dpdp

DPDP Compliance Checklist for EdTech Companies in India 2026

JO
Joginder Poswal
07 Jun 2026 3 min read
Share:
DPDP Compliance Checklist for EdTech Companies in India 2026

If you run an edtech platform in India, complying with the DPDP rules is trickier for you than for most other businesses. And most edtech founders don't know that yet.

Here's your thing: you're not just a Data Fiduciary. You might also be collecting data about children. Under the DPD, children's data, meaning anyone under 18, needs the highest level of protection and parental consent.

Let's break down what this means for your children's data problem

If your platform has school students, you're handling one of the most sensitive types of data under the Act. For anyone under 18, you must get real, verifiable parental consent before collecting their data. A simple checkbox labelled I confirm I’m 18" isn't enough. It has to be truly verifiable.

The government is still deciding in detail what “verifiable” means, but the message is clear: you can't just assume a user is an adult. EdTech platforms serving K–12 students need to add real age verification and parent consent steps to their products. Can't you also collect a child's data for behavioral profiling or targeted advertising? That's missing. That's not allowed.

Your Data You're Probably Collecting

Take a moment to consider all the data your platform collects:

  • Name, age, grade, parents' school

  • Parent's email and phone

  • Learning history, test scores, and progress records

  • Session recordings and video call data

  • Payment information (if parents pay directly)

  • Device and location data

All of this counts as personal data, and most of it is sensitive. Many edtech platforms store this information in databases without proper access controls or a clear deletion schedule and use third-party tools without data processing agreements.

Your DPDP Compliance Checklist (EdTech Edition)

Consent and age verification

  • Map every point where you collect student or parent data

  • Build age verification for any student-facing signup

  • Get parental consent for users under 18, with a clear consent notice

  • Make withdrawing consent just as easy as giving it

Privacy notices

  • Update your privacy policy so it's easy to understand, using plain English or the user's preferred language.

  • Specifically explain how you use student data, learning data, and parent information.

  • State clearly that student data will not be used for advertising

Data storage and access

  • Audit who in your team has access to student data

  • Ensure your cloud storage and databases have proper access controls

  • Set data retention schedules, and delete a student's account if it is inactive for a reasonable period

Third-party tools

  • List every third-party tool that touches student or parent data (LMS, video conferencing, payment gateway, CRM, email platform)

  • Get Data Processing Agreements in place with each vendor

  • Check that your video conferencing vendor isn't storing recordings beyond your specified retention period

Breach readiness

  • Build a process to detect and report a data breach within 72 hours

  • Know who contacts the DPBI, and what information to provide

The Deadline That Matters

May 13, 2027, is the full compliance deadline. But the Consent Manager Framework goes live in November 2026. EdTech platforms that rely on consent, and you definitely do, need to be ready for Consent Manager integration. That's then, less than 18 months from now. Building parental consent flows, age verification, and vendor contracts takes longer than most founders think.

Check the platform's DPDP compliance score for free atdcomply.in/tools. The assessment is tailored to your data types and provides a prioritized list of fixes.

Found this useful? Share it:

Ready to Get DPDP Compliant?

Start free and explore All 89 compliance modules

Talk to Sales