Take one child in your school. Let's call her Meera, Class 5.
Your school knows her full name, date of birth, home address and photograph. It knows both parents' phone numbers, their jobs and perhaps their income bracket if there's a fee concession. It knows her blood group, her peanut allergy, her marks in every subject since nursery, her attendance, her bus stop, and the time she gets off the bus each afternoon.
Now multiply that by every student. Then add your teachers' salaries, bank details and ID proofs.
A school is one of the most data-rich places a child will ever be part of. For years, that data sat in registers and nobody thought much about it. Today it sits in software, apps, WhatsApp groups and Excel sheets on personal laptops. And India now has a law that cares about where it goes.
A note before we start. We make school software. We are not lawyers, and this article is not legal advice. It's a plain-language guide to help you ask better questions of your vendor, your staff and your legal adviser.
The short answer
The Digital Personal Data Protection (DPDP) Act, 2023 applies to schools, because schools collect and use digital personal data. Anyone under 18 is a child under the Act, so almost all of your student data gets extra protection. Schools need to know what data they hold, keep it secure, limit who sees it, and hold their software vendors to the same standard. The detailed Rules were notified in November 2025, and most duties are being phased in, so this is the time to get ready.
The DPDP Act in plain words
Here is the gist, without the legal language.
-
You are a "data fiduciary": That's the law's term for any organisation that decides why and how personal data is used. A school fits.
-
Parents and students are "data principals": The data is about them, and they have rights over it.
-
Your ERP vendor is a "data processor": They handle data on your behalf. The key point is that the responsibility stays with the school, even when a vendor does the processing.
-
A child is anyone under 18: So nearly every student record is a child's data.
-
Children's data gets special care. The Act asks for verifiable parental consent before processing a child's data. It also restricts tracking, behavioural monitoring and advertising aimed at children.
-
Schools get some relief: The 2025 Rules give educational institutions limited exemptions for activities tied to education and student safety. These come with conditions, and they are not a free pass. Ask your legal adviser exactly what they cover for you.
-
Security is not optional: Reasonable safeguards are required, breaches have to be reported, and penalties for serious failures can run into hundreds of crores of rupees.
On timing: the Rules were notified in November 2025, with most obligations taking effect after a transition period. The government has also discussed shortening that window. Check the current dates on the Ministry of Electronics and IT website, or with your adviser. Don't rely on any blog for them, including this one.
Six things your school software must get right
Here's what to look for, in plain terms.
1. Access by role
A class teacher should see her own class. The accountant should see fees, but not medical notes. The transport in-charge should see names, stops and phone numbers, nothing more. Parents see only their own child. If everyone shares one admin password, you don't have security. You have a shared notebook.
2. Individual logins and a trail
Every staff member gets their own login. The system should record who viewed, changed or exported what. When a teacher resigns, their access ends that day.
3. Security basics
Data should be encrypted when stored and when it travels. Passwords should be strong. Sessions should time out. The vendor should be able to explain all this in simple language. If they can't, that tells you something.
4. Backups, and proof they work
Ask how often data is backed up, where it's kept and when the vendor last restored from a backup as a test. A backup that has never been tested is a hope, not a backup.
5. Collect only what you need
This is called data minimisation. Does your admission form really need parents' income, religion or ID numbers for every child? If there's no clear school purpose, don't collect it. Data you don't hold can't leak.
6. Export and deletion
You should be able to take all your data out in a standard format if you change vendors. And when a record is no longer needed, there should be a way to delete or archive it. "Keep everything forever" is no longer a safe default.
Ten questions to ask your ERP vendor
Put these in an email, and keep the reply on file.
-
Where exactly is our data hosted?
-
Who in your company can access it, and under what controls?
-
Is data encrypted at rest and in transit?
-
How do role-based permissions work? Can we design our own roles?
-
Do you keep an audit log of views, edits and exports?
-
How often do you back up, and when did you last test a restore?
-
If there's a breach, how quickly will you inform us, and what help will you give?
-
Which other companies handle our data through your product, such as SMS, WhatsApp, payment or hosting providers?
-
Can we export all our data at any time, at no cost?
-
When our contract ends, how is our data deleted, and will you confirm it in writing?
A vendor who answers these calmly has thought about them before. One who gets irritated probably hasn't.
Ask for a data processing clause in your contract too. It should say the vendor handles data only on your instructions, keeps it secure, tells you about incidents and deletes it at the end.
It's not only about software
Most school data leaks don't involve hackers. They involve habits. Here are the usual ones.
-
Class WhatsApp groups that expose every parent's number to forty others. Moving to a school mobile app and official WhatsApp messaging from the ERP removes this risk.
-
Excel exports of full student lists sitting on personal laptops and pen drives.
-
Student photos on social media with full names and classes, without clear parental consent.
-
Shared passwords written on a sticky note in the office.
-
Ex-staff logins are still active months after they've left.
-
Third-party forms, such as free online form tools used for admissions, where nobody knows where the data goes.
Fixing these costs almost nothing. It takes a one-page policy, a 30-minute staff briefing each year and someone senior who cares.
A word on consent
Consent is where schools feel most unsure, so here's a practical approach to discuss with your adviser.
-
Be open at admission. Tell parents, in simple words, what you collect, why, and who it's shared with, such as the ERP provider, the payment gateway and the transport tracker.
-
Separate the optional things. Running the school, such as attendance, exams and fees, is one matter. Photos on Instagram, third-party learning apps and biometric attendance are another. Ask for clear, separate permission for these, and let parents say no.
-
Keep a record. Note who agreed to what, and when. An ERP can store this against the student.
-
Make it easy to update or withdraw. Parents should know who to contact.
A 7-step readiness checklist
-
Name one person responsible for data protection in the school.
-
Make the data map from the table above.
-
Trim your admission form to what you really need.
-
Set up roles and individual logins in your ERP. Remove old accounts.
-
Send the ten questions to every vendor who handles your data.
-
Write a one-page staff policy on WhatsApp, exports, photos and passwords.
-
Get a lawyer to review your consent wording and vendor contracts.
You can do steps 1 to 6 this term, with no new budget.
How One Flawless approaches student data
One Flawless is a secure, cloud-based school ERP with separate logins and role-based dashboards for management, staff, students and parents. Parents see only their own child's information. Communication goes through the app and a central parent communication portal, not through personal phones. We've also said publicly that your data is yours and can be exported in standard formats.
We won't claim that any software makes a school "DPDP compliant" by itself. It doesn't. Compliance depends on your policies and practices, with the software as one part. What good software does is make the right habits easy.
Shortlisting vendors? Put the security questions above alongside the functional ones in our guide on how to choose the best school ERP software in India.
Ask us the ten questions
Book a free demo and bring the list. We'll show you how roles and permissions work, tell you where your data is hosted and how it's backed up, and answer in writing. If any vendor, including us, can't do that, you've learned what you needed to know.
Frequently Asked Questions
1. Does the DPDP Act apply to schools?
Yes. Schools collect and use digital personal data of students, parents and staff, so they need to understand their duties under the Act and its Rules.
2. Who is a "child" under the DPDP Act?
Anyone below 18 years of age. That means almost every student's record counts as children's data and gets extra protection.
3. Do schools need parental consent to process student data?
The Act asks for verifiable parental consent for children's data, while the Rules give educational institutions limited exemptions for certain purposes. Get legal advice on how this applies to your school.
4. Who is responsible if the ERP vendor has a data breach?
The school remains responsible for the data it collects, even when a vendor processes it. That's why vendor checks and a clear contract matter.
5. What should schools ask software vendors about data security?
Ask about hosting location, access controls, encryption, audit logs, backups, breach response, third parties involved, data export and deletion at contract end.
6. Is this article legal advice?
No. It's a practical guide from a school software provider. Please consult a qualified legal or privacy professional for advice specific to your school.
