DPDP Exemptions6 mins

DPDP Act Exemption Explained: Section 9(4) for Educational Institutions

A definitive guide to the Section 9(4) and Rule 12 exemption for children's data, explaining why EdTech platforms are rarely exempt from verifiable parental consent and behavioral tracking bans under the DPDP Act, 2023.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The Educational Exemption Explained

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), processing the personal data of a child generally triggers stringent legal obligations. Section 4 of the Act establishes that any processing must be for a lawful purpose, relying on either the consent of the Data Principal or certain legitimate uses. When the Data Principal is a child, the standard consent framework is heavily modified. However, specific statutory carve-outs exist to accommodate distinct, non-commercial use cases. Section 9(4), read in conjunction with Rule 12 and the Fourth Schedule Part A Item 3 of the DPDP Rules, 2025, specifically exempts recognized educational institutions from two critical mandates: the verifiable parental consent requirement under Section 9(1) and the tracking and targeted advertising ban under Section 9(3). Crucially, this exemption applies strictly when the processing of children's data is conducted exclusively for educational activities or child safety.

Statutory Anchors in the Act and Rules

To fully grasp the scope of this exemption, compliance teams must look closely at the interplay between the sub-sections of Section 9. Section 9(1) establishes that a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data. Section 9(3) fundamentally prohibits tracking, behavioral monitoring, or targeted advertising directed at children. Recognizing that schools and similar institutions cannot functionally operate modern learning environments under these strict prohibitions, Section 9(4) empowers the Central Government to exempt specific entities or purposes from the provisions of sub-sections (1) and (3). The DPDP Rules, 2025 activate this legislative intent through Rule 12 and the Fourth Schedule Part A Item 3, which explicitly lists educational institutions conducting educational activities as eligible for this limited relief.

Conditions and Limits for EdTech Platforms

A severe risk area under the DPDP Act involves EdTech platforms attempting to improperly leverage this exemption. To rely on this carve-out, the entity must formally qualify as an educational institution under statutory definitions, and the data processing must be tied directly to educational delivery or child safety protocols. Large EdTech enterprises cannot automatically claim this exemption simply because they operate within the broader education sector. If an EdTech platform provides supplementary learning modules, test preparation applications, or commercial courses directly to consumers, the platform remains a standard Data Fiduciary. As standard Data Fiduciaries, they must acknowledge that consent is the primary basis for processing, except where Section 7 legitimate uses apply. Consequently, the Chief Product Officer and Head of Legal must ensure the product roadmap accounts for seamless verifiable parental consent workflows, as attempting to bypass these requirements under the guise of an educational exemption will invite severe regulatory penalties.

Obligations That Still Bind Exempt Institutions

Claiming the Section 9(4) exemption does not grant a recognized educational institution blanket immunity from the rest of the DPDP Act. Most importantly, Section 9(2) remains fully active, stipulating that a Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. Furthermore, Section 8(1) responsibility for data processing and Section 8(5) requirements for implementing reasonable security safeguards continue to bind the institution. If a personal data breach occurs, the exempt entity must still execute standardized breach notification protocols. This includes sending an intimation to affected Data Principals without delay and filing a detailed incident report with the Data Protection Board of India within 72 hours, exactly as mandated by the DPDP Rules, 2025. Furthermore, cross-border data transfer rules under Section 16 apply uniformly; an educational institution must monitor government notifications to ensure they do not transfer data to restricted countries or territories.

Common Misconceptions Regarding the Exemption

A dangerous misconception pervasive in the technology sector is that any digital learning application functionally acts as an educational institution. An EdTech platform selling monthly subscriptions is commercial software, not a statutory school, and therefore must architect verifiable parental consent systems. Another persistent myth is that exempt entities face unique, sector-specific restrictions on overseas data sharing. In reality, under Section 16 of the DPDP Act, cross-border transfers are generally permitted for all entities unless the Central Government formally restricts the transfer of personal data to notified countries or territories. Finally, some product development teams mistakenly believe they can still run recommendation algorithms to upsell paid courses to children under the pretense of 'educational activities'. If the entity is not strictly an exempt educational institution utilizing the data solely for education or safety, Section 9(3) strictly prohibits this behavioral tracking, demanding fundamental changes to user onboarding, analytics, and engagement features.

Evidence to Keep for Audit Readiness

To comprehensively prove compliance to the Data Protection Board of India or an authorized external auditor, enterprise compliance teams and educational bodies must maintain a documented audit trail detailing their handling of children's data.

1. Applicability Assessment - The Head of Legal must document and sign a formal legal opinion assessing whether the entity strictly meets the statutory definition of an educational institution under the Fourth Schedule Part A Item 3, securely storing this analysis in the enterprise compliance repository.

2. RoPA Updates - The control owner responsible for data mapping must update the Record of Processing Activities (RoPA). They must clearly tag which specific datasets and workflows rely on the Section 9(4) educational exemption versus those that require verifiable parental consent.

3. Detrimental Effect DPIA - The product and security teams must conduct and formally document a Data Protection Impact Assessment (DPIA) explicitly demonstrating that no processing activity causes a detrimental effect on child well-being, thereby satisfying the non-exempt mandate of Section 9(2).

4. Vendor Oversight Agreements - The Head of Compliance must ensure all contracts with third-party Data Processors, such as analytics firms or cloud hosting providers, explicitly forbid behavioral tracking on any data sets classified as child data.

5. Section 16 Transfer Mapping - Institutions must maintain an updated register of all international data flows, ensuring no student or child data is transferred to any country or territory specifically restricted by Central Government notification.

Key Cross-References

Section 4(1) - Establishes that all processing must be for a lawful purpose, relying on either the consent of the Data Principal or certain legitimate uses.

Section 8(5) - Mandates reasonable security safeguards to prevent personal data breaches, applicable universally to all child data regardless of any Section 9 exemptions.

Section 16(1) - Outlines the cross-border transfer framework, allowing the Central Government to restrict transfers to notified countries, applicable to commercial EdTech and schools alike.

Rule 10 of the DPDP Rules, 2025 - Details the exact mechanisms for obtaining verifiable parental consent via token-based systems for commercial entities that do not qualify for the educational exemption.

Closing the Compliance Gap

With exactly 270 days remaining until the DPDP Act's hard compliance deadline of 13 May 2027, EdTech platforms, digital learning enterprises, and recognized educational institutions must definitively determine their exact regulatory obligations regarding children's data. Misclassifying a commercial application as an exempt educational institution carries severe financial exposure and operational risk for breaching Section 9 provisions. Organizations must ensure their product workflows securely capture verifiable parental consent without fundamentally degrading the user experience. To meticulously evaluate your applicability for the Section 9(4) exemption and systematically identify gaps in your Rule 10 consent architecture, book a comprehensive gap check at freescan.complydp.com today.

Sources

Frequently asked questions

Does the Section 9(4) exemption apply to all EdTech companies?

No. The exemption under Rule 12 and the Fourth Schedule Part A Item 3 specifically applies to recognized educational institutions processing data strictly for educational activities or child safety. Commercial EdTech platforms offering supplementary learning or consumer subscriptions remain standard Data Fiduciaries and must fully comply with all verifiable consent and tracking provisions for children.

If an educational institution is exempt, do they still need to report personal data breaches?

Yes. The Section 9(4) carve-out only suspends the verifiable parental consent mandate and tracking bans. Exempt institutions must still send an intimation to affected Data Principals without delay and file a detailed report with the Data Protection Board of India within 72 hours of a breach, per the DPDP Rules, 2025.

Can an exempt educational institution share student data outside the country?

Yes, cross-border transfers are generally permitted under Section 16 unless the Central Government specifically restricts the transfer of personal data to notified countries or territories. Educational institutions must still ensure that sharing the data complies with their broader Section 8 obligations and does not cause a detrimental effect on the child under Section 9(2).

How should product teams handle user onboarding if the educational exemption does not apply?

Product teams operating commercial platforms must implement verifiable parental consent workflows as required by Rule 10 of the DPDP Rules, 2025. This involves integrating token-based age-gating and consent mechanisms before processing any data of a child, ensuring legal obligations are met.

What obligations continue to apply to children's data under Section 9(4)?

Even if entirely exempt from verifiable parental consent and tracking bans, the educational institution must legally comply with Section 9(2), which strictly prohibits any processing that has a detrimental effect on a child's well-being. Furthermore, they must implement reasonable security safeguards under Section 8(5) and fulfill all baseline Data Fiduciary responsibilities.