When Mihir Jana’s IT team sits down with a new client these days, the conversation no longer starts only with features or pricing. Instead, they ask more about where the data is going and how long it will be kept.Mr. Jana is the managing director of EDZLearn Services, a Delhi-based company that builds learning management systems and AI-driven platforms for schools, universities, banks, and other institutions. Since India’s Digital Personal Data Protection (DPDP) Act began taking effect, he said, “the entire ballgame has changed” for the ed-tech industry his company serves.(Sign up for THEdge, The Hindu’s weekly education newsletter.)Passed by the Parliament in August 2023 and rolled out in phases since the DPDP Rules were notified in November 2025, the law is reshaping how education technology companies collect, store and delete the personal data of schoolchildren, some of India’s youngest and most vulnerable internet users.The Data Protection Board of India became operational the same month the rules were notified; penalties and a consent manager registration system are due to take effect in November, and full compliance covering consent, breach reporting, audits and data principal rights becomes mandatory by May, 2027.Join THEdge LinkedIn groupFor an industry built on collecting exactly the kind of data the law now regulates — names, quiz scores, attendance records, AI tutoring conversations, sometimes biometric identifiers — the compliance bill is proving to be substantial. The price tag can be huge and vary sharply depending on the size of the business, the sector it operates in, and the amount of risk it is prepared to carry. This has become one of the more contentious corners of the DPDP rollout.Costly complianceThough Mr. Jana declined to put a hard number on the cost, he confirmed that figures circulating in the industry, roughly ₹3 lakh to ₹8 lakh a month for a general-purpose platform, are “a good figure.” The costs rise sharply in regulated sectors. “For a bank to adhere to the DPDP Act, the cost will go up to ₹12-15 lakh,” he said, and healthcare clients handling medical data push costs higher still.That range is broadly consistent with what compliance consultancies are quoting publicly. MYITMANAGER, a Gurgaon-based cybersecurity and DPDP advisory firm, estimates compliance costs of ₹3 lakh to ₹8 lakh for startups and small and mid-sized enterprises, rising to ₹8 lakh to ₹20 lakh for mid-market firms and ₹20 lakh to ₹50 lakh for large enterprises. This is after data protection officers, gap assessments, consent-mechanism builds, and technical safeguards are factored in.Kumar Priyank, CEO and co-founder of DPDP Consultants, said the expense is layered rather than one-time. At the technology level, ed-tech firms must integrate with government-registered Consent Manager platforms, whether by licensing outside infrastructure or building their own. Companies that cross the threshold into what the law calls a Significant Data Fiduciary must appoint an India-based, board-reporting data protection officer and staff to support them.Recurring costs pile on top: employee training, independent audits, data protection impact assessments, and accessibility retrofitting to meet WCAG standards wherever children’s data is involved. “Collectively, these obligations represent both one-time capital outlay and sustained operational cost,” Mr. Priyank said.Whether that spending is proportionate to the risk it addresses depends on the source. Viplav Baxi, who runs AmplifiU, a pedagogy-focused platform for teachers, pushed back on the framing that compliance is crushing the sector. “I do not think there is too much of a hurdle, it is just a law that needs to be implemented,” he said, arguing the technical piece — telling users what data is held, why, and for how long, then letting them withdraw permission — “is not technically that complicated.” Mr. Baxi called for deeper scrutiny of how the average ₹3-8 lakh has come about. “You should get deeper into the cost structure, why they are saying that,” he said, noting that scale — a platform with 1,000 students versus 1 million — changes the calculus, as does how much of that spending was already necessary good governance that firms had simply deferred.Handling children’s data The DPDP Act imposes the highest compliance cost on how ed-tech handles data of minors. Mr. Jana said his firm now builds workflows requiring parental sign-off before any student data reaches a system, with stricter rules governing sharing, deletion, and audit access once a minor is involved. “For the children and minors, it’s even stricter,” he said.Mr. Baxi described the practical tangle this creates for school-facing platforms. Students cannot legally consent for themselves, so parents must, and it remains unclear how that consent is captured by the platform directly or funnelled through the school. He said that it is not clear how the approval mechanism will work at the school level, but eventually schools will have to document consent even for data collected offline. He also pointed to a structural asymmetry: a student objecting to activity tracking embedded in a learning management system has little real choice, since the school, not the child, controls what tools are deployed in the classroom.Retention is the other flashpoint. Mr. Jana said his firm now separates personal data from learning data — quiz scores, certificates — assigning each its own retention window rather than storing everything indefinitely, a shift he called overdue. AI-driven features compound the complexity. Any AI conversation on a learning platform now requires disclosure of which AI provider processes it, where the data goes, and how quickly it is purged, sometimes within a day of the interaction.Mr. Priyank, whose firm advises ed-tech clients directly, said the sector’s early-stage companies are least equipped to absorb simultaneous spending on consent infrastructure, compliance staff, security tooling and accessibility upgrades.Without “calibrated relief such as staggered timelines, shared compliance utilities, or RegTech-as-a-service models,” he warned, smaller entrants risk being priced out altogether, consolidating advantage with larger, better-capitalised incumbents, a concern industry stakeholders have raised with regulators directly.His advice to ed-tech founders, regardless of size: start now, and start with data minimisation. “Incremental action taken today will invariably prove less disruptive and considerably less costly than compliance undertaken under regulatory compulsion,” Mr. Priyank said.