DPDP Act compliance checklist for coaching institutes
What the DPDP Act 2023 and DPDP Rules 2025 require of coaching institutes: notices, consent, parental consent, security, breach reporting, retention and the May 2027 deadline.
On this page 18 sections
- Does the DPDP Act apply to your institute?
- Key dates under the DPDP Rules 2025
- Notice and consent
- What your notice must say
- What valid consent looks like
- Leads and legitimate uses
- Data you collected before the law applied
- Children's data
- Security safeguards
- Breach reporting
- A 72-hour response plan
- Retention, deletion and penalties
- How long to keep data
- Penalties
- Rights, grievances and a contact person
- Your DPDP compliance checklist
- Key takeaways
- Frequently asked questions
DPDP Act compliance, for a coaching institute, comes down to five duties: tell students, parents and leads what data you collect and why, get valid consent (a parent's for anyone under 18), protect the data with reasonable security safeguards, report breaches, and delete what you no longer need. Most of these duties under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 apply from May 2027. This checklist turns them into tasks you can assign now.
Does the DPDP Act apply to your institute?
Almost certainly. The Act applies to digital personal data processed in India, including data collected on paper and digitised later (Section 3). An admission form typed into a spreadsheet counts. There is no turnover threshold. The Act does let the government exempt some classes of businesses, including startups, from a few duties (Section 17(3)), so check whether a notification covers you rather than assuming one does.
In the Act's language, your institute is a Data Fiduciary: you decide why and how the data is used. Vendors who handle it for you, such as your LMS, CRM, SMS or WhatsApp provider and cloud host, are Data Processors. You remain responsible for what they do with it (Section 8(1)), and you may use them only under a valid contract (Section 8(2)).
Start by listing what you hold. A typical institute's list looks like this:
| Data | Whose | Where it usually sits |
|---|---|---|
| Name, phone, class, target exam, city | Leads | CRM, WhatsApp, spreadsheets |
| Date of birth, photo, address, school, marks | Students | Admission forms, LMS |
| Name, phone, occupation, sometimes income for scholarships | Parents | Admission and scholarship forms |
| Transaction IDs, invoices | Students or parents | Payment gateway, accounts |
| Watch history, test scores, ranks, attendance, doubts | Students | LMS and app |
| Device IDs, IP addresses, login records | Students and staff | App and server logs |
Note who can access each system; every later step depends on this list.
Key dates under the DPDP Rules 2025
The Rules were notified in November 2025 and bring the law into force in phases:
| When | What applies |
|---|---|
| November 2025 | Definitions and the provisions that set up the Data Protection Board of India |
| November 2026 | Registration of consent managers (Rule 4) |
| May 2027 | Almost everything an institute must do: notices (Rule 3), security safeguards (Rule 6), breach reporting (Rule 7), retention and erasure (Rule 8), a published contact person (Rule 9), parental consent (Rule 10), data principals' rights (Rule 14) and penalties |
These dates come from the notified DPDP Rules, 2025. Check MeitY's website for any later change before you plan around them. Treat May 2027 as the date your work must be finished, not the date it starts.
Notice and consent
What your notice must say
Every request for consent must come with, or after, a notice (Section 5). Rule 3 says the notice must make sense on its own, in clear and plain language, and include at least:
- an itemised list of the personal data you collect;
- the specific purposes, and the service the data is needed for;
- a link or other means to withdraw consent, exercise rights and complain to the Data Protection Board.
People must have the option to read it in English or any of the 22 languages in the Eighth Schedule to the Constitution (Section 5(3)). Plan translations, starting with the languages your students and parents actually use.
What valid consent looks like
Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", and limited to the data the purpose needs (Section 6(1)). For an institute that means:
- no pre-ticked boxes;
- separate choices for optional uses, such as promotional messages or using a student's result and photo in advertising;
- withdrawal as easy as giving consent (Section 6(4)): if agreeing took one tap, withdrawing shouldn't need a letter;
- a record of every notice and consent, because if consent is disputed, you have to prove it (Section 6(10)).
Leads and legitimate uses
Not everything needs a consent form. Section 7(a) allows processing for a purpose for which someone voluntarily gave you their data, as long as they haven't objected. A parent who fills in an enquiry form about your NEET batch can be called back about that batch. If they say they're no longer interested, stop. Putting them on every promotional list for the next two years is a different purpose, so ask for consent.
If the person enquiring is a student under 18, the parental consent rules below apply, so enquiry forms for school-level courses should ask for a parent's details.
An illustrative notice for an enquiry form:
We will use your name, phone number, class and target exam to call or WhatsApp you about the course you asked about. We keep these details for 12 months after our last conversation. Tick the box below if you also want updates about other courses. To withdraw consent, correct or delete your details, or raise a grievance, write to privacy@yourinstitute.in. You can also complain to the Data Protection Board of India.
Data you collected before the law applied
For consent you obtained before these provisions apply, you must send people a notice "as soon as it is reasonably practicable" and may continue processing until they withdraw (Section 5(2)). Plan a notice campaign for current students, alumni and old leads by email, SMS or in-app message.
Children's data
Anyone below 18 is a child under the Act (Section 2(f)). In foundation, board, JEE and NEET batches, that is most of your students. Section 9 adds three rules:
- get verifiable consent from a parent before processing a child's data, using the checks in Rule 10;
- don't process data in a way likely to harm a child's well-being;
- don't track or behaviourally monitor children, or target advertising at them.
Educational institutions get a narrow exemption for tracking and monitoring done for educational activities or for children's safety. It doesn't cover advertising. Our guide to verifiable parental consent explains how to check a parent, what the exemption means and how to design sign-up.
Security safeguards
Section 8(5) requires "reasonable security safeguards to prevent personal data breach", and failing at it carries the Act's highest penalty. Rule 6 lists the minimum. Here is what each item means in an institute:
| Rule 6 minimum | What it looks like in an institute |
|---|---|
| Encryption, obfuscation, masking or virtual tokens | HTTPS on every page and app call; encrypted databases and backups; phone numbers masked in counsellor screens and exports |
| Access control | Individual logins with roles; no shared admin passwords; access removed the day someone leaves |
| Logs, monitoring and review | A record of who viewed or exported student and lead lists, and someone who checks it |
| Continued processing after an incident | Backups that you have actually restored in a test |
| Keeping logs and personal data for one year | Log retention of at least a year, so incidents can be investigated |
| Security terms in processor contracts | A clause in every vendor contract: LMS, CRM, SMS, WhatsApp, cloud |
| Technical and organisational measures | A named owner, short staff training and a written process |
Many real risks are ordinary: a counsellor forwards a lead sheet on WhatsApp, a Google Sheet is shared with "anyone with the link", or a former employee still has a CRM login. Fix those before buying tools. If the terms are new, start with what encryption is, then read encryption at rest vs in transit and encryption vs tokenization.
Breach reporting
The Act defines a personal data breach broadly: any unauthorised processing, or accidental disclosure, sharing, alteration, destruction or loss of access, that compromises personal data (Section 2(u)). A leaked lead list counts. So does ransomware that locks your student database.
Rule 7 sets two duties:
- Affected people: tell each one without delay, in plain language, what happened, the likely consequences, what you are doing about it, what they can do, and whom to contact.
- The Data Protection Board: an initial description without delay, then a detailed report within 72 hours of becoming aware of the breach, covering the causes, mitigation, any findings about who caused it and the notices you sent. The Board can allow more time on a written request.
A 72-hour response plan
- First hours: contain it. Revoke the leaked link, reset passwords, disable the compromised account and preserve the logs.
- Same day: work out whose data, which fields and how many people. Send the Board the initial description.
- As soon as you know who is affected: notify each student and parent through the app, SMS or email, with a named contact.
- Within 72 hours: file the detailed report with the Board, or ask in writing for more time.
- Afterwards: fix the root cause and write down what changed.
Write this plan now, with names and phone numbers, so nobody reads the Rules for the first time during an incident.
Retention, deletion and penalties
How long to keep data
Erase personal data once its purpose is served or consent is withdrawn, unless a law requires you to keep it, and make your vendors erase their copies (Section 8(7)). The Rules also set a floor: keep personal data, traffic data and processing logs for at least one year from the processing (Rule 8(3)). The fixed three-year inactivity periods in the Third Schedule apply only to very large e-commerce, gaming and social media platforms, so an institute sets its own schedule.
| Data | Illustrative retention |
|---|---|
| Leads who didn't enrol | 12 months after the last contact |
| Enrolled students' learning data | Course end plus 12 months |
| Results and photos published with consent | Until consent is withdrawn |
| Invoices and payment records | As long as tax law requires |
| Server and access logs | At least 12 months |
These periods are examples, not legal requirements. Agree yours with your lawyer and accountant, write them down and automate the deletion.
Penalties
| Breach | Maximum penalty |
|---|---|
| Failing to take reasonable security safeguards | ₹250 crore |
| Failing to notify the Board or affected people of a breach | ₹200 crore |
| Breaking the additional obligations for children | ₹200 crore |
| Any other breach of the Act or Rules | ₹50 crore |
These are ceilings from the Schedule to the DPDP Act, 2023. When setting an amount, the Board must weigh the nature, gravity and duration of the breach, the type of data, repetition, any gain made, how quickly and effectively you mitigated, and proportionality (Section 33(2)).
Rights, grievances and a contact person
- Publish on your website and app the contact details of someone who can answer questions about how you use personal data (Rule 9).
- Publish how students and parents can ask for a summary of their data, a correction or erasure, and which identifier you need, such as an enrolment ID (Rule 14).
- Publish your grievance response time, which cannot exceed 90 days (Rule 14(3)), and meet it. People must use your grievance process before approaching the Board (Section 13(3)).
- Let people nominate someone to exercise their rights if they die or become incapacitated (Section 14).
Your DPDP compliance checklist
| Task | Suggested owner |
|---|---|
| 1. List every kind of personal data, where it sits and who can access it | Operations head |
| 2. Rewrite enquiry, admission and app sign-up forms with a Rule 3 notice | Counselling head, with a lawyer |
| 3. Separate optional consents (marketing, publicity) from required ones | Marketing |
| 4. Build parental consent into sign-up and admissions for under-18 students | Tech team or vendor |
| 5. Remove ad pixels and custom audiences that reach under-18 users | Marketing |
| 6. Give everyone individual, role-based logins; remove shared and old ones | Tech team |
| 7. Encrypt data in transit and at rest, including backups | Tech team or vendor |
| 8. Keep logs for at least a year and review exports | Tech team or vendor |
| 9. Sign contracts with security and erasure terms with every vendor | Founder |
| 10. Write and rehearse the 72-hour breach plan | Operations head |
| 11. Publish a contact person, a rights process and a grievance timeline | Operations head |
| 12. Set a retention schedule and automate deletion | Tech team, with your accountant |
| 13. Send notices to existing students, parents and leads | Counselling head |
When you next compare platforms, add data protection to your LMS features checklist: ask each vendor for its security measures, its breach process and its data processing terms in writing.
Key takeaways
- The DPDP Act applies to almost every institute, including data first collected on paper.
- Most duties apply from May 2027. Notices, consent flows and vendor contracts take time, so start now.
- Anyone under 18 is a child: you need verifiable parental consent, and you must not track children or target ads at them.
- Rule 6 sets minimum safeguards: encryption or masking, access control, logs kept for a year, backups and vendor contracts.
- Tell affected people about a breach without delay, and send the Board a detailed report within 72 hours.
This is general information, not legal advice. For your situation, speak to a lawyer.
Frequently asked questions
What is DPDP Act in simple words?
The Digital Personal Data Protection Act, 2023 is India's data protection law. Organisations may use a person's digital personal data only for a lawful purpose, usually with that person's consent. They must protect it, report breaches and delete it once it is no longer needed. People get rights to access, correct and erase their data, and the Data Protection Board can impose penalties of up to ₹250 crore.
Is DPDP Act in force in India?
Partly. Parliament passed the Act in August 2023 and the government notified the Rules in November 2025. The provisions that set up the Data Protection Board applied at once, consent manager registration follows in November 2026, and most duties on businesses, including notices, consent, security, breach reporting, children's data and penalties, apply from May 2027. Check MeitY's website for any later change to these dates.
Is DPDP Act retrospective?
Its duties apply from the dates they come into force, not to earlier conduct. It does, however, reach data you already hold. Where you collected data with consent before the Act applied, you must send people a notice as soon as reasonably practicable, and you may continue processing until they withdraw consent (Section 5(2)). Old lead lists, alumni records and past students' data are all covered.
What is DPDP Act compliance?
It means running your data practices so they meet the Act and the Rules: a clear notice and valid consent (a parent's for under-18s), reasonable security safeguards, breach reporting on time, erasure when data is no longer needed, a published contact person and a working grievance process. For an institute, it also means proper contracts with every vendor that handles student or lead data on your behalf.