DPDP for Preschools & Playgroups
Preschools must manage child data with verifiable parental consent. Learn how to handle photos, health records, and parent data under DPDP rules.
Discuss this page with an LLM
DPDP Action Sheet
Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.
For DPDP for Preschools & Playgroups, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.
1. Lead Forms
Check:
- What data are you collecting?
- Is the purpose clear at the point of collection?
- Is marketing consent separate from service communication?
- Can the user withdraw consent later?
Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.
2. Email and WhatsApp
Check:
- Who is on the list?
- Where did consent come from?
- Is the list imported from a vendor, event, webinar, scrape or old CRM?
- Can you prove the source of consent?
Common mistake: treating every lead as permanently marketable.
3. Ads and Retargeting
Check:
- Are pixels or ad platforms receiving identifiable user behavior?
- Are audiences built from customer lists?
- Are lookalike or remarketing audiences using personal data?
Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.
4. Website Analytics
Check:
- Which tools run on the site?
- Are IP address, device identifiers, session IDs or form fields being captured?
- Is analytics used only for measurement, or also for profiling and targeting?
Common mistake: installing tools first and asking privacy questions later.
5. Vendor List
Make a quick list:
- CRM
- Email platform
- WhatsApp provider
- Analytics
- Ad pixels
- Form tool
- Landing page builder
- Webinar tool
For each vendor, answer: what data goes there, why, who can access it and how deletion works.
6. This Week's Action
Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.
If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.
Book a DPDP clarity callWant all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
Verifiable Parental Consent Requirements
Preschools process data belonging to children. Under DPDP, you cannot process a child’s data without verifiable consent from a parent or legal guardian. This means you must have a reliable way to prove that the person signing the form is actually the child’s guardian. You are also prohibited from tracking child behavior for advertising or engaging in any processing that likely causes them harm.
Managing Photos and Daily Updates
Most preschools share photos and videos on WhatsApp groups or social media. This is a high-risk activity under DPDP. You must separate your consent requests. A parent might agree to have their child’s photo in a private class update but refuse to have that photo used on your public Facebook page. You must keep a clear list of which children can and cannot appear in promotional materials.
Security of Health and Safety Records
Preschools collect sensitive details like food allergies, vaccination dates, and emergency contact numbers. While this data is necessary for child safety, it must be protected. If you share allergy information with a third-party catering service or transport provider, you must inform the parents. All digital and paper records should be stored in locked cabinets or encrypted folders with restricted staff access.
Data Workflows in Preschools
| Activity | Data Involved | DPDP Risk |
|---|---|---|
| Admission | Birth certificate, Aadhaar, home address | High |
| Daily Care | Photos, videos, sleep and food logs | High |
| Health Tracking | Allergies, chronic conditions, doctor info | Very High |
| Transport | Live GPS location, pick-up/drop-off logs | Medium |
| Marketing | Social media posts, brochures, testimonials | High |
This week
Review your student registration form. Add a specific, separate checkbox for “Social Media Photo Consent.” Ensure this checkbox is not pre-filled and is distinct from the general enrollment agreement.
Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?
Frequently asked questions
Can I post photos of school events on Instagram?
Only if you have verifiable parental consent specifically for marketing. A general admission form is not enough. You must give parents a clear choice to opt out of public social media posts.
How do I verify a parent's identity for consent?
You should collect a government ID from the parent or use a digital signature. This proves the person giving consent is the legal guardian authorized to share the child's data.
What should I do with files of students who graduated?
You must delete personal data once the child leaves and the purpose for keeping it ends. Only keep records required by education board regulations or tax laws.