Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

India's Revised APAAR Consent Form Fixed the Opt-Out — and Kept a Tick-Box for Sending Children's Records to Recruiters

India's revised APAAR consent form adds the court-ordered opt-out, then offers a tick-box routing a child's record to recruitment agencies.

D
DPDPBot Research Team
🕐 12 min read

#India's Revised APAAR Consent Form Fixed the Opt-Out — and Kept a Tick-Box for Sending Children's Records to Recruiters

The APAAR consent form now in circulation to Indian schools does what two courts told the government to do: it gives parents an explicit box marked "I DO NOT CONSENT (OPT-OUT)". Immediately above that box sits an optional tick-box offering to route the child's academic data to "Talent/Skill Identification Agencies (Recruitment)" — six weeks after the Supreme Court held that data collected under APAAR "cannot be disclosed, shared, or otherwise made available to any private entity or third party except in accordance with law."

That contradiction is the story, and it is worth being precise about, because APAAR is not a pilot. As of 2 July 2026, the Ministry of Education's own PIB backgrounder records 26.35 crore verified APAAR IDs generated across India, of which 16.62 crore sit in school education — which is to say, overwhelmingly, in the hands of people the DPDP Act 2023 defines as children.

The document circulating to schools is headed "Annexure-1 — PARENTAL CONSENT / REFUSAL FORM FOR APAAR ID GENERATION". Its structure is a genuine improvement on what came before. Under "PLEASE SELECT ONE OPTION BELOW (MANDATORY)", a parent picks:

  • Option A: I CONSENT — sharing the ward's Aadhaar number or an alternate government-issued PIC with the Ministry of Education "for the sole purpose of creating an APAAR ID and opening a DigiLocker account."
  • Option B: I DO NOT CONSENT (OPT-OUT) — with the assurance that "refusing APAAR ID will not affect my ward's admission, promotion, or access to government benefits."

A school-use box at the foot records the outcome in UDISE+ as either "CONSENT GIVEN (Proceed to Generate ID)" or "CONSENT REFUSED (Mark as 'Denied' in System – Do Not Process)". A withdrawal clause names a Data Protection Officer contact — in the copy reviewed, apaarsupport@ciet.nic.in, the CIET–NCERT support address.

Nested inside Option A, though, is this:

Optional: Additional Consent for Third-Party Services (Tick if you agree): [ ] I also consent to my ward's academic data being used for direct benefit services like Scholarship Portals and value-added services such as Talent/Skill Identification Agencies (Recruitment).

One tick-box. Two materially different purposes. Zero named recipients. No retention period. No description of which fields travel. The clause was flagged in the last 48 hours by MediaNama, which raised the obvious unanswered question — which entities actually qualify as "Talent/Skill Identification Agencies (Recruitment)", and whether any student data has moved to them yet.

Note also where this form is not: the official portal at apaar.education.gov.in publishes no downloadable consent form at all. Parents encounter the notice only when a school hands it to them.

#What the courts actually ordered

Two orders sit behind the redraft, and they did different work.

The Orissa High Court decided Rohit Anand Das v. State of Odisha, W.P.(C) No. 8285 of 2025, on 12 December 2025. A school had written to parents seeking consent for APAAR ID generation, demanded Aadhaar details, and offered no way to say no. The Court held that a scheme professed to be voluntary, whose model consent form contains no refusal option, is mandatory in substance — and directed the authorities to amend the form to include an opt-out within two months. SCC Online's report frames it as an Article 21 informational-privacy holding.

The Supreme Court then took it national. In Abhishek Baxi v. Union of India, 2026 LiveLaw (SC) 719 (also reported as 2026 SCC OnLine SC 1391), a Bench of Chief Justice Surya Kant with Justices Joymalya Bagchi and V. Mohana directed that the Orissa directions apply pan-India, and added two things the High Court had not. Per LiveLaw's report of the 25 July 2026 order, the Court held that:

  1. any personal information collected under the APAAR scheme "cannot be disclosed, shared, or otherwise made available to any private entity or third party except in accordance with law"; and
  2. collection, processing, storage and retention must comply strictly with the DPDP Act 2023 and the fiduciary duties it imposes — regardless of whether APAAR is characterised as an administrative scheme or a statutory one.

The opt-out was the High Court's ask, and the form delivers it. The third-party bar is the Supreme Court's addition, and the form — drafted before that order — still contains the clause pointing the other way.

#Where the tick-box collides with the DPDP Act

Strip out the litigation and the clause has four independent problems under the DPDP Act 2023 and the DPDP Rules 2025, notified on 13 November 2025.

It is not specific. Section 6(1) requires consent to be free, specific, informed, unconditional and unambiguous, signifying agreement to processing "for the specified purpose." A single tick covering both a scholarship portal and a recruitment agency is bundled consent for two unrelated purposes. A parent who wants their child considered for a scholarship cannot decline the recruiter without declining the scholarship.

The notice is not itemised. Section 5 requires the notice to describe the personal data and the purpose of processing. Rule 3 of the DPDP Rules requires that notice to stand on its own, in clear and plain language, with an itemised description. "Academic data" naming no fields, no recipients and no retention period is a category, not an itemisation.

Purpose limitation runs the other way. Option A states the Aadhaar number is being shared "for the sole purpose of creating an APAAR ID and opening a DigiLocker account." An onward flow to recruitment intermediaries is not that purpose, and cannot be reconciled with it by a checkbox further down the same page.

The subjects are children. Section 9(1) requires verifiable parental consent before processing a child's personal data, with a child defined as anyone under 18 — Rule 10 sets out what "verifiable" has to mean in practice, including DigiLocker-backed verification of the parent and of the parent–child relationship. Section 9(2) separately bars processing "likely to cause any detrimental effect on the well-being of a child", and Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children. Handing a minor's verified academic record to a commercial talent-identification business is precisely the kind of processing those provisions were drafted against. The penalty limb for failures around children's data runs to ₹200 crore; the security-safeguards limb runs to ₹250 crore.

The APAAR scheme is not, incidentally, insulated from any of this by the Supreme Court's own reasoning. The Court explicitly declined to let the administrative-versus-statutory distinction carry weight.

#What the Fourth Schedule does — and does not — excuse

The most common defence heard in the education sector is that schools are exempt. That defence is real, and it is narrower than it is usually made to sound.

Rule 11 of the DPDP Rules, read with the Fourth Schedule, does exempt certain classes of data fiduciaries — including educational institutions, healthcare establishments, creches and child-transport services — from the Section 9(1) verifiable-consent requirement and the Section 9(3) tracking prohibition. But the exemption is conditional and purposive: an educational institution gets relief for processing tied to its educational activities and to the safety of enrolled children, and only to the extent necessary and proportionate to that purpose.

A recruitment agency is not an educational institution. Sending a child's record to one is not an educational activity, and it is not child safety. The Fourth Schedule does not reach it. Nor does the exemption touch Section 9(2), the notice and consent architecture in Sections 5 and 6, or the data-minimisation duty that survives exemption status regardless.

That reading is not theoretical. On 1 June 2026 the Central Consumer Protection Authority fined the ed-tech platform PhysicsWallah ₹5 lakh over a pre-ticked donation checkbox and a registration wall on "free courses" that collected phone number and email with no demonstrated functional necessity. Writing in LiveLaw on 27 August 2026, the analysis of that order made the same point about the limits of the Fourth Schedule — and about how little coordination exists between the consumer regulator that acted and the data-protection regulator that has not.

#The older form is still out there

There is a second document, and it is worse. A copy of the previous model form — "CONSENT BY FATHER/MOTHER/LEGAL GUARDIAN OF STUDENT FOR APAAR ID GENERATION" — remains hosted on a gov.in content delivery network from a March 2025 upload. It has no refusal option at all. It states that a student's personally identifiable information "may be made available to entities engaged in various educational activities such as the UDISE+ database, scholarships, maintenance of academic records, and other stakeholders like Educational Institutions and recruitment agencies" — and then, two paragraphs later, assures the parent that the information "shall be kept confidential and shall not be divulged to any third party except as may be required by law."

Both statements cannot be true. The form contradicts itself on its own page.

Its withdrawal clause has a separate defect: it tells the parent that on withdrawal "any personal data already processed shall remain unaffected." Under Section 6 of the DPDP Act a data principal may withdraw consent at any time and the fiduciary must cease processing; Section 8(7) requires erasure once consent is withdrawn or the purpose is no longer being served, unless retention is required by law. A blanket carve-out for everything already processed is not the statutory position.

An old document sitting on a government CDN is not necessarily the operative one. But schools, district officers and parents find forms by searching for them, and this one is findable.

#16.62 crore children, and no regulator to complain to

The scale figures in the PIB backgrounder are what make this more than a drafting quibble. APAAR is a 12-digit identifier linked to Aadhaar and reachable through DigiLocker. The Ministry publishes APIs so institutional platforms can verify a student's APAAR ID, and a "login with APAAR ID" single-sign-on module. Common Service Centres in villages act as on-ground registration points — the same VLE channel whose data-fiduciary status was itself contested last week. And the backgrounder advertises that students aged 13 to 30 can authenticate their APAAR ID for up to 10% off base airfares and 10kg of extra baggage, which is a commercial benefit flow already wired to a school ID.

An identifier with that reach, that many child subjects, and an interface designed to be consumed by third parties is exactly the architecture that makes purpose limitation load-bearing rather than decorative.

Which brings up the part with no comfortable answer. The Data Protection Board of India was established in law when the Rules were notified on 13 November 2025. As of the most recent reporting through August 2026 it has no appointed Chairperson and no appointed Members; MeitY invited applications on 6 May 2026 and no appointments have followed. A parent who reads this tick-box, objects, and wants to escalate has a statutory right of complaint and no one to make it to. The forum that acted against PhysicsWallah was the consumer regulator, not the privacy one.

Meanwhile the compliance clock keeps running: Rule 4 and the consent-manager registration framework commence on 13 November 2026, and the bulk of the substantive obligations — Rules 3 and 5 to 16 — on 13 May 2027.

#What education-sector data fiduciaries should do now

The APAAR form is the government's problem to fix. The pattern it exhibits is everybody's.

  • Unbundle every optional consent. If a form offers one tick covering two purposes with different recipients, it is not specific consent under Section 6(1), whatever the tick-box is labelled. Split them.
  • Name the recipient class, or drop the clause. "Third-party services" and "value-added services" are not itemised descriptions. If you cannot list who receives the data and for what, you cannot lawfully ask for the consent.
  • Audit forms already in the field. Superseded versions live on school websites, WhatsApp groups and government CDNs long after a redraft. Retire them explicitly; do not assume a new annexure displaces an old PDF.
  • Check your withdrawal language against Section 8(7). Clauses that immunise "data already processed" from withdrawal are common and wrong.
  • Do not lean on the Fourth Schedule beyond its terms. It exempts specified classes for specified purposes. Marketing, recruitment intermediation and onward commercial sharing are not among them.
  • Write down the necessity test. Data minimisation survives every exemption in the Rules. If you cannot articulate why a field is needed for the stated purpose, that is the finding an auditor will write up.

The consent architecture is the whole compliance surface for anyone processing children's data in India, and it is the piece most often inherited from a template drafted before the Rules existed. If you are rebuilding yours, our consent manager walks through granular purpose separation and withdrawal handling, and the resources library tracks the DPDP Rules commencement dates as they land.

APAAR's redraft got the hard, contested part right — parents can now refuse, and the refusal is recorded in UDISE+ as a denial rather than a gap. That is a real win, and it took a High Court and the Supreme Court to get it. The remaining defect is a single optional line offering a child's academic record to unnamed recruiters. It should be the easiest thing on the page to delete.


Sources: PIB Backgrounder, "Academic Bank of Credits and APAAR", 4 July 2026; LiveLaw on Abhishek Baxi v. Union of India; SCC Online on Rohit Anand Das v. State of Odisha; MediaNama on the APAAR consent form; LiveLaw on the CCPA's PhysicsWallah order; LiveLaw on the Data Protection Board's vacancy. Consent form text quoted from the Ministry of Education's "Annexure-1 Parental Consent / Refusal Form for APAAR ID Generation" and from the earlier model consent form hosted at cdnbbsr.s3waas.gov.in.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial