TL;DR

  • Section 6(1), DPDPA 2023 limits consent to the personal data necessary for the specified purpose. Most Indian admission forms fail here before a single record is stored — they collect by template, not by purpose.
  • Aadhaar is not a special category under the DPDPA — the Act does not retain the old SPDI “sensitive personal data” tier. It is personal data with full fiduciary duties, and holding photocopies you cannot justify is a minimisation and security exposure, not a filing habit.
  • Photographs are a separate purpose. Website, prospectus, Instagram and parent WhatsApp groups each need their own consent line — and under Section 6, admission must never be made conditional on agreeing to them.
  • Every applicant under 18 is a child. Section 9(1) requires verifiable parental or guardian consent; Section 9(3) bans tracking, behavioural monitoring and targeted advertising directed at children, and parental consent cannot override it.
  • Fix it before the phased commencement date of 13 May 2027 — the 2027–28 admission cycle runs under the new regime. Mandatory annual audits under Rule 13 apply only to Significant Data Fiduciaries, but the Data Protection Board can demand your consent evidence from any school.
  • If the admission file leaks, the dual clock starts: 6 hours to CERT-In and 72 hours to the Data Protection Board. Failure of reasonable security safeguards under Section 8(5) carries the ₹250 crore slab.

Where Does School Admission Form Data Privacy Break Under the DPDPA?

School admission form data privacy breaks in the same three places in almost every Indian school: the form collects more than the stated purpose needs, one signature is treated as consent for everything, and the resulting file then leaves the office — as a photocopy in a cupboard, a WhatsApp forward to a class teacher, an unrestricted ERP export, a photographer’s hard drive.

The Act’s operative rules are quiet but strict. Section 5 requires an itemised notice of what you collect and why. Section 6(1) limits consent to what is necessary for that specified purpose. Section 8(7) requires erasure once consent is withdrawn or the purpose is served. And because applicants are children, Section 9 sits above all of it.

So a “leak” under the DPDPA is not only a hack. It is any personal data sitting in your school without a purpose, a lawful ground, and a retention end-date.

School admission form data privacy leak map under DPDPA — Aadhaar, photographs, medical and income fields flowing to office, ERP, WhatsApp and vendors

Which Admission Form Fields Actually Leak — and How Should Each Be Handled?

Run this table against the form you are printing for the next cycle.

Admission fieldStated purposeWhere it leaksDPDPA handling
Aadhaar number / photocopy”Identity proof”Photocopy files, ERP free-text, vendor formsDrop unless a named scheme or board requirement applies; verify and do not retain
Student photographID card, recordsWebsite, brochures, Instagram, WhatsApp groupsSplit into internal vs published purposes; separate consent for each
Birth certificateAge / eligibilityScanned into shared drivesNecessary; verify, retain minimum, restrict access
Medical, allergy, disability detailsInfirmary, emergenciesClass teacher WhatsApp, trip formsSeparate purpose line; access-controlled; never bundled into admission consent
Parent income, ITR, salary slipsFee concession, scholarshipRetained for all applicants, not just applicants for aidCollect only for the concession cohort; erase after the decision
Caste / category certificateStatutory quotaFull copies retained indefinitelyCollect only where the quota applies; retain per the mandating authority
Parent phone, email, WhatsAppCommunicationExported to marketing lists and broadcast toolsAdmission communication ≠ marketing; marketing needs its own consent
Sibling and previous school detailsVerificationRetained long after admission closesErase for rejected and withdrawn applications
Rejected applicants’ full filesNone after the decisionCupboards, ERP archives, foreverSection 8(7) erasure — set a date and enforce it

The row that surprises principals most is the last one. A school that admits 300 students often holds complete files for 1,200 applicants — including 900 children it never enrolled, whose data now has no purpose at all.

Why Is Collecting Aadhaar on School Admission Forms a Minimisation Problem?

Because for most private admissions, nothing requires the school to hold the number. Where a specific government scheme, state directive or board requirement makes an Aadhaar-linked identifier necessary, cite it in your Section 5 notice and collect it for that cohort only. Absent such a requirement, age and identity are already established by the birth certificate and transfer certificate you also collect — which makes the Aadhaar copy a duplicate you must now secure, log, and eventually erase.

Two corrections to the common school position:

  • Aadhaar is not “extra-sensitive” under the DPDPA. The Act has no sensitive-personal-data tier. It is personal data, and every fiduciary duty applies to it — notice, purpose limitation, security, erasure.
  • That is not good news. A high-value national identifier held in bulk, in a system with weak access control, is precisely the fact pattern that turns a lost laptop into a Section 8(5) security-safeguards failure, which carries the ₹250 crore penalty slab.

The practical fix has three steps: verify at the counter and do not retain the copy; if a scheme genuinely requires retention, hold it in a sealed vault with per-access logging rather than in the admission file; and never let it travel into WhatsApp, Google Forms, or a vendor spreadsheet.

Yes — and this is where schools create the leak that is hardest to reverse.

Photo surfacePurposeConsent neededReversibility
ID card, ERP student recordAdministrationCovered by core admission consentHigh — internal only
Classroom / internal displaySchool operationsInternal purpose lineHigh
School website and prospectusMarketingSeparate, optional, verifiable parental consentLow — indexed, cached, scraped
Instagram, Facebook, YouTubeMarketingSeparate, optional; never a condition of admissionVery low — reshared beyond your control
Parent WhatsApp groupsConvenienceSeparate; treat as publicationVery low — forwarded instantly
Press, newspaper featuresPublicitySeparate, per-event consentNone once printed
External photographer’s archiveEvent coverageProcessor contract with deletion termsDepends entirely on the contract

Three rules follow. Section 6 makes consent unconditional — a parent must be able to say yes to admission and no to the yearbook without consequence. Section 6(4) makes withdrawal as easy as giving consent, so you need a route to pull a child’s image from every surface above. And Section 9(3) prohibits targeted advertising directed at children outright: a student’s face in a paid enrolment campaign is not a consent question you can win with a signature.

Not that a form was signed — that four things are true, and provable later.

Section 9 verifiable parental consent and data minimisation flow for school admission forms under DPDPA

  1. Who consented — an adult who is the child’s parent or lawful guardian, established through the due diligence in Rule 10 of the DPDP Rules, 2025 (reliable identity and age details you already hold, details voluntarily provided, or a virtual token mapped to such details).
  2. What they consented to — purpose by purpose, against the exact notice version they were shown.
  3. When — timestamped, with the withdrawal state on any later date.
  4. That the record has not been altered since — which a signed PDF re-scanned into a shared drive cannot demonstrate.

This is an architecture problem, not a stationery problem. Privigo’s design answer is a sealed PII vault so admission data stops living in scattered spreadsheets, cryptographically immutable consent records so every grant and withdrawal is tamper-evident, and an evidentiary-grade audit trail that propagates withdrawal to every Data Processor — ERP, edtech, transport, photographer.

For the form-design mechanics, see our pillar guide on parental consent in school admissions under the DPDPA; for the verification workflow itself, see verifiable parental consent: a step-by-step guide for schools.

Who Owns Fixing Admission Leaks Before 13 May 2027?

AreaOwnerStatus
Field-by-field audit of the admission form (drop, defer, seal)Admissions Head☐
Aadhaar decision: collect, verify-only, or drop — with the reason documentedPrincipal☐
Photograph consent split: internal vs website vs social vs pressAdmissions Head + Comms☐
Retention and erasure schedule for rejected and withdrawn applicationsIT / ERP Admin☐
Access control and logging on medical, income and category fieldsIT + School Doctor☐
WhatsApp practice: what staff may and may not forwardPrincipal☐
Photographer and ERP vendor contracts: deletion, no reuse, no profilingPrincipal + IT☐

Board-specific workflows for schools sit on our education solution page, and the full fiduciary checklist sits in the Privigo DPDP guide.

Closing: Three Steps Before the Next Admission Cycle

  1. Line-audit one form. Take your current admission form and write the purpose next to every field. Anything without a purpose comes off the 2027–28 print run.
  2. Set an erasure date for rejected applicants. Pick the date, put it in the ERP, and run it once manually so you know it works.
  3. Map your photo surfaces. List every place a student’s face appears, then check whether you could remove it within a week if one parent withdrew consent.

Start free and get your school’s DPDPA Ready badge →

Frequently asked questions

Can a school ask for Aadhaar on the admission form under DPDPA?

No, not by default. Section 6(1) of the DPDPA 2023 limits consent to the personal data necessary for the specified purpose, so a school must be able to name the statutory or scheme requirement that makes an Aadhaar number necessary for admission. Where identity or age can be established by a birth certificate or transfer certificate, collecting and retaining Aadhaar copies is over-collection — and it is still personal data attracting full fiduciary duties, including the security obligation under Section 8(5).

Do schools need separate parental consent to post student photos on the website or Instagram?

Yes. Publication is a distinct purpose from admission or ID cards, and Section 6 requires consent to be specific, informed and unconditional — so admission cannot be made conditional on agreeing to marketing photographs. Because the subject is a child, Section 9(1) requires verifiable parental or guardian consent, and Section 9(3) bars any use amounting to targeted advertising directed at children.

No. Section 6 of the DPDPA requires consent that is specific and unambiguous, given by a clear affirmative action for each purpose. Admission processing, health records, photographs, transport tracking and edtech accounts are separate purposes and need separate consent lines, each with its own notice under Section 5.

Does DPDPA treat medical details on an admission form as sensitive personal data?

No. The DPDPA 2023 does not carry forward the old SPDI “sensitive personal data” category — there is a single class of personal data. That is not a relaxation for schools: because the data belongs to a child under 18, Section 9 applies to allergy, disability and medical fields exactly as it does to the rest of the form.

Sources

  1. Ministry of Electronics and Information Technology, Digital Personal Data Protection Act, 2023 — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  2. Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
  3. Press Information Bureau, Government of India — Digital Personal Data Protection (DPDP) Rules, 2025 — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014

This article is for general information only and is not legal advice. Consult a qualified professional for advice on your school’s specific DPDPA obligations.