TL;DR
- Section 9(1), DPDPA 2023: before processing any personal data of a child (under 18), a school must obtain verifiable consent of the parent or lawful guardian — the child’s own consent is legally irrelevant.
- Verifiable does not mean “signed a form”. It means the school can prove who consented, that they are an adult guardian of that child, what they consented to, when, and that the record has not been altered since — under Rule 10 of the DPDP Rules, 2025.
- The consent itself must still meet Section 6: free, specific, informed, unconditional, unambiguous, and given by a clear affirmative action — one purpose, one choice.
- Section 9(3) bans tracking, behavioural monitoring, and targeted advertising directed at children. Parental consent cannot override this; Rule 12 read with the Fourth Schedule allows educational institutions only narrow safety- and education-linked exemptions.
- The consent obligations land with the phased commencement on 13 May 2027 — admissions season 2027–28 will run under the new regime.
- Getting it wrong is not a paperwork issue: breach of additional obligations for children under Section 9 can attract penalties up to ₹200 crore (Schedule). The ₹250 crore slab applies to failure of security safeguards under Section 8(5), not to Section 9 itself.
What Counts as Verifiable Parental Consent in India Under Section 9?
Verifiable parental consent India is the DPDPA’s answer to a simple problem: children cannot lawfully consent to their own data being processed, and anyone can type a parent’s name into a form. Section 9(1) of the DPDPA 2023 therefore requires a Data Fiduciary — your school — to obtain the consent of a parent or lawful guardian and to be able to verify it.
Rule 10 of the DPDP Rules, 2025 spells out the due diligence: the school must adopt appropriate technical and organisational measures so that verifiable parental consent is obtained, and must check that the person identifying as the parent is an adult who is identifiable — by reference to reliable identity and age details already held by the school, details of identity and age voluntarily provided, or a virtual token mapped to such details (for example via authorised Digital Locker infrastructure). A checkbox that says “I am the parent” verifies nothing.
Two sections work together here, and conflating them is the most common school mistake:
- Section 6 defines what valid consent is — free, specific, informed, unconditional, unambiguous, clear affirmative action, purpose-limited.
- Section 9 defines whose consent is needed for a child and adds child-specific prohibitions.
A school needs both: a Section 6-grade consent, given by a Section 9-verified guardian. This article covers the operational workflow. For how to split purposes on the admission form itself, see our pillar guide on parental consent in school admissions under DPDPA.
How Does a School Actually Verify the Guardian? (The 4-Step Workflow)
Step 1 — Establish guardian identity and adulthood. Match the consenting person to the child. For existing families, your admission records already link guardian to student — use them. For new admissions, collect reliable age/identity details or a Digital Locker-mapped token at the point of consent. Record which method you used.
Step 2 — Serve a purpose-itemised notice. Section 5 requires a notice in clear, plain language (and available in English or any Eighth Schedule language) describing the personal data and each purpose. For schools this means itemising: admission processing, health records, photographs, transport, edtech platforms — each as a separate, describable purpose.
Step 3 — Capture a clear affirmative action per purpose. No pre-ticked boxes, no bundling (“consent to all school activities”), no making admission conditional on consenting to optional purposes like marketing photos. Unconditional means the parent can say yes to admission-essential processing and no to the yearbook.
Step 4 — Seal the evidence. Log guardian identity method, notice version, purposes consented, timestamp, and channel — in a record that cannot be silently edited later. This record is what survives a parent dispute, a vendor audit, or a Data Protection Board inquiry.
Which Child Data Purposes Need Which Handling?
| Data category | Typical purpose | Consent handling | Sharing risk |
|---|---|---|---|
| Admission & identity data | Enrolment, records | Core purpose; verifiable guardian consent at admission | ERP vendor (Data Processor contract needed) |
| Health & medical info | Infirmary, allergies, emergencies | Separate purpose line; never bundled with admission | School doctor, insurers |
| Photographs & videos | Yearbook, website, social media | Optional purpose; admission must not depend on it | Public internet — hardest to unwind |
| Transport & GPS data | Bus routing, pickup safety | Safety-linked; narrow Rules exemption may apply to tracking for the child’s safety | Transport vendor apps |
| Edtech / LMS accounts | Learning platforms, assessments | Separate consent; vendor must not repurpose child data | Highest risk: profiling, ads |
| Counselling records | Student wellbeing | Strictly access-controlled; separate purpose | Internal only |
What Is Absolutely Prohibited Even With Parental Consent?
Section 9(3) prohibits a Data Fiduciary from undertaking tracking or behavioural monitoring of children or targeted advertising directed at children. This is not a consent question — a parent cannot sign it away.
Rule 12 read with the Fourth Schedule (Part A) gives educational institutions narrow, purpose-bound relief from Section 9(1) and 9(3) only where processing is restricted to tracking and behavioural monitoring for the institution’s educational activities or in the interests of safety of enrolled children. A transport provider engaged by the school may track location during travel solely for child safety. What the exemption never covers: profiling students for ad targeting, letting an edtech vendor build behavioural profiles for commercial use, or ad-funded “free” platforms monetising student attention. If your LMS contract is silent on this, that silence is your liability — the school is the Data Fiduciary; the vendor is merely your Data Processor. Our deep-dive on minors, guardian consent and edtech under the DPDP framework covers vendor clauses in detail.
One myth to retire: DPDPA has no “sensitive personal data” tier carried over from the old SPDI Rules. Health data and photographs of children are not “extra-sensitive” as a legal category — but they are child data, which makes Section 9 the operative standard for all of it.
How Does Consent Evidence Survive Withdrawal, Vendors, and the Board?
Consent under Section 6(4) can be withdrawn as easily as it was given. Operationally, withdrawal is where paper-based consent collapses: the office file shows a signature from June, but cannot show that processing stopped in November, or that the transport vendor was told.
An evidentiary-grade setup needs three properties:
- Sealed storage — child PII held in a locked-down vault, not scattered across Excel sheets, WhatsApp groups, and vendor CSVs.
- Cryptographically immutable consent records — every grant and withdrawal timestamped and tamper-evident, so the school can prove the state of consent on any given date.
- A propagating audit trail — evidence that withdrawal reached every Data Processor holding that child’s data.
This architecture is Privigo’s core design: the consent record is built to be shown to a regulator, not just filed. And if a breach does occur, remember the dual clock — 6 hours to CERT-In under the CERT-In directions and 72 hours to the Data Protection Board under the DPDP Rules. Both clocks assume you can identify affected children fast, which again comes back to where the data lives.
(Note: mandatory annual audits under Rule 13 apply only to Significant Data Fiduciaries — most schools will not be notified as SDFs, but the Board can still demand your consent evidence in any inquiry.)
Who Owns What Before 13 May 2027? (Governance Table)
| Area | Owner | Status |
|---|---|---|
| Guardian identity verification method & records | Principal | ☐ |
| Purpose-itemised admission consent forms | Admissions Head | ☐ |
| ERP consent flags, immutable logging, withdrawal propagation | IT / ERP Admin | ☐ |
| Counselling & health record access controls | Counsellor / School Doctor | ☐ |
| Transport tracking scope (safety-only) & vendor terms | Transport In-charge | ☐ |
| Edtech vendor contracts: no profiling, no ads to children | Principal + IT | ☐ |
For ICSE-affiliated schools, our programmatic page on DPDPA compliance for ICSE schools in India maps these owners to board-specific workflows, and the Privigo DPDP guide walks through the full fiduciary checklist.
Closing: Three Steps Before the Next Admission Cycle
- Audit this week’s forms. Pull your current admission form and count the purposes hiding behind one signature line. Split them.
- Pick your verification method. Decide — and document — how you will establish guardian identity and adulthood for new admissions (existing records, ID details, or Digital Locker token).
- Test a withdrawal. Run one mock consent withdrawal end-to-end: can you show when consent stopped and that every vendor was informed?
Schools that can produce this evidence pack on demand will treat 13 May 2027 as a formality, not a fire drill.
Get your school’s free DPDPA Ready badge — start with a free gap scan →
Is verifiable parental consent mandatory for every child a school enrols?
Yes. Section 9(1) of the DPDPA 2023 requires a Data Fiduciary to obtain verifiable consent of the parent or lawful guardian before processing any personal data of a child (anyone under 18). Schools cannot rely on the child’s own consent, and the consent itself must still meet the Section 6 standard — free, specific, informed, unconditional, unambiguous, and given by a clear affirmative action.
Can a school track students or show them targeted ads if parents consent?
No. Section 9(3) of the DPDPA prohibits tracking, behavioural monitoring of children, and targeted advertising directed at children. Parental consent does not cure this — the prohibition sits above consent. Rule 12 read with the Fourth Schedule carves out narrow exemptions for educational institutions only for tracking and behavioural monitoring for educational activities or child safety — never for advertising.
Does a WhatsApp ‘OK’ from a parent count as verifiable parental consent under DPDPA?
No. A chat acknowledgement fails on two fronts: it does not verify that the responder is an adult who is the child’s parent or lawful guardian (the due-diligence duty under Rule 10 of the DPDP Rules, 2025), and it is not a specific, informed, purpose-linked affirmative action under Section 6. Schools need identity-checked, purpose-itemised consent with a tamper-evident record.
What happens if a parent withdraws consent mid-year?
Parents may withdraw at any time — Section 6(4) makes withdrawal as easy as giving consent. The school must stop the specific processing covered by that consent and have its Data Processors (ERP, edtech, transport vendors) do the same, unless another lawful ground applies. Processing done before withdrawal remains lawful, which is exactly why an immutable, timestamped consent record matters.
Sources
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Act, 2023 — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025 (Gazette notification) — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- Press Information Bureau, Government of India — Digital Personal Data Protection Bill, 2023 passed by Parliament — https://pib.gov.in/PressReleseDetail.aspx?PRID=1947264
This article is for general information only and is not legal advice. Consult a qualified professional for advice on your school’s specific DPDPA obligations.

