Readiness assessment
EdTech

The DPDP Act for EdTech

Because EdTech so often processes the data of children, it triggers the strictest rules the Act has on consent and advertising.

In short

EdTech handles learner data, and very often data of children under 18, which triggers the strictest rules the Act has: verifiable parental consent, and no tracking or targeted ads at children. The usual consent, security and rights duties also apply. Penalties reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Verifiable parental consent

For under-18s, get consent that is genuinely verifiable from a parent or guardian.

No tracking of children

No behavioural tracking or targeted advertising directed at children.

Consent and notice

Clear notices and consent for every learner and, where relevant, their parent.

Data minimization

Collect only what teaching and assessment need, not more.

Learner and parent rights

Support access, correction and erasure for learners and guardians.

Security and processors

LMS, proctoring and analytics vendors are processors you must oversee.

Go deeper

Niche guides for this area, each naming the specific regulation.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Take the readiness check