If you run an edtech platform in India, complying with the DPDP rules is trickier for you than for most other businesses. And most edtech founders don't know that yet.
Here's your thing: you're not just a Data Fiduciary. You might also be collecting data about children. Under the DPD, children's data, meaning anyone under 18, needs the highest level of protection and parental consent.
Let's break down what this means for your children's data problem
If your platform has school students, you're handling one of the most sensitive types of data under the Act. For anyone under 18, you must get real, verifiable parental consent before collecting their data. A simple checkbox labelled I confirm I’m 18" isn't enough. It has to be truly verifiable.
The government is still deciding in detail what “verifiable” means, but the message is clear: you can't just assume a user is an adult. EdTech platforms serving K–12 students need to add real age verification and parent consent steps to their products. Can't you also collect a child's data for behavioral profiling or targeted advertising? That's missing. That's not allowed.
Your Data You're Probably Collecting
Take a moment to consider all the data your platform collects:
Name, age, grade, parents' school
Parent's email and phone
Learning history, test scores, and progress records
Session recordings and video call data
Payment information (if parents pay directly)
Device and location data
All of this counts as personal data, and most of it is sensitive. Many edtech platforms store this information in databases without proper access controls or a clear deletion schedule and use third-party tools without data processing agreements.
Your DPDP Compliance Checklist (EdTech Edition)
Consent and age verification
Map every point where you collect student or parent data
Build age verification for any student-facing signup
Get parental consent for users under 18, with a clear consent notice
Make withdrawing consent just as easy as giving it
Privacy notices
Update your privacy policy so it's easy to understand, using plain English or the user's preferred language.
Specifically explain how you use student data, learning data, and parent information.
State clearly that student data will not be used for advertising
Data storage and access
Audit who in your team has access to student data
Ensure your cloud storage and databases have proper access controls
Set data retention schedules, and delete a student's account if it is inactive for a reasonable period
Third-party tools
List every third-party tool that touches student or parent data (LMS, video conferencing, payment gateway, CRM, email platform)
Get Data Processing Agreements in place with each vendor
Check that your video conferencing vendor isn't storing recordings beyond your specified retention period
Breach readiness
Build a process to detect and report a data breach within 72 hours
Know who contacts the DPBI, and what information to provide
The Deadline That Matters
May 13, 2027, is the full compliance deadline. But the Consent Manager Framework goes live in November 2026. EdTech platforms that rely on consent, and you definitely do, need to be ready for Consent Manager integration. That's then, less than 18 months from now. Building parental consent flows, age verification, and vendor contracts takes longer than most founders think.
Check the platform's DPDP compliance score for free atdcomply.in/tools. The assessment is tailored to your data types and provides a prioritized list of fixes.