Current as of August 2026. The DPDPA is an evolving area; revisit this as Phase 2 (November 2026) and Phase 3 (May 2027) approach. This is written from a marketing and operational perspective, not as legal advice. Consult your legal counsel for formal compliance sign-off.
India’s Digital Personal Data Protection Act is now real. Not theoretical. Real, with a phased enforcement timeline and penalties up to ₹250 crore for a single breach.
Most writing on the DPDP Act for universities covers legal obligations. This article covers what it means operationally: for the admissions office running lead campaigns, the marketing team managing CRM records and retargeting pixels, and the digital agencies handling ads on behalf of the institution.
The timeline, briefly
The DPDPA was enacted in 2023. The Rules were notified by MeitY on 13 November 2025, starting a three-phase schedule:
- Phase 1 (November 2025): The Data Protection Board was established.
- Phase 2 (13 November 2026): The Consent Manager framework comes into effect.
- Phase 3 (13 May 2027): Full enforcement of core obligations begins.
Phase 3 is 9 months away. That’s a tight window for institutions running multiple lead channels and CRM data going back years, with remarketing campaigns live across Google and Meta.
Your university is a data fiduciary
Under the DPDPA, any institution that collects and processes student personal data is classified as a Data Fiduciary (the entity that decides why and how data is collected). Universities, colleges, and coaching centres all qualify. So do the EdTech platforms they use.
Being a Data Fiduciary is an accountability position. You’re responsible for what happens to student data, including what your vendors do with it.
The data you’re processing goes further than most marketing teams realize: enquiry form submissions, CRM records, WhatsApp logs, website cookies, Google Ads audience lists, Meta pixel data. All of it falls under the DPDPA.
Every admissions lead form is now a compliance surface
This is the operational shift most marketing teams haven’t fully absorbed.
Under the DPDPA, collecting a name, phone number, or email from a prospective student requires a standalone consent notice. Not a checkbox buried in a privacy policy. The consent notice must specify what data you’re collecting, why, who you’ll share it with, and how long you’ll keep it.
That means every enquiry form on your website, every Facebook Lead Ad, every “Download Brochure” form, every webinar registration page needs its own compliant consent mechanism before Phase 3. Ten lead generation campaigns across five programmes means ten consent touchpoints to audit.
This isn’t technically complex work. It requires coordination between your marketing team, web developers, and legal counsel. Institutions that treat this as an IT ticket will struggle. Those that treat it as a marketing practice change will be better placed.
The minor problem nobody’s talking about
Most undergraduate applicants are 17 when they first fill an enquiry form.
The DPDPA treats anyone under 18 as a minor. Processing their personal data requires verifiable parental consent. Not from the applicant. From the parent.
Consider what that means in practice. A prospective BBA student in Class 12 clicks a Google Ad, lands on a course page, fills an enquiry form. Adding that record to your CRM without verified parental consent will be non-compliant under Phase 3 enforcement.
No institution currently has a clean answer to how “verifiable” works in practice. The mechanisms are still developing. What’s clear: UG admissions needs a separate consent flow from PG or executive education, where applicants are almost always adults. The architecture is solvable: collect year of study before processing, gate the consent flow on that result, route underage leads through a parental consent path. It needs to be designed now, not when enforcement begins.
Your digital marketing agency’s pixels are your problem
Your digital agency running Google Ads? The Meta pixel collecting visitor data on your website for retargeting? The remarketing lists your agency builds from your CRM exports?
Under the DPDPA, your agency processes data on your instructions. You remain accountable as the Data Fiduciary. If that pixel tracks applicants across the web after they leave your site, that processing needs to be covered in your consent notice. Your agency agreement needs to explicitly restrict them from using your student data for any purpose beyond what you’ve defined.
Most university-agency agreements don’t currently have these clauses. Adding them to your next contract renewal is a practical, low-cost step that most institutions haven’t taken yet.
Remarketing and retargeting inside DPDPA’s scope
Running Google Ads remarketing to website visitors who didn’t convert? Facebook Custom Audiences built from CRM exports of past enquiries? Instagram retargeting to students who visited your programme pages? All common tactics in a performance marketing setup for admissions.
All of it processes personal data. Pixels and cookies collect identifiable user information. CRM data is personal data. Using it for targeted advertising requires consent that explicitly covers remarketing, not just the original data collection.
If someone filled your enquiry form two years ago to download a brochure, the consent they gave almost certainly didn’t mention serving them targeted ads on third-party platforms. That gap needs to close.
This doesn’t mean remarketing stops. It means the consent notice at the point of data collection must describe all the ways you plan to use that data, including Google remarketing lists and Meta Custom Audiences.
Old CRM data has an expiry date
The DPDPA requires erasing personal data once its original purpose is fulfilled. For admissions, that means enquiry records for students who never progressed past the initial contact can’t sit in your CRM indefinitely.
If you’ve run digital campaigns for four or five years, your CRM almost certainly holds records from students who enquired once and never engaged again. No active relationship, no current consent. Under Phase 3, that’s a liability.
The practical fix: set a data retention policy before enforcement begins. Twelve to 24 months from last contact is defensible for most institutions. Beyond that, records should be purged from your CRM, removed from remarketing lists, and excluded from email sequences. This is far easier to build now than to retrofit into a live CRM holding 50,000+ records under enforcement pressure.
The Significant Data Fiduciary question
The DPDPA creates a category called Significant Data Fiduciaries, entities processing large volumes of personal or sensitive data, with additional compliance obligations.
No institution has been designated as an SDF as of August 2026. Designation is expected to develop through 2026 into Phase 3. Large national universities processing hundreds of thousands of enquiries annually are paying close attention. If a tier-1 university gets designated, the additional obligations change the compliance burden substantially. These include annual data protection impact assessments and a designated Data Protection Officer, among other requirements.
For most private universities and colleges, SDF designation is unlikely in the first wave. Building basic data governance infrastructure now is still cheaper than retrofitting it later.
Getting ahead of May 2027
The institutions redesigning their admissions funnels before enforcement arrives do more than avoid penalties. They build something prospective students and parents increasingly notice: transparency about how data is handled.
Students weigh up multiple institutions before committing. Parents are more privacy-aware than they were two years ago. A consent experience that’s honest and clear is starting to outperform one that buries consent in fine print. The enforcement deadline creates a floor. The smarter question is what you build above it.
Where to start with DPDPA compliance for your university
If your marketing or admissions team hasn’t started this yet, five things are worth doing now.
Audit every active lead form and CRM intake point. Check whether consent language covers all the ways you’re actually using that data: CRM, WhatsApp, email, remarketing, sharing with agencies. Most will find the language is narrower than the actual usage.
Review your agency contracts. Add clauses restricting your agency from using student data for their own purposes, and requiring DPDPA-aligned safeguards. This is a contract change, not a conversation.
Separate your UG and PG lead flows. The minor-consent requirement is real. Waiting for MeitY guidance on implementation details doesn’t reduce the underlying obligation. Get the consent architecture designed now.
Set a data retention schedule. Decide how long enquiry records for students who never applied stay in your CRM. Twelve to 24 months from last contact is defensible for most institutions. Then build the CRM rules to enforce it.
Align with your marketing automation setup on consent tracking. Phase 2 (November 2026) brings the Consent Manager framework. Your CRM needs to store and act on consent flags before that date.
Then take those questions to your legal counsel.
Getting your admissions funnel DPDPA-ready without sacrificing lead volume is a design challenge as much as a legal one. If your team is working through what this means for your setup, we’re happy to think it through at EDU SolPro.
Frequently asked questions about the DPDP Act for universities
Does the DPDP Act apply to universities and colleges?
Yes. The DPDPA applies to any organisation processing digital personal data, and universities are specifically classified as Data Fiduciaries because they decide why and how student data is collected. This covers public and private universities, deemed universities, autonomous colleges, and coaching centres. Foreign EdTech platforms offering services to Indian students also fall within scope.
What is the penalty for a university that doesn’t comply with the DPDPA?
The Data Protection Board can levy penalties up to ₹250 crore per contravention. Violations involving children’s data sit at the highest end of enforcement risk under the Act. Beyond financial penalties, institutions face reputational consequences and potential loss of student trust in a market where parents are increasingly data-aware.
How should universities handle enquiry forms for under-18 applicants?
Under the DPDPA, processing personal data of anyone under 18 requires verifiable parental consent, not just the applicant’s. The practical architecture most institutions are designing involves collecting the applicant’s year of study before processing the lead, then routing underage leads through a parental consent flow. This needs to be built before Phase 3 enforcement begins in May 2027.
Does DPDPA cover Google and Meta remarketing campaigns?
Yes. Retargeting pixels, Custom Audiences, and remarketing lists all involve processing personal data. If your consent notice at the point of data collection doesn’t explicitly mention that you’ll use the data for targeted advertising on third-party platforms, your remarketing activity is outside the scope of lawful consent. The fix is updating consent language before running those audiences.
When does DPDPA enforcement start for universities?
Full enforcement begins at Phase 3 on 13 May 2027. Phase 2 (13 November 2026) brings the Consent Manager framework into effect, which has direct implications for how CRM and email platforms store consent flags. Institutions should treat November 2026 as the functional deadline for having consent infrastructure in place.
Related resources
- Lead Generation Services for Universities
- Google and Meta Ads for Universities
- Retargeting for Universities: Reduce Student Drop-offs
- Marketing Automation for Universities
- UGC Equity Regulations 2026: What Universities Need to Know
- Education Lead Generation Strategies
- University Landing Page Optimization
- Digital Marketing for Indian Universities