EdTech and schools
DPDP compliance for EdTech: most of your users are children
Under the Act anyone under 18 is a child. For an EdTech business that is most of the people it serves, so the extra duties for children's data apply to almost everything it does.
The data you hold
- Student names, classes and dates of birth
- Parent contact details
- Class recordings
- Quiz scores and progress
- Tutor notes
What the Act asks of you
- Verifiable consent from a parent
- Before processing a child's data, get the consent of a parent or guardian, and check that the person giving it is an identifiable adult. A ticked box on sign-up is not enough.
- Section 9(1), Rule 10
- No tracking, monitoring or targeted ads
- Children can't be tracked, behaviourally monitored or shown targeted advertising. The Rules exempt some processing by educational institutions; check whether your activity is covered before relying on it.
- Section 9(3), Fourth Schedule
- Recordings and notes don't last forever
- Class recordings, quiz history and tutor notes have to be erased once their purpose is served, unless a law requires keeping them.
- Section 8(7)
- Video and messaging vendors under contract
- Video-class platforms, messaging services and analytics tools that handle student data must work under a valid contract.
- Section 8(2)
How GRC Flow handles it
Discovery flags dates of birth under 18 as children's data, and health details hidden in notes.
See how it worksConsent records show who consented, when, and for which purpose; DPIAs cover profiling features.
See how it worksThe privacy notice adds a section for parents when children's data is in scope.
See how it works