Compliance8 min read

DPDP Act 2025 and homeschooling in India: a parent's guide

What India's Digital Personal Data Protection Rules 2025 mean for homeschooling families using edtech platforms — verifiable parental consent, DigiLocker, the ₹200 crore penalty cap, and how Docent is DPDP-compliant.

What is the DPDP Act and why does it matter to homeschoolers?

India's Digital Personal Data Protection Act 2023 (DPDP Act) came into force progressively, with the implementing rules — the Digital Personal Data Protection Rules 2025 — notified in January 2025 after extensive stakeholder consultation. Together, the Act and Rules constitute India's most comprehensive data protection framework, bringing India broadly into alignment with global standards like GDPR (EU) and PDPA (Singapore).

For homeschooling families using digital education platforms, the DPDP framework creates specific rights and obligations that are different from — and in some respects stronger than — what applied under the previous IT Act 2000 framework. Understanding these protections helps you make better decisions about which platforms to trust with your child's learning data.

How children's data is protected differently under the DPDP Rules

The DPDP Act creates a special category for "children" — defined as persons under 18 years of age. For this category, the Rules impose requirements that go beyond the standard data protection obligations.

Verifiable parental consent is mandatory. A Data Fiduciary (the legal term for a platform that processes personal data) may not process the personal data of a child without obtaining verifiable consent from a parent or guardian. Crucially, the consent must be verifiable — a simple checkbox claiming "I confirm I am 18 or have parental permission" does not satisfy the Rules.

Processing that may be harmful is prohibited. The Rules include a broad prohibition on processing children's data in ways that could cause harm. The Rules specifically mention processing for behavioural monitoring, targeted advertising, and tracking of children. This is a direct response to the documented harms of social media and attention-economy platforms for younger users.

Age verification must precede consent. Platforms are required to verify that the consenting person is actually a parent or guardian (and is themselves an adult) before obtaining consent for a child. This creates a meaningful verification step, not merely a declaration.

What "verifiable parental consent" means and how DigiLocker enables it

The challenge of verifiable parental consent is an identity challenge: how does a platform confirm that the person claiming to be a parent is (a) a real adult and (b) actually a parent or guardian of the child in question?

India's national digital infrastructure provides an elegant mechanism: DigiLocker. DigiLocker is the Government of India's digital document wallet, linked to Aadhaar. It stores verified digital copies of official documents — PAN cards, driving licences, birth certificates, school leaving certificates, and more.

Under the DPDP Rules, a platform can use DigiLocker to verify parental consent as follows:

1. The parent authenticates via DigiLocker (which in turn authenticates against Aadhaar, confirming their identity as an adult)

2. The parent provides consent through the DigiLocker consent flow

3. The platform records the DigiLocker consent token as evidence of verifiable parental consent

This mechanism is more robust than email-based confirmation or SMS OTP, because it ties consent to a verified identity rather than merely an email address or phone number that could belong to anyone. For edtech platforms serving children, DigiLocker-based consent is quickly becoming the industry standard.

Even where DigiLocker integration is not available, platforms must use alternative methods that achieve genuine verification — not mere assertion. The Rules will specify approved verification methods as the framework matures.

The ₹200 crore penalty cap and why it matters

The DPDP Act sets out a tiered penalty structure for violations. The maximum penalty for breaching the obligations relating to children's data protection is ₹200 crore (approximately US$24 million at current exchange rates).

This is significant for two reasons.

First, it is a meaningful financial consequence for platforms. Prior to the DPDP Act, enforcement of data protection obligations in India was weak and penalties were low. A ₹200 crore exposure creates genuine incentive for platforms to invest in compliance.

Second, it signals the Indian legislature's view of the seriousness of children's data harms. The ₹200 crore cap applies specifically to failures in the children's data protection provisions — notably higher than the caps for some other categories of violation. Platforms that process children's data without verifiable parental consent, or that engage in prohibited processing such as behavioural tracking, are in the highest-penalty tier.

For homeschooling parents choosing an edtech platform for their child, the penalty cap is a proxy signal: a platform that takes its DPDP children's obligations seriously has structured its architecture, consent flows, and data processing practices to avoid that exposure.

How homeschooling works legally in India

Before addressing DPDP compliance specifically, it is worth noting the legal context for homeschooling in India. The Right to Education Act 2009 (RTE) mandates free and compulsory education for children aged 6–14, which creates a superficially complex situation for home educators.

In practice, homeschooling is legally possible in India through two primary pathways:

1. NIOS (National Institute of Open Schooling): NIOS is a national board under the Ministry of Education that offers open and distance learning for Grades 3–12. Students registered with NIOS are considered enrolled in education for RTE purposes, even if they are learning primarily at home. NIOS allows flexible pacing and home-based study.

2. Private school affiliation with homeschool arrangement: Some families maintain affiliation with a registered CBSE or ICSE school while conducting most of their learning at home, sitting the board examinations as registered students.

The DPDP framework applies equally regardless of which pathway you choose — any digital platform processing your child's learning data is a Data Fiduciary with obligations under the Rules.

How Docent is DPDP-compliant

Docent's compliance with the DPDP Act 2025 Rules is built into the platform's architecture, not bolted on afterwards.

Verifiable parental consent: Docent's onboarding flow for India-region accounts requires parental identity verification before any child's account is created. The platform supports DigiLocker-based consent flows where available, and collects and stores consent records with timestamps, consent text versions, and verification method.

No behavioural tracking or targeted advertising: Docent does not run advertising on the platform. It does not build behavioural profiles for marketing purposes. The only data processing that occurs is what is necessary to deliver the tutoring service — lesson delivery, mastery tracking, and compliance document generation.

Data localisation: India accounts are processed on infrastructure in ap-south-1 (Mumbai region), consistent with the data localisation expectations that are emerging from DPDP Rules implementation guidance.

Parental rights are operationalised: Parents can export their child's complete data record or schedule account deletion through the Account page at any time. These rights exist in the platform's user interface — they are not administrative processes that require contacting support.

DPDP consent flags are stored per tenant: When a family onboards via the India pathway, the dpdpConsent flag is recorded in the tenant record alongside the consent timestamp and the version of the privacy policy in force at the time. This creates an auditable consent record that could be produced in response to a regulatory enquiry.

What you should look for in any edtech platform

When evaluating an edtech platform for your home-educated child, the DPDP framework gives you a concrete checklist:

1. Does the platform ask for verifiable parental consent before creating your child's account — not just a checkbox, but something that confirms your identity?

2. Does the platform refrain from behavioural tracking and targeted advertising directed at your child?

3. Can you export your child's data and delete the account yourself through the platform's interface?

4. Where is your data processed and stored? Is it in India or in a jurisdiction with equivalent data protection?

5. Does the platform publish a DPDP-specific privacy notice that addresses children's data processing explicitly?

Platforms that cannot answer these questions confidently are not yet compliant with the Rules — and under the DPDP Act, that is not a minor administrative gap. It is exposure to the highest-tier penalty.

Related posts

Compliance

How to write a VRQA learning plan that passes first time

A step-by-step guide to writing a Victorian Registration and Qualifications Authority (VRQA) learning plan that satisfies assessors, covers all eight learning areas, and uses your child's mastery data as evidence.

Read more →
Compliance

New York IHIP quarterly reports: what to include and when to file

A complete guide to New York State's Individualized Home Instruction Plan (IHIP) quarterly report requirements under Education Law section 100.10 — deadlines, subjects, structure, and tips for the annual assessment.

Read more →
Built by Innovenses Pty Ltd · Melbourne. Docent is an AI tool; it supports — and never replaces — a parent or qualified teacher. Privacy · Terms · Blog · System status.