Author: Dr. Pawan Kumar
DOI Link: https://doi.org/10.70798/Bijmrd/04080020
Abstract: Background: Educational institutions are among the largest processors of personal data including minors’ data. With rapid digitization of admission, Learning Management Systems (LMS), fee payments and surveillance, data vulnerability has increased. Objective: This review article analyzes the provisions of the Digital Personal Data Protection Act, 2023 and its relevance, mandatory requirements, and implementation challenges for schools, colleges and universities in India. Methods: A doctrinal and systematic review of the DPDP Act, 2023, Draft DPDP Rules 2025, Data Protection Board notifications, and secondary literature from 2018-2026 was conducted. Comparative analysis with GDPR, FERPA and Indian IT Act was performed. Results: The Act imposes fiduciary obligations on educational institutions including verifiable parental consent under Section 9, purpose limitation, data minimization, breach notification within 72 hours, and penalties up to INR 250 crore. Conclusion: DPDP compliance is not merely legal obligation but strategic enabler of trust, data security and global academic collaboration. A phased implementation model is proposed.
Keywords: DPDP Act 2023; Data Fiduciary; Student Privacy; Children Data; Educational Institutions; Data Protection Board of India; Verifiable Parental Consent.
Page No:154-161
