Skip to content
ANANTATECH HUB

Guide

You are holding data about children

The DPDP Act treats anyone under 18 as a child and applies stricter rules. Most institutions are holding more of it than they need.

1 min read

The threshold is 18, not 13

The Digital Personal Data Protection Act, 2023 defines a child as anyone under 18, which is higher than the threshold many international frameworks use and higher than most institutions assume.

For that data the Act requires verifiable parental consent, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. A school running an ad-supported tool or a service that profiles students should look carefully at what that tool does.

Write down what you hold

Institutions accumulate data. Admission forms capture parental occupation and income that nothing downstream ever uses. Medical details are collected once and retained indefinitely. Photographs are taken for one purpose and reused for another.

The exercise worth doing is listing every field and naming the purpose it serves today. Fields with no current purpose are liability with no benefit.

Photographs need their own answer

Student photographs on a website, in a prospectus or on social media are the most common place institutions get this wrong, because consent was given for an identity card and reuse was never discussed.

Ask separately, record the answer, and make it easy to withdraw. A parent who says no should not have to say it twice.

Where to get advice

Retention periods for academic records, what may be disclosed to a non-custodial parent, and obligations under education regulations sit alongside the DPDP Act and vary by board and state. Those are questions for a professional who knows your institution, not for a guide.

Questions about anything here, or a situation this does not cover? contact@anantatechhub.com