Students may forget the systems they used at school. Those systems may continue to remember them.
Most students think their school has their name, photograph, address and marks.
That is only the visible part of the record.
A school, college, examination body or education platform may also hold Aadhaar details, APAAR IDs, family-income information, caste certificates, disability records, medical information, counselling notes, disciplinary records, fingerprints, facial images, CCTV footage, transport-location data, hostel-entry logs, examination recordings, device information, aptitude scores and placement records.
Some of this is submitted through forms. Some is uploaded to apps. Some is generated automatically whenever a student enters a campus, uses the institution’s Wi-Fi, attends an online class or takes a remotely proctored examination.
The lasting risk
The student may forget the system. The system may continue to remember the student.
The APAAR controversy has brought one part of this problem into public view: can a scheme genuinely be called voluntary when the form explains how to consent but does not clearly explain how to refuse?
That question is much larger than APAAR. Students and parents are constantly asked to provide data. They are rarely taught what they should ask before providing it—or what rights they may have afterwards.
The DPDP Act will change what students can ask
Most substantive provisions of the Digital Personal Data Protection Act, 2023 relating to consent, student rights, children’s data, security and breach notification are scheduled to become operational on 14 May 2027.
These protections should therefore be understood as forthcoming statutory rights and obligations, not remedies that are fully available today.
The Act applies to personal data collected digitally and also to information collected on paper and digitised later. A scanned medical certificate, an admission form entered into a school ERP and a counselling record uploaded to cloud storage can all fall within its framework.
For anyone below eighteen, the Act treats the parent or lawful guardian as part of the “Data Principal.” Parents will therefore exercise many of these rights on behalf of the child. Once the student becomes an adult, the student becomes the person entitled to exercise them directly.
Potential rights every student and parent should understand
1. The right to know what data is being collected
Where consent is sought, the institution must explain the personal data it proposes to process and the purpose for which it will be used.
The Rules require an itemised description of the data and a specific explanation of the services or uses enabled by that processing. A statement such as “your information may be used for educational purposes” should not be enough to explain the collection of Aadhaar details, biometrics, health records, location information and examination recordings.
Each category should be explained separately.
2. The right to receive a clear explanation
Consent requests must be presented in clear and plain language. Students and parents must also be given the option to access the notice and consent request in English or a language listed in the Eighth Schedule to the Constitution.
A dense declaration hidden inside an admission booklet should not replace a clear explanation of what is being collected, why it is needed and how rights can be exercised.
3. The right to make a genuine choice
Consent under the Act must be free, specific, informed, unconditional and unambiguous. It must involve clear affirmative action and must be limited to data necessary for the stated purpose.
This means an institution cannot make consent appear compulsory merely by giving the student only one visible option: “I agree.”
It also means one signature should not silently authorise several unrelated activities. Admission, publication of photographs, behavioural profiling, commercial marketing, AI-model training and alumni communication are different purposes.
The APAAR lesson
The ability to withdraw consent later is not a substitute for the ability to refuse before processing begins.
4. The right to refuse unnecessary data collection
A school or education platform should collect only the information necessary for the specified purpose.
A scholarship application may require income information. It does not need access to the student’s phone contacts.
A transport application may need location during the journey. It does not automatically need to track the student on weekends.
An examination platform may need identity verification. That does not automatically authorise indefinite retention of the recording or use of the student’s face to train another product.
The fact that a person clicked “agree” does not validate the collection of data that was unnecessary for the stated purpose.
5. The right to withdraw consent
Where consent is the legal basis for processing, it may be withdrawn at any time. Withdrawing it must be as easy as giving it.
A school cannot obtain consent through a single click and then require letters, physical visits and several administrative approvals to withdraw it.
Withdrawal does not make earlier lawful processing illegal. It may also have consequences where the data is genuinely necessary to provide a requested service. But the institution must ordinarily stop the relevant processing within a reasonable time and require its processors to stop, unless continued processing is authorised by law.
6. The right to know what is being done with the data
Where the processing is based on consent, the student or parent may ask for a summary of the personal data being processed and the processing activities being carried out.
The word summary matters. The Act does not provide an unrestricted right to obtain every internal record, recording, teacher’s note or algorithmic score.
But a student may still ask:
- Is biometric information being processed?
- Are examination recordings retained?
- Is behavioural profiling being conducted?
- Has an automated system generated a cheating flag or risk score?
- For what purpose is each category being used?
7. The right to know who received the data
The access right also allows the student or parent to ask for the identities of other Data Fiduciaries and Data Processors with whom the information has been shared, together with a description of what was shared.
This may be one of the most useful rights in education.
A school may use one company for its ERP, another for attendance, another for transport, another for online examinations, another for fee collection and another for cloud storage.
Parents may believe the data remains “with the school” when it is travelling through an entire vendor ecosystem. This right can make that ecosystem visible.
8. The right to correct inaccurate information
A wrong date of birth, category, disability status, attendance record, disciplinary entry or examination result can affect admissions, scholarships, certificates and employment.
For consent-based processing, the Act provides rights to seek correction of inaccurate or misleading data, completion of incomplete data and updating of outdated data.
The institution also has an obligation to ensure that data is complete, accurate and consistent where it will be used to make a decision affecting the student or shared with another Data Fiduciary.
This becomes particularly important when institutions use facial recognition, automated attendance, remote-proctoring systems or AI-based student analytics.
9. The right to seek erasure
For consent-based processing, students and parents may seek erasure of personal data where continued retention is no longer necessary, unless it must be retained for the specified purpose or to comply with another law.
This raises basic questions that institutions should be able to answer:
- Why is an unsuccessful admission applicant’s documentation still being retained?
- Why does a proctoring company continue to hold webcam footage after the examination and dispute period have ended?
- Why is transport-location data retained after the student has left the institution?
Erasure is not absolute. Educational records, accounting information, examination records or evidence connected with legal disputes may need to be retained. But retention should have a reason, not merely continue because deletion requires effort.
10. The right to raise a grievance
Every Data Fiduciary must establish an effective grievance-redressal mechanism and publish the contact details of a person who can answer questions about the processing of personal data.
A student or parent may raise a grievance about excessive collection, unauthorised sharing, refusal to correct records, continued processing after withdrawal, improper retention or failure to facilitate statutory rights.
The institution’s grievance process must ordinarily be used before approaching the Data Protection Board.
11. The right to be informed of a data breach
When a personal data breach occurs, the affected student or parent must be informed without delay.
The notification must explain the nature and extent of the breach, its likely consequences, the steps taken by the institution, the precautions the affected person can take and whom they may contact for answers.
Students should not learn through social media that their Aadhaar details, medical records, counselling information or examination recordings have been leaked.
12. Additional protection for children
The Act generally requires verifiable parental consent before processing a child’s personal data.
It also prohibits processing likely to cause a detrimental effect on a child’s well-being and generally restricts tracking, behavioural monitoring and targeted advertising directed at children. These protections are subject to specific exemptions prescribed in the Rules.
The well-being protection is particularly important.
A system that publicly ranks weak students, exposes counselling information, permanently labels children through behavioural predictions or treats an unreliable AI output as fact may harm a child even when the original data was collected for an educational purpose.
One important limitation
The rights to access, correction and erasure are framed mainly around processing for which the student or parent previously gave consent.
Where an institution or government authority relies on another legal basis—such as compliance with law or the provision of a government benefit, service or certificate—these rights may not apply in precisely the same way.
Students must therefore learn to ask one additional question:
Ask for the legal basis
What legal basis are you relying on to process this data?
Calling something “mandatory” is not an explanation. The institution should be able to identify the law, rule, policy or consent on which it relies.
Five questions every student and parent should always ask
Whenever a school, college, examination body, education platform or government scheme asks for personal data, ask:
- What exactly are you collecting?
- Why do you need each item?
- Is providing it compulsory, and under which law?
- Who will receive or process it, and how long will they retain it?
- What happens if I refuse or later withdraw consent?
Students are taught how to upload documents, activate accounts, link identifiers and accept terms.
They must also be taught how to question collection, identify unnecessary data, trace where their information has travelled and exercise the rights available to them.
A student’s data may begin as an admission record. Over time, it can become a lifelong digital profile.
Knowing how to protect that profile is now part of being educated.
Official sources
- Digital Personal Data Protection Act, 2023
- Digital Personal Data Protection Rules, 2025
- Government commencement notification, 13 November 2025
This article is general educational information and not legal advice. The relevant substantive provisions are scheduled to commence on 14 May 2027.