Your child’s school app holds their name, class, roll number, attendance, marks, bus stop, fee record, and sometimes their allergies and medical notes. Almost none of this is collected to keep an eye on your family. It is collected because a school cannot run admissions, attendance, examinations, transport and fee accounting without it.
So the useful question is not “why does the school have this?” It is: what exactly is held, who can see it, how long it is kept, what happens if it leaks, and what a parent can reasonably ask when something looks wrong.
What a school app normally collects
The list is longer than most families expect, and it helps to know which parts are routine:
- Identity and enrolment — name, date of birth, admission number, class and section, photograph, previous school records.
- Family and contact details — parent and guardian names, addresses, phone numbers, emergency contacts, and often custody or pickup arrangements.
- Attendance — daily marking, late arrivals, and increasingly bus boarding and alighting events.
- Academic records — marks, grades, report cards, teacher remarks, and in some schools assessment and behaviour notes.
- Fees and payments — invoices, payment history, concessions, and sometimes bank or UPI reference numbers.
- Health and safety — allergies, medical conditions, immunisation records, and incident reports.
- Transport — route, stop, vehicle, and the location of the bus a child is travelling on.
- Communication and media — messages, notices, and photographs or video from school events.
Each of these can be legitimate. What matters is that each one has a stated purpose, an owner, and a limit. A record collected “just in case” is the one most likely to become a problem later.
What the law says about children’s data
India’s Digital Personal Data Protection Act, 2023 governs this. Under the Act, a child is anyone who has not yet completed eighteen years of age, and children’s data carries stricter obligations than adult data.
- A school or app vendor must obtain verifiable consent of a parent before processing a child’s personal data (Act, section 9(1), read with Rule 10 of the Rules notified in 2025).
- Processing likely to have a detrimental effect on a child’s well-being is prohibited, and so is tracking or behavioural monitoring of children, and targeted advertising directed at them (Act, section 9(3)).
- There is a narrow exemption for schools. Under Rule 12 and Part A of the Fourth Schedule, an educational institution may carry out tracking and behavioural monitoring only for its own educational activities or in the interests of the safety of children enrolled with it. That exemption is not a general licence to profile a child, and it does not cover advertising.
- A parent can ask for correction or erasure. Once consent is withdrawn, or the purpose has been served, personal data must be erased unless another law requires it to be kept (Act, section 8(7)).
One timing note, current as of October 2026. The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rules 1, 2 and 17 to 21 came into force on publication, Rule 4 one year later, and the operative provisions — Rules 3, 5 to 16, 22 and 23 — eighteen months after publication. In practice that means the child-data and security provisions described here apply in full by mid-May 2027. Schools and their vendors should already be working to them, and the gazette notification is public if you want to read the rule text yourself.
What good practice looks like from the inside
Rule 6 describes what “reasonable security safeguards” means at a minimum: protecting personal data with encryption, masking or tokenisation; controlling who can access the systems that hold it; keeping logs and monitoring access so that unauthorised use can be detected; maintaining backups; and retaining logs and personal data for at least one year unless another law requires longer. Any vendor processing the data has to be bound to the same safeguards by contract.
Two more things follow from the rules. If there is a breach, the school must intimate affected parents without delay, describing what happened, the consequences for them, and the steps they can take — and must inform the Data Protection Board of India, with full detail within 72 hours (Rule 7). And every data fiduciary must prominently publish, on its website or app, contact information for a person who can answer questions about how personal data is processed (Rule 9).
What good practice looks like from your side
You do not need to audit a server to judge most of this. Practical signals, in roughly the order they matter:
- You can see in the app what is held about your child, and correct what is wrong without a phone call to the office.
- Staff see only what their role needs — a class teacher does not see another class’s fee records.
- Notifications on a locked phone screen do not spell out marks, medical detail or disciplinary notes.
- The school can say plainly which vendor stores the data, where it is hosted, and what happens to the record when a child leaves.
- Photographs of children are shared with families on a restricted basis, not published on open social media.
- There is a named person to contact about data questions, and a documented route for complaints.
Questions a parent can reasonably ask
Ask in writing, and expect a written answer. These are specific and answerable:
- Which app and which company store my child’s records, and who at the school decides what is entered?
- What categories of my child’s data are collected, and what is each one used for?
- Who inside the school can see my child’s record, and how is that access controlled?
- How do I correct a wrong entry, and how long does a correction take?
- What is the retention rule — what is deleted, and when, once my child leaves the school?
- Is my child’s data used for anything beyond schoolwork, such as analytics, marketing or product development?
- Is any data transferred or processed outside India, and under what arrangement?
- What happens if there is a breach — how and when will I be told?
- Who is the school’s contact person for data questions, and what is the grievance process?
- Is there a parent-facing privacy notice in plain language that I can read?
If the answer to the first question is a shrug, that itself is information.
Where a concern goes
Start with the school, because it is the data fiduciary and it holds the relationship with your family. Ask for the contact information published under Rule 9. If the school cannot answer, ask whether the matter has been raised with its software vendor, and whether the vendor is contractually bound to the same safeguards.
If a concern is not resolved, the Act provides a grievance redressal route with the data fiduciary, and beyond it the Data Protection Board of India, whose inquiry process is prescribed in the Rules and which works as a digital office. Records of who accessed what, kept under the retention requirement, are the evidence a school would need to answer a serious question — which is one reason good logging is not just an IT preference.
None of this requires you to become a privacy lawyer. It requires knowing that the information exists, that it has a stated purpose, and that a parent has a right to ask. Schools that handle this well answer quickly, and the asking itself tends to raise the standard.
For a related perspective at the school’s end, see Role-based access protects school data and The Role of Technology in Indian Schools: From Chalk to Cloud.
