Skip to content
← All resources

Compliance · 20 May 2026 · 6 min read

A practical DPDP checklist for schools

The Digital Personal Data Protection Act is coming. Here’s what a school should have in place before 2027.

In short - Before DPDP enforcement in 2027, a school should map every data category to a lawful purpose and plain-language notice, capture verifiable parental consent for children, honour access, correction and erasure on a clock, and run a dual CERT-In and Data Protection Board breach response.

India’s Digital Personal Data Protection Act, 2023 phases in through 2027. For a school - which holds a great deal of children’s data - the operative obligations are significant, with penalties that are not.

Start with lawful basis and notice: every category of data should map to a clear purpose, described to parents in plain language. For children’s data, consent must be verifiable - the consenting adult identified, and the parent-child link retained as evidence.

Then data-principal rights: parents and staff can ask to access, correct or erase their data, and you must be able to honour that within DPDP’s timelines. Erasure has to fan out across every system that holds the record.

Finally, breach response: a dual clock to CERT-In (6 hours) and the Data Protection Board (72 hours), running concurrently. Vidyom builds these in so the school is ready before the deadline, not scrambling after it.

Get started

See it on your own school’s data

Register or book a demo. We set you up and migrate your data, with nothing lost.

Register your schoolBook a demo