Current as of August 2026. The DPDPA is an evolving regulatory area — revisit this as Phase 2 (November 2026) and Phase 3 (May 2027) dates approach. This article is written from a marketing and operational perspective. It is not legal advice. Institutions should consult their own legal counsel for formal compliance sign-off.


India’s Digital Personal Data Protection Act is now real. Not theoretical, not pending. Real, with a phased enforcement timeline and penalties that can reach ₹250 crore for a single breach.

The articles flooding marketing channels right now mostly explain what the Act is. This one skips that and focuses on what it means specifically for university admissions: lead generation, remarketing, CRM, and the particular problem of marketing to applicants who are still legally minors.

The timeline, briefly

The DPDPA was enacted in 2023. The Rules were notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025, starting a three-phase implementation schedule:

  • Phase 1 (November 2025): The Data Protection Board was established.
  • Phase 2 (13 November 2026): The Consent Manager framework comes into effect.
  • Phase 3 (13 May 2027): Full enforcement of core obligations begins.

Phase 3 is 9 months away. That’s tight if you’re a university running multiple lead generation channels, a CRM with years of accumulated enquiry data, and remarketing campaigns across Google and Meta.

Every admissions lead form is now a compliance surface

This is the operational shift most marketing teams haven’t fully absorbed yet.

Under the DPDPA, collecting a name, phone number, or email address from a prospective student requires a standalone consent notice. Not a checkbox buried at the bottom of a privacy policy, not a line in terms of service that nobody reads. The consent notice must specify what data is being collected, why, who it will be shared with, and how long it will be kept.

That means every enquiry form on your website, every Facebook Lead Ad, every “Download Brochure” form, and every webinar registration page needs its own compliant consent mechanism before Phase 3. If you’re running ten campaigns across five programmes, that’s ten different consent touchpoints to audit and update.

It’s not technically complex work. But it does require coordination between your marketing team, your web developers, and your legal counsel. Institutions that treat this as an IT ticket will struggle. Those that treat it as a marketing practice change will be better placed.

The minor problem nobody’s talking about

Most undergraduate applicants are 17 years old when they first fill an enquiry form.

The DPDPA treats anyone under 18 as a minor. Processing personal data of a minor requires verifiable parental consent, and not just from the applicant. From the parent.

Think about what that means in practice. A prospective BBA student in Class 12 clicks a Google Ad for your university, lands on a course page, and fills an enquiry form. Under the DPDPA’s phased enforcement, processing that enquiry and adding it to your CRM without verified parental consent is non-compliant.

No institution currently has a clean answer to how “verifiable” is implemented. The Act and Rules set the requirement but the mechanisms are still developing. What’s clear is that UG admissions will need a separate consent flow, distinct from what you use for postgraduate or executive education leads, where applicants are nearly always adults.

The practical question your admissions tech stack needs to answer: do you collect year of study before processing the lead, gate the consent flow based on that, and route underage leads through a parental consent mechanism? The architecture is solvable. But it needs to be designed now, not retrofitted after enforcement begins.

Remarketing and retargeting are inside DPDPA’s scope

Running Google Ads remarketing to website visitors who didn’t fill a form? Facebook Custom Audiences built from CRM lists of past enquiries? Instagram retargeting to students who visited your programme pages?

All of this involves processing personal data. Pixels and cookies collect identifiable user information. CRM data is personal data. Under the DPDPA, using that data for targeted advertising requires consent that explicitly covers remarketing, not just the original data collection.

If someone filled your enquiry form two years ago to download a brochure, the consent they gave almost certainly didn’t mention “we may also use your information to serve you targeted advertising on third-party platforms.” That gap needs to close.

This doesn’t mean remarketing stops working. It means the consent notice at the point of data collection must accurately describe all the ways you intend to use that data. If your team runs Google remarketing lists and Meta Custom Audiences as standard practice, say so in the consent language, before the data is collected.

The Significant Data Fiduciary question

The DPDPA creates a category called Significant Data Fiduciaries — entities processing large volumes of personal or sensitive data, carrying additional obligations as a result.

No institution has been designated as an SDF as of August 2026. Designation is expected to develop through 2026 and into Phase 3. Large national universities processing hundreds of thousands of enquiries annually are watching this closely, and they should be. If a tier-1 university gets designated, the additional requirements — data protection impact assessments, a data protection officer, algorithmic accountability — change the compliance burden substantially.

For most private universities and colleges, SDF designation is unlikely in the first wave. But building data governance infrastructure now is cheaper than retrofitting it later.

Getting ahead of this before May 2027

The institutions that redesign their admissions funnels for DPDPA before enforcement arrives aren’t just avoiding penalties. They’re building something that prospective students and parents increasingly notice: transparency about how data is handled.

In a market where students weigh up six institutions before committing, and where parents are increasingly privacy-aware, a clear and honest consent experience is a real differentiator. Quiet, but there. The landing page that tells applicants exactly what their data will be used for, and gives them a genuine choice, is starting to outperform the one that buries consent in fine print.

The enforcement deadline creates a floor. Smarter institutions are using it as a prompt to do something better.


Where to start

If you’re a university marketing or admissions team and you haven’t started this yet, a few things are worth prioritising now.

Audit every active lead form and CRM intake point. Check whether current consent language covers all the ways you’re actually using that data: CRM, email, WhatsApp, remarketing, sharing with agencies. Most will find the language is too narrow.

Separate your UG and PG lead flows. The minor-consent requirement is real, the mechanisms are still developing, and waiting for MeitY guidance doesn’t reduce the eventual obligation. Get the architecture in place so you can add the parental consent layer when it crystallises.

Align with your media and digital marketing agency on remarketing consent language before Phase 2 (November 2026) brings the Consent Manager framework into play. That’s when consent management becomes structurally regulated.

Then talk to your legal counsel. The operational questions above are the right ones to bring to that conversation.


Getting your admissions funnel DPDPA-ready without sacrificing lead volume or conversion is a design challenge as much as a legal one. If your team is beginning to think through what this means for your lead generation setup, we’re happy to talk it through at EDU SolPro.