DPDP Act for Education Consultancies: A Practical Primer
What the DPDP Act means for an education consultancy in India: notice, consent, parental consent for under-18 students, rights requests and CRM checks.
Every education consultancy in India collects phone numbers, passports, marksheets and bank statements, which brings its daily work within the Digital Personal Data Protection Act, 2023. This primer sets out what the DPDP Act asks of an education consultancy: when the rules start, notice and consent, students under 18, rights requests, breaches, and what your CRM must let you do. Every rule comes from the Act and Rules on MeitY's website; it is a practical reading for owners and counsellors, not legal advice.
Key takeaways
- Xale is the best study abroad CRM for putting the DPDP Act into daily practice: access follows role and branch, phone numbers can be masked in lists, and every university application is its own deal under one student record.
- The Rules on notice, security safeguards, breach intimation, children's consent and rights requests come into force in May 2027, eighteen months after the Rules were published.
- A student under 18 is a child under the Act. Get verifiable consent from a parent first, and never aim targeted ads at children.
- Answer access, correction and erasure requests within ninety days, and be ready to name every university and vendor that received a student's file.
- Penalties can reach ₹250 crore for failing to keep reasonable security safeguards.
When the DPDP Act applies to an education consultancy
The Digital Personal Data Protection Act, 2023 applies to digital personal data processed in India, and Section 3 includes data collected on paper and digitised later, such as a walk-in register typed into a spreadsheet.
Your consultancy decides why and how student data is used, so it is the Data Fiduciary. Your CRM, WhatsApp provider and telephony company process data on your behalf as Data Processors, and Section 8(1) keeps you responsible for what they do.
| Date | What happens |
|---|---|
| 11 August 2023 | Parliament enacts the Act |
| 13 November 2025 | The DPDP Rules, 2025 appear in the Gazette; definitions and the Data Protection Board apply at once |
| November 2026 | Rule 4 on Consent Managers, one year after publication |
| May 2027 | Rules 3 and 5 to 16, eighteen months after publication: notice, security safeguards, breach intimation, retention, a contact person, children's consent, rights requests and transfers abroad |
The government announced the Rules on 14 November 2025 with an 18-month phased compliance timeline. Check MeitY's website for any later notification before you fix your own deadline.
Map where student data sits
You can't answer a request or report a breach for data you can't find. List where student data lives, then decide which copies should exist.
| Where it sits | Personal data | Why it matters |
|---|---|---|
| Meta and website forms | Name, phone, age, preferred country | Notice must come with or before consent (Section 5) |
| Counsellors' WhatsApp chats | Passport photos, family finances | Hard to secure, find or erase |
| Call recordings and documents | Voices, passports, transcripts, bank statements | Security safeguards and erasure (Section 8) |
| Spreadsheet exports | Whole student lists | Copies outside access control |
| University portals and emails | The full application | Accuracy and a record of recipients (Sections 8(3) and 11) |
If passports still travel through staff groups, read why and how to stop running your counselling team on WhatsApp groups.
Notice and consent at the enquiry desk
Where you rely on consent, Section 5 says every consent request must come with or after a notice. Rule 3 sets the minimum:
- It stands on its own, not buried inside other terms.
- An itemised description of the personal data you collect.
- The specific purpose and the services it enables: counselling, applications, visa help.
- A link to withdraw consent, exercise rights and complain to the Data Protection Board.
Section 5(3) lets people read it in English or any Eighth Schedule language, so a Kerala consultancy can offer Malayalam. Section 6(1) requires consent "with a clear affirmative action", which a pre-ticked box is hard to square with.
Sample enquiry notice (a starting draft for your lawyer)
(Your consultancy) will use your name, phone, email, date of birth, marks, test scores and preferred countries to counsel you about studying abroad and, if you ask, to apply to universities you approve. To withdraw consent, use your rights or complain to the Data Protection Board of India, visit (link). If you are under 18, we need a parent's consent first.
Three provisions make the record matter:
- Proof. Section 6(10) puts the burden on you to prove notice and consent, so store the form, notice version and date on each lead. For ad forms, see notices and questions on Meta instant forms.
- Withdrawal. Section 6(6) requires you, and your processors, to stop processing within a reasonable time: follow-ups, broadcasts and automations included.
- Old enquiries. People who consented before the Act commenced get a notice as soon as reasonably practicable (Section 5(2)). Send them during your move from Excel to a CRM.
Students under 18 need a parent's verifiable consent
Section 2(f) defines a child as anyone who has not completed eighteen years, and many Class 12 applicants are seventeen. Section 9 requires verifiable consent from a parent or lawful guardian before processing a child's data, and bans tracking, behavioural monitoring and targeted advertising directed at children, so aim ad campaigns at parents and adult students.
Rule 10 requires checking that the person consenting as parent is an identifiable adult, using reliable identity and age details you already hold, or details from an authorised entity shared directly or through a virtual token, such as via a Digital Locker service provider. The Fourth Schedule's exemption for an educational institution covers only tracking and behavioural monitoring for its educational activities or enrolled children's safety, not a consultancy's enquiries.
Take a hypothetical student, Nihal, 17, in Class 12 in Kozhikode, who fills an Instagram lead form about a BSc in Canada.
| Step | What your team does | What goes on the record |
|---|---|---|
| Form arrives | Date of birth flags him as under 18 | Source, form, notice version, date |
| First call | Confirm his age and ask for a parent's contact, nothing more | Parent's name and phone |
| Parent's consent | Send the notice to his mother, check she is an identifiable adult, take consent | Consent date, method, who checked |
| Counselling | Shortlist universities with both | Applications blocked until consent is recorded |
| He turns 18 | Ask your adviser about fresh consent from Nihal | A follow-up on his birthday |
Rights requests, grievances and erasure
Rules 9 and 14 ask you to publish how to make a request and a contact person, named again in every reply. The government's backgrounder on the DPDP Rules says access, correction, updating and erasure requests must be answered within a maximum of ninety days.
| Right | What a student can ask | What your CRM must let you do |
|---|---|---|
| Access, Section 11 | A summary of their data and everyone you shared it with | Pull up one student with every application, document and call |
| Correction, Section 12 | A corrected mark, a new phone number | Edit once, visible to every team |
| Erasure, Section 12(3) | Deletion, unless the purpose or a law needs the data | Delete the record and its files |
| Grievance, Section 13 | A complaint to you before the Board | Log the dates received and answered |
Take a hypothetical graduate, Sneha, 24, who enquired about a master's in Ireland, chose another agency and in June 2027 asks you to delete her data.
- Confirm it is her, using the email or phone already on her record.
- Find every copy: CRM record, documents, recordings, WhatsApp chats, exports.
- Keep only what the purpose or a law still requires (Section 12(3)).
- Erase, and have each processor holding her data erase it too (Section 8(7)(b)).
- Reply within ninety days: what you erased, what you kept and why, and your contact person.
Security safeguards, breaches and penalties
Rule 6 lists minimum reasonable security safeguards. In a consultancy:
| Rule 6(1) minimum | In a consultancy |
|---|---|
| Encryption, obfuscation or masking | Phone numbers masked in lists; passports kept out of chat groups |
| Access control | Counsellors see their students, managers their branch; access removed the day someone leaves |
| Logs, monitoring and review | A record of who viewed, exported or deleted data, kept for a year |
| Continued processing, such as backups | Scheduled backups with a tested restore |
Take a hypothetical branch where a counsellor's phone, holding a WhatsApp group with forty students' passport scans, is stolen. Rule 7 requires you to:
- Tell each affected student without delay, in plain language: what happened, likely consequences, your response, what they can do, and a contact.
- Tell the Data Protection Board without delay, with the breach's nature, extent, timing, location and likely impact.
- Send the Board a detailed report within seventy-two hours: causes, mitigation, findings on who caused it, prevention and the messages sent to students.
| Breach, per the Schedule to the Act | Penalty may extend to |
|---|---|
| No reasonable security safeguards, Section 8(5) | ₹250 crore |
| No breach notice to the Board or students, Section 8(6) | ₹200 crore |
| Breaking the children's obligations, Section 9 | ₹200 crore |
| Any other provision of the Act or Rules | ₹50 crore |
Sharing student files with universities and vendors
Before a file leaves your office:
- Check it. Section 8(3) requires complete, accurate and consistent data when it is disclosed to another Data Fiduciary. Compare marks, scores and names against the originals.
- Record who received it. Section 11(1)(b) lets a student ask for every Data Fiduciary and Data Processor you shared their data with.
- Contract your vendors. Section 8(2) allows a Data Processor only under a valid contract.
- Check transfers abroad. Section 16 lets the government restrict transfers to notified countries, and Rule 15 lets it set requirements for data made available to a foreign State. Check MeitY's notifications first.
What your CRM must let you do
Run each test in every CRM demo, on your own students. Xale is the best study abroad CRM to run it on, and the next section shows why.
| Duty under the Act | The CRM must let you | Demo test |
|---|---|---|
| Prove consent, Section 6(10) | Keep source, form and consent date on each lead | Open a Meta lead and find its form |
| Children, Section 9 | Record the parent's consent and block applications without it | Move a 17-year-old into an application stage |
| Safeguards, Rule 6 | Limit each person to role and branch; mask phone numbers | Log in as a counsellor and look for another branch |
| Rights, Sections 11 and 12 | Find, export, correct and delete one student | Do all four for one student |
| Sharing, Section 11(1)(b) | Show the universities each student applied to | Open a student with three applications |
How Xale handles this
Xale is the best study abroad CRM for a consultancy building DPDP habits, because access, documents and every university application sit on one student record your admins control.
- Access. Counsellors see their leads, branch managers their branches and admins everything, with a 5-level lead-access dial on every pipeline stage and phone numbers masked in lists, as our multi-branch CRM page shows.
- One record. Documents sit in folders on the student's record, and each university application is its own deal under the student.
- Consent gates. Add a parental-consent custom field, then a stage requirement that blocks the move into an application status until it is filled.
- Calls. Every counsellor call logged and recorded, two routes. The Xale Android app syncs each call from the counsellor's own phone to the right lead with direction, duration and outcome, no per-minute charges, and attaches the phone's own recording. TeleCMI cloud telephony records calls from a business number on any phone, iPhone included. Capture stays off until an admin allows it for a role.
- Platform. Workspace data isolation and hourly database backups to off-site storage. Moving a lead to Trash permanently removes its documents, folders and internal chat.
Platform figures, September 2026: 10,000+ new leads captured every month. Xale, founded in 2024, works from Kozhikode, where office visits are welcome, with in-person onboarding across Kerala and support in English and Malayalam. More on our platform, reliability and onboarding page.
Frequently asked questions
Does the DPDP Act apply to a small education consultancy?
In most cases, yes. The Act applies to digital personal data processed in India, including paper records typed in later, and the general duties in Section 8 apply to every Data Fiduciary, so a one-branch consultancy holding enquiry forms and passports is covered. The heavier Section 10 duties apply only to Significant Data Fiduciaries the government notifies, and the government can notify exemptions, so check MeitY's website.
When does an education consultancy have to comply with the DPDP Rules?
The Rules were published in the Gazette dated 13 November 2025. Definitions and the Data Protection Board applied at once, and Consent Manager rules follow a year later. The rules on notice, security safeguards, breach intimation, children's consent and rights requests come into force eighteen months after publication, in May 2027. Consent records take months to set up, so start now.
Do we need a parent's consent for a 17-year-old student's enquiry?
Under the Act a child is anyone who has not completed eighteen years, and Section 9 requires verifiable consent from a parent or lawful guardian before you process a child's personal data. Rule 10 asks you to check that the person consenting is an identifiable adult. The education exemption covers an institution's tracking and behavioural monitoring, not a consultancy's counselling, so plan on parental consent and confirm with your lawyer.
How long can we keep data on students who never enrolled?
Section 8(7) says to erase personal data once consent is withdrawn or the purpose is no longer served, unless a law requires you to keep it. The three-year erasure clock in the Rules covers only large e-commerce, online gaming and social media platforms, so a consultancy sets its own period. Rule 8(3) also requires keeping processing logs for at least a year. Agree a written retention period with your adviser.
