New Delhi, India – For Mihir Jana, managing director of EDZLearn Services, the landscape of digital engagement has fundamentally transformed. When his IT team, responsible for building learning management systems and AI-driven platforms for a diverse clientele spanning schools, universities, and banks, now engages with a new client, the initial dialogue no longer revolves solely around features or pricing. Instead, the critical questions center on data flow: where is the data going, and for how long will it be retained? This pivotal shift, according to Jana, marks a "new ballgame" for the entire ed-tech sector his Delhi-based company serves, all thanks to India’s burgeoning Digital Personal Data Protection (DPDP) Act.
The DPDP Act, India’s landmark legislation designed to safeguard individual privacy in the digital age, is poised to redefine how technology companies handle personal information. Its impact is particularly profound within the education technology industry, which inherently collects vast amounts of sensitive data from some of India’s most impressionable internet users: schoolchildren. As the law rolls out in phases, ed-tech firms face a comprehensive overhaul of their data collection, storage, and deletion practices, demanding significant investment and strategic reorientation.
The Genesis of a New Data Era: A Chronology
The journey to a more secure digital India gained significant momentum with the passage of the Digital Personal Data Protection Act by Parliament in August 2023. This legislative milestone laid the groundwork for a robust framework aimed at protecting personal data, defining the rights of individuals (data principals), and establishing the obligations of entities (data fiduciaries) that process such data.
The practical implementation of the Act commenced with the notification of the Digital Personal Data Protection Rules in November 2025. This crucial step operationalized the legal framework, providing detailed guidelines for compliance. Concurrently, the Data Protection Board of India (DPBI) became operational, marking the establishment of the independent regulatory body tasked with enforcing the Act, investigating breaches, and imposing penalties.
The phased rollout continues with critical milestones on the horizon. By November 2026, the provisions for penalties for non-compliance and the framework for a consent manager registration system are slated to take effect. This will introduce tangible consequences for organizations failing to adhere to the Act’s stipulations and provide individuals with a standardized mechanism to manage their data consent. The culmination of this transition period is set for May 2027, by which time full compliance will become mandatory across all aspects of the Act. This includes comprehensive adherence to consent mechanisms, stringent breach reporting protocols, regular independent audits, and robust provisions safeguarding data principal rights, ensuring that individuals have greater control and transparency over their personal information. This structured timeline allows businesses a window to adapt, though the magnitude of the changes demands immediate and proactive engagement.
The Staggering Cost of Compliance: Supporting Data
For an industry built upon the meticulous collection and analysis of user data – encompassing everything from names, quiz scores, and attendance records to AI tutoring conversations and, in some cases, biometric identifiers – the DPDP Act presents a formidable compliance challenge. The financial outlay required to meet these new legal mandates is proving substantial, varying sharply based on factors such as business size, operational sector, and the inherent risk profile of the data handled. This financial burden has emerged as one of the most contentious aspects of the DPDP rollout.
Mihir Jana, while refraining from disclosing exact figures for EDZLearn, confirmed that industry estimates circulating – ranging from ₹3 lakh to ₹8 lakh per month for a general-purpose ed-tech platform – are indeed "a good figure." He underscored that these costs escalate significantly in highly regulated sectors. "For a bank to adhere to the DPDP Act, the cost will go up to ₹12-15 lakh," he stated, adding that healthcare clients, due to the sensitive nature of medical data, face even higher compliance expenditures.
These figures are corroborated by public quotes from specialized compliance consultancies. MYITMANAGER, a cybersecurity and DPDP advisory firm based in Gurgaon, provides a tiered cost estimation: ₹3 lakh to ₹8 lakh for startups and small to mid-sized enterprises (SMEs), rising to ₹8 lakh to ₹20 lakh for mid-market firms, and a hefty ₹20 lakh to ₹50 lakh for large enterprises. These estimates factor in essential components such as appointing Data Protection Officers (DPOs), conducting thorough gap assessments to identify non-compliant areas, building sophisticated consent mechanisms, and implementing advanced technical safeguards.
Kumar Priyank, CEO and co-founder of DPDP Consultants, further elaborated that the expense is not a one-time capital outlay but a layered and continuous commitment. At the technological level, ed-tech firms must integrate with government-registered Consent Manager platforms. This can involve licensing third-party infrastructure or developing proprietary solutions, both of which entail significant investment. Furthermore, companies that cross the threshold into what the law defines as a "Significant Data Fiduciary" are mandated to appoint an India-based Data Protection Officer who reports directly to the board, alongside a dedicated support staff. This requirement adds a substantial recurring personnel cost.
Beyond initial setup and DPO appointments, a multitude of recurring costs compound the financial burden. These include ongoing employee training programs to ensure a data protection-aware workforce, regular independent audits to verify compliance, periodic Data Protection Impact Assessments (DPIAs) to evaluate and mitigate privacy risks, and accessibility retrofitting to meet Web Content Accessibility Guidelines (WCAG) standards, particularly wherever children’s data is involved. "Collectively, these obligations represent both one-time capital outlay and sustained operational cost," Mr. Priyank emphasized, highlighting the long-term financial commitment required.
However, not everyone views the compliance costs with the same apprehension. Viplav Baxi, who leads AmplifiU, a pedagogy-focused platform for teachers, offered a counter-perspective, challenging the narrative that compliance is unduly stifling the sector. "I do not think there is too much of a hurdle, it is just a law that needs to be implemented," he asserted. Baxi argued that the core technical requirements – transparently informing users about the data collected, its purpose, retention period, and providing a clear mechanism for withdrawing consent – "is not technically that complicated." He called for a deeper investigation into the genesis of the average ₹3-8 lakh cost, suggesting that factors like platform scale (e.g., 1,000 students versus 1 million) and the extent to which these expenditures represent deferred "good governance" practices, rather than entirely new mandates, should be critically examined.
The Regulatory Imperative: Official Responses and Intent
While the article does not contain direct quotes from government officials or the Data Protection Board of India, the very existence and phased implementation of the DPDP Act serve as a powerful "official response" to the growing global imperative for data privacy. The Act’s intent is clear: to establish a legal framework that balances innovation and the growth of India’s digital economy with the fundamental right to privacy for its citizens.
The operationalization of the Data Protection Board of India in November 2025 signals the government’s commitment to active enforcement. The Board’s mandate includes ensuring compliance, investigating data breaches, and levying significant penalties for violations. The upcoming enforcement of penalties in November 2026 will serve as a strong deterrent, compelling data fiduciaries to prioritize data protection. The introduction of a government-registered Consent Manager system also reflects a desire to standardize and simplify the consent process for individuals, thereby empowering data principals.
Industry stakeholders, while grappling with the practical challenges, largely acknowledge the necessity of such legislation in an increasingly digital world. The government’s messaging, implicit in the Act’s design, is that data protection is not merely a regulatory burden but a foundational element of trust in the digital ecosystem. By mandating transparency, accountability, and user control, India aims to foster a secure environment for digital services, including the rapidly expanding ed-tech sector. The phased approach, culminating in full compliance by May 2027, is designed to provide a transition period, suggesting a regulatory intent to facilitate adaptation rather than impose immediate, overwhelming demands. However, concerns raised by smaller firms regarding the potential for consolidation due to high compliance costs indicate that dialogue between regulators and industry remains crucial to ensure the Act achieves its objectives without stifling innovation or competition.
Profound Implications: Protecting Minors and Shaping the Industry
The DPDP Act’s most stringent and, consequently, most costly compliance obligations revolve around the handling of data pertaining to minors. Recognizing children as particularly vulnerable internet users, the law imposes heightened duties on data fiduciaries. Mihir Jana confirmed that EDZLearn has had to re-engineer its workflows to incorporate mandatory parental sign-off before any student data enters their systems. Once a minor’s data is involved, even stricter rules apply to its sharing, deletion, and audit access. "For the children and minors, it’s even stricter," Jana highlighted, emphasizing the layered protections.
Viplav Baxi elaborated on the practical complexities this creates for school-facing platforms. Children, by law, cannot provide consent for themselves, necessitating parental approval. The mechanism for capturing this consent – whether directly by the platform or funneled through the school – remains a significant operational challenge. Baxi noted the ambiguity surrounding how approval mechanisms will function at the school level, predicting that schools will ultimately be responsible for documenting consent, even for data initially collected offline. He also pointed to a structural asymmetry: a student’s ability to object to activity tracking embedded in a learning management system is severely limited, as the school, not the child, dictates the digital tools deployed in the classroom, creating a potential power imbalance in the consent process.
Another critical flashpoint is data retention. Jana noted that EDZLearn has now implemented a crucial distinction, separating personal data from learning data (e.g., quiz scores, certificates). Each data category is assigned its own specific retention window, a significant departure from the previous practice of indefinite storage – a shift Jana deemed long overdue. The proliferation of AI-driven features further compounds this complexity. Any AI conversation occurring on a learning platform now necessitates explicit disclosure of the AI provider, the data’s processing location, and its purge schedule, sometimes requiring deletion within a day of the interaction. This demands sophisticated data lineage tracking and automated deletion protocols.
Kumar Priyank of DPDP Consultants expressed particular concern for early-stage companies within the ed-tech sector. These smaller entrants are often least equipped to absorb the simultaneous financial burden of developing consent infrastructure, hiring compliance staff, procuring robust security tooling, and undertaking necessary accessibility upgrades. Without "calibrated relief such as staggered timelines, shared compliance utilities, or RegTech-as-a-service models," Priyank warned, these smaller players risk being priced out of the market entirely. This could lead to a significant consolidation of advantage with larger, better-capitalized incumbents, a concern that industry stakeholders have directly conveyed to regulators. The Act, while aiming to protect, inadvertently poses a challenge to the vibrant startup ecosystem in India’s ed-tech space.
Priyank’s advice to all ed-tech founders, irrespective of their company’s size, is unequivocal: "Start now, and start with data minimisation." Data minimisation, a core principle of data protection, involves collecting only the data that is absolutely necessary for a specified purpose. He stressed that "incremental action taken today will invariably prove less disruptive and considerably less costly than compliance undertaken under regulatory compulsion."
The DPDP Act represents a monumental step for India, aligning its digital regulatory framework with global best practices. While the journey to full compliance presents significant operational and financial hurdles for the ed-tech industry, particularly concerning the sensitive data of minors, it also ushers in an era of greater transparency, accountability, and trust. The ultimate success of this paradigm shift will depend on the industry’s adaptability, the regulators’ responsiveness to practical challenges, and a shared commitment to fostering a secure and privacy-respecting digital learning environment for all of India’s students.
(Hanan Zaffar is a Delhi-based journalist covering tech environment and AI)
