Abstract:
The Digital Personal Data Protection Act, 2023 (DPDP Act), marks a watershed moment in India’s legal landscape, introducing a comprehensive framework for safeguarding personal data in the digital age. The central idea of this legislation is to protect the children’s data, defined as information of individuals below the age of eighteen years. This article critically examines whether schools, as data fiduciaries, may lawfully publish students’ marks and ranks online without parental consent. The issue of significance in long-standing practice is the publicly disclosed academic performance in India, which is often justified on the grounds of transparency and accountability.
Drawing upon constitutional jurisprudence, especially Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), the analysis situates the DPDP Act in the broader framework of the Right to Privacy. Section 9 of the Act mandates verifiable parental consent before processing children’s personal data, thereby rendering routine publication of marks and ranks unlawful absent such authorisation. Case studies, including controversies surrounding the CBSE’s merit list disclosures, highlight the risks of stigmatisation, reputational harm, and psychological distress that accompany the public exposure of academic performance. Comparative perspectives from the European Union’s General Data Protection Regulation (GDPR) and the United States’ Children’s Online Privacy Protection Act (COPPA) reinforce India’s approach, situating it within a global consensus on child privacy.
The article argues that, though the transparency in education remains a legitimate institutional goal, it cannot override statutory and constitutional obligations to protect dignity and privacy. Schools must adopt privacy‑compliant alternatives such as secure portals, anonymised reporting, and consent‑based publication models. Ultimately, the DPDP Act compels a cultural shift in educational governance, moving away from public displays of meritocracy toward child‑centric practices that prioritise autonomy, mental health, and constitutional rights.
Keywords: Privacy, consent, accountability, transparency, regulation, anonymity, and governance
Introduction:
The enactment of the Digital Personal Data Protection Act, 2023, has raised pressing questions about the treatment of children’s personal data in educational institutions. A central issue is whether schools may lawfully publish students’ marks and ranks online, a practice long justified on grounds of transparency and accountability. Contemporarily, the debates reveal that legal frameworks are not merely instruments of regulation but also reflections of evolving social values and political priorities. Whether the subject is intellectual property, environmental sustainability, or financial regulation, the challenge lies in balancing innovation with accountability and individual rights with collective responsibilities. The enactment of the Digital Personal Data Protection Act, 2023, marks a moment in India’s approach to safeguarding privacy in the digital age. Among its applications, the most contested question that arises is the treatment of children’s personal data, particularly in educational settings where schools routinely collect, process, and sometimes disclose sensitive information such as marks and ranks. While transparency in academic performance has long been viewed as a tool for accountability, the online publication of such data raises pressing questions about consent, dignity, and the potential for harm. This article examines the intersection of child rights, parental consent, and institutional responsibilities under the DPDP Act, situating the debate within broader constitutional principles and international privacy standards. By analysing statutory provisions, regulatory guidance, and judicial reasoning, it clarifies whether schools can lawfully publish students’ marks and ranks online and what measures must accompany such practices.
Background:
The Digital Personal Data Protection Act, 2023 (DPDP Act), is the first comprehensive legislative framework in India dedicated exclusively to safeguarding personal data in the digital ecosystem. It has been enacted as a response to the recognition of the Supreme Court’s right to privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017). The Act seeks to balance individual autonomy with the legitimate needs of institutions and the state. It introduces key concepts such as “data fiduciaries,” “data principals,” and “consent managers,” thereby aligning Indian law with global data protection regimes, including the EU’s General Data Protection Regulation (GDPR).
Within this framework, children’s data occupies a particularly sensitive category. The Act defines a child as any person below the age of eighteen and imposes obligations on data fiduciaries when such information is processed. Section 9 mandates verifiable parental consent before any processing of children’s personal data, reflecting concerns about vulnerability, exploitation, and long-term reputational harm. However, the Act also recognises limited exceptions under Section 7, such as compliance with legal obligations or judicial orders. These exceptions do not extend to discretionary publication of marks, but they show that the consent requirement must be interpreted contextually rather than as an absolute bar. Educational institutions that collect and manage vast amounts of student data in a routine manner emerge as critical stakeholders in the implementation of the Act.
Legal Framework:
The Digital Personal Data Protection Act, 2023, establishes the statutory foundation for regulating the collection, processing, and disclosure of personal data in India. Rooted in the constitutional recognition of privacy as a fundamental right under Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), the Act seeks to harmonise individual rights with institutional responsibilities in the information age. It introduces the concepts of Data Fiduciary and Data Principal that relate to the entity that determines the purpose and means of processing, and the individual whose data is related. In this way, there is a creation of a rights‑based framework for data governance. Section 2(1)(t) defines personal data, and Section 4 outlines the lawful processing. Section 9 governs children’s data, and Section 33 empowers the Data Protection Board. For schools, obligations include notice, consent, purpose limitation, and grievance redressal. The exceptions under Section 7 may apply, but do not extend to discretionary publication of marks.
A critical dimension of the Act is the treatment of children’s personal data. Section 9 explicitly prohibits the processing of data relating to children (defined as persons below 18 years) without verifiable parental consent. This provision reflects international best practices, particularly the European Union’s General Data Protection Regulation (GDPR), which imposes safeguards for minors. The DPDP Act further prohibits tracking, behavioural monitoring, and targeted advertising directed at children, underscoring the legislature’s intent to prioritise dignity and protection over institutional convenience.
In the educational basis, schools qualify as Data Fiduciaries when they collect, store, and disclose student information. Marks, ranks, and performance records are personal data, as they directly identify a child and reveal sensitive aspects of their academic profile. Under Section 9 of the Act, any online publication of such data without parental consent would lead to an unlawful process. The Act empowers the Data Protection Board of India to investigate breaches and impose penalties, which may extend up to ₹200 crore depending on the severity and recurrence of violations.
The framework also consists of broader constitutional and statutory principles. Article 21 of the Constitution of India guarantees the right to life and personal liberty, which the Supreme Court interpreted to include the right to privacy. The Information Technology Act, 2000 and its rules on sensitive personal data provide safeguards, though the DPDP Act now serves as the primary legislation. Together, these instruments create a layered regime that mandates schools to balance transparency in academic evaluation with the privacy rights of children and their families.
Therefore, the legal framework is situated at the intersection of constitutional rights, statutory obligations, and institutional practices. It clarifies that educational institutions must adopt privacy‑compliant mechanisms, for example, secure portals with restricted access rather than public disclosure of marks and ranks, unless parental consent has been obtained.
Main Analysis:
The central question is whether schools can publish students’ marks and ranks online under the Digital Personal Data Protection Act, 2023 (DPDP Act), without parental consent. Marks and Ranks and academic performance data qualify as personal data under Section 2(1)(t) of the DPDP Act, as it relates to an identifiable individual. When such data pertains to minors, it falls within the protection regime of Section 9 of the Act. The publication of marks and ranks online, even if intended for transparency, constitutes “processing” and “disclosure” under the Act. Thus, schools act as Data Fiduciaries and must comply with obligations imposed.
Section 9(1) mandates verifiable parental consent for processing children’s personal data. This requirement is stringent but not absolute and does not provide exceptions for educational institutions. Unlike internal record‑keeping or communication directly with parents, public disclosure online is not “necessary processing” but rather discretionary. Therefore, absent parental consent, such publication is unlawful. However, the requirement is not absolute in all contexts. The Act allows a process where it is strictly required for the provision of educational services, provided such processing does not involve public disclosure.
The DPDP Act is animated by the principle of prevention of harm to data principals. Public disclosure of ranks can stigmatise children, foster unhealthy competition, and expose them to bullying or reputational damage. These risks go along with the Supreme Court’s emphasis on dignity in Puttaswamy and subsequent privacy judgments. Applied to schools, this means that publishing ranks online without consent directly infringes the information privacy recognised in Puttaswamy and undermines the dignity principle reaffirmed. The Act’s prohibition on profiling and tracking children further underscores the legislature’s intent to shield minors from unnecessary exposure.
International regimes reinforce this interpretation. Under the GDPR, Article 8 requires parental consent for processing children’s data who are under the age of 16, with Member States permitted to lower the age to 13, and educational institutions are expected to adopt privacy‑preserving practices. Similarly, the Children’s Online Privacy Protection Act (COPPA) in the United States prohibits disclosure of children’s personal information without parental consent. Unlike GDPR, COPPA does not regulate offline school disclosures, but its principles reinforce the necessity of parental authorisation in digital contexts. India’s DPDP Act mirrors these safeguards, situating its approach within global privacy norms.
Schools, as Data Fiduciaries, bear direct responsibility for compliance. Section 33 empowers the Board to investigate breaches and impose penalties up to ₹200 crore. This creates a strong deterrent against unauthorised disclosures. Moreover, schools must adopt privacy‑compliant mechanisms such as secure portals with restricted access, anonymised performance reports, or consent‑based publication models.
While transparency in evaluations is a legitimate institutional goal, it cannot override statutory privacy protections. The DPDP Act requires schools to recalibrate their practices; instead of public rankings, they may provide individual performance reports accessible only to parents through secure logins. This approach reconciles accountability with compliance, ensuring that children’s dignity and privacy remain paramount.
Case Studies:
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017): The landmark judgment that recognised privacy as a fundamental right under Article 21 of the Constitution of India. Although its principles do not directly apply to schools but to educational institutions. The Court emphasised informational privacy and the need for consent in data processing. Publishing students’ marks and ranks online without parental consent would contravene the spirit of Puttaswamy, as it exposes minors to reputational harm and infringes their right and dignity. Applied to schools, these principles mean that publishing ranks online without consent infringes informational privacy recognised in Puttaswamy, and undermines dignity as emphasised in Navtej Singh Johar.
CBSE Merit List Controversy (India, 2020): The Central Board of Secondary Education (CBSE) faced criticism for the publication of detailed merit lists online, which included the students’ names, marks, and ranks of students. While this practice was to promote transparency, it raised concerns over privacy and mental health. Under the DPDP Act, such disclosure would now require verifiable parental consent, and failure to obtain it could invite penalties from the Data Protection Board. This controversy illustrates how institutional practices of transparency can conflict with statutory privacy obligations, reinforcing the need for consent-based disclosure under Section 9.
Navtej Singh Johar v. Union of India (2018): Privacy and Dignity, although primarily about decriminalisation of homosexuality, the Court reiterated the dignity and autonomy as an integral part of privacy. This reasoning expands to children’s data as public disclosure of ranks without consent undermines dignity and autonomy, especially in formative years.
GDPR and Schools (European Union): Under the GDPR, schools are considered data controllers and must obtain parental consent before processing children’s data. Several EU member states have issued guidance prohibiting schools from publishing student performance data online without safeguards. For example, in Germany, schools were instructed to use secure portals rather than public websites to share marks. This comparative perspective reinforces the DPDP Act’s approach.
COPPA Enforcement (United States): The Children’s Online Privacy Protection Act (COPPA) requires parental consent before collecting or disclosing data of children under 13. In enforcement actions, U.S. regulators have penalised institutions and platforms that disclosed children’s personal information without consent. Though focused on online services, the principle is analogous: schools must treat marks and ranks as sensitive data requiring parental authorisation.
Critical Analysis and Evaluation:
The DPDP Act, 2023, marks a major change in India’s data protection rules, with benefits and challenges for educational institutions. It’s designed to verify parental consent before handling children’s data, protecting minors from harm and aligning with global standards. However, strict consent rules can burden schools, especially during high-volume data processing like exams.
The traditional practice of publishing marks and ranks online was justified on the grounds of transparency and accountability. However, the DPDP Act reframes this practice as a potential violation of privacy. The critical issue is whether transparency can be achieved without compromising dignity. Secure portals accessible only to parents may serve as a middle ground, but they require technological infrastructure and digital literacy that not all schools possess. Thus, while the law is normatively sound, its implementation may exacerbate inequalities between well‑resourced and under‑resourced institutions.
The Supreme Court’s judgment in the K.S. Puttaswamy and Navtej Singh Johar cases emphasises privacy and dignity as integral to Article 21 of the Constitution. Public disclosure of ranks risks stigmatisation and psychological harm, particularly in competitive educational environments. The DPDP Act operationalises these constitutional values, but its enforcement will depend on whether regulators adopt a child‑centric approach or defer to institutional convenience. A critical evaluation suggests that prioritising dignity over transparency is consistent with constitutional morality.
International regimes, for example, the GDPR and COPPA, provide useful legal frameworks. Both of them require verified parental consent and prohibit the disclosure of minors’ data without safeguards. India’s DPDP Act is broad and aligned, but its age threshold of 18 is higher than the GDPR’s 16, which may be criticised as overly paternalistic. Moreover, unlike the GDPR, the DPDP Act does not provide nuanced exceptions for educational necessity, which could lead to challenges with rigid compliance. A comparative lens thus reveals both strengths (strong child protection) and weaknesses (lack of flexibility).
The Act empowers the Data Protection Board to impose penalties up to ₹200 crore, signalling a strong deterrent. However, the capacity for enforcement remains uncertain. Schools may argue that publishing ranks serve legitimate educational purposes, but such defences are unlikely to withstand scrutiny unless parental consent is obtained. The evaluation here is that compliance will require cultural change within institutions, moving from a transparency‑driven model to a privacy‑driven one.
Critically, the Act may reshape educational practices that are beyond data disclosure. Schools may need to adopt anonymised ranking systems, consent‑based publication models, or individualised reporting mechanisms. While these reforms enhance privacy, they also challenge entrenched notions of meritocracy and public recognition. The evaluation suggests that the DPDP Act could catalyse a broader shift toward child‑centric education policy, where the child’s dignity and mental health are prioritised alongside academic performance.
Conclusion:
The Digital Personal Data Protection Act, 2023, establishes a clear and uncompromising mandate that children’s personal data cannot be processed or disclosed without verifiable parental consent. In the educational context, this means that schools may no longer publish marks and ranks online as a matter of routine transparency. While such practices were once justified by tradition and institutional convenience, they now stand in direct conflict with statutory obligations and constitutional principles of privacy and dignity.
The analysis demonstrates that marks and ranks qualify as sensitive personal data, and their disclosure without consent risks stigmatisation, reputational harm, and psychological distress. Comparative perspectives from the GDPR and COPPA reinforce India’s approach, situating the DPDP Act within a global consensus that child privacy must be prioritised over institutional expediency. Case studies further highlight the dangers of public disclosure and the judiciary’s consistent emphasis on dignity as a cornerstone of privacy rights.
Ultimately, the Act compels schools to reimagine their practices. Secure portals, anonymised reporting, and consent‑based publication models offer pathways for the reconciliation and transparency with compliance. Yet, this transition also demands cultural change as institutions must move away from public displays of meritocracy to the models of child-centric, respecting the autonomy and mental health.
References:
1.) Digital Personal Data Protection Act, No. 22 of 2023, § 9, Acts of Parliament, 2023 (India)
2.) Information Technology Act, No. 21 of 2000, Acts of Parliament, 2000 (India)
3.) Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 S.C.C. 1 (India)
4.) Navtej Singh Johar v. Union of India, (2018) 10 S.C.C. 1 (India)
5.) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), art. 8, 2016 O.J. (L 119) 1
6.) Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 (2018)