DPDP Audits

DPDP Compliance for EdTech Platforms and Schools

Children's data under the DPDP Act 2023: verifiable parental consent, the ban on tracking and targeted ads to children, and what EdTech platforms and schools must fix.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 25 September 2026

Under the Digital Personal Data Protection Act 2023, anyone under 18 is a child. That puts EdTech platforms, schools, coaching institutes and test-prep apps squarely under the Act's strictest provisions, because most of their users are children.

What the Act requires for children's data

Failing to meet the obligations for children's data can attract penalties of up to ₹200 crore.

Gaps commonly found in EdTech and schools

Priorities before May 2027

  1. Identify every place a child's data enters the system, including apps, forms and admissions.
  2. Implement a verifiable parental consent flow suited to your users.
  3. Remove ad and behavioural-tracking SDKs from child-facing products.
  4. Document which exemptions you rely on and for exactly which purposes.
  5. Set retention limits for proctoring recordings, assessments and admission documents.

See DPDP Rules 2025 explained for the timeline, and the DPDP audit checklist for a full self-assessment.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.