DPDP Insights › All sectors › Education
Schools, colleges and ed-tech platforms hold children's data at scale. Rule 12 and the Fourth Schedule exempt educational institutions from some children's-data limits for educational activities and safety, but not for marketing or unrelated tracking.
Open the interactive tool for this sectorThis sector is in its core view. The law, guides and seat notes apply in full; the sector pack with role briefs and worked examples is being written.
| Rule | What it says | What it means alongside DPDP | Source |
|---|---|---|---|
| CERT-In Directions, 2022 | Report specified cyber incidents within six hours; keep ICT logs 180 days within India. | Applies alongside the DPDP breach steps. | CERT-In |