For learning apps, online course platforms and ed-SaaS
DPDP compliance for edtech platforms
Edtech carries some of the heaviest DPDP duties: a large share of your users are children, your product depends on analytics, and your growth depends on ads. ConsentKit adds age gating, parent verification and child-safe defaults to your app and web sign-up.
- Tracking children
- Prohibited
- Targeted ads to children
- Prohibited
- Full compliance
- 13 May 2027
Create your account
Where the DPDP Act touches your product
For children, some things need a parent’s consent and some are not allowed at all. Pick a stage to see which is which.
What changes for your platform on 13 May 2027
Most edtech products were built for growth first. These are the changes that touch product and engineering.
Age gating before anything elseSection 9 and Rule 10
You need to know if a user is a child before you process their data for purposes that need a parent’s consent.
An age gate for web and app, with a parent verification flow and child-safe defaults.
No tracking or targeted ads at childrenSection 9(3)
Behavioural monitoring and targeted advertising directed at children are prohibited. This hits ad SDKs, retargeting and engagement tooling.
SDK controls that keep ad and profiling tools off for child accounts.
Nothing detrimental to a child’s well-beingSection 9(2)
You may not process a child’s data in a way likely to cause detrimental effects on their well-being. Dark patterns and streak pressure deserve a review.
A purpose register where each feature’s processing is reviewed and signed off.
Consent per purpose, withdrawal in one tapSections 6 and 7
Lessons, analytics, marketing and partner sharing are separate purposes. Withdrawal must be as easy as sign-up.
In-app preference centre and webhook so your backend stops processing instantly.
Data rights inside the appSections 11 to 14
Users and parents can ask for access, correction and erasure. An in-app route keeps support tickets down.
Drop-in request screens and an admin queue with deadlines.
Large platforms may be Significant Data FiduciariesSection 10 and Rule 13
If the government notifies you as a Significant Data Fiduciary, you need a DPO in India, annual audits and impact assessments.
Audit trail and evidence exports that make those audits faster.
Is your platform an educational institution?
The Rules exempt educational institutions from parental consent and the tracking ban for educational activities and child safety. Whether an edtech app qualifies is not settled. Plan as if the exemption does not apply to you.
This is general guidance, not legal advice. Confirm how it applies to you with your counsel.
A plan for product and engineering
Most of the work is in the app, so treat it as a product release with a clear deadline.
Audit SDKs and data flows
Inventory every SDK, event and third party receiving user data, and tag what fires for children.
Ship age gating
Release the age gate, parent verification and child-safe mode on web and app.
Rework analytics and ads
Move child accounts off ad networks and limit analytics to learning purposes.
Rights and breach readiness
Ship in-app data requests, deletion and a 72-hour breach runbook.
For every kind of edtech product
SDKs and APIs for your stack, with templates for your model.
K-12 learning apps
Mostly children, parent-paid subscriptions.
Test-prep platforms
Teen users, heavy marketing and live classes.
Upskilling and higher-ed
Mostly adults, with lending and placement partners.
School LMS and ERP vendors
Processor terms and school-level consent.
Language and hobby apps
Mixed ages, freemium and ads.
Tutor marketplaces
Tutors and learners on both sides of the data.
DPDP compliance for edtech companies near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions edtech teams are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Can we show ads to children in our app?
Targeted advertising directed at children is prohibited under Section 9(3). Contextual, non-tracking placements carry less risk, but most edtech firms keep ads off child accounts entirely.
How do we verify a parent?
Rule 10 accepts reliable identity and age details you already hold or that the parent provides, or a token from an authorised service such as DigiLocker. ConsentKit supports both and records which was used.
Can we use analytics on child accounts?
Analytics that deliver the lesson and measure learning carry less risk. Behavioural monitoring and profiling of children for engagement or advertising is prohibited unless an exemption applies.
Does the education exemption apply to us?
Unclear for direct-to-consumer apps. Assume it does not, and take legal advice on your specific model.
Do we need a Data Protection Officer?
Only if you are notified as a Significant Data Fiduciary. All platforms must publish a contact for data questions and grievances.
Make your app child-safe before the deadline
The readiness check takes about ten minutes and gives you a gap report for edtech products, whether or not you use ConsentKit.