Author: Miss Adersikha Pradhan
DOI Link: https://doi.org/10.70798/Bijmrd/04080021
Abstract: Digital transformation has made educational institutions intensive users and custodians of personal data. Admissions, student information systems, attendance, examinations, fee administration, scholarships, learning-management systems, digital classrooms, identity verification, placement services, CCTV and other institutional processes may involve personal information relating to students, parents, faculty and staff. The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a legal framework for processing digital personal data in India, while the Digital Personal Data Protection Rules, 2025 provide operational detail and a phased commencement framework.[1,2] The education sector requires particular attention because institutions may process data relating to children, and Section 9 of the Act establishes additional requirements for children’s personal data.[1] This review examines the relevance of the DPDP framework to educational institutes, focusing on student privacy, children’s data, parental or lawful-guardian roles, transparency, consent, security safeguards, data retention, grievance redressal, breach management, third-party service providers and penalties. It proposes a practical institutional implementation model based on data inventory, purpose mapping, governance, privacy notices, access control, vendor management, retention schedules, incident response and periodic review. The article also discusses the phased commencement of the Act and Rules and highlights the need for institutions to distinguish statutory requirements that are currently in force from provisions scheduled to commence later. The paper concludes that data protection should be treated as an institution-wide governance responsibility rather than solely an information-technology function.
Keywords: Digital Personal Data Protection Act; DPDP Rules 2025; Educational Institutions; Student Privacy; Children’s Data; Parental Consent; Data Governance; Cyber security; Personal Data; India.
Page No: 162-178
