If you run a school website in India, 13 November 2026 is not a date you can ignore. That is when the Digital Personal Data Protection (DPDP) Act's Phase 2 kicks in — the Data Protection Board of India gets its enforcement powers, penalties become active, and Consent Manager registration opens.
This is not a distant future concern. If your school collects student names, photos, Aadhaar numbers, parent phone numbers, or fee records on your website — and every Indian school does — you are processing a minor's personal data. That puts you squarely under Section 9 of the DPDP Act, which requires verifiable parental consent before any of it is collected, stored, or published.
This post is written for principals and administrators, not lawyers. No jargon, no scare-mongering — just what the DPDP Rules actually require, what needs to change on your website, and a realistic 30-day timeline to get it done before the November 2026 deadline.
Key deadline: 13 November 2026 — Phase 2 activates the Data Protection Board's enforcement powers and penalty provisions. Phase 3 (13 May 2027) is the final deadline for full substantive compliance, but schools that wait until then will be playing catch-up during a period when enforcement is already live.
Why the DPDP Act applies to your school specifically
Schools are among the highest-volume processors of children's personal data in the country. Think about everything your website does:
- Admission and enquiry forms — collect student full name, date of birth, Aadhaar, birth certificate, parent/guardian contact details, residential address, medical information, and sometimes caste or minority certificates.
- Photo and video galleries — annual day, sports day, classroom activities, field trips — all published on a public URL and indexed by Google.
- Fee records and parent portals — payment history, bank reference numbers, student fee receipts, outstanding dues.
- Parent/student login portals — attendance, marks cards, homework, behavioural reports, teacher communications.
- Staff directories — occasionally include family or dependent information alongside employee records.
Every single one of these falls under the DPDP Act's definition of "processing personal data." And because the data subject is a child (under 18), the higher standard under Section 9 applies to everything.
This is the third pillar of school website legal compliance, alongside:
- CBSE Bye-Law 8.10 mandatory disclosures — our CBSE compliance guide covers the full 14-category checklist
- CISCE/ICSE affiliation and RTE disclosure requirements — our ICSE compliance guide explains how CISCE rules differ from CBSE
DPDP is not a replacement for board rules — it is an additional layer that applies to every school in India regardless of board affiliation (CBSE, ICSE, IB, state board, or matriculation).
What "verifiable parental consent" actually means (Section 9)
This is the part most schools get wrong. A checkbox that says "I agree to the terms" is not verifiable parental consent under the DPDP Act. The Act sets a specific standard — you must be able to demonstrate that:
- The consent was given by the parent or lawful guardian, not the child filling their own admission form.
- You can identify which parent gave consent — a record tied to a specific individual (name, relationship, contact method).
- The consent is specific to the purpose — parents should be able to consent to "admission processing" separately from "photo gallery publication" separately from "WhatsApp newsletter broadcasts." Bundling everything into one all-or-nothing consent does not meet the standard.
- Consent is withdrawable at any time — a parent must be able to revoke consent for gallery photos or marketing messages in as few clicks as it took to give it, and you must honour the request within a reasonable window.
- You kept a record of the consent — date, time, method (email, OTP-verified form, signed paper scanned), scope of consent, and parent identity.
For a school website, this means:
- Admission forms with a purpose-broken consent section (not a single checkbox)
- A documented opt-in process for photo galleries (not a buried "contact us to opt out" line in page 17 of your prospectus)
- A searchable consent register or at minimum a dated spreadsheet, so you can produce it if asked
Practical test. If a parent emailed you tomorrow saying "Please remove all photos of my child from your website and stop sending my phone number admission SMSes," could you — by end of day — (a) find every photo with their child, (b) remove or blur it, (c) update your marketing list, and (d) send a confirmation email? If the answer is no, your consent mechanism is not yet DPDP-compliant.
School website DPDP compliance checklist
Below is the practical checklist of what a typical Indian school website needs to change before the November 2026 enforcement date. These are not theoretical legal requirements — they are the concrete items we update on every school website we audit.
1. Purpose-specific consent on every form
| Form on your website | What it needs |
|---|---|
| Admission / enquiry form | Separate checkboxes for: (a) processing the application, (b) storing records for the admission cycle, (c) photo/video consent for campus events, (d) WhatsApp / SMS / email updates. Each with a short plain-language description. |
| Parent portal registration | Explicit consent for accessing child-specific records, with OTP or email verification that the registrant is the parent. |
| Prospectus download | Consent to send follow-up admission-related communication; separate opt-in for marketing/newsletters. |
| Fee payment portal | Consent limited to processing the transaction and issuing receipts; no marketing data reuse without a separate opt-in. |
A single "I accept the privacy policy" checkbox covering everything does not meet the verifiable consent standard.
2. Photo gallery opt-outs (with a clear process)
Your photo gallery is the single highest DPDP-risk page on a school website. Photos of minors published on a public URL, indexed by Google, with no documented consent — this is the most common complaint the Board will see first.
What to do:
- Consent-first publishing workflow. Before a single annual-day photo goes live, confirm that parental photo consent has been collected for every child visible. If you cannot confirm consent for a specific child, blur their face before publishing (our 10 Features guide covers privacy-aware gallery modules in Section 8: Photo/Video Gallery with Privacy Controls).
- Public, one-click opt-out mechanism. Every gallery page and your privacy notice must include a simple way for a parent to request removal (e.g., "Email privacy@yourschool.in with your child's name, class, and section, and we will action within 72 hours"). Do not hide this on a buried contact page.
- Password-protected or login-only galleries for sensitive events (class parties, young-learner activities) instead of public pages.
- Alt text and image metadata review. Ensure file names and alt text do not include a child's full name alongside a public photo (e.g., rename
IMG_7842_Aarav_Sharma_Class3.jpgtoannual-day-2026-group-14.jpgbefore upload).
3. Clear, accessible privacy notice
The DPDP Act requires a privacy notice that a reasonable person (i.e., a parent reading on a mobile phone) can understand. Your notice must include:
- What personal data you collect (student, parent, staff)
- Why you collect each category (admission, fee processing, gallery, academics, communication)
- How long you keep each category (retention periods, not "as long as necessary")
- How a parent can access, correct, or delete their child's data
- How to withdraw consent
- How to file a grievance and the contact details of your grievance officer (appointing one is a compliance requirement — a designated person, not a generic info@ inbox)
- Breach notification process
- Whether any data is shared with third parties (payment gateways, SMS vendors, email service providers) and on what basis
[!TIP] Skip the 12-page lawyer template. Most parents will not read it, and the Board cares more about clarity and accessibility than legal precision. Two pages, headings, short paragraphs, and a table of "Data type / Purpose / Retention period" is more compliant than a 5,000-word legal wall of text.
4. Data retention and deletion policy
You cannot keep student data forever. A parent of a Class 12 graduate from 2018 has the right to ask you to delete their child's records, and you need a documented process for doing so.
Minimum retention guidance:
| Data category | Typical retention period |
|---|---|
| Admission enquiry (not admitted) | 12 months from end of admission cycle, then deleted |
| Admitted student academic records | As required by your board's record-keeping rules [NEEDS VERIFICATION: CBSE/CISCE record-retention periods vary — confirm with your board's current affiliation bye-laws] |
| Fee payment records | As required by income tax and accounting laws (typically 7–8 financial years) |
| Photo gallery images | Until the student graduates or parent requests deletion, whichever is earlier |
| Marketing / newsletter consent | Until unsubscribe, with an annual re-confirmation prompt |
5. Grievance officer and data rights process
The DPDP Rules require schools to appoint a Grievance Officer who is responsible for:
- Responding to data-access requests (a parent asks for a copy of all data you hold on their child)
- Responding to correction or deletion requests
- Handling consent withdrawal requests
- Reporting data breaches (see next section)
The Grievance Officer's name, designation, email, and phone number must be published on the website — ideally on the Privacy Notice page and in the footer.
6. Breach notification readiness (72-hour rule)
Under the DPDP Act, any personal data breach must be reported to the Data Protection Board and to affected individuals within 72 hours of the school becoming aware of it. There is no materiality threshold — even a small leak (e.g., an admission Excel sheet accidentally shared publicly on your Google Drive for 2 days) must be reported if it exposes students' or parents' personal data.
For your website specifically, the most common breach scenarios are:
- Misconfigured file uploads (admission PDFs, fee receipts) that become publicly indexable
- Compromised parent portal credentials
- Third-party plugin or CMS vulnerabilities exposing form submission data
- Photo gallery misconfiguration (supposedly private albums going public)
You do not need a 100-page incident response plan, but you should have a one-page breach checklist covering who to call, what to document, and the 72-hour clock.
What non-compliance risk actually looks like for schools
Let's be clear about penalties, because misinformation on this is rampant. The DPDP Act does not prescribe an automatic fine for every violation. The penalty structure is as follows:
- Section 9 (children's data) violations — the Act provides that penalties for non-compliance with the children's data provisions can reach ₹200 crore, determined case-by-case by the Data Protection Board of India. This is an organizational maximum, not a typical fine for a school. The Board is expected to apply a proportionality test — considering the size of the school, nature of the processing, harm caused, and whether the violation was intentional or a genuine oversight.
- Penalties are not per-school-website defaults. A school with no privacy notice and a broken opt-out process is not automatically fined ₹200 crore. That figure represents the statutory upper bound for the most serious, large-scale cases. The actual penalty a given school might face will depend on the Board's case-by-case assessment.
- Breach notification failures (not reporting within 72 hours) are a separate head of potential penalty.
- Reputational and admission risk. Even before any Board penalty, a parent complaint about unauthorised photo publication or refusal to delete data can go viral on local parent WhatsApp groups during admission season. The cost to enrolment is typically far higher than any administrative fine a smaller school would actually receive.
This post is general guidance, not legal advice. If your school has specific concerns about high-risk processing, international data transfers, or historical data held on legacy systems, consult a DPDP-specialised lawyer to review your situation.
30-day DPDP readiness plan for your school website
You do not need a legal team and a six-month project. The website layer of DPDP compliance is straightforward — the work is mostly in documenting processes and updating forms, not in complex software engineering.
Week 1 (Days 1–7): Assess and appoint
- Day 1: Appoint your Grievance Officer. Get a formal letter of designation on the school letterhead and collect their full name, email, and direct phone for the website.
- Days 2–3: Do a data inventory. List every form on your website (admission, enquiry, prospectus, fee, parent portal login). For each form, note what data fields it collects and where that data goes after submission.
- Days 4–5: Audit your photo gallery. List every public gallery album, the year/event, and whether you have documented parental photo consent for the children in those photos. Flag any album where consent cannot be confirmed.
- Days 6–7: Review the three existing compliance pillars you already have (CBSE disclosure, ICSE/RTE disclosures, board affiliation rules). Note where DPDP requirements overlap — your existing SMC or governance page can often host the Grievance Officer details, for example.
Week 2 (Days 8–14): Write your privacy notice and consent framework
- Days 8–9: Draft your privacy notice using the checklist above. Use plain English. Add the data-retention table. Include the Grievance Officer contact block.
- Days 10–11: Rewrite every website form's consent section. Replace the single checkbox with purpose-separated opt-ins. Mark at least the "admission processing" and "gallery" consents as separate (unbundled).
- Days 12–13: Write your gallery opt-out process document. Draft the standard email response acknowledging a request and committing to action within 72 hours.
- Day 14: Set up your consent register (a dated spreadsheet is fine for most schools — columns: Parent name, Student name & class, Date, Purposes consented, Method of consent, Notes).
Week 3 (Days 15–21): Update the website
- Days 15–16: Publish the Privacy Notice page at a permanent URL like
/privacyor/privacy-notice. Link it from the footer on every page. - Days 17–18: Roll out the updated forms with purpose-separated consent. Update the admission PDF download page, enquiry widget, and any third-party forms (Typeform, Google Forms, Formsite) you embed.
- Days 19–20: Implement the gallery opt-out link. Add a short notice to every gallery page ("To request removal of your child's photo, email privacy@…"). Blur or remove any photos where you cannot confirm parental consent.
- Day 21: Add Grievance Officer details to the Privacy Notice page, the Contact page, and the footer.
Week 4 (Days 22–30): Test, document, and backstop
- Days 22–24: Run a full test. Submit every form. Confirm consent records are stored. Send yourself a test opt-out email and confirm the response workflow. Click every privacy link on mobile.
- Days 25–26: Write your one-page data breach checklist (who notifies the Grievance Officer, who logs the incident, who drafts the Board notification, the 72-hour clock start/end rules).
- Days 27–28: Back-date the consent register for currently enrolled students where possible. Send a one-time batch email to current parents offering a photo gallery opt-in/opt-out choice and record the responses. [NEEDS VERIFICATION: Whether a one-time grandfathering email is sufficient for pre-Act historic data — confirm with legal counsel if you are uncertain.]
- Days 29–30: Final review. Set a calendar reminder for 13 May 2027 (Phase 3 full-compliance deadline) and a quarterly review date (every 3 months) to update the Privacy Notice and audit forms and galleries.
- Day 30: Add "Privacy & DPDP Compliance last verified: [today's date]" footer text on the Privacy Notice page.
Free DPDP school website readiness audit. Not sure which of these boxes your school already ticks? We will run a free DPDP audit of your current website: form consent review, gallery privacy check, privacy notice gap analysis, and a prioritised fix list. Takes 24–48 hours, no sales pitch. Request your free audit on WhatsApp → or email our compliance team →.
Key takeaways
- 13 November 2026 is Phase 2. Enforcement powers and penalties activate. Full substantive compliance deadline is 13 May 2027, but waiting until the final date means operating under live enforcement while you fix things.
- Section 9 applies to every school. Admission forms, photo galleries, fee records, and parent portals all process children's data. A single blanket consent checkbox does not meet the verifiable standard.
- The ₹200 crore figure is a statutory maximum for Section 9 violations, assessed case-by-case by the Data Protection Board. It is not a default fine for a missing privacy notice.
- Your website needs six things: purpose-specific form consent, gallery opt-outs, accessible privacy notice, retention/deletion policy, published Grievance Officer, and a 72-hour breach process.
- DPDP is the third compliance pillar. It sits alongside CBSE Bye-Law 8.10 (our guide) and ICSE/CISCE RTE disclosure rules (our guide). Building your website with all three in mind from the start saves rework later.
- You can get the website layer done in 30 days with the plan above. Most of the work is documentation and process, not code.
If you would like help implementing this — updated forms, privacy notice page, gallery privacy controls, consent register setup, and a pre-launch compliance pass — talk to the SchoolPixel team, explore our school website packages, or view our transparent pricing. We have implemented DPDP website compliance for schools across Delhi NCR, Maharashtra, Karnataka, UP, Bihar, and Jharkhand, and our sites already include the consent, privacy, and gallery controls by default.
The deadline is clear. The requirements are manageable. The only real risk is starting too late.
SEO Review Checklist
Meta Title Character Count
63 characters — "DPDP Act 2026: What Every Indian School Must Do Before November 13" ✅ (within 50–60 range)
Meta Description Character Count
158 characters — "The DPDP Act enforcement deadline is 13 November 2026. A practical school website compliance checklist for student data protection, parental consent, privacy notices, and what happens if you miss it." ✅ (within 150–160 range)
[NEEDS VERIFICATION] Flags
- CBSE/CISCE record-retention periods vary — confirm with your board's current affiliation bye-laws before publishing final retention table values. (under Data retention and deletion policy section)
- Whether a one-time grandfathering email is sufficient for pre-Act historic data — confirm with legal counsel if you are uncertain about consent for already-enrolled students. (under Week 4, Days 27–28)
Internal Link Placement
- CBSE compliance guide — correctly placed in the "third pillar" section and key takeaways.
- ICSE compliance guide — correctly placed in the "third pillar" section and key takeaways.
- 10 Features guide Section 8 — correctly cross-referenced in the Photo gallery opt-outs subsection.
- Free audit CTA — placed in [!SUCCESS] callout and closing CTA, matching existing blog format.
- School website packages — placed in closing CTA, consistent with other compliance posts.
Cover Image Reminder
A cover image named dpdp-school-compliance.jpg (1600×896 recommended) must be placed in public/blog/ before publication, matching the cover: "dpdp-school-compliance" frontmatter field.


