On this page
If you run a coaching centre or a school, you hold more personal data than almost any other kind of business on your street. Names, ages, addresses, parents’ phone numbers, attendance, marks, sometimes photographs. And because nearly all of it belongs to someone under eighteen, you are in the strictest corner of India’s data protection law.
This is not an argument for panic. It is an argument for spending a week on it before May 2027, when the substantive obligations and the penalty schedule take effect.
The rule that catches everyone
Under the Digital Personal Data Protection Act, 2023, anyone under eighteen is a child. That is a higher bar than most people assume — a seventeen-year-old preparing for entrance exams is a child under this law, and so is every student in your eleventh-standard batch.
Two things follow, and both of them are absolute:
- You need verifiable consent from a parent or guardian before processing a child’s personal data.
- You may not carry out behavioural monitoring, tracking, or targeted advertising directed at children. At all. There is no consent that unlocks it.
The second one is where most coaching centres are quietly in trouble, and it has nothing to do with admissions paperwork.
The advertising pixel on your results page
Almost every coaching website in the country has a Meta pixel or a Google Ads remarketing tag on it. It was added so that visitors could be shown adverts later, which is ordinary practice and works well.
Now put it on the page where students log in to check their results, or on the batch timetable, or on the admission form itself. That tag is now tracking children for advertising purposes on a page only children and their parents visit.
That is the prohibited thing, in the most literal sense the Act contains. It is also about ten minutes of work to remove, which is why it is worth checking this week rather than next year.
”Verifiable” is doing a lot of work
Ticking a box that says I am a parent is not verifiable consent. Nor is a form filled in by a student who wrote their father’s name in a text field.
What is defensible is a route where the parent is actually the one acting: the admission form is completed by the parent, or a confirmation is sent to the parent’s number and they respond, or the form is signed in person at the office along with the fee receipt. That is the same number most admissions are actually settled on, so it is rarely an extra step to ask for. Most centres in Varanasi already do the last one — the gap is that nobody records the consent as consent, so a year later there is no way to show it happened.
The fix is usually not a new system. It is one extra field on a form you already use, and keeping the record.
Where student data actually lives
When we look at this for a client, the data is never in one place. It is typically:
- the admission register in the office
- an Excel sheet on the front-desk computer, and an older copy on someone’s laptop
- two or three WhatsApp groups, containing parents’ numbers and often photographs
- the fee software, if there is one
- a teacher’s personal phone, with the batch group in it
Every one of those is data you are answerable for. The WhatsApp groups are the sharpest edge: when a teacher leaves, the parents’ numbers leave with them, and that is a disclosure you never agreed to and cannot undo.
What good looks like
Nothing here requires expensive software. It requires deciding things and writing them down.
On the admission form. Say what you collect, why, how long you keep it, and who to contact to have it removed — on the form itself, not in a policy nobody opens. Record parental consent as its own field, separate from the rest.
Split admission data from marketing. The list you use to send fee reminders should not be the list you use to send offers about next year’s batch. Separate consent, separate list, and the second one has to be refusable without affecting the first.
Give retention a number. “As long as necessary” is not a retention period. Decide how long you keep records after a student leaves — often driven by what your board or university requires — write it down, and act on it.
Have one person who answers. The Act requires a published contact for data questions and complaints. For a single centre, that is usually the proprietor. Put the name and an email address on the website.
Get student data off personal phones. This is the hardest one culturally and the most valuable. A shared system that staff access with their own login, and lose access to when they leave, solves a problem that no policy document can.
If something goes wrong
A breach has to be reported to the Data Protection Board and to the people affected without delay, with a detailed report inside 72 hours. For a school, “the people affected” means parents, and that is a conversation nobody wants to have unprepared.
The awkward part is that most centres would never know. A laptop with the student list on it goes missing and nothing anywhere records that it held personal data. Knowing what you hold and where — the first item in this article — is what makes the rest possible.
Where to start
If you want a sense of where you stand before talking to anyone, our DPDP readiness check asks twelve questions and gives you a list of what to fix first. It runs entirely in your browser, and nothing you answer is sent anywhere — which matters, because the honest answers are not things you would hand to a stranger.
If you would rather have it built properly, that is what our DPDP compliance work covers, and we have done it before: the Victors Home Tutors platform was designed around handling identity documents when the obvious verification route is not legally open to a private business in India.
One honest caveat. We are a software company, not a law firm. We build the part of this that lives in your website, your forms and your systems, and we will tell you plainly when a question needs a lawyer instead of a developer. Anyone offering you a “DPDP certified” website is selling something that does not exist.