The DPDP Act for Indian preschools: what to do before 13 May 2027

India's data protection law now covers every preschool holding children's records. What the Act actually asks of you, in plain English, and the order to tackle it in.

9 min read · Updated 3 September 2026 · Written by the team at TantraDev

Why this became urgent

The Digital Personal Data Protection Act was passed in 2023, but for most schools nothing changed, because the rules that make it operable had not been notified. That happened on 14 November 2025, and the compliance clock started with it. Full compliance is expected by 13 May 2027.

If you run a preschool, you are in scope. Not because anyone singled out preschools, but because the Act covers anyone who decides what happens to digital personal data — and a preschool holds an unusually sensitive set of it: names, dates of birth, photographs, allergies, medical notes, who is permitted to collect a child, and home addresses.

In the language of the Act your school is the Data Fiduciary: the one who decides what happens to that data, and the one answerable for it. Your software vendor is a Data Processor acting on your instructions. The responsibility does not transfer when you buy software.

Children's data has its own rules

Section 9 sets a higher bar for anyone under eighteen, which for a preschool means every single child on the register. Two obligations matter most in practice.

Verifiable parental consent. A child’s personal data may be processed only with the consent of a parent or lawful guardian, and that consent must be verifiable — you must be able to demonstrate it was given, by whom, and for what. A verbal “yes” at the school gate does not survive that test. Nor, generally, does a single tick box that covers everything at once, because consent has to be specific about purpose.

No tracking or targeted advertising directed at children. The Act prohibits behavioural monitoring and targeted advertising aimed at children. For a preschool this mostly means being careful about what you allow third parties to do with the data you collect.

What the Act actually asks of a school

Stripped of the legal drafting, the obligations that will affect you day to day are:

  • Give notice (s.5). Before or when you take a parent’s consent, tell them in clear language what data you are collecting, what you will use it for, how they can exercise their rights, and how to complain to the Data Protection Board.
  • Take consent properly (s.6). Free, specific, informed and unambiguous, given by a clear affirmative act — and withdrawable as easily as it was given.
  • Keep it secure (s.8(5)). Reasonable safeguards, proportionate to how sensitive the data is. Children’s health notes in a class WhatsApp group are the most common failure here.
  • Report a breach (s.8(6)). If data is exposed, you must inform the Data Protection Board of India and the affected parents.
  • Erase when done (s.8(7)). When consent is withdrawn or the purpose has been served, delete the data — unless a law requires you to keep it.
  • Name someone (s.8(10), s.13). Publish a contact who can answer questions and handle grievances, and actually answer them.
  • Contract your processors (s.8(2)). Anyone handling this data on your behalf — software, photographer, transport contractor — must be under a written contract.

A sensible order to do this in

None of this needs to happen at once, and trying to do it all in a week is how it stalls. A workable sequence for a small school:

  • Name your grievance contact. One person, with an email address, told to parents. This is the cheapest item on the list and one of the few that is simply missing rather than partly done at most schools.
  • Fix the admission form. Add a short, readable data notice covering what you collect, why, and who to contact. Separate the photo-sharing consent from the rest, because it is the one parents most often want to treat differently.
  • Find out where the data actually is. Not where it is supposed to be — where it is. Staff phones, personal drives, old WhatsApp exports, a cupboard of paper forms. You cannot secure or erase what you cannot locate.
  • Narrow who can see what. A class teacher does not need another class’s medical notes; a transport helper does not need fee history.
  • Get your vendor contracts in place with anyone processing on your behalf.
  • Decide what happens to leavers. A retention period, then deletion. Keeping every register since 2015 because nobody deleted it is itself a risk.

What software can and cannot do about it

It is worth being clear-eyed here, because plenty of vendors are not. A large part of this list is process, and no platform fixes it for you: naming a person, rewriting your admission form, signing contracts, deciding a retention period. Those remain yours whichever system you use, and they are worth doing even if you never buy software at all.

Where software genuinely helps is the record-keeping half — holding consent as a dated record you can produce later rather than a memory, checking it automatically before a photograph is shared, keeping access scoped to a person’s actual role, and leaving a trail when someone asks to see, correct or delete their child’s data. That is the part that is tedious and error-prone to do by hand, and it is the part that falls over first when a school grows past one branch.

If you want a quick sense of where your school currently stands, our ten-question readiness check walks the obligations above and tells you which ones you have covered. It takes about five minutes, nothing is sent anywhere, and it will not tell you that you are compliant — no self-assessment honestly can.

Where to read the source

The Act itself is worth a look — it is short by the standards of Indian legislation. The Ministry of Electronics and Information Technology publishes the text and the notified rules. For anything consequential, take advice: this article is written by software engineers who have read the Act closely in order to build against it, not by lawyers.

If your school would like to talk any of this through, we are at admin@tantradev.com.