DPDPA Exemptions for Schools and Educational Institutions
DPDPA Exemptions for Schools and Educational Institutions
The school's exemption does not travel with the vendor's pitch deck.
The scene
The vendor's sales deck said ‘DPDPA exempt for schools’. The school believed it. The app tracked attendance, which the Rules contemplate. It also profiled students for a scholarship marketplace, which they do not.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Schools are exempt from DPDPA.
Exemptions in the Rules cover specified processing for specified purposes, not all processing.
Read the exemption as a list, not a label.
The vendor is covered by the school's exemption.
The vendor processes for the school; anything it does for itself needs its own basis.
Contract the vendor to the school's purpose only.
What remains
Even where an exemption applies to parts of Section 9, security safeguards, breach intimation and purpose limitation continue to apply.
Monday morning
01 List the purposes for which you rely on an exemption.
02 Check each against the text of the Rules.
03 Remove vendor features that fall outside it.
Questions, answered plainly
Are schools exempt from DPDPA? +
No. The Rules exempt certain processing of children's data by educational institutions for specified purposes, such as educational activities and safety, from some Section 9 requirements. Other obligations continue to apply.
Do EdTech vendors benefit from a school's exemption? +
Only to the extent they process data for the school's exempt purpose on its behalf. Processing for the vendor's own purposes needs its own lawful basis.
Sector · EdTech A child's data is not a cookie. Stop treating it like one. Read →
EdTech & children's data · Deep dive A tick from a twelve-year-old is not a parent's consent. Read →
EdTech & children's data · Deep dive Personalisation is monitoring with a better name. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).