APAAR Opt-Out Mandate And DPDP Act: Reinstating Parental Choice In Student Surveillance
Who decides how long a child's disciplinary record at school is maintained? Along the same lines, when your child's admission card comes with a lifelong digital surveillance tag, can a parent say no, or just put his signature across the dotted lines?
The "One Nation, One Student ID" framework through the Automated Permanent Academic Account Registry (APAAR) scheme brought these questions to the forefront, with the enormity and diversity of student data being collected and recorded by schools as part of the scheme. Since the scheme involves collection of personal data of minor students, parents are required to fill a consent form for linking the student Aadhar to APAAR ID. Interestingly, while the model consent form states that information collected through the APAAR framework will be shared with third-party entities, it does not provide the parent with an opt-out clause at the time of signing. The model form only provides for a post facto withdrawal option, which can be invoked after the ID has been created and loaded with sensitive student information.
APAAR being a nascent scheme introduced in 2023, what was officially styled as a voluntary choice has metamorphosed to a de facto prerequisite for board exams, raising serious privacy implications for students.
Voluntary on Paper, Mandatory in Practice: The APAAR ID Impasse
APAAR ID serves as a lifelong repository of academic information, tracking academic records, grades, disciplinary records, behavioural profiling and even analytical reports of learning disorders of students. It is prone to misuse as a tool for perennial surveillance and tracking of digital footprints even after graduation and has far-reaching implications on a child's privacy.
The Orissa High Court, in Rohit Anand Das v. State of Odisha, 2025 SCC OnLine Ori 4535 has intervened to check whether the consent mechanism prescribed under the APAAR Scheme constituted valid, informed and meaningful consent. The petitioner was aggrieved by the school authorities' insistence on signing the model consent form for generation of APAAR ID. The Petitioner asserted that the model consent form did not provide the right to opt out of the requirement to submit Aadhaar details. The new mandate is violative of the fundamental right to education under Article 21-A of the Constitution as it runs against the Supreme Court's mandate in Justice K.S. Puttaswamy (Retd.) v. Union of India [(2017) 10 SCC 1 that there can be no compulsory requirement of Aadhaar for school admissions. Besides, the consent form could infringe their right to privacy, as their personal information could be made available to other entities and that the mandate to sign the form is contrary to the stated position that the initiative is entirely voluntary in nature.
Observing that the APAAR ID scheme per se is not defective, the Court found that the model consent form does not reflect the voluntariness envisaged under the scheme.
Anchoring firmly in the foundational principles of Puttaswamy judgment, the court held that children's privacy calls for special protection and no form of coercive surveillance is acceptable. If the consent is a forced entry with an exit option held captive in administrative trapdoors, it would not amount to informed or voluntary consent.
The requirement to sign the model form at the outset and providing an option for refusal of consent post-signing is a structural entrapment that vitiates both the informed and voluntary nature of the consent, reducing it to a legal fiction, rather than an affirmative right.
If a parent cannot outrightly reject data tracking from day one, then it is not voluntary consent.
Consequently, the High Court directed administrative authorities to amend the consent form to include explicit opt-out checkboxes to safeguard voluntary parental choice.
Pan India Standard Consent
The Supreme Court took this one step further in Abhishek Baxi Vs Union of India, 2026 SCC Online SC 1391 requiring pan-India implementation of the amended model consent form with an opt-out clause as directed in Rohit Anand Das.
The petition in Abhishek Baxi was instituted under Article 32 of the Constitution, challenging the constitutional validity of the APAAR Scheme. The Petitioners, parents of CBSE students were aggrieved by the requirement of furnishing Aadhaar details as a precondition for APAAR registration. Further, they contended that CBSE has made the generation of the ID a mandatory precondition for the registration of students of Classes IX to XII for Board examinations.
While declining to intervene in the operation of the APAAR scheme, the court ruled that the prescribed consent form must expressly provide parents or guardians with the option to withhold consent, since such a safeguard is paramount to ensure meaningful and informed consent.
Redeeming the scheme from administrative whims, the court has anchored the entire student data cycle including collection, processing, storage, retention and sharing of personal data under the APAAR Scheme to the Digital Personal Data Protection Act, (DPDP) Act 2023.
Reiterating that student data needs to be firewalled, the court stated that sharing of data with third parties are banned unless explicitly authorised by statute. The Court unequivocally held that a child's right to education under Article 21A is sacrosanct and cannot be bartered away for administrative convenience, forcing them a lifetime digital compliance.
Dismantling the Digital Panopticon: Enforcing DPDP Compliance in Student Data Collection
A significant breakthrough is that the Abhishek Baxi judgment has strategically aligned the administrative overreach in APAAR scheme with India's emerging data privacy laws.
Section 9 of the DPDP Act, 2023 inter alia, stipulates that agencies must obtain proof of consent from parent or guardian before using personal data pertaining to a minor. The Courts have aligned the student data collection under APAAR to the Act by stipulating an amended model consent form with a clear opt out clause.
Furthermore, Section 9 (2) and (3) explicitly bars data fiduciaries from undertaking tracking, behavioural monitoring, or targeted profiling of children if it is likely to cause privacy violation. The current consent form provides an institutionalised, if not state-sponsored surveillance licence to third parties, as many schools are insisting it is a pre-requisite for academic admissions and registration for public examinations. This is particularly significant given the wide ramifications of the usage of student data by third parties such as EdTech companies and career guidance firms. Apart from quantitative metrics like report cards, assessment records and attendance logs, significant qualitative data including career preferences, behavioural tracking, individual student psychological profiles and student-teacher communications make their way to the stored data. This diverse data provides a perfect grazing ground for predatory third-party companies for targeted advertising, individual tracking and career gatekeeping, thereby leading to intimate privacy infringement of students. For instance, EdTech companies could deploy dynamic pricing models targeting students with learning disabilities, or restrict future employment opportunities based on childhood disciplinary records, eventually leading to a de facto monetisation of childhood.
Leaving students trapped within this digital panopticon is catastrophic.
Defining the Shelf Life of Student Data: The Need to Calibrate Section 12 With a Stipulated Timeline for Data Deletion
Despite the Supreme Court's mandate for an opt-out clause, the regulatory framework is conspicuously silent on time-bound deletion protocols for qualitative student profiles-rendering the statutory right to erasure an illusory textual promise to the parents.
For instance, Section 12 of the DPDP Act gives parents as Data principals the explicit right to correction, completion, and erasure of data once the specific purpose is fulfilled. However, the Act does not mention specific data purge timelines for deleting sensitive student data from centralised systems.
Although Section 12 of the DPDP Act provides a generic right to erasure of data upon withdrawal of consent, it leaves the timeline for execution open-ended to the whims of the data fiduciary. At this point, it would be worthwhile to compare the data erasure and retention frameworks under Article 17 of the European Union's General Data Protection Regulation (GDPR).
Article 17 provides a right to be forgotten without undue delay and stipulates a dedicated timeline of up to a maximum of 30 days for data erasure. Where the rights of students are at stake, this timeline is non-negotiable, making it clear that compliance cannot be a matter of administrative discretion.
On the contrary, in India, data fiduciaries can circumvent Section 12 by stating an open-ended "specified purposeā like continuous internal institutional evaluations under the pretext that APAAR is a lifelong unique identifier for tracking long-term academic metrics. To curb this, we need to introduce a mandatory purge timeline of 30 days akin to the GDPR for deleting non-scholastic data sets such as behavioural analytics and disciplinary metrics.
Additionally, all disciplinary records and psychological profiling including learning issues be subjected to an automated digital data sunsetting at the end of each academic cycle, preventing the creation of lifelong detrimental data under the APAAR ID scheme.
While the Supreme Court verdicts in Rohit Anand Das and Abhishek Baxi give a constitutional lifeline to the sacrosanct privacy rights of students, robust statutory interventions are imperative to bridge lingering structural gaps and make enforcement timelines watertight.
Author is an Advocate practicing at High Court of Kerala. Views are personal.