Mandatory Section 9 Compliance · ₹200Cr Penalty Tier

DPDPA Compliance for Education & EdTech — Section 9 Changes Everything

If your platform serves students under 18 — and in India, that means anyone under 18, not just young children — Section 9 of the DPDP Act applies. This is among the strictest children's data protection regimes globally, with a uniform 18-year threshold that captures teenagers, college students under 18, and school-age children equally.

EdTech platforms, learning management systems, online tutoring services, school information systems, examination portals, and student assessment platforms all process children's personal data at scale. Section 9 does not just require consent — it imposes absolute prohibitions on behavioural tracking and targeted advertising, even with parental consent. Penalties reach ₹200 crore per violation.

Child Data Safeguards

Key Compliance Challenges for EdTech

Verifiable Parental Consent (Section 9(1))

Before processing any student data, you must obtain verifiable consent from the parent or guardian. A student clicking “I am over 18” does not count. You need age verification gates and verified parental consent workflows — via existing parent accounts or DigiLocker verification.

Absolute Tracking and Advertising Bans (Section 9(3))

No behavioural tracking of students for engagement optimisation. No targeted advertising directed at students based on their data. No profiling for any purpose. These prohibitions apply even with parental consent. If your platform runs analytics on student behaviour to optimise content or targets ads to students, you are non-compliant.

Student Data Across Multiple Systems

Student information systems, learning management platforms, assessment engines, payment systems, communication tools, and parent portals all hold student personal data. Data discovery must map this across every system.

Teacher and Staff Data

Education institutions also process employee personal data — teachers, administrative staff, and support personnel. This is standard DPDPA compliance separate from children's data obligations.

Third-Party Learning Tools

EdTech platforms integrate with content providers, video conferencing tools, assessment vendors, and payment gateways. Each vendor processing student data needs a DPA with specific children's data protections.

Platform Capability Mapping

Which PrivacyOS Modules You Need

ModuleWhy It Matters for EdTech
Children's Data ProtectionAge verification, parental consent workflows, tracking/ad restrictions
Consent ManagementParental consent capture, multilingual notices for diverse parent base
DSR AutomationParent-initiated access and erasure requests for student data
Data DiscoveryMap student PII across LMS, SIS, assessment, and payment systems
Vendor RiskContent providers, video tools, assessment vendors with children's data DPAs
Compliance TrainingTeacher and staff training on student data handling
Frequently Asked Questions

Section 9 & EdTech Questions

STUDENT PRIVACY & SECTION 9

Eliminate Child Data Penalties & Verify Parental Consent

Deploy automated DigiLocker/SMS guardian authentication, kill tracking pixels, and secure student databases.