TL;DR
- Section 6(1), DPDPA 2023 limits consent to the personal data necessary for the specified purpose. Most Indian admission forms fail here before a single record is stored — they collect by template, not by purpose.
- Aadhaar is not a special category under the DPDPA — the Act does not retain the old SPDI “sensitive personal data” tier. It is personal data with full fiduciary duties, and holding photocopies you cannot justify is a minimisation and security exposure, not a filing habit.
- Photographs are a separate purpose. Website, prospectus, Instagram and parent WhatsApp groups each need their own consent line — and under Section 6, admission must never be made conditional on agreeing to them.
- Every applicant under 18 is a child. Section 9(1) requires verifiable parental or guardian consent; Section 9(3) bans tracking, behavioural monitoring and targeted advertising directed at children, and parental consent cannot override it.
- Fix it before the phased commencement date of 13 May 2027 — the 2027–28 admission cycle runs under the new regime. Mandatory annual audits under Rule 13 apply only to Significant Data Fiduciaries, but the Data Protection Board can demand your consent evidence from any school.
- If the admission file leaks, the dual clock starts: 6 hours to CERT-In and 72 hours to the Data Protection Board. Failure of reasonable security safeguards under Section 8(5) carries the ₹250 crore slab.
Where Does School Admission Form Data Privacy Break Under the DPDPA?
School admission form data privacy breaks in the same three places in almost every Indian school: the form collects more than the stated purpose needs, one signature is treated as consent for everything, and the resulting file then leaves the office — as a photocopy in a cupboard, a WhatsApp forward to a class teacher, an unrestricted ERP export, a photographer’s hard drive.
The Act’s operative rules are quiet but strict. Section 5 requires an itemised notice of what you collect and why. Section 6(1) limits consent to what is necessary for that specified purpose. Section 8(7) requires erasure once consent is withdrawn or the purpose is served. And because applicants are children, Section 9 sits above all of it.
So a “leak” under the DPDPA is not only a hack. It is any personal data sitting in your school without a purpose, a lawful ground, and a retention end-date.
Which Admission Form Fields Actually Leak — and How Should Each Be Handled?
Run this table against the form you are printing for the next cycle.
| Admission field | Stated purpose | Where it leaks | DPDPA handling |
|---|---|---|---|
| Aadhaar number / photocopy | ”Identity proof” | Photocopy files, ERP free-text, vendor forms | Drop unless a named scheme or board requirement applies; verify and do not retain |
| Student photograph | ID card, records | Website, brochures, Instagram, WhatsApp groups | Split into internal vs published purposes; separate consent for each |
| Birth certificate | Age / eligibility | Scanned into shared drives | Necessary; verify, retain minimum, restrict access |
| Medical, allergy, disability details | Infirmary, emergencies | Class teacher WhatsApp, trip forms | Separate purpose line; access-controlled; never bundled into admission consent |
| Parent income, ITR, salary slips | Fee concession, scholarship | Retained for all applicants, not just applicants for aid | Collect only for the concession cohort; erase after the decision |
| Caste / category certificate | Statutory quota | Full copies retained indefinitely | Collect only where the quota applies; retain per the mandating authority |
| Parent phone, email, WhatsApp | Communication | Exported to marketing lists and broadcast tools | Admission communication ≠ marketing; marketing needs its own consent |
| Sibling and previous school details | Verification | Retained long after admission closes | Erase for rejected and withdrawn applications |
| Rejected applicants’ full files | None after the decision | Cupboards, ERP archives, forever | Section 8(7) erasure — set a date and enforce it |
The row that surprises principals most is the last one. A school that admits 300 students often holds complete files for 1,200 applicants — including 900 children it never enrolled, whose data now has no purpose at all.
Why Is Collecting Aadhaar on School Admission Forms a Minimisation Problem?
Because for most private admissions, nothing requires the school to hold the number. Where a specific government scheme, state directive or board requirement makes an Aadhaar-linked identifier necessary, cite it in your Section 5 notice and collect it for that cohort only. Absent such a requirement, age and identity are already established by the birth certificate and transfer certificate you also collect — which makes the Aadhaar copy a duplicate you must now secure, log, and eventually erase.
Two corrections to the common school position:
- Aadhaar is not “extra-sensitive” under the DPDPA. The Act has no sensitive-personal-data tier. It is personal data, and every fiduciary duty applies to it — notice, purpose limitation, security, erasure.
- That is not good news. A high-value national identifier held in bulk, in a system with weak access control, is precisely the fact pattern that turns a lost laptop into a Section 8(5) security-safeguards failure, which carries the ₹250 crore penalty slab.
The practical fix has three steps: verify at the counter and do not retain the copy; if a scheme genuinely requires retention, hold it in a sealed vault with per-access logging rather than in the admission file; and never let it travel into WhatsApp, Google Forms, or a vendor spreadsheet.
Do School Photos on Websites and WhatsApp Need Separate Parental Consent?
Yes — and this is where schools create the leak that is hardest to reverse.
| Photo surface | Purpose | Consent needed | Reversibility |
|---|---|---|---|
| ID card, ERP student record | Administration | Covered by core admission consent | High — internal only |
| Classroom / internal display | School operations | Internal purpose line | High |
| School website and prospectus | Marketing | Separate, optional, verifiable parental consent | Low — indexed, cached, scraped |
| Instagram, Facebook, YouTube | Marketing | Separate, optional; never a condition of admission | Very low — reshared beyond your control |
| Parent WhatsApp groups | Convenience | Separate; treat as publication | Very low — forwarded instantly |
| Press, newspaper features | Publicity | Separate, per-event consent | None once printed |
| External photographer’s archive | Event coverage | Processor contract with deletion terms | Depends entirely on the contract |
Three rules follow. Section 6 makes consent unconditional — a parent must be able to say yes to admission and no to the yearbook without consequence. Section 6(4) makes withdrawal as easy as giving consent, so you need a route to pull a child’s image from every surface above. And Section 9(3) prohibits targeted advertising directed at children outright: a student’s face in a paid enrolment campaign is not a consent question you can win with a signature.
What Does Section 9 Require Schools to Prove for Parental Consent?
Not that a form was signed — that four things are true, and provable later.
- Who consented — an adult who is the child’s parent or lawful guardian, established through the due diligence in Rule 10 of the DPDP Rules, 2025 (reliable identity and age details you already hold, details voluntarily provided, or a virtual token mapped to such details).
- What they consented to — purpose by purpose, against the exact notice version they were shown.
- When — timestamped, with the withdrawal state on any later date.
- That the record has not been altered since — which a signed PDF re-scanned into a shared drive cannot demonstrate.
This is an architecture problem, not a stationery problem. Privigo’s design answer is a sealed PII vault so admission data stops living in scattered spreadsheets, cryptographically immutable consent records so every grant and withdrawal is tamper-evident, and an evidentiary-grade audit trail that propagates withdrawal to every Data Processor — ERP, edtech, transport, photographer.
For the form-design mechanics, see our pillar guide on parental consent in school admissions under the DPDPA; for the verification workflow itself, see verifiable parental consent: a step-by-step guide for schools.
Who Owns Fixing Admission Leaks Before 13 May 2027?
| Area | Owner | Status |
|---|---|---|
| Field-by-field audit of the admission form (drop, defer, seal) | Admissions Head | ☐ |
| Aadhaar decision: collect, verify-only, or drop — with the reason documented | Principal | ☐ |
| Photograph consent split: internal vs website vs social vs press | Admissions Head + Comms | ☐ |
| Retention and erasure schedule for rejected and withdrawn applications | IT / ERP Admin | ☐ |
| Access control and logging on medical, income and category fields | IT + School Doctor | ☐ |
| WhatsApp practice: what staff may and may not forward | Principal | ☐ |
| Photographer and ERP vendor contracts: deletion, no reuse, no profiling | Principal + IT | ☐ |
Board-specific workflows for schools sit on our education solution page, and the full fiduciary checklist sits in the Privigo DPDP guide.
Closing: Three Steps Before the Next Admission Cycle
- Line-audit one form. Take your current admission form and write the purpose next to every field. Anything without a purpose comes off the 2027–28 print run.
- Set an erasure date for rejected applicants. Pick the date, put it in the ERP, and run it once manually so you know it works.
- Map your photo surfaces. List every place a student’s face appears, then check whether you could remove it within a week if one parent withdrew consent.
Start free and get your school’s DPDPA Ready badge →
Frequently asked questions
Can a school ask for Aadhaar on the admission form under DPDPA?
No, not by default. Section 6(1) of the DPDPA 2023 limits consent to the personal data necessary for the specified purpose, so a school must be able to name the statutory or scheme requirement that makes an Aadhaar number necessary for admission. Where identity or age can be established by a birth certificate or transfer certificate, collecting and retaining Aadhaar copies is over-collection — and it is still personal data attracting full fiduciary duties, including the security obligation under Section 8(5).
Do schools need separate parental consent to post student photos on the website or Instagram?
Yes. Publication is a distinct purpose from admission or ID cards, and Section 6 requires consent to be specific, informed and unconditional — so admission cannot be made conditional on agreeing to marketing photographs. Because the subject is a child, Section 9(1) requires verifiable parental or guardian consent, and Section 9(3) bars any use amounting to targeted advertising directed at children.
Is one signature on the admission form enough consent for everything the school does?
No. Section 6 of the DPDPA requires consent that is specific and unambiguous, given by a clear affirmative action for each purpose. Admission processing, health records, photographs, transport tracking and edtech accounts are separate purposes and need separate consent lines, each with its own notice under Section 5.
Does DPDPA treat medical details on an admission form as sensitive personal data?
No. The DPDPA 2023 does not carry forward the old SPDI “sensitive personal data” category — there is a single class of personal data. That is not a relaxation for schools: because the data belongs to a child under 18, Section 9 applies to allergy, disability and medical fields exactly as it does to the rest of the form.
Sources
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Act, 2023 — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- Press Information Bureau, Government of India — Digital Personal Data Protection (DPDP) Rules, 2025 — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
This article is for general information only and is not legal advice. Consult a qualified professional for advice on your school’s specific DPDPA obligations.


