DPDP Act for schools. Children’s data deserves the highest care.

The Digital Personal Data Protection (DPDP) Act changes how every school handles student, parent and staff data. Here is what the DPDP Act for schools means in practice, exactly what Schoolcanvas commits to, what we already do, and our published roadmap to full readiness.

How we look after school dataIn place today, and committed in writing
  • Stored in IndiaToday
  • Teacher and parent numbers hidden from each otherToday
  • Never used to train AIIn writing
  • No ads, everIn writing
  • Your data, your schoolIn writing

8 written commitments, ready for your Data Processing Agreement · DPDP programme under way since 1 Oct 2026

The law in plain words

What the DPDP Act for schools asks of you.

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection law. It applies to all digital personal data, and schools hold some of the most sensitive data there is: children’s.

How it arrives

  1. 13 Nov 2025The DPDP Rules are notified, and the Data Protection Board is set up.
  2. About Nov 2026Rules for Consent Managers take effect.
  3. About May 2027Most obligations apply: notices, security safeguards, breach reporting, retention and children’s data.
Dates as notified in the Rules. We will update this page if the government changes them.

It covers everything about a person

Names, photos, phone numbers, marks, attendance, fees and medical notes are all personal data, whether they sit in an app, a spreadsheet or an e-mail.

Children need parental consent

For students under 18, schools need verifiable consent from a parent or guardian. Tracking, behavioural monitoring and targeted advertising aimed at children are not allowed.

People have rights

Parents and students can ask what data is held, have it corrected and, in some cases, erased. Requests have to be answered within 90 days.

Security must be reasonable

Encryption or masking, access control, access logs and backups are the minimum the Rules expect, and logs have to be kept for a year.

Breaches must be reported

To the people affected and to the Data Protection Board without delay, with a detailed report to the Board within 72 hours.

The penalties are serious

Up to ₹250 crore for failing to keep reasonable security safeguards, and up to ₹200 crore for breach-notice failures or breaking the rules on children’s data.

The life of one parent’s data

One parent’s data, stamped at every stage.

Follow Priya Rao, a Green Valley parent, from the admission form to the day her data is erased. Each page shows who is responsible and whether a protection is in place today, committed in writing or planned on our roadmap, so your staff follow the rules without extra work.

  1. Page 01 · Collected1 of 6

    Collected, with a clear notice

    • Your school
    • Schoolcanvas

    It starts on the admission form. Your school, as the Data Fiduciary, decides what is collected and why, and tells parents about it. A line at the bottom of the form won’t be enough: Priya sees a clear notice before she shares anything.

    • Schoolcanvas processes data only on the school’s documented instructionsIn writing
    • A new plain-language privacy notice, with regional language versionsPhase 1
    In writingCommitment 01 Phase 1Planned
  2. Page 02 · Consent2 of 6

    Consent, recorded purpose by purpose

    • Parent
    • Your school
    • Schoolcanvas

    Priya gives consent purpose by purpose, and every consent is recorded with the date, time and the text she was shown. Optional really means optional: publishing Ananya’s photo or sending promotional messages each needs its own opt-in, and a parent who says no still gets the full core service.

    • Consent capture goes livePhase 1
    • Verifiable parental consent for students under 18Phase 2
    Phase 1Planned Phase 2Planned
  3. Page 03 · Stored3 of 6

    Stored in India, opened only by the right role

    • Schoolcanvas
    • Your school

    Her details sit on a private cloud in a tier-IV data centre in India, with cloud mirroring and four backup copies, and no school can access another school’s data. Inside the school, each person sees only what their role needs: a subject teacher won’t see medical or fee records, and a class teacher sees their own class.

    • Role-based access, biometric and access-code login, multi-level securityToday
    • Roles tightened to least privilege, and an audit trailPhase 1
    • OTP login for administrators and staff first, then parentsPhase 1
    In placeToday Phase 1Planned
  4. Page 04 · Used4 of 6

    Used only for the purpose it was given for

    • Schoolcanvas

    Schoolcanvas processes her data only on the school’s instructions, never for any purpose of its own. It is never sent to an external AI or machine-learning provider for training, never sold, rented or shared for marketing, and there is no advertising or adtech anywhere in Schoolcanvas. Teachers and parents never see each other’s personal phone numbers, and messages go out in the school’s name.

    • Contact details masked by default; a full download with phone numbers becomes a permission-based, logged actionPhase 0
    • Export approvals and watermarkingPhase 2
    In writingCommitments 01–04 Numbers hiddenToday Phase 0In progress
  5. Page 05 · Her rights5 of 6

    She can see it, correct it and say no to extras

    • Parent
    • Your school
    • Schoolcanvas

    Priya can ask what data is held about her family, have it corrected and, in some cases, erased, and the school has to answer within 90 days. Your school responds to her request, and Schoolcanvas delivers the export, correction or deletion on the school’s instruction.

    • Parent self-service to view and correct dataPhase 2
    • A consent dashboard for the schoolPhase 2
    • Full rights, including erasure and nominationPhase 3
    Phase 2Planned Phase 3Planned
  6. Page 06 · Erased6 of 6

    Kept only as long as needed, then erased

    • Schoolcanvas
    • Your school

    At the end of its retention period, her data is truly removed, not just hidden. If the school ever leaves Schoolcanvas, it gets a full export of its data, then we delete it within the agreed time and give the school a Certificate of Deletion.

    • Your data back, then deleted, with a Certificate of DeletionIn writing
    • Automatic retention and purgePhase 2
    • Offboarding with a Certificate of DeletionPhase 3
    In writingCommitment 08 Phase 2Planned
Phases follow our DPDP programme, which began on 1 October 2026. Priya Rao and Green Valley Public School are examples. See the full roadmap
Roles

Your school decides. We protect and process.

Under the Act, compliance is shared. Your school is the Data Fiduciary, and Schoolcanvas is your Data Processor. Here is who does what.

Your school

Data Fiduciary

Decides what data is collected and why, tells parents and staff about it, and answers to them and to the Data Protection Board.

Schoolcanvas

Data Processor

Stores and processes the data only on your school’s instructions, keeps it secure, and gives you the tools to meet your obligations.

Your schoolSchoolcanvas
PurposeDecides what data is collected, and whyProcesses data only on the school’s instructions
Privacy noticeShares the privacy notice with parents and staffProvides the tools for notices, consent and requests
ConsentObtains parental consent, using the platform’s workflowRecords every consent with the date, time and text shown
AccessManages staff accounts and rolesKeeps data secure: encryption, access control, logging, backups
RequestsResponds to parents’ requests and grievancesDelivers exports, corrections and deletions on instruction
BreachesReports any breach to the BoardInforms the school within 24 hours of confirming a breach, with the facts

For our own customers’ contact details, website enquiries and support tickets, Schoolcanvas is a Data Fiduciary in its own right and follows the full obligations. Consent recording and the request tools arrive through our roadmap, below.

Our commitments

Eight promises we put in writing.

These are standing commitments to every partner school, and we are prepared to write them into your Data Processing Agreement.

01

Your instructions only

We process your school’s data only on your documented instructions, never for any purpose of our own.

02

Never used to train AI

School data is never sent to any external AI or machine-learning provider for training.

03

Never sold or shared

We don’t sell, rent, license or share school data with anyone for marketing, advertising, research or any other external purpose.

04

No ads, no adtech

There are no ad networks, ad SDKs or adtech partners anywhere in Schoolcanvas.

05

Stored in India

All production data, backups and logs are kept on India-region infrastructure.

06

Every school separate

No school can access another school’s data.

07

Open about our partners

We keep and publish a current list of the service providers who process data for us, and give notice before adding a new one.

08

Your data back, then deleted

If you leave, you get a full export of your data, then we delete it within the agreed time and give you a Certificate of Deletion.

In place today

Protection that is already working for 1000+ schools.

Long before the Act, children’s data shaped how Schoolcanvas was built. These protections are live for every school on the platform right now.

Indian data centre

Your data is hosted in a tier-IV data centre in India, on a private cloud with cloud mirroring.

Four backup copies

Data is backed up with four copies, so a hardware failure never costs a school its records.

Role-based access

Every user sees only what their role needs, with biometric and access-code login options and multi-level security.

Numbers kept private

Teachers and parents never see each other’s personal phone numbers. Messages go out in the school’s name.

Verified gate passes

When a student leaves early, the exit is verified by an OTP sent to the parent, and every visitor is logged.

ISO 9001:2015 and CMMI Level 4

Our quality management and software development processes are independently assessed.

Our roadmap

A clear plan, shared openly with our schools.

Our DPDP programme began on 1 October 2026, with more than 80 tracked actions across governance, consent, security, children’s data and independent testing. Here is what schools will see along the way.

Phase 0In progress

Quick protections

Month 1 · from 1 Oct 2026
  • Passwords removed from all screens and downloads
  • Contact numbers masked
  • Standard exports without personal data
  • Documents behind secure, expiring links
  • Tracking SDKs removed from student apps
Phase 1Planned

Agreements and consent

Month 2
  • A Data Processing Agreement to sign
  • A new plain-language privacy notice, with regional language versions
  • Consent capture goes live
  • OTP mandatory for staff and administrators
  • Roles tightened to least privilege
  • Audit trail goes live
Phase 2Planned

Parent rights and controls

Month 3
  • Verifiable parental consent
  • Parent self-service to view and correct data
  • Consent dashboard for the school
  • School-visible audit logs
  • Automatic retention and purge
  • Export approvals and watermarking
Phase 3Planned

Independent testing

Month 5
  • Independent security testing results shared
  • Full rights, including erasure and nomination
  • Offboarding with a Certificate of Deletion
  • A published trust page
Phase 4Planned

Full readiness

Month 6
  • Full readiness ahead of enforcement
  • Regular impact assessments
  • Quarterly governance reviews
  • Ongoing security audits
Everything on this roadmap is planned work. We will keep this page updated as each phase completes, and bring dates forward if the law requires.
Children first

Extra care for every child’s data.

Most of the people in a school’s records are children. The DPDP Act gives their data the strongest protection, and so do we.

The Rules include narrow exemptions for schools, for example for educational activities, for children’s safety and for tracking the school bus on the way to and from school. They are limited to those purposes, so uses such as publishing photos or sending promotional messages still need a parent’s consent. Your own legal adviser can confirm how they apply to your school.

A teacher helping young students with tablets in class, where every child's data needs extra care

How Schoolcanvas protects children’s data

  • Parental consent before a child’s data is processed, through a verifiable workflow (planned, Phase 2)
  • No advertising and no adtech, anywhere in Schoolcanvas
  • Children’s data never used to train AI, including in Assist
  • Teacher and parent phone numbers hidden from each other today, with contact details masked by default and controlled exports through the roadmap
  • Every school’s data kept separate, stored in India
Your next steps

Three simple steps, no technical work.

Most of the work sits with us. What we need from your school is a named contact, a signature and an honest picture of how you use Schoolcanvas.

Already a Schoolcanvas school?

Your account manager will guide you through each step and send the agreement and questionnaire as each phase begins.

Your school’s DPDP checklist 3 items
  1. Step 1

    Name a data protection contact

    Share the name, role, e-mail and phone of the person who handles data questions at your school.

  2. Step 2

    Sign the Data Processing Agreement

    Review and sign the agreement when we send it. It includes our 8 commitments.

  3. Step 3

    Complete the data questionnaire

    Tell us how your school uses Schoolcanvas, so consent and retention settings match reality.

Questions

Questions schools ask about DPDP.

The law
What does the DPDP Act mean for schools?

Schools hold digital personal data about students, parents and staff, and much of it belongs to children, so the Act applies to almost every school. Your school is the Data Fiduciary and decides how that data is used; software providers such as Schoolcanvas process it on your behalf. The Rules come in stages, with most obligations, including notices, security safeguards, breach reporting, retention and extra care for children’s data, applying from about May 2027.

Is Schoolcanvas DPDP compliant?

Schoolcanvas is DPDP-ready school software, with written commitments to every school and a published roadmap to full readiness ahead of enforcement. Under the law, compliance is shared: your school is the Data Fiduciary and Schoolcanvas is your Data Processor, and we give you the tools to meet your obligations.

Is there a DPDP certificate we should ask for?

No. There is no official DPDP certification, so be careful of any vendor that claims one. Ask instead for written commitments, a Data Processing Agreement and a clear plan, which is what we share with every school.

When does the DPDP Act apply?

The DPDP Rules were notified in November 2025 and come into force in stages, with most obligations applying from about May 2027. Our roadmap is designed to have everything in place well before then.

Does the education exemption mean we don’t need consent?

Not for everything. The Rules exempt some processing by schools, for educational activities and children’s safety, but only for those purposes. Uses such as publishing photos or sending promotional messages will still need a parent’s consent. Take your own legal advice on how it applies to you.

Your data
Is student data safe in a school ERP?

It depends on how the software is built and run, so ask any vendor where data is stored, who can see it and who owns it. In Schoolcanvas, data is hosted in a tier-IV data centre in India with four backup copies, every user sees only what their role needs, and the data belongs to your school.

Where is our data stored?

In India. All production data, backups and logs are kept on India-region infrastructure, in a tier-IV data centre.

Who owns the data?

Your school does. We process it only on your instructions, and if you leave, you get a full export and a Certificate of Deletion.

Is student data used to train AI?

No. School data is never sent to any external AI or machine-learning provider for training. That includes Assist, our AI-powered LMS, where every AI draft is also reviewed by the teacher.

Do you share or sell our data?

No. We never sell, rent, license or share school data for marketing, advertising, research or any other external purpose, and there is no advertising or adtech in Schoolcanvas.

Working together
What happens if there is a data breach?

We inform your school within 24 hours of confirming a breach, with the facts you need for your report to the Data Protection Board, which expects a detailed report within 72 hours, and we support you through the response.

Does the school need to do anything?

Yes, three simple things: name a data protection contact, sign the Data Processing Agreement, and complete a short questionnaire about how you use Schoolcanvas.

Can we see the full DPDP document?

Yes. Our DPDP compliance document is a 37-page guide for school leaders covering the law, who does what, our commitments and the full roadmap. Book a free demo and our team will walk you through the full document.

Book my free demo

See how Schoolcanvas looks after your school’s data.

A 45-minute walkthrough with a school software specialist, including our full DPDP document: the law in plain words, who does what, our commitments and the roadmap. We’ll call you within 4 working hours to fix a time.

Your free demo can cover

  1. Your own data, formats and processes
  2. The modules you need, from admissions to fees
  3. The apps for parents, teachers and staff
  4. Assist, the AI LMS for your teachers
  5. A setup plan and a quote for your school
  • Call back in 4 working hours
  • Free data migration
  • 1-month free trial

Book my free demo

Takes 30 seconds. No commitment.

Interested in
Get started

Your school’s data, in careful hands.

Mon–Fri 9 am – 6 pm · Sat 9 am – 4 pm