Breaks down how school admission forms — Aadhaar copies, photos, medical and income fields — quietly violate DPDP Act purpose-limitation and children's-consent rules, and how to fix them before May 2027.
Walk into any school admissions office in March, and you'll find the same stack: photocopied Aadhaar cards, income certificates, medical history sheets, birth certificates, passport photos — all collected on one form, filed under one signature, for one stated purpose that rarely matches what actually gets asked. Nobody in that office is trying to violate a law. They're following a template that's been unchanged for a decade. But under the DPDP Act, that template is now a live compliance risk, and the applicants involved are children — which makes the stakes considerably higher than a routine administrative habit.
This is worth working through in detail, because the admission form is a useful microcosm of a much bigger problem: almost every organization has some version of it — a legacy form or process built long before anyone thought about "purpose limitation" or "verifiable consent," quietly collecting more than the law now allows.
The Form Fails Before a Single Record Is Even Stored
Section 6(1) of the DPDP Act limits consent to the personal data that's actually necessary for the specified purpose. Most admission forms fail this test structurally — they collect by template, not by purpose. A single signature at the bottom is treated as consent for identity verification, health records, fee-concession eligibility, and marketing photography, all at once. Under the Act, those are separate purposes, and each one needs its own notice under Section 5 and its own affirmative consent under Section 6.
A closer look at where a typical form actually leaks:
| Field Collected | Stated Purpose | Where It Actually Ends Up | What DPDP-Aligned Handling Looks Like |
|---|---|---|---|
| Aadhaar number/photocopy | "Identity proof" | Photocopy files, ERP free-text fields, vendor forms | Collect only where a specific scheme or board requirement makes it necessary; otherwise verify and don't retain |
| Student photograph | ID card, records | Website, prospectus, Instagram, parent WhatsApp groups | Separate internal-use and publication purposes, each with its own consent |
| Medical/allergy/disability details | Infirmary, emergencies | Class-teacher WhatsApp threads, trip permission forms | Distinct, access-controlled purpose — never bundled into general admission consent |
| Parent income/ITR/salary slips | Fee concession | Retained for every applicant, not just those seeking aid | Collect only from the concession-seeking cohort; erase after the decision |
| Rejected applicants' full files | None, once the decision is made | ERP archives and cupboards, indefinitely | Erasure required once the purpose lapses (Section 8) |
That last row is where most schools are quietly sitting on the largest exposure. A school admitting 300 students in a cycle often retains complete files for well over a thousand applicants — the majority of whom it never enrolled, and for whom no purpose for holding that data still exists.
Aadhaar Isn't "Extra Sensitive" — Which Is the Problem, Not the Relief
A common misconception is that Aadhaar sits in some heightened "sensitive data" category requiring extra caution, while everything else on the form is comparatively low-risk. The DPDP Act doesn't actually create that tiered structure — there's no separate "sensitive personal data" category carried over from earlier data protection frameworks. Aadhaar is personal data, full stop, which means it carries the exact same fiduciary obligations as any other field: notice, purpose limitation, security, and eventual erasure.
That's not a relaxed standard — it's arguably a stricter one in practice. A high-value national identifier, retained in bulk with weak access controls, is precisely the kind of exposure that turns a misplaced laptop or an unsecured shared drive into a failure of "reasonable security safeguards" under Section 8 — the provision carrying the Act's steepest penalty tier, up to ₹250 crore. Where identity and age can already be established through a birth certificate or transfer certificate — which most schools also collect — retaining an Aadhaar photocopy on top of that is duplication without a clear justification.
Photos Are a Separate Consent Problem Entirely
Few fields travel further from their original purpose than a student's photograph. It gets collected for an ID card, then resurfaces on the school website, the admissions brochure, an Instagram post, and a parent WhatsApp group — each a different audience, different reversibility, and under the Act, a different consent requirement.
Section 6 requires that consent be unconditional — a parent must be able to agree to admission while declining the yearbook photo or the Instagram feature, without the admission itself being put at risk. Because the subject is a child, Section 9 layers on additional restrictions, including an outright prohibition on behavioral monitoring or targeted advertising directed at children — which makes using a student's image in any paid promotional campaign considerably harder to justify than a simple signed consent form might suggest.
What "Verifiable Parental Consent" Actually Requires
Section 9 doesn't just require a parent's signature — it requires proof that can hold up later. That generally means being able to show who consented (a verified parent or lawful guardian, per the due-diligence methods set out in the DPDP Rules), what exactly they agreed to, when, and confirmation that the record hasn't been altered since. A signed form re-scanned into a shared drive, with no timestamp and no version control, doesn't meet that bar particularly well.
This is fundamentally a records and systems question, not a stationery one. It calls for admission data being logically separated by purpose, consent captured and timestamped per purpose rather than as one blanket signature, and a process for withdrawal that can actually reach every place the data (or the photograph) has traveled — the ERP, the transport vendor, the photographer's archive.
Getting Ahead of the May 2027 Deadline
The DPDP Rules' substantive compliance obligations — notices, consent standards, erasure timelines — come into force on 13 May 2027, which means the 2027–28 admission cycle is the first one that has to run under the new regime by design, not by retrofit. That sounds distant until you map out the actual work: auditing every field on the form against a stated purpose, splitting photo consent by surface, building an erasure schedule for rejected applicants, and reviewing vendor contracts with photographers and ERP providers for deletion obligations. None of that happens in the weeks before an admission cycle opens.
Schools that start with a single, honest line-by-line audit of their current form — writing the actual purpose next to every field, and cutting anything that doesn't have one — tend to find the rest of the compliance picture becomes far clearer.
Where TheDPDPAct.com Fits In
Mapping an admission form field by field is a useful start, but it's one document out of many — enrollment systems, HR records, vendor contracts, and communication platforms all carry the same kind of purpose-drift over time.
TheDPDPAct.com's assessment platform is built to surface exactly this kind of gap across an institution's full data footprint, not just the form parents fill out at the front desk — so the fixes happen well before the Data Protection Board asks for evidence, not after.