Skip to content

EdTech and schools

DPDP compliance for EdTech: most of your users are children

Under the Act anyone under 18 is a child. For an EdTech business that is most of the people it serves, so the extra duties for children's data apply to almost everything it does.

The data you hold

  • Student names, classes and dates of birth
  • Parent contact details
  • Class recordings
  • Quiz scores and progress
  • Tutor notes

What the Act asks of you

Verifiable consent from a parent
Before processing a child's data, get the consent of a parent or guardian, and check that the person giving it is an identifiable adult. A ticked box on sign-up is not enough.
Section 9(1), Rule 10
No tracking, monitoring or targeted ads
Children can't be tracked, behaviourally monitored or shown targeted advertising. The Rules exempt some processing by educational institutions; check whether your activity is covered before relying on it.
Section 9(3), Fourth Schedule
Recordings and notes don't last forever
Class recordings, quiz history and tutor notes have to be erased once their purpose is served, unless a law requires keeping them.
Section 8(7)
Video and messaging vendors under contract
Video-class platforms, messaging services and analytics tools that handle student data must work under a valid contract.
Section 8(2)

How GRC Flow handles it

  • Discovery flags dates of birth under 18 as children's data, and health details hidden in notes.

    See how it works
  • Consent records show who consented, when, and for which purpose; DPIAs cover profiling features.

    See how it works
  • The privacy notice adds a section for parents when children's data is in scope.

    See how it works