
According to Business Standard reports, more than 60% of schools and colleges in India still lack a formal cybersecurity policy, creating significant vulnerabilities in educational data protection. As reported by Sophos India & SAARC's Ravindra Baviskar, the gap between where educational institutions need to be and where they currently stand remains substantial in terms of cybersecurity. Many EdTech platforms continue to rely on generic consent checkboxes that fall short of the verifiable parental consent required under the Digital Personal Data Protection (DPDP) Rules.
As reported by Business Standard, educational institutions begin collecting personal information even before children enter classrooms, gathering names, dates of birth, addresses, identity documents and contact information during admissions. This expands significantly as students progress through school to include attendance records, scores, health records, photographs, videos and participation in extracurricular activities. Schools increasingly adopt digital platforms for learning and administration, with learning management systems, attendance apps, online examinations, digital report cards and parent communication platforms collecting information to support teaching operations.
According to The Mobile Times reports cited by Business Standard, India recorded more than 24,000 cybercrime cases involving minors in 2026, highlighting growing concerns around children's digital safety. The report notes that once a child's photograph or personal information becomes publicly accessible, it can be difficult to remove and may be misused for impersonation, image morphing or online harassment. The issue extends beyond schools to coaching institutes, sports academies and other educational organizations that often publish students' photographs and achievements online.
As reported by Business Standard, the Digital Personal Data Protection (DPDP) Act, 2023 brings schools, edtech companies and other organizations that process children's personal data within a national compliance framework. Under the law, such entities are treated as Data Fiduciaries and are required to obtain verifiable parental consent before processing personal data of individuals under 18. The Act mandates that data be collected only for defined purposes, protected through enhanced security safeguards and handled with transparency, particularly when shared with third-party service providers.
According to Ascend Education recommendations reported by Business Standard, schools can strengthen student data security by implementing role-based access controls, enabling multi-factor authentication, enforcing strong password policies and regularly reviewing user access. The company recommends encrypting sensitive records, using secure cloud storage, maintaining regular backups and avoiding unsecured file-sharing methods. Baviskar emphasizes that compliance with the DPDP Act is the floor, not the ceiling, requiring schools to map data collection, storage locations, access permissions and third-party vendor relationships before adopting any EdTech tools.