ConsentKit DPDP

For colleges, universities and higher education institutes

DPDP compliance for colleges and universities

From the first admission enquiry to the alumni newsletter, your college holds personal data on thousands of students and parents. ConsentKit handles the consent, parental verification, placement sharing and deletion the DPDP Act requires, on your website, admission portal and ERP.

Full compliance
13 May 2027
Students under 18
Count as children
Breach report to the Board
Within 72 hours
admissions.yourcollege.ac.inStep 2 of 5

Applicant details

Change the date to see how ConsentKit routes the consent.
    Every step is saved to the consent log

    Where the DPDP Act touches a student’s journey

    Each stage collects different data for different reasons, and each reason needs its own legal basis. Pick a stage to see what your college collects and what the Act expects.

    What changes for your college on 13 May 2027

    The Act applies to every private, deemed and autonomous institution that holds personal data digitally. These are the duties colleges tend to miss.

    Admission forms need a proper noticeSections 5 and 6

    A one-line “I agree to the terms” checkbox will not do. Each purpose, whether processing the application, counselling calls or marketing other courses, needs its own clear notice, readable in English or a scheduled Indian language.

    ConsentKit adds itemised notices to your admission portal and logs every choice.

    First-year students are often under 18Section 9 and Rule 10

    A 17-year-old applicant is a child under the Act. Anything beyond education and student safety, such as sharing with partner institutions or promotional messages, needs a parent’s verified consent.

    Age check on the form, then parent verification by OTP or DigiLocker before those purposes switch on.

    Placement sharing needs specific consentSections 6 and 8

    Sending CVs, marks and contact details to recruiters is a separate purpose. Students must opt in, and must be able to opt out mid-season.

    A placement consent your T&P cell can check before every drive, with withdrawals synced to your placement portal.

    Students can ask to see, correct or erase their dataSections 11 to 14

    Students, parents and alumni can file requests and grievances, and you must respond within the time the Rules set. Most colleges have no process for this today.

    A request portal with identity checks, due dates and a record of every reply.

    Old enquiry data must goSection 8(7) and Rule 8

    Applicants who never joined, years of old lead lists and expired hostel records should be deleted once their purpose ends. Degree and marks records you must keep by law stay.

    Retention rules per data category, with deletion records you can show an auditor.

    Your ERP vendor’s breach is your breachSection 8 and Rule 7

    The college stays responsible for data held by its ERP, LMS, admission portal and fee-payment vendors. A breach at any of them must be reported to the Board and to affected students.

    A vendor register, processor contract checklist and a 72-hour breach workflow.

    The education exemption is narrower than it sounds

    The DPDP Rules let educational institutions process students’ data without a parent’s verified consent, and monitor behaviour, only as far as needed for educational activities and the safety of students.

    Usually coveredAttendance, marks, timetables, LMS activity, campus safety and CCTV.
    Usually not coveredMarketing other courses, sharing with coaching partners or lenders, publishing toppers’ photos for promotion.

    This is general guidance, not legal advice. Confirm how it applies to you with your counsel.

    A plan that fits the academic calendar

    Admissions for the 2027–28 session open right around the enforcement date. Working back from that gives you four stages.

    1. Map your data

      List every form, portal and vendor holding student, parent, staff and alumni data. The readiness check does most of this.

    2. Fix the admission flow

      Go live with notices, age checks and parent verification before the next admission cycle starts.

    3. Clean up and sign vendors

      Delete stale enquiry data, set retention rules and get processor terms signed with your ERP and LMS providers.

    4. Train and go live

      Train admissions, T&P and IT staff on requests and breaches, and publish your grievance officer’s contact.

    Built for every kind of campus

    Purpose templates are set up for how each type of institution works, and you can edit every one.

    Private universities

    Multiple campuses and schools under one consent log, with per-school admins.

    Engineering and management colleges

    Heavy placement activity, recruiter sharing and entrance-exam lead data.

    Medical and nursing colleges

    Hospital postings and clinical training alongside student records.

    Autonomous and affiliated colleges

    Data shared with the affiliating university, mapped and recorded.

    Deemed universities

    Large alumni networks, fundraising and research participant data.

    Online and distance programmes

    Fully digital admissions, proctoring and LMS analytics.

    Questions colleges are asking

    For the full picture, read our DPDP Act guide or compliance checklist.

    Does the DPDP Act apply to colleges and universities?

    Yes. Any college or university that collects students’, parents’, staff or alumni’s personal data in digital form is a data fiduciary under the DPDP Act, whether it is private, deemed or autonomous. Full obligations apply from 13 May 2027.

    Do colleges need parental consent for students under 18?

    Many first-year students are 17. The DPDP Act treats anyone under 18 as a child. The Rules exempt educational institutions from verifiable parental consent for processing that is needed for educational activities and the safety of students, but purposes outside that, such as marketing or sharing with third parties for other reasons, still need a parent’s verified consent.

    Can a college share student data with recruiters for placements?

    Share it only with the student’s specific consent for placements, stating what is shared and with whom. Students must be able to withdraw that consent as easily as they gave it.

    How long can a college keep student data?

    Only as long as the purpose needs it, or as long as a law or regulator requires. Degree and marks records are usually kept long-term; enquiry data from applicants who did not join should be deleted once the admission cycle closes.

    Who is responsible if our ERP vendor has a data breach?

    The college remains the data fiduciary and is responsible for reporting the breach and for choosing processors that protect data. Your ERP, LMS and admission-portal vendors are data processors and need contracts that bind them to security and breach reporting.

    Get your college ready before the 2027 admission cycle

    The readiness check takes about ten minutes and gives you a gap report built for colleges, whether or not you use ConsentKit.