Solutions · Education & edtech

Lifetime access means
rights that never expire.

The DPDP Act tells a fiduciary to erase personal data when “the purpose is no longer being served.” A course sold with lifetime access has no such moment: the purpose is perpetual by contract. So every account ever created stays a live obligation forever, the denominator only grows, and the Rules give edtech no safe-harbour retention clock — that bright line went to e-commerce, gaming and social media. Layer on India’s eighteen-year threshold for a child, a parental-consent mechanism whose infrastructure is not yet notified, and a tracking ban that consent cannot cure, and the sector’s collisions are structural, not paperwork.

FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 10 PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT

What the ground actually looks like

Four collisions, each read from the instrument.

Each of these is marked confirmed: two independent sources, at least one the Gazette text itself (read verbatim from our checksum-pinned corpus) or a practitioner record. Sources are linked so your counsel can read them.

01 · THE PURPOSE THAT NEVER ENDS

A lifetime-access platform can never say the purpose is served, so every DPDP right stays live for every account, forever — with no Third Schedule clock to lean on.

Section 8(7)(a) requires erasure once the purpose is no longer served; ss.6(4) and 6(6) allow withdrawal at any time. Rule 8 and the Third Schedule give bright-line retention clocks only to e-commerce, gaming and social media above their user thresholds — edtech is not a named class, so the fiduciary must defend a purpose judgment per account. Rule 8(2) adds a 48-hour individual notice before any time-based erasure, which turns even voluntary cleanup into a mass-notification pipeline. Marketplace-scale platforms sell lifetime access as a headline feature, and the largest of them now operate two separate account estates under one group.

SOURCES · DPDP Rules 2025, Rule 8 and Third Schedule, G.S.R. 846(E) (Gazette, verbatim) · Udemy pricing — lifetime access (company statement) · Coursera investor release, May 2026 (practitioner)

Confirmed · sweep of 2 Sep 2026
02 · VERIFIABLE PARENTAL CONSENT

Rule 10 prescribes a mechanism whose infrastructure — notified Digital Locker providers, virtual-token issuers — does not exist at signup volume, and nothing in it proves the parent–child relationship.

Section 9(1) requires verifiable parental consent for anyone under eighteen. Rule 10(1) requires due diligence that “the individual identifying herself as the parent is an adult who is identifiable” — via details already held, details voluntarily provided, or a virtual token from an authorised entity; Rule 10(2)’s Digital Locker providers are “as may be notified,” and none has been. The rule verifies that the claimed parent is an identifiable adult. It never verifies that the adult is that child’s parent. A hard gate on revenue: no verified consent, no processing, no signup.

SOURCES · DPDP Rules 2025, Rule 10 (text; Gazette read verbatim) · PIB note on the notified Rules (government) · ORF, “Governing Learner Data Risks in India”, Jun 2026 (research)

Confirmed · Rule 10 in force mid-May 2027; no provider notified as of 2 Sep 2026
03 · THE TRACKING BAN AND THE DEFINITIONAL CLIFF

Section 9(3)’s flat ban on tracking and behavioural monitoring of children collides with adaptive learning — and the exemption turns entirely on whether you are an “educational institution.”

Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children; neither “tracking” nor “behavioural monitoring” is defined. The Fourth Schedule exempts “an educational institution” for tracking and monitoring in the interests of educational activities or safety, and its note defines the term as “an institution of learning that imparts education, including vocational education.” Whether a pure-online platform qualifies has no ruling, no clarification and — because there is no government DPDP FAQ by policy — no guidance. Targeted advertising at children is exempt for nobody.

SOURCES · DPDP Act s.9(3); DPDP Rules 2025, Rule 12 and Fourth Schedule with Notes (Gazette, verbatim) · ORF (research) · convergent firm analyses (context, not confirmation)

Confirmed as a collision · its resolution could not be assessed
04 · CONSENT QUALITY IS ALREADY ENFORCED

Consent patterns in edtech are being penalised today under consumer law — a pre-ticked checkbox and courses gated on surrendering contact details — the exact patterns s.6(1) makes data-law violations from May 2027.

In June 2026 the Central Consumer Protection Authority ordered a penalty against a listed edtech company for a pre-ticked donation checkbox at checkout and for “free” courses gated on a phone number and email. Regulators reach edtech consent design before DPDP’s children provisions commence, through whichever statute is in force; after May 2027 the same evidence supports an s.6 claim. Unbundling is the only shape that survives both.

SOURCES · CCPA order, 1 Jun 2026, as analysed by LiveLaw (enforcement record) · DPDP Act s.6(1) and its illustration (statute)

Confirmed · enforcement is present-tense, under a different statute
What the law actually says — and what it doesn’t

Claims we corrected before putting them here.

The register started from AI-drafted hypotheses and kept only what the Gazette text supported. These are the education-specific claims that changed on the way.

A global learner count is not an India learner count.

The most-repeated user figure for the largest course marketplace is its worldwide registered-learner total; India is its second-largest market at a fraction of that. The obligation survives at the smaller number in full — it scales with cumulative accounts, not with headlines — but the register does not publish the inflated one.

Ninety days is a ceiling you publish, not a fixed SLA.

Rule 14(3) caps a response period the fiduciary itself publishes at ninety days. Publishing the maximum is lawful slack; what no fiduciary is exempt from is the identity verification and the logging behind every response.

The children’s exemptions are inside the Rules, and no one is exempt from the advertising ban.

Rule 12 and the Fourth Schedule sit inside G.S.R. 846(E), not in a separate notification. Schools are exempt from s.9(1) and s.9(3) only for the restricted tracking-and-monitoring purposes described. Targeted advertising at children is exempt for nobody.

“UGC mandates permanent academic records” is not a single instrument.

The UGC order commonly cited schedules the UGC’s own office records. The permanence of the academic record is real but lives in the APAAR and NEP-2020 instruments and in university statutes. The collision — a transcript kept forever beside hostel biometrics and marketing profiles that are not — stands; the citation changed.

No DPDP penalty can be imposed on anyone today.

The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. What is being enforced today is consent design under consumer law, as collision 04 records. The DPDP penalty schedule is stated plainly here, once.

RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM

Where Consent Tree fits today

Rights that never expire
need a queue that never sleeps.

Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.

FOR 01 · THE PERPETUAL QUEUE

A rights request executed, timed and evidenced — at whatever volume the account base produces

Every access, correction and erasure request carries a response deadline computed when it is filed, against the period you publish under Rule 14, with an escalation ladder when it slips. An erasure is executed against the stores you connect and the destruction is recorded, not asserted. A self-serve rights portal lets the learner file and track the request themselves; a broken queue never has to become a Board complaint.

Live: DSR orchestration · SLA tracking · self-serve rights portal · grievance workflows
FOR 02 · THE GUARDIAN

Parent and guardian consent flows for age-gated processing

A guardian’s consent is captured as its own record, tied to the child’s, with the verification method it was obtained by stated on the record — never a stronger claim than the mechanism supports. We do not claim Digital Locker or virtual-token verification, because the providers Rule 10(2) contemplates have not been notified; when they are, the flow will name them.

Live: guardian consent flows for age-gated processing
FOR 03 AND 04 · PURPOSE, UNBUNDLED

Consent per purpose, never pre-ticked, with expiry and versioning built in

Analytics, personalisation and marketing are separate, specified purposes with separate decisions, and non-essential purposes are never pre-checked — the widget enforces that itself rather than trusting the configuration. Notices are versioned so a change forces re-consent; consent expiry is built in with a prompt only when needed. The pattern the consumer regulator penalised cannot be rendered.

Live: purpose-by-purpose consent · no pre-ticked non-essential purpose · consent expiry · versioned notices
FOR ALL OF IT · EVIDENCE

An audit trail a regulator can verify without trusting us

Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. When a parent or a regulator asks what a learner agreed to and when, the answer is a receipt that verifies in a browser. Anyone can check it.

Live: tamper-evident audit trail · independent anchoring · verifiable receipts