Industries/EdTech and LMS

If your platform has learners under 18, the stakes are different.

Under the DPDP Act, every user under 18 is a child. That means verifiable parental consent before any data is collected, no behavioural tracking, and no targeted advertising. Most EdTech platforms are nowhere near compliant. We build the age verification, consent infrastructure, and vendor guardrails that the law requires.

Penalty₹200 crore for children's data violations
The data chain

Six entities. Children at the centre of all of them.

EdTech platforms sit at the intersection of institutional permissions, parental rights, and vendor data flows. Under DPDP, the platform bears responsibility for every entity that touches a child's data — regardless of what the school contract says.

Learner (under 18)

Data Principal (minor)

Data handled

Name, photo, performance data, behavioural analytics, device identifiers

DPDP obligation

Verifiable parental consent required before any data is collected. Age must be verified for every user.

Parent / Guardian

Consent Principal for minors

Data handled

Identity credentials used to verify guardianship

DPDP obligation

Must be verified using authoritative identity credentials. Verification log must be maintained for audit.

EdTech Platform

Primary Data Fiduciary

Data handled

Academic records, quiz performance, engagement patterns, learning paths

DPDP obligation

Owns consent, age verification, purpose limitation, no-tracking obligation, rights fulfilment, and breach notification.

School / Institution

Data Fiduciary or Processor (context-dependent)

Data handled

Enrolment records, attendance, assessment results

DPDP obligation

Clear contractual allocation of roles is essential. School-level permissions do not satisfy DPDP parental consent requirements.

Analytics and Proctoring Vendors

Data Processor

Data handled

Behavioural signals, screen recordings, keystroke data, facial recognition (if used)

DPDP obligation

Processor contract required. Facial recognition and behavioural monitoring without consent creates severe enforcement exposure.

Third-Party Ad / Marketing Platforms

Independent Data Fiduciary

Data handled

Engagement data used for targeting

DPDP obligation

Sharing student data with advertisers or affiliates is a ₹200 crore exposure. Prohibited for children without explicit parental consent.

What we build

Five obligations. All of them are engineering problems.

Verifiable parental consent for every minor

DeliverableAge gate, DigiLocker verification integration, consent ledger, parent dashboard

Self-declared birthdates and generic checkboxes are not valid. DPDP requires a layered approach: age detection, parent identification using government-backed credentials such as DigiLocker, and a verified link between the parent and the child account. We build this into your onboarding flow — not as a bolt-on, but as a core product component with an immutable audit log.

Tracking and profiling guardrails

DeliverableThird-party integration audit, tracking exclusion controls, consent-scoped analytics

Behavioural tracking, profiling, and targeted advertising directed at children are prohibited under Section 9 of the DPDP Act. If your platform uses analytics tools, proctoring software, or recommendation engines, they must be configured to exclude users under 18 from profiling mechanisms. We audit your third-party integrations and implement the technical controls that enforce this.

Parental rights portal

DeliverableParental rights portal, consent withdrawal flow, data deletion pipeline

Parents have the right to access the data held about their child, correct inaccuracies, and withdraw consent — which triggers data deletion. We build a parental rights portal that handles these requests end-to-end with 7-day SLA automation and full audit trails for every action taken.

Vendor and processor agreements

DeliverableDPA templates, school partnership agreements, vendor classification register

Every learning management tool, analytics vendor, proctoring platform, and cloud provider that processes student data is a processor. Each needs a written data processing agreement. For school partnerships, the contractual allocation of Data Fiduciary vs Processor roles must be explicit — a school-level permission does not transfer your consent obligations to the institution.

Breach notification within 72 hours

DeliverableBreach runbook, Board notification template, detection integration

A data breach involving children's records triggers the standard DPDP 72-hour notification clock — and carries a ₹200 crore penalty specifically for failure to notify. We build a breach runbook and detection hooks so your team is never improvising when it matters most.

Common questions

Questions we get from EdTech platforms.

Our platform serves both adults and minors. Do we need separate flows?

Yes. You need an age verification mechanism for every user. Where a user is identified as under 18, they must be routed through the parental consent flow before any data is collected or processed. Adult users follow the standard consent flow. The two paths must be technically enforced — a minor cannot bypass the parental gate by self-declaring an adult age.

The school collects consent from parents on enrollment. Is that sufficient?

No. School-level enrollment permissions are not DPDP-compliant parental consent. The school's enrollment agreement is between the school and the parent for the institution's purposes. When an EdTech platform processes student data — even under a school contract — it requires its own verified parental consent for the purposes it intends to use that data for.

We use proctoring software. Does that create additional risk?

Yes. Proctoring tools typically capture keystroke data, screen recordings, webcam feeds, and in some cases facial recognition. Processing facial recognition data without clear necessity justification and strong security controls creates significant compliance exposure. Even where permitted, it requires explicit notice, minimal retention, and a processor contract with the proctoring vendor.

What is the penalty for children's data violations specifically?

The DPDP Act schedules a penalty of up to ₹200 crore specifically for failure to observe obligations relating to children's personal data. This sits alongside the ₹250 crore penalty for general security safeguard failures. For platforms serving large numbers of minors, the Data Protection Board is expected to treat violations with the highest scrutiny.

We are an LMS platform that only processes data under school instructions. Are we a processor?

Typically yes, when operating strictly under the school's instructions. But if your platform independently determines how student data is used — for product development, analytics, or research — you become a Fiduciary for those processing activities. The classification depends on who controls the purpose, not who signs the contract.

Penalties for children's data violations reach ₹200 crore under the DPDP Act. This engagement covers the technical and product layer. Pair it with your legal counsel for complete coverage across DPDP obligations and any sector-specific education regulations.

Ready to build child-safe data infrastructure into your product?

Take the readiness check