30 July 2026 · Starkid Team
DPDP Rules for Preschools: What Changes in November 2026
India's DPDP Rules take full effect in November 2026, and children's data gets the strictest treatment. Here's what preschool owners need to know — and show.
If you run a preschool in India, you handle children's personal data every single day — admission forms, photographs, attendance records, parent phone numbers, medical notes. From November 2026, the law starts holding you to a much higher standard for how you handle it.
This post explains what's changing, in plain language, and what a preschool owner can realistically do about it before the deadline.
The DPDP Act and Rules, in plain language
The Digital Personal Data Protection Act, 2023 is India's data-protection law. It applies to any organisation that collects or processes personal data digitally — which includes a preschool the moment an admission form is typed into a spreadsheet or a child's photo lands in a group chat.
The Act itself has been law for a while. What changes now is enforcement: the DPDP Rules give organisations a compliance runway, and that runway ends in November 2026. After that, the Data Protection Board can act on complaints and impose penalties.
Three ideas from the law matter most for schools:
- Consent — you need permission to collect and use personal data, for a stated purpose.
- Purpose limitation — data collected for one purpose (say, admissions) can't quietly be used for another.
- Data-principal rights — parents can ask what data you hold about their child, and ask you to correct or delete it.
Why children's data gets the strictest treatment
The Act singles out children. For anyone under 18, processing their personal data requires verifiable parental consent — not an assumption, not a nod at the admission desk, but consent you can actually demonstrate was given.
The law also prohibits tracking, behavioural monitoring, and targeted advertising directed at children. For preschools, the practical consequence is simpler but stricter: every photo, every attendance record, every observation you share involves a child's personal data, and a parent's recorded consent needs to sit behind it.
The penalty schedule reflects this seriousness: failing your obligations around children's data carries penalties of up to ₹200 crore. No preschool will see a number like that — but the same schedule applies to a small school's worst week that applies to a big edtech company's, and "we didn't know" is not a defence.
What actually changes for your preschool in November 2026
Practically, three things:
- Complaints get teeth. A parent unhappy about how their child's photos were shared can complain to the Data Protection Board, and the Board can investigate and fine.
- You can be asked to show your records. Not your intentions — your records. Who consented to what, when, and how you honoured requests.
- "Everyone does it this way" stops working. WhatsApp groups and paper registers are how most preschools run today. After November 2026, the question becomes: can that setup evidence anything?
The WhatsApp problem: consent you can't evidence
Here's the uncomfortable audit of a typical preschool WhatsApp group:
- Children's photos sit in a chat visible to every parent in the class — and to whoever inherits a recycled phone number.
- Consent to be in the group was implied, not recorded. There's no record of who agreed to have their child's photos shared, or for what purpose.
- When a family leaves the school, their child's photos remain in the group's shared media, on dozens of phones, forever. There is no delete.
- Messages, photos, and phone numbers are all mixed together — the opposite of purpose limitation.
None of this makes preschool owners bad actors. It makes them normal. But an exemption you can't evidence is one you don't have — and a WhatsApp group cannot evidence purpose limitation over children's data.
What the Data Protection Board can ask you to show
If a complaint lands, expect questions like:
- What personal data of this child do you hold, and where?
- Show the parental consent for collecting and sharing it.
- Who had access to the child's photographs, and on what basis?
- The parent asked for deletion — show what you deleted and when.
A school that runs on group chats and paper files can't answer these. A school whose parent communication runs through a system with per-parent accounts, role-based access, and deletion controls answers them as a by-product of normal use.
A DPDP readiness checklist for preschool owners
Before November 2026, aim to be able to say yes to each of these:
- We know what data we hold — a simple list: admissions data, photos, attendance, health notes, and where each lives.
- Consent is recorded per parent — each family has affirmatively joined our communication system, and we can show it.
- Access is role-based — parents see only their own child; teachers see their own classes; nothing is broadcast to a group.
- We can delete — when a family leaves or asks, we can remove their child's data and show that we did.
- We've retired the class WhatsApp groups — or at minimum, stopped sharing children's photos through them.
- Someone owns this — one named person at the school handles data questions from parents.
How Starkid helps you build the evidence
Starkid was built consent-first for exactly this world: parents join through their own verified accounts, see only their own child's photos and updates, and deletion requests can be honoured — records your school can actually show. It replaces the class WhatsApp group with structured, purpose-limited communication, and the app is free for schools.
Read how it works on our DPDP readiness page, or see everything Starkid does for preschools.
Starkid is a tool that helps your school demonstrate good data practices — it is not a compliance certification, and this article is not legal advice. For your school's specific obligations, consult a professional.