India’s Digital Personal Data Protection Act, 2023 phases in through 2027. For a school — which holds a great deal of children’s data — the operative obligations are significant, with penalties that are not.
Start with lawful basis and notice: every category of data should map to a clear purpose, described to parents in plain language. For children’s data, consent must be verifiable — the consenting adult identified, and the parent-child link retained as evidence.
Then data-principal rights: parents and staff can ask to access, correct or erase their data, and you must be able to honour that within DPDP’s timelines. Erasure has to fan out across every system that holds the record.
Finally, breach response: a dual clock to CERT-In (6 hours) and the Data Protection Board (72 hours), running concurrently. Vidyom builds these in so the school is ready before the deadline, not scrambling after it.
Ready when you are
See Vidyom for your school
Register your school or book a demo — we’ll set you up and migrate your data.