DPDP Act compliance checklist for coaching institutes

What the DPDP Act 2023 and DPDP Rules 2025 require of coaching institutes: notices, consent, parental consent, security, breach reporting, retention and the May 2027 deadline.

12 min read
On this page 18 sections
  1. Does the DPDP Act apply to your institute?
  2. Key dates under the DPDP Rules 2025
  3. Notice and consent
  4. What your notice must say
  5. What valid consent looks like
  6. Leads and legitimate uses
  7. Data you collected before the law applied
  8. Children's data
  9. Security safeguards
  10. Breach reporting
  11. A 72-hour response plan
  12. Retention, deletion and penalties
  13. How long to keep data
  14. Penalties
  15. Rights, grievances and a contact person
  16. Your DPDP compliance checklist
  17. Key takeaways
  18. Frequently asked questions

DPDP Act compliance, for a coaching institute, comes down to five duties: tell students, parents and leads what data you collect and why, get valid consent (a parent's for anyone under 18), protect the data with reasonable security safeguards, report breaches, and delete what you no longer need. Most of these duties under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 apply from May 2027. This checklist turns them into tasks you can assign now.

Does the DPDP Act apply to your institute?

Almost certainly. The Act applies to digital personal data processed in India, including data collected on paper and digitised later (Section 3). An admission form typed into a spreadsheet counts. There is no turnover threshold. The Act does let the government exempt some classes of businesses, including startups, from a few duties (Section 17(3)), so check whether a notification covers you rather than assuming one does.

In the Act's language, your institute is a Data Fiduciary: you decide why and how the data is used. Vendors who handle it for you, such as your LMS, CRM, SMS or WhatsApp provider and cloud host, are Data Processors. You remain responsible for what they do with it (Section 8(1)), and you may use them only under a valid contract (Section 8(2)).

Start by listing what you hold. A typical institute's list looks like this:

DataWhoseWhere it usually sits
Name, phone, class, target exam, cityLeadsCRM, WhatsApp, spreadsheets
Date of birth, photo, address, school, marksStudentsAdmission forms, LMS
Name, phone, occupation, sometimes income for scholarshipsParentsAdmission and scholarship forms
Transaction IDs, invoicesStudents or parentsPayment gateway, accounts
Watch history, test scores, ranks, attendance, doubtsStudentsLMS and app
Device IDs, IP addresses, login recordsStudents and staffApp and server logs

Note who can access each system; every later step depends on this list.

Key dates under the DPDP Rules 2025

The Rules were notified in November 2025 and bring the law into force in phases:

WhenWhat applies
November 2025Definitions and the provisions that set up the Data Protection Board of India
November 2026Registration of consent managers (Rule 4)
May 2027Almost everything an institute must do: notices (Rule 3), security safeguards (Rule 6), breach reporting (Rule 7), retention and erasure (Rule 8), a published contact person (Rule 9), parental consent (Rule 10), data principals' rights (Rule 14) and penalties

These dates come from the notified DPDP Rules, 2025. Check MeitY's website for any later change before you plan around them. Treat May 2027 as the date your work must be finished, not the date it starts.

What your notice must say

Every request for consent must come with, or after, a notice (Section 5). Rule 3 says the notice must make sense on its own, in clear and plain language, and include at least:

  • an itemised list of the personal data you collect;

  • the specific purposes, and the service the data is needed for;

  • a link or other means to withdraw consent, exercise rights and complain to the Data Protection Board.

People must have the option to read it in English or any of the 22 languages in the Eighth Schedule to the Constitution (Section 5(3)). Plan translations, starting with the languages your students and parents actually use.

Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", and limited to the data the purpose needs (Section 6(1)). For an institute that means:

  • no pre-ticked boxes;

  • separate choices for optional uses, such as promotional messages or using a student's result and photo in advertising;

  • withdrawal as easy as giving consent (Section 6(4)): if agreeing took one tap, withdrawing shouldn't need a letter;

  • a record of every notice and consent, because if consent is disputed, you have to prove it (Section 6(10)).

Leads and legitimate uses

Not everything needs a consent form. Section 7(a) allows processing for a purpose for which someone voluntarily gave you their data, as long as they haven't objected. A parent who fills in an enquiry form about your NEET batch can be called back about that batch. If they say they're no longer interested, stop. Putting them on every promotional list for the next two years is a different purpose, so ask for consent.

If the person enquiring is a student under 18, the parental consent rules below apply, so enquiry forms for school-level courses should ask for a parent's details.

An illustrative notice for an enquiry form:

We will use your name, phone number, class and target exam to call or WhatsApp you about the course you asked about. We keep these details for 12 months after our last conversation. Tick the box below if you also want updates about other courses. To withdraw consent, correct or delete your details, or raise a grievance, write to privacy@yourinstitute.in. You can also complain to the Data Protection Board of India.

Data you collected before the law applied

For consent you obtained before these provisions apply, you must send people a notice "as soon as it is reasonably practicable" and may continue processing until they withdraw (Section 5(2)). Plan a notice campaign for current students, alumni and old leads by email, SMS or in-app message.

Children's data

Anyone below 18 is a child under the Act (Section 2(f)). In foundation, board, JEE and NEET batches, that is most of your students. Section 9 adds three rules:

  • get verifiable consent from a parent before processing a child's data, using the checks in Rule 10;

  • don't process data in a way likely to harm a child's well-being;

  • don't track or behaviourally monitor children, or target advertising at them.

Educational institutions get a narrow exemption for tracking and monitoring done for educational activities or for children's safety. It doesn't cover advertising. Our guide to verifiable parental consent explains how to check a parent, what the exemption means and how to design sign-up.

Security safeguards

Section 8(5) requires "reasonable security safeguards to prevent personal data breach", and failing at it carries the Act's highest penalty. Rule 6 lists the minimum. Here is what each item means in an institute:

Rule 6 minimumWhat it looks like in an institute
Encryption, obfuscation, masking or virtual tokensHTTPS on every page and app call; encrypted databases and backups; phone numbers masked in counsellor screens and exports
Access controlIndividual logins with roles; no shared admin passwords; access removed the day someone leaves
Logs, monitoring and reviewA record of who viewed or exported student and lead lists, and someone who checks it
Continued processing after an incidentBackups that you have actually restored in a test
Keeping logs and personal data for one yearLog retention of at least a year, so incidents can be investigated
Security terms in processor contractsA clause in every vendor contract: LMS, CRM, SMS, WhatsApp, cloud
Technical and organisational measuresA named owner, short staff training and a written process

Many real risks are ordinary: a counsellor forwards a lead sheet on WhatsApp, a Google Sheet is shared with "anyone with the link", or a former employee still has a CRM login. Fix those before buying tools. If the terms are new, start with what encryption is, then read encryption at rest vs in transit and encryption vs tokenization.

Breach reporting

The Act defines a personal data breach broadly: any unauthorised processing, or accidental disclosure, sharing, alteration, destruction or loss of access, that compromises personal data (Section 2(u)). A leaked lead list counts. So does ransomware that locks your student database.

Rule 7 sets two duties:

  • Affected people: tell each one without delay, in plain language, what happened, the likely consequences, what you are doing about it, what they can do, and whom to contact.

  • The Data Protection Board: an initial description without delay, then a detailed report within 72 hours of becoming aware of the breach, covering the causes, mitigation, any findings about who caused it and the notices you sent. The Board can allow more time on a written request.

A 72-hour response plan

  1. First hours: contain it. Revoke the leaked link, reset passwords, disable the compromised account and preserve the logs.

  2. Same day: work out whose data, which fields and how many people. Send the Board the initial description.

  3. As soon as you know who is affected: notify each student and parent through the app, SMS or email, with a named contact.

  4. Within 72 hours: file the detailed report with the Board, or ask in writing for more time.

  5. Afterwards: fix the root cause and write down what changed.

Write this plan now, with names and phone numbers, so nobody reads the Rules for the first time during an incident.

Retention, deletion and penalties

How long to keep data

Erase personal data once its purpose is served or consent is withdrawn, unless a law requires you to keep it, and make your vendors erase their copies (Section 8(7)). The Rules also set a floor: keep personal data, traffic data and processing logs for at least one year from the processing (Rule 8(3)). The fixed three-year inactivity periods in the Third Schedule apply only to very large e-commerce, gaming and social media platforms, so an institute sets its own schedule.

DataIllustrative retention
Leads who didn't enrol12 months after the last contact
Enrolled students' learning dataCourse end plus 12 months
Results and photos published with consentUntil consent is withdrawn
Invoices and payment recordsAs long as tax law requires
Server and access logsAt least 12 months

These periods are examples, not legal requirements. Agree yours with your lawyer and accountant, write them down and automate the deletion.

Penalties

BreachMaximum penalty
Failing to take reasonable security safeguards₹250 crore
Failing to notify the Board or affected people of a breach₹200 crore
Breaking the additional obligations for children₹200 crore
Any other breach of the Act or Rules₹50 crore

These are ceilings from the Schedule to the DPDP Act, 2023. When setting an amount, the Board must weigh the nature, gravity and duration of the breach, the type of data, repetition, any gain made, how quickly and effectively you mitigated, and proportionality (Section 33(2)).

Rights, grievances and a contact person

  • Publish on your website and app the contact details of someone who can answer questions about how you use personal data (Rule 9).

  • Publish how students and parents can ask for a summary of their data, a correction or erasure, and which identifier you need, such as an enrolment ID (Rule 14).

  • Publish your grievance response time, which cannot exceed 90 days (Rule 14(3)), and meet it. People must use your grievance process before approaching the Board (Section 13(3)).

  • Let people nominate someone to exercise their rights if they die or become incapacitated (Section 14).

Your DPDP compliance checklist

TaskSuggested owner
1. List every kind of personal data, where it sits and who can access itOperations head
2. Rewrite enquiry, admission and app sign-up forms with a Rule 3 noticeCounselling head, with a lawyer
3. Separate optional consents (marketing, publicity) from required onesMarketing
4. Build parental consent into sign-up and admissions for under-18 studentsTech team or vendor
5. Remove ad pixels and custom audiences that reach under-18 usersMarketing
6. Give everyone individual, role-based logins; remove shared and old onesTech team
7. Encrypt data in transit and at rest, including backupsTech team or vendor
8. Keep logs for at least a year and review exportsTech team or vendor
9. Sign contracts with security and erasure terms with every vendorFounder
10. Write and rehearse the 72-hour breach planOperations head
11. Publish a contact person, a rights process and a grievance timelineOperations head
12. Set a retention schedule and automate deletionTech team, with your accountant
13. Send notices to existing students, parents and leadsCounselling head

When you next compare platforms, add data protection to your LMS features checklist: ask each vendor for its security measures, its breach process and its data processing terms in writing.

Key takeaways

  • The DPDP Act applies to almost every institute, including data first collected on paper.

  • Most duties apply from May 2027. Notices, consent flows and vendor contracts take time, so start now.

  • Anyone under 18 is a child: you need verifiable parental consent, and you must not track children or target ads at them.

  • Rule 6 sets minimum safeguards: encryption or masking, access control, logs kept for a year, backups and vendor contracts.

  • Tell affected people about a breach without delay, and send the Board a detailed report within 72 hours.

This is general information, not legal advice. For your situation, speak to a lawyer.

Frequently asked questions

What is DPDP Act in simple words?

The Digital Personal Data Protection Act, 2023 is India's data protection law. Organisations may use a person's digital personal data only for a lawful purpose, usually with that person's consent. They must protect it, report breaches and delete it once it is no longer needed. People get rights to access, correct and erase their data, and the Data Protection Board can impose penalties of up to ₹250 crore.

Is DPDP Act in force in India?

Partly. Parliament passed the Act in August 2023 and the government notified the Rules in November 2025. The provisions that set up the Data Protection Board applied at once, consent manager registration follows in November 2026, and most duties on businesses, including notices, consent, security, breach reporting, children's data and penalties, apply from May 2027. Check MeitY's website for any later change to these dates.

Is DPDP Act retrospective?

Its duties apply from the dates they come into force, not to earlier conduct. It does, however, reach data you already hold. Where you collected data with consent before the Act applied, you must send people a notice as soon as reasonably practicable, and you may continue processing until they withdraw consent (Section 5(2)). Old lead lists, alumni records and past students' data are all covered.

What is DPDP Act compliance?

It means running your data practices so they meet the Act and the Rules: a clear notice and valid consent (a parent's for under-18s), reasonable security safeguards, breach reporting on time, erasure when data is no longer needed, a published contact person and a working grievance process. For an institute, it also means proper contracts with every vendor that handles student or lead data on your behalf.

Share this article

Looking for something else?

Talk to Us