
EdTech & Online Learning
DPDPA Impact on EdTech & Online Learning
EdTech platforms routinely process the personal data of learners who are children — placing verifiable parental consent and the prohibition on behavioural monitoring at the centre of compliance.
In short
EdTech and online-learning platforms fall under the DPDP Act, 2023 because they process the personal data of learners, many of whom are children. Verifiable parental consent under Section 9 read with Rule 10 is central, and behavioural monitoring or targeted advertising directed at children is prohibited.
- Where learners are children, verifiable parental consent is required under Section 9 read with Rule 10 before processing.
- Behavioural tracking and targeted advertising directed at children are prohibited.
- Analytics and proctoring vendors must be engaged under a valid Section 8(2) contract.
When the Act applies
The Act applies to learner and parent personal data processed in India, and to platforms outside India offering learning services to Data Principals in India.
Personal data typically in play
- Learner and parent account data
- Age and school/institution details
- Assessment, progress and engagement analytics
- Payment references
- Session recordings and support chats
Mapped obligations
Children & persons with disability
Obtain verifiable consent of a parent or lawful guardian before processing a child’s personal data, and do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Itemised notice
Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.
Consent that is free & withdrawable
Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.
Retention limits & erasure
Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.
Reasonable security safeguards
Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.
Breach intimation
On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).
Data Principal rights
Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.
Recurring compliance risks
- Onboarding children without verifiable parental consent
- Behavioural monitoring or targeted advertising directed at children
- Retaining learner data beyond the course or subscription
- Analytics vendors processing learner data without a Section 8(2) contract
Actions that follow
- 1Implement verifiable parental-consent flows for child learners
- 2Disable behavioural tracking and targeted ads for children
- 3Minimise and time-box learner analytics
- 4Contract analytics and proctoring vendors under Section 8(2)
