Most principals treating CBSE DPDPA compliance as a Board circular are solving the wrong problem. Affiliation keeps you in the CBSE system; the Digital Personal Data Protection Act, 2023 asks whether parents can still trust the school with their child’s data by 13 May 2027.
TL;DR
- CBSE DPDPA compliance is a Data Fiduciary duty under Section 2(i) of the Digital Personal Data Protection Act, 2023. Affiliation, OASIS, and SARAS do not discharge it.
- As at 25 September 2026, there is no Gazette notice that a CBSE circular is a DPDPA substitute. Watch MeitY and the Data Protection Board of India (DPB), not only cbse.gov.in.
- What parents actually test is operational: admission files, photographs, ERP / LMS vendors, and parent WhatsApp. Section 9 sits on all of it because the student is a child (under 18).
- Ordinary schools still owe Sections 4–9 and 11–14 in full by 13 May 2027. Rule 13 annual DPIA and audit is Significant Data Fiduciary only, after Section 10 notification.
- If a student file leaks, the dual clock starts: CERT-In (6 hours) and the Board (Rule 7, 72 hours). Section 8(5) security failures sit under the ₹250 crore Schedule slab; additional Section 9 children’s duties sit under ₹200 crore.
What does CBSE DPDPA compliance actually require from an affiliated school?
CBSE DPDPA compliance is not a new affiliation category. It is the same Act every Indian school already sits under once it processes digital personal data — names, parent phones, photographs, fee records, medical notes, bus GPS, edtech logins.
The school is the Data Fiduciary. ERP, LMS, transport, photographer, and fee-gateway vendors are Data Processors. Processor data is still personal data. Section 8(2) wants a contract; the fiduciary remains accountable. Substantive duties under the DPDP Rules, 2025 (G.S.R. 846(E)) phase in on 13 May 2027. The 2027–28 admission cycle runs under that regime.
What the Act actually asks a CBSE school to prove:
- Section 5 notice — itemised purposes, in clear language, including Board reporting where you upload student particulars.
- Section 6 consent — free, specific, informed, unconditional, unambiguous, by clear affirmative action — plus Section 9(1) verifiable parental or guardian consent, with Rule 10 due diligence.
- Section 8 baseline — processor contracts, Rule 6 security, a published Section 8(9) contact read with Rule 9, Section 8(10) grievance redressal, Section 8(7) erasure when the purpose ends.
- Section 9(3) prohibitions — no tracking or behavioural monitoring of children, and no targeted advertising directed at children. Parental consent cannot override this. Rule 12 read with the Fourth Schedule carves only narrow education- and safety-linked monitoring, never ads.
The DPDPA does not revive the old SPDI “sensitive personal data” category. Aadhaar copies, allergy notes, and photographs are personal data under Section 2(t) — and they are child data, which is why Section 9 is the operative overlay.
Form-level leaks are in admission forms, Aadhaar, and photos. Guardian checks are in verifiable parental consent for schools. This piece is the principal / trustee cut.
Does CBSE affiliation replace a school’s DPDPA duties?
No. Affiliation is a Board relationship. DPDPA is a statute. Completing one does not complete the other.
CBSE affiliated schools already send personal data to the Board: OASIS updates, SARAS affiliation filings, and Class IX / XI registration lists with student particulars under the Affiliation Bye-Laws (the Board restated para 14.2 in its 15 September 2025 registration circular). Those uploads are a purpose. Name them in the Section 5 notice. They are not a privacy programme.
| Regime | Who it answers to | What “done” looks like | What it does not do |
|---|---|---|---|
| CBSE affiliation / OASIS / SARAS | The Board | Accurate student and staff particulars, on the Board’s timeline | Discharge Sections 5, 6, 8 or 9 to parents |
| DPDPA (ordinary Data Fiduciary) | Data Principals + the DPB | Reconstructable consent, named contact, processor contracts, dual-clock drill | Replace Affiliation Bye-Laws, exam, or UDISE filings |
| DPDPA after Section 10 SDF notice | Same, plus extra SDF stack | India-based DPO, independent auditor, Rule 13 twelve-month DPIA/audit | Grant a grace period until 13 May 2027 |
Website-disclosure circulars pull in a third direction: publish the documents the Board requires, not student photographs, medical notes, or Aadhaar as “transparency.” Staff processing necessary for employment can sit under Section 7(i); optional staff publicity still needs Section 6.
Do not invent a CBSE–DPDPA mapping circular. If counsel is relying on one, put the number in the trustee pack. This article does not cite one.
Where does parent trust break on WhatsApp, ERP, and photos?
Parents do not read Affiliation Bye-Laws. They notice the class group, the annual-day reel, and the ERP login that still works after they withdrew a child.
| Surface | Typical school habit | What the Act asks | Trust failure |
|---|---|---|---|
| Admission file | One signature covers Aadhaar, medical, income, photos | Purpose-split Section 6 + Section 9(1); drop fields you cannot justify | Over-collection sitting in a cupboard and the ERP |
| Photographs | Website, Instagram, yearbook, press from the same consent line | Separate, optional, unconditional purpose; Section 9(3) bars ads directed at children | Indexed faces you cannot pull back |
| Parent WhatsApp | Class list, trip lists, medical flags in the group | Treat as publication; separate consent; no forwarding of child PII | Numbers and faces leave the school the minute they are posted |
| ERP / LMS / fee app | Vendor “has privacy” | Section 8(2) contract; no profiling; withdrawal must propagate | Edtech reuse and ad-funded “free” tools |
| Transport GPS | Live tracking shared widely | Narrow Rule 12 safety monitoring only; processor terms | Location as a broadcast, not a safety control |
Three rules keep repeating. Section 6 makes consent unconditional — a parent must be able to say yes to enrolment and no to the yearbook. Section 6(4) makes withdrawal as easy as giving consent, so you need a route to pull a child’s image and stop a vendor. Section 9(3) is not a consent question: targeted advertising directed at children is prohibited even if a parent would sign it.
Rejected applicants are the quiet leak. A school that admits 300 often still holds complete files for children it never enrolled. Section 8(7) wants those files gone when the purpose ended.
How should OASIS, SARAS, and edtech vendors be treated under DPDPA?
Treat Board portals as a named purpose, not as cover. Treat vendors as processors, not as the school’s privacy officer.
| Recipient | Why the school sends data | Fiduciary control to keep |
|---|---|---|
| CBSE OASIS / affiliation | Board-required school and staff particulars | Disclose in Section 5 notice; send what the circular requires, not extra child files |
| CBSE exam / Class IX–XI registration | Candidate lists and particulars | Purpose-limited extract; access-logged; no copy left in a teacher’s Drive |
| UDISE+ | Education-system statistical / administrative reporting | Same: named purpose, minimum fields, no WhatsApp side-channel |
| ERP / LMS / fee gateway / photographer / transport | School operations | Section 8(2) contract: purpose lock, no ads to children, breach escalation, deletion at exit |
Disclose OASIS or UDISE uploads as a named purpose and confirm the ground with counsel. Do not treat an upload as having obtained Section 9 verifiable parental consent for every other use.
If the LMS contract is silent on profiling and advertising directed at children, that silence is the school’s. The vendor is your processor; you remain the fiduciary. ICSE-shaped owner maps sit on the DPDPA ICSE schools page. The architecture is the same: sealed child PII, immutable consent, an audit trail that reaches the vendor.
Rule 13 does not change this table. Most schools will not be notified as Significant Data Fiduciaries. The Board can still demand consent evidence in any inquiry. SDF extras, if they ever land, are in Significant Data Fiduciary under DPDPA.
Who owns the CBSE school’s DPDPA checklist before 13 May 2027?
The trustee pack needs owners, not a policy PDF.
| Area | Owner | Status ☐ |
|---|---|---|
| Confirm SDF status from Gazette / MeitY Section 10 notices — do not self-score from enrolment size | Principal / Chair | ☐ |
| Named, published Section 8(9) contact, read with Rule 9 (not titled DPO unless notified) | Principal / office | ☐ |
| Section 8(10) grievance path with a real owner and a clock | Office / counsellor | ☐ |
| Purpose-split admission + photo + medical + transport consent; Rule 10 guardian check | Admissions Head | ☐ |
| WhatsApp rule: what staff may not forward; class groups treated as publication | Principal | ☐ |
| Section 8(2) contracts: ERP, LMS, transport, photographer, fee gateway — no child ads, deletion at exit | Principal + IT | ☐ |
| Board-reporting purpose named in the Section 5 notice (OASIS / registration extracts) | Principal + IT | ☐ |
| Saturday dual-clock drill: CERT-In 6h + DPB 72h | IT / Principal | ☐ |
| Do not buy a Rule 13 audit pack or DPO retainer unless and until notified | Trust / finance | ☐ |
Privigo’s design claim for this cohort is architecture, not a certificate: identifying data sealed and tokenised (aligned to Rule 6(1)), consent records append-only, an evidentiary trail that can follow a withdrawal into the ERP. That is the education solution argument. Software is not your DPO and it is not your statutory auditor.
What should a CBSE principal put in the trustee pack this term?
Three moves, in order:
- Write the two-regime sentence — “We are CBSE-affiliated. We are / are not a notified SDF as of [date]. Affiliation filings do not discharge DPDPA.” Put it in the trustee pack. Do not let a vendor slide replace that sentence.
- Close one parent-trust gap this fortnight — usually WhatsApp forwarding, photograph purpose-split, or the ERP processor contract. One closed gap beats a 40-page policy.
- Rehearse the dual clock on a student file — 6 hours to CERT-In, 72 hours to the Board. A named contact who has never run that drill is still theatre.
Sources
- Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), MeitY — Sections 2, 5–10, 33 and the Schedule: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY — Rules 6, 7, 9, 10, 12, 13: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- DPDP Act commencement, G.S.R. 843(E), 13 November 2025, MeitY: https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
- Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
- CERT-In — Directions under section 70B(6) of the IT Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- CBSE — Submission of Registration Data of Candidates for Class IX and XI, 2025–26, 15 September 2025 (Affiliation Bye-Laws para 14.2 restated): https://www.cbse.gov.in/cbsenew/documents/Submission_Registration_Data_Class_IXXI2526_15092025.pdf
- CBSE — Affiliation applications in SARAS 6.0 for session 2026–27, 11 March 2025: https://www.cbse.gov.in/cbsenew/documents/Circular_Aff_SARAS_6_0_11032025.pdf
This article is operational commentary for CBSE principals, trustees, and school management, not legal advice and not a determination of whether any named school is or will be a Significant Data Fiduciary. Confirm positions with qualified Indian counsel. CBSE affiliation, examination, and UDISE obligations continue in parallel with the DPDPA.
FAQ
Does CBSE affiliation make a school DPDPA-compliant?
No. Affiliation is a Board relationship under the Affiliation Bye-Laws. DPDPA duties attach because the school is a Data Fiduciary under Section 2(i) processing children’s personal data. Completing OASIS or SARAS does not discharge Sections 5, 6, 8 or 9.
Do CBSE schools need a Rule 13 annual DPDPA audit?
No. Rule 13 of the DPDP Rules, 2025 applies only after Section 10 notifies you as a Significant Data Fiduciary. Ordinary school Data Fiduciaries still owe Sections 4 to 9 and 11 to 14 in full by 13 May 2027, including Section 9 children’s duties.
Can a CBSE school post student photos in parent WhatsApp groups without separate consent?
No. A class WhatsApp group is publication, not internal admin. Section 6 requires consent that is free, specific, informed, unconditional, unambiguous, and given by clear affirmative action for that purpose, and Section 9(1) requires verifiable parental consent. Section 9(3) still bars targeted advertising directed at children.
Does submitting OASIS or UDISE data satisfy DPDPA?
No. Board reporting is a purpose you must name in the Section 5 notice. It does not replace a published Section 8(9) contact, a Section 8(10) grievance path, Section 8(2) processor contracts, or reconstructable consent evidence.


