An edtech privacy framework for student accounts, parental verification, learning analytics, proctoring, teacher access, advertising, safety and deletion.
Student engagement data can improve learning, but it can also become a permanent behavioural profile used outside education.
The DPDP framework is phased. The 14 November 2025 commencement notification brought specified institutional and enabling provisions into force immediately; Consent Manager-related provisions follow after one year; most operating duties and Rules follow eighteen months after Gazette publication. As of 22 June 2026, the control should distinguish current obligations from future-state DPDP readiness.
The Act defines a child as a person below eighteen and contains specific child-data duties and restrictions, subject to phased commencement and notified exemptions.
Student, parent and teacher data should be separated because each person has different purposes and controls.
Proctoring, emotion detection, attention scoring and behavioural analytics require necessity, accuracy and harm review.
| Check | What to examine |
|---|---|
| User | Child, parent, teacher or adult learner. |
| Data | Identity, performance, behaviour, device and video. |
| Purpose | Teaching, assessment, safety, support or marketing. |
| Access | Teacher, school, parent, vendor and administrator. |
| End | Course completion, school exit and deletion. |
An app retains webcam recordings and attention scores after the exam and later uses them to rank students for unrelated courses. That new purpose needs separate scrutiny and may create child-data risk.
Design child and adult journeys separately. Verify parental involvement proportionately without creating unnecessary identity stores.
Give schools and parents clear controls over class rosters, exports, teacher access and end-of-term deletion.
Identify the people, data, systems, purpose, owner, processor, user journey and failure scenario. Review user, data and purpose together. A policy statement or vendor assurance cannot replace evidence of how the live product behaves.
Apply the 14 November 2025 commencement notification provision by provision. Continue complying with currently operative CERT-In, banking, telecom, insurance, employment, consumer, contract and criminal-law requirements. Build the scheduled DPDP workflow now, but do not describe a future provision as already enforceable.
Run the workflow in the live or controlled test environment. Preserve screenshots, approvals, logs, vendor responses, user communications, exceptions and remediation. Assign a named owner and completion date to every failed control so management can distinguish an operating safeguard from a policy intention.
Privacy and cyber maturity are visible in operating behaviour: what the organisation collects, who can use it, how vendors are controlled, how users exercise choices, how incidents are handled and whether evidence survives scrutiny.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.