DPDP Act: are compliance costs of privacy law crushing ed-tech businesses?

Polity & Governance · 29 August 2026 · Based on The Hindu (original report)

Worth reading — 1 past UPSC question on this theme (Prelims GS-1 2018).

2-minute summary

The phased implementation of India's Digital Personal Data Protection (DPDP) Act, 2023, is introducing substantial compliance costs for the domestic education technology (ed-tech) sector. Since the notification of the DPDP Rules in November 2025, ed-tech companies—which routinely collect student names, learning metrics, and AI-tutor conversation logs—are restructuring their data architectures. Industry estimates place recurring compliance costs for startups and SMEs at ₹3 lakh to ₹8 lakh per month, escalating to ₹20 lakh to ₹50 lakh for larger enterprises. These expenses stem from integrating with government-registered Consent Managers, appointing India-based Data Protection Officers (DPOs) for Significant Data Fiduciaries, conducting independent audits, and retrofitting platforms to meet Web Content Accessibility Guidelines (WCAG) for children's data. While some industry experts view these costs as a necessary correction for deferred data governance, others warn that the financial and technical overhead could stifle early-stage innovation in India's digital education ecosystem.

Why it's in the news

The transition timeline of the DPDP Act is reaching critical milestones, with the Data Protection Board of India (DPBI) operationalized, consent manager registrations starting in late 2026, and full compliance mandatory by May 2027. This has triggered intense debate over the financial viability of compliance for data-heavy startups, particularly in the ed-tech sector.

Background and context

The right to privacy was declared a fundamental right under Article 21 of the Constitution by a nine-judge bench of the Supreme Court in the landmark Justice K.S. Puttaswamy v. Union of India case (2017). Following this, the Ministry of Electronics and Information Technology (MeitY) constituted the Committee of Experts on a Data Protection Framework, chaired by Justice B.N. Srikrishna, which submitted its report in 2018. After multiple iterations and withdrawals of previous drafts, the Parliament passed the Digital Personal Data Protection (DPDP) Act in August 2023. The Act establishes a framework for processing digital personal data in a manner that recognizes both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes.

Constitutional provisions

  • Article 21 — Guarantees the Right to Life and Personal Liberty, which the Supreme Court interpreted as encompassing the Right to Privacy in the Puttaswamy judgment.
  • Article 19(1)(g) — Guarantees the right to practice any profession or carry on any occupation, trade, or business, which is balanced against reasonable state restrictions under Article 19(6) for public interest and data protection.

Committees and reports

  • Justice B.N. Srikrishna Committee of Experts on a Data Protection Framework — Laid the foundational principles for data protection in India, emphasizing consent, data minimization, purpose limitation, and the creation of a regulatory authority.

Government schemes

  • DIKSHA (Digital Infrastructure for Knowledge Sharing) — As a national digital platform for school education handling student and teacher data, its architecture must align strictly with the DPDP Act's standards for public sector ed-tech.

International organisations

  • European Union (General Data Protection Regulation - GDPR) — The global benchmark for data privacy laws. India's DPDP Act shares similarities with GDPR regarding data subject rights and consent, but differs by adopting a more simplified, business-friendly compliance structure with distinct provisions for 'Data Principals' and 'Data Fiduciaries'.

Previous UPSC questions on this theme

  • Prelims GS-1 2018 — Right to Privacy is protected as an intrinsic part of Right to Life and Personal Liberty. Which of the following in the Constitution of India correctly and appropriately imply the above statement ? (a) Article 14 and the provisions under the 42nd Amendment to the Constitution (b) Article 17 and the Directive Principles of State Policy in Part IV (c) Article 21 and the freedoms guaranteed in Part III (d) Article 24 and the provisions under the 44th Amendment to the Constitution

Mains practice: The Digital Personal Data Protection (DPDP) Act, 2023, represents a paradigm shift in India's digital governance. However, concerns persist regarding its compliance burden on MSMEs and startups. Critically analyze this statement with special reference to the ed-tech sector.

The Digital Personal Data Protection (DPDP) Act, 2023, establishes a comprehensive legal framework to protect personal data in India's expanding digital economy. While it empowers 'Data Principals' (citizens), its implementation presents a dual challenge of safeguarding privacy and maintaining the ease of doing business for startups, particularly in data-intensive sectors like educational technology (ed-tech).

**Compliance Challenges for the Ed-Tech Sector:**

• **High Operational Costs:** Startups face significant recurring expenses (estimated at ₹3 to ₹8 lakh monthly) for deploying technical safeguards, conducting independent audits, and integrating with government-registered Consent Managers.

• **Strict Children's Data Regulations:** Ed-tech platforms primarily serve minors. The Act mandates verifiable parental consent and strictly prohibits tracking, behavioral monitoring, or targeted advertising directed at children. Implementing robust age-verification mechanisms without violating privacy is technically complex and costly.

• **Significant Data Fiduciary (SDF) Obligations:** Platforms designated as SDFs must appoint an India-based Data Protection Officer (DPO), conduct periodic Data Protection Impact Assessments (DPIAs), and undertake regular audits, creating substantial administrative overhead.

• **Retrofitting Legacy Systems:** Migrating existing databases to comply with data minimization, purpose limitation, and prompt deletion protocols requires extensive software overhaul.

**The Counter-Perspective (Necessity of Regulation):**

• **Vulnerability of Minors:** Children are highly susceptible to profiling and commercial exploitation. Strict regulations prevent the monetization of sensitive student data (e.g., biometrics, learning disabilities, AI tutor chats).

• **Long-term Trust:** Robust data protection fosters consumer trust, which is vital for the sustainable growth of India's digital education market.

**Conclusion:**

To prevent compliance costs from crushing startup innovation, the government should adopt a tiered regulatory approach. Providing compliance toolkits, standard operating templates, and regulatory sandboxes for early-stage startups can help balance the constitutional right to privacy with India's entrepreneurial aspirations.

Prelims practice questions

Q1. With reference to the Digital Personal Data Protection (DPDP) Act, 2023, consider the following statements: 1. A 'Data Principal' refers to the individual, company, or state department that determines the purpose and means of processing personal data. 2. A 'Data Fiduciary' is the individual to whom the personal data relates. 3. The Act completely prohibits the transfer of personal data outside India, except to countries specifically whitelisted by the Central Government. Which of the statements given above is/are incorrect?

  1. 1 and 2 only
  2. 2 and 3 only
  3. 1 and 3 only
  4. 1, 2 and 3

Answer: D. All three statements are incorrect. Under the DPDP Act 2023: (1) 'Data Principal' is the individual to whom the personal data relates (not the entity processing it). (2) 'Data Fiduciary' is the entity (individual, company, state) that determines the purpose and means of processing personal data. (3) The Act allows the transfer of personal data outside India to all countries by default, except to those countries specifically blacklisted (restricted) by the Central Government.

Q2. Consider the following statements regarding the Data Protection Board of India (DPBI): 1. It is established as a statutory body under the provisions of the DPDP Act, 2023. 2. The Board has the power to impose financial penalties for non-compliance with the provisions of the Act. 3. Appeals against the decisions of the DPBI lie directly before the Supreme Court of India. Which of the statements given above are correct?

  1. 1 and 2 only
  2. 2 and 3 only
  3. 1 and 3 only
  4. 1, 2 and 3

Answer: A. Statements 1 and 2 are correct. The DPBI is a statutory body established under the DPDP Act, 2023, and has the power to adjudicate non-compliance and levy penalties. Statement 3 is incorrect because appeals against the decisions of the DPBI lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), not directly before the Supreme Court.

Q3. Under the Digital Personal Data Protection (DPDP) Act, 2023, which of the following is/are mandatory obligations for processing the personal data of a child? 1. Obtaining verifiable consent of the parent or lawful guardian. 2. Refraining from processing personal data that is likely to cause any detrimental effect on the well-being of a child. 3. Ensuring no tracking, behavioral monitoring, or targeted advertising is directed at children. Select the correct answer using the code given below:

  1. 1 and 2 only
  2. 2 and 3 only
  3. 1 and 3 only
  4. 1, 2 and 3

Answer: D. All three statements are correct. Section 9 of the DPDP Act, 2023, outlines special provisions for children's data, which include obtaining verifiable parental consent, prohibiting any processing that causes detrimental effects on the child, and strictly banning tracking, behavioral monitoring, or targeted advertising.

Revision flashcards

  • Who is a 'Data Fiduciary' under the DPDP Act, 2023? Any person, company, or state entity that alone or in conjunction with others determines the purpose and means of processing personal data.
  • Who is a 'Data Principal' under the DPDP Act, 2023? The individual to whom the personal data relates. In the case of a child (under 18) or a person with a disability, it includes their parent or lawful guardian.
  • What is a 'Consent Manager' under the DPDP Act framework? A data fiduciary registered with the Data Protection Board of India (DPBI) that enables a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform.
  • What criteria determine a 'Significant Data Fiduciary' (SDF)? Designated by the Central Government based on factors like the volume and sensitivity of personal data processed, risks to the rights of Data Principals, potential impact on national security, and public order.
  • Where do appeals against the orders of the Data Protection Board of India (DPBI) lie? Appeals lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which must be filed within 60 days.

Related briefs

All stories for 29 August 2026 · ← 28 August 2026 · 30 August 2026 →