Supreme Court mandates opt-out clause in APAAR consent form, applies DPDP Act 2023

In a landmark ruling on student data privacy, the Supreme Court of India has directed pan-India implementation of an explicit opt-out clause in consent forms under the Automated Permanent Academic Account Registry (APAAR) Scheme, while firmly anchoring all data handling under the scheme to the Digital Personal Data Protection (DPDP) Act, 2023.

A three-judge bench comprising the Chief Justice, Justice Joymalya Bagchi, and Justice V. Mohana disposed of a writ petition filed under Article 32 of the Constitution by Abhishek Baxi and other parents of students enrolled in schools affiliated with the Central Board of Secondary Education (CBSE), who were represented by senior advocate Indira Jaising.

A Consent Form With No 'No'

The APAAR Scheme, introduced pursuant to the National Education Policy, 2020, envisages the creation of an Aadhaar-linked, lifelong digital academic identifier for every student. Designed to ensure seamless continuity of academic records, facilitate transfers across institutions and states, and enable academic credit mobility through the Academic Bank of Credits, the scheme maintains a consolidated digital repository of a student's personal and academic information — from school enrolment through their entire educational journey.

The petitioners contended that despite the scheme being officially styled as voluntary, the model consent form prescribed by the Ministry of Education since its October 2023 circular provided no option to decline participation. What compounded the concern was that CBSE circulars dated August 5 and August 27, 2025, made the generation of an APAAR ID a mandatory precondition for registration of students of Classes IX to XII for Board examinations commencing from the academic session 2026 onwards.

The cumulative effect of these measures, Jaising argued, rendered the purported requirement of parental consent illusory and compelled participation in what she described as a State-run surveillance mechanism in the education sector. The petition further alleged that schools were, in practice, threatening denial of admission, registration for board examinations, and access to other educational services if parents refused to furnish Aadhaar details. Some schools reportedly informed parents that their continued recognition, registration, or eligibility for State funding could be jeopardised if prescribed APAAR enrolment targets were not achieved.

Puttaswamy's Enduring Standard

The petitioners anchored their challenge in the foundational principles laid down by the nine-judge bench in Justice K.S. Puttaswamy (Retd.) v. Union of India [(2017) 10 SCC 1], which declared the right to privacy a fundamental right. They argued that the impugned measures failed to satisfy the constitutional requirements of legality, legitimate aim, necessity, and proportionality governing State action that infringes the fundamental right to privacy.

The Court was persuaded. Drawing on the High Court of Orissa's judgment in Rohit Anand Das v. State of Odisha , the bench directed that the consent form must expressly provide parents or guardians the option to withhold or refuse consent.

"We are of the considered view that such a safeguard is essential to ensure that the requirement of consent is meaningful and informed," the Court observed, directing that the Orissa High Court's directions in paragraph 19 of its judgment be given effect on a pan-India basis by the concerned authorities implementing the scheme.

A Statutory Safety Net, Not an Administrative Discretion

Addressing concerns about the possible misuse of personal information of those who voluntarily opt to enrol, the Court made a significant clarification: the absence of a statutory mandate for the scheme does not dilute data protection obligations.

"Merely because the collection of such information is undertaken pursuant to an administrative scheme and not under a statutory mandate does not absolve the authorities of their obligations in relation to the protection of personal data," the bench stated.

The Court firmly declared that any collection, processing, storage, retention, sharing, or use of personal information under the APAAR Scheme shall be strictly governed by the provisions of the DPDP Act, 2023, and the obligations cast upon data fiduciaries to ensure lawful, secure, and purpose-limited processing of personal data. It further held that personal information collected cannot be disclosed, shared, or made available to any private entity or third party except in accordance with law and strictly for purposes authorized under the enactment.

"Any sharing of such information beyond the scope of the Scheme or for extraneous purposes shall be impermissible," the Court declared.

Key Observations

  • "We are of the considered view that such a safeguard is essential to ensure that the requirement of consent is meaningful and informed."
  • "Merely because the collection of such information is undertaken pursuant to an administrative scheme and not under a statutory mandate does not absolve the authorities of their obligations in relation to the protection of personal data."
  • "Any collection, processing, storage, retention, sharing, or use of personal information under the APAAR Scheme shall, therefore, be strictly governed by the provisions of the Digital Personal Data Protection Act, 2023 ."
  • "Any sharing of such information beyond the scope of the Scheme or for extraneous purposes shall be impermissible."

A Checkpoint, Not the Final Destination

The judgment represents a significant milestone in India's student data governance. By mandating a genuine opt-out mechanism and applying the DPDP Act's child-specific protections — which require verifiable parental consent and prohibit behavioural tracking, monitoring, or targeted profiling of children — the Court has constrained what critics describe as a potential digital panopticon around students.

However, structural gaps remain. Section 12 of the DPDP Act provides parents the right to correction, completion, and erasure of data once the specified purpose is fulfilled, yet it leaves the timeline for execution open-ended. Experts have urged the introduction of time-bound data purge procedures comparable to the European Union's GDPR Article 17, which mandates deletion without undue delay within a maximum of 30 days, particularly for non-scholastic data sets such as behavioural analytics and disciplinary records.

The writ petition was disposed of with liberty granted to respondents to seek clarification if required, and all pending interlocutory applications were closed.