India’s Supreme Court tightens rules on children’s academic data
15 September 2026
The Supreme Court of India, in Abhishek Baxi & Ors. v. Union of India & Ors., W.P. (C) No. 832/2026, issued an order on July 20, 2026, directing authorities implementing the Automated Permanent Academic Account Registry (APAAR) to provide parents and guardians with an explicit option to refuse or withhold consent for the scheme.
The court also clarified that personal information collected through APAAR must be handled in accordance with the Digital Personal Data Protection Act, 2023 and restricted the sharing of such data with private entities or third parties except where permitted by law.
The parents, however, argued that although APAAR was described as voluntary, the system was becoming compulsory in practice. They raised concerns that schools were requiring APAAR registration, that the prescribed consent mechanism did not provide a meaningful way to refuse consent at the outset, and that creating a lifelong repository of children’s academic and personal information could enable long-term tracking, profiling and use of that information beyond legitimate educational purposes.
Importantly, the Supreme Court did not strike down APAAR or hold the scheme itself unconstitutional. Instead, it imposed important safeguards around how the scheme must operate.
- Consent must be genuinely voluntary. The court adopted the approach that the APAAR model consent mechanism must expressly permit parents or guardians to withhold or refuse consent. The court described such a safeguard as essential to making consent meaningful and informed.
- APAAR is subject to the Digital Personal Data Protection (DPDP) Act. The court made an especially important clarification: the fact that APAAR operates through an administrative scheme rather than a statutory mandate does not exempt the Government or implementing authorities from India’s data-protection framework. Collection, processing, storage, retention, sharing and use of APAAR personal data must comply with the DPDP Act, 2023 and the obligations applicable to data fiduciaries.
- The court imposed a strong purpose limitation on student data. Personal information collected through APAAR cannot be disclosed or made available to private entities or third parties except in accordance with law and strictly for authorized purposes. Sharing information outside the scope of APAAR or for extraneous purposes is impermissible.
Ankita Sabharwal | a partner @ Chadha & Chadha, Bengaluru
According to Ankita Sabharwal, a partner at Chadha & Chadha in Bengaluru, that distinction is important. “This is less a judgment against digital academic infrastructure and more a judicial warning that administrative convenience cannot dilute privacy and data-protection obligations, particularly where children’s lifelong data is concerned,” she said.
“That makes the business takeaway quite powerful: APAAR may establish the infrastructure through which academic information moves, but it does not give the State or a private participant in that ecosystem an unrestricted right to use that information.”
Implications under the DPDP Act
For Sabharwal, the immediate consequence is that consent can no longer be treated as an administrative formality. “The DPDP framework requires consent, where relied upon, to be free, specific, informed, unconditional and unambiguous, and it gives the individual a right to withdraw consent. For children’s data, the act separately requires verifiable parental consent, subject to prescribed exemptions. The court’s insistence on an express refusal or opt-out mechanism therefore reinforces an important distinction: participation in an educational ecosystem does not automatically amount to consent to every downstream use of the student’s data.”
“That becomes particularly important because APAAR is not merely an identification number,” she added. “The government describes it as a lifelong academic identity capable of linking marksheets, grades, degrees, diplomas, certificates, credits and co-curricular achievements. APAAR generation also involves identifiers including the student’s PEN and Aadhaar-related information.”
She said that for institutions and technology providers, this pushes compliance toward purpose limitation, data minimization, access control and demonstrable consent governance. An institution should be able to answer not simply “Do we have the data?” but “Why are we processing this particular field, under what authority, for how long, and who receives it?” The current APAAR privacy policy itself describes consent in terms of being free, specific, informed, unconditional and unambiguous.
“The IP point needs some precision,” she said. “The judgment does not, by itself, transfer or redefine copyright, patent or other IP ownership. Personal-data rights and IP rights remain distinct legal regimes. A student’s academic record being available through APAAR does not automatically make the underlying material public-domain material or confer an IP licence on a recipient.”
“The more interesting future issue is the intersection of data access and content exploitation. Suppose an ed-tech, recruiter, AI company, analytics provider or credentialing business obtains access to APAAR-linked information. Even where access to particular personal data is lawful, that does not necessarily authorize the recipient to reproduce, commercialize, train models on, create derivative datasets from or otherwise exploit underlying protected content. Lawful access is not synonymous with lawful reuse.”
“That distinction could become especially relevant to dissertations, research papers, portfolios, creative works, software projects and other student-generated material if such material is ever linked to interoperable academic-record systems. Businesses should therefore run two separate legal analyses: (a) are we permitted to process the personal data? and (b) do we possess the necessary IP rights or licences for what we intend to do with the underlying content?”
What to look out for
Sabharwal said that for businesses, she would treat the decision as establishing a “no secondary-use by assumption” principle. If an ed-tech company, university vendor, recruiter, verification service, AI provider or analytics company receives APAAR-linked information, it should not assume that access for one function permits reuse for another. The Supreme Court specifically said information collected through APAAR cannot be made available to private entities or third parties except according to law and for authorized purposes; extraneous sharing is impermissible.
For individuals and parents, the most important development is simpler: “consent” now has to mean that saying no is genuinely possible.
“I would not read this merely as an ‘APAAR judgment’,” she said. “It is potentially an early judicial marker for India’s emerging digital public infrastructure with DPDP relationship. The court is effectively signalling that the State may build interoperable digital systems, but interoperability cannot become a legal shortcut around informational autonomy. Scale, efficiency and convenience do not extinguish purpose limitation, meaningful choice or restrictions on downstream sharing.”
“That principle matters well beyond education,” she noted. “As identity, credentials, payments, health, employment and AI systems become increasingly interoperable, the strategically important asset will not simply be access to data, but lawful authority to use that data for a particular purpose.”
- Excel V. Dyquiangco