of safety of children entrusted in the care of such institution, crèche or centre” — safety only, with no educational limb. Entry 5 names a Data Fiduciary engaged for the transport of children, and restricts processing to tracking the location of those children, in the interests of their safety, “during the course of their travel to and from such institution, crèche or centre” — location only, during the journey only. These are not broad grants. They are narrow permissions written for a specific activity.

What the education entry disapplies

  • Section 9(1), verifiable parental consent, for processing of a child's personal data, within the stated condition
  • Section 9(3), the prohibition on tracking and behavioural monitoring of children, within the stated condition
  • For two stated purposes only: the educational activities of the institution, or the safety of children enrolled with it

What the entry does not appear to reach

  • Section 9(2): processing likely to cause a detrimental effect on a child's wellbeing, which is named in neither sub-rule of Rule 12
  • Targeted advertising directed at children, which on the wording of the condition sits outside both limbs
  • Anything that is neither an educational activity of the institution nor a matter of the enrolled child's safety
  • Section 9(1) as it applies to a person with disability who has a lawful guardian, since Rule 12(1) is worded for processing of a child's personal data
  • The rest of the Rules: notice, security safeguards, retention and erasure, breach intimation and data principal rights, which apply to a child's data as they do to anyone else's
  • The position of any other party in the chain that is not itself a class listed in the Fourth Schedule

The two words that decide how wide this is

The condition says processing is restricted to tracking and behavioural monitoring for those two purposes. That phrasing supports more than one reading, and the difference between them is large.

The narrower reading. The disapplication reaches only processing that is itself tracking or behavioural monitoring, carried out for educational activities or for child safety. On this reading, ordinary school record-keeping that is not tracking or behavioural monitoring — an admission record, a fee ledger, a marks register — is not covered by the entry at all, and its position under section 9(1) falls to be worked out on its own terms.

The wider reading. The entry identifies a class of Data Fiduciary, and the condition describes the activity the exemption was written for, so an educational institution processing a child's data for its educational activities or for the child's safety sits inside the disapplication whether or not each individual operation would be described as monitoring.

Both readings are arguable on the text as it stands, and we are not aware of any guidance from the Central Government or the Data Protection Board addressing this entry as at the date of writing. Where two readings are defensible, the more conservative one is the safer basis to plan on — and here that is the narrower reading, because it assumes fewer obligations have been lifted. That is a planning observation, not a legal conclusion, and it is not a substitute for advice on a particular institution's facts.

What verifiable consent involves, where it is required

Where section 9(1) does apply, Rule 10 sets out what verifying a parent means in practice, and it is more specific than the phrase suggests.

The Data Fiduciary is to adopt appropriate technical and organisational measures to ensure that verifiable consent is obtained before processing, and to observe due diligence to check that the individual identifying herself as the parent is an adult — someone who has completed eighteen years of age — and is identifiable if required in connection with compliance with any law for the time being in force in India. The Rule contemplates three routes: reliable identity and age details already available with the Data Fiduciary; identity and age details voluntarily provided; or a virtual token mapped to those details, issued by an entity authorised to do so, which the Rule says includes a Digital Locker service provider.

Four illustrations are attached to Rule 10. They work through a parent who is already a registered user of the same service and can be checked against details the Data Fiduciary already holds, and a parent who is not a user at all and comes through a token issued against a verified identity, in each case both where the child is the one seeking the account and where the parent is.

The category that Rule 12 does not appear to reach

Section 9(1) applies to a child or a person with disability who has a lawful guardian. Rule 12(1) disapplies section 9(1) for “processing of personal data of a child”, and is not worded to extend to that second category. Rule 11 then sets out separate due diligence where consent is given by a lawful guardian: verifying that the guardian is appointed by a court, or by a designated authority under the Rights of Persons with Disabilities Act, 2016, or by a local level committee. For a special school, or for any institution with adult learners who have a lawful guardian, that is a different position from the one the education entry describes, and it is not one this post can resolve on an institution's behalf.

For an institution, the practical shape of all this is a question about records rather than about software. Whether Rule 10 or Rule 11 can be satisfied depends largely on what is already held about the parent or guardian on each learner's file, and how reliably that record identifies them. That is a factual question about a particular institution's records, and the answer will differ between institutions.

An open question the text does not answer

Learning platforms routinely score engagement. Time on page, login cadence, submission patterns, quiz attempt behaviour — these get combined into a signal, and learners get surfaced to a teacher as at risk. The feature is old and widely deployed. Whether any given institution has ever classified it against section 9(3) is a question we have not often seen asked.

Where the learner is under eighteen and the institution is relying on the Fourth Schedule condition, is that scoring within “the educational activities of such institution”, or is it behavioural monitoring of a kind the condition does not reach? The argument for the first is that identifying a struggling learner sits close to the core educational activity of an institution. The argument for the second is that the condition permits monitoring for that activity, which implies a boundary somewhere, and an inferred behavioural profile of a fourteen-year-old is one place a boundary could sit.

We are not going to answer that here. The text does not resolve it, we are not aware of any guidance from the Central Government or the Board addressing it, and a confident answer from a platform vendor is worth very little to an institution that has to defend a position. We raise it because it is the question we would want on the table early, while there is time to ask it properly, rather than in 2027.

Two things are worth saying alongside it, so that raising the question does not push anyone in an unsafe direction. First, nothing in this uncertainty touches section 9(2): processing likely to cause a detrimental effect on a child's wellbeing is not disapplied by Rule 12 at all, on either reading of the condition. Second, an exemption is not a reason to stop doing something protective. Where an institution monitors because a child's safety depends on it, the Fourth Schedule condition points towards that activity, not away from it.

What holds whichever reading is correct

A few things do not move with the interpretation, and they are the parts worth being clear about.

The disapplication is only about section 9. Rule 12 names two sub-sections of one section. It says nothing about the notice requirements in Rule 3, the security safeguards in Rule 6, retention and erasure, the breach intimation duties in Rule 7 including the detailed report to the Board within seventy-two hours of becoming aware, or the rights a Data Principal can exercise. Those apply to a child's personal data as they apply to anyone else's.

It attaches to a class, and to conditions. It is written for educational institutions doing certain things. Where an institution runs a platform operated by someone else, the two parties occupy positions under the Act that depend on what each of them actually does with the data — the institution ordinarily determining the purpose and means of processing, the platform operator ordinarily processing on its behalf, though a platform operator can itself be a Data Fiduciary depending on what it does with the data. How the obligations fall between them turns substantially on the contract that section 8(2) of the Act requires before a Data Processor is engaged, and on the security provisions Rule 6(1)(f) requires within it. Which party is which in a specific deployment is a question about that deployment.

The interval is eighteen months. The substantive provisions, including the whole children's framework, commence on the expiry of eighteen months from the publication of the Rules on 13 November 2025, which falls in mid-May 2027. What an institution does with that interval depends on how much it already knows about what its systems hold about its learners. Knowing what is collected, by which system, for which stated purpose, is the part that takes time; the classification questions above cannot even be asked until that is written down.

Advice on an institution's own facts

Whether any of this changes anything at a particular school, college or training provider depends on what that institution actually collects, from whom, for what stated purpose, and under what arrangement with whoever holds it. Those are questions for the institution's own legal advisers and for whoever carries its data protection responsibilities. A blog post — this one included — is not a basis for changing a child-protection practice.

Frequently asked questions

Are schools exempt from the DPDP Act?

No. Rule 12(1) read with Part A of the Fourth Schedule disapplies sub-sections (1) and (3) of section 9 for educational institutions, subject to a condition specified in that Part. That is a disapplication of two children's-data provisions within one section, not an exemption from the Act or the Rules generally. Notice, security safeguards, retention and erasure, breach intimation and data principal rights continue to apply.

Does a school need verifiable parental consent under DPDP?

Section 9(1) requires the verifiable consent of a parent or lawful guardian before processing a child's personal data. Rule 12(1) disapplies it for educational institutions only within the condition recorded in the Fourth Schedule, which is written in terms of tracking and behavioural monitoring for the institution's educational activities or the safety of enrolled children. Processing falling outside that condition is not covered by the disapplication. How far the condition reaches is not settled by the text, and whether it covers a given activity at a given institution is a question for that institution's own advisers.

What does the Fourth Schedule say about educational institutions?

Educational institutions are entry 3 in Part A. The condition recorded against that entry is, in the words of the Schedule, that processing is restricted to tracking and behavioural monitoring - (a) for the educational activities of such institution; or (b) in the interests of safety of children enrolled with such institution.

Is section 9(2) affected by the disapplication?

On the text, no. Rule 12 names sub-sections (1) and (3) of section 9 only. The prohibition in sub-section (2) on processing likely to cause a detrimental effect on the wellbeing of a child is named in neither sub-rule and so is not disapplied for any class in the Fourth Schedule.

Does the exemption cover a person with disability who has a lawful guardian?

Section 9(1) covers a child or a person with disability who has a lawful guardian. Rule 12(1) is worded for processing of personal data of a child, so on its face it does not extend to that second category. Rule 11 sets out separate due diligence where consent is given by a lawful guardian, including verifying the guardian's appointment by a court, by a designated authority under the Rights of Persons with Disabilities Act, 2016, or by a local level committee.

Who counts as a child under the DPDP Act?

An individual who has not completed eighteen years of age. In a school setting that covers essentially the whole student body, and in a college it covers part of the first-year intake.

When do the children's data provisions commence?

Rule 1(2) sets a three-part commencement. The rules carrying notice and consent, security safeguards, retention and erasure, breach intimation, data principal rights and the children's data framework take effect on the expiry of eighteen months from the publication of the Rules on 13 November 2025, which falls in mid-May 2027.

Does an at-risk-learner score count as behavioural monitoring?

That is genuinely open. Both readings are arguable on the text, and we are not aware of any guidance from the Central Government or the Board addressing it. This post sets out the two readings and deliberately does not choose between them.

Sources

Every provision described above is in the public domain. The post relies on the following, and on nothing else.

  • The Digital Personal Data Protection Act, 2023 — sections 2 (definitions), 8(2) (engagement of a Data Processor under a valid contract) and 9 (children and persons with disability). Published on the Ministry of Electronics and Information Technology website.
  • The Digital Personal Data Protection Rules, 2025 — notified in the Official Gazette on 13 November 2025 by notification G.S.R. 846(E). Rules relied on: 1(2) (commencement), 3 (notice), 6 (reasonable security safeguards, including 6(1)(f)), 7 (breach intimation), 10 (verifiable consent for a child), 11 (consent by a lawful guardian) and 12 (exemptions), together with the Fourth Schedule, Part A entries 3 to 5 and Part B.

Quotations from the Rules and the Fourth Schedule are reproduced from the notified text. Where this post characterises rather than quotes, it says so. Nothing here reports the affairs of any client, institution or individual, and no figure in this post is our own estimate.

Where this connects to the rest of the series

This post sits inside a wider read of the Rules from inside a learning platform. The overview — the three commencement phases, who the Rules treat as a Data Fiduciary in a learning context, the security, retention and breach provisions, and the penalty structure — is in DPDP for LMS and Edtech: what the Rules say, and when they apply.

The part of this that is practical rather than interpretive is usually the inventory. Before an institution can ask whether an activity sits inside a condition, someone has to be able to say what the systems hold, which plugin or integration put it there, what a SCORM package sends onward, and what a reporting export quietly accumulated. That question comes up in almost every deployment conversation we have, and it is answerable.

Want to map what your learning platform actually holds about students?

Book a Free Demo

Full product detail: the edzlms platform

Tags

DPDPchildren's dataschoolsparental consentdata protectionIndia

See EdzLMS in action.

Book a 45-minute demo tailored to your industry.

Book a Free Demo →