Mission Safe Schools (“Mission Safe Schools”, “Mission”, “we”, “us” or “our”) is an initiative of the National Council for School Safety (NCSS).
We recognise that privacy, responsible data governance and child protection are fundamental to safe schools. This Privacy Policy explains how we collect, process, use, disclose, retain and protect personal data in connection with the Mission Safe Schools website, programmes, assessments, events, publications, Founding Cohort, National School Safety Benchmark (NSSB), National School Safety Index and related activities.
This Policy is intended to operate in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), to the extent applicable and in force from time to time, and other applicable legal and regulatory requirements.
The entity responsible for determining the purpose and means of processing personal data under this Policy is:
National Council for School Safety (NCSS)
Holistic School Safety Entente of India Foundation (HSSEIF)
C2, Sector 1, Block C, Sector 1, Noida, Uttar Pradesh 201301
India
Privacy Contact / Grievance Contact:
Vrinda Sareen
National Council for School Safety
Email: missionsafeschools@ncss.org.in
Phone: +91 9354101121
For the purposes of applicable data-protection law, NCSS may act as a Data Fiduciary in relation to personal data for which it determines the purpose and means of processing.
Where NCSS processes personal data solely on documented instructions of another organisation, the applicable relationship and responsibilities may differ depending on the arrangement and applicable law.
This Policy applies to personal data processed in connection with:
The Mission Safe Schools website;
Website enquiries and contact forms;
Founding Cohort applications and participation;
Mission Safe Schools registrations;
National School Safety Benchmark (NSSB) processes;
School safety assessments and benchmarking;
National School Safety Index processes;
Events, conferences and conclaves;
Mission Safe Schools Magazine and other publications;
Research, impact and advocacy activities;
Donations and payment-related administration;
Communications with schools, institutions, professionals and other stakeholders;
Photographs, videos, testimonials and institutional stories;
Other Mission Safe Schools activities operated or administered by NCSS.
This Policy does not automatically govern third-party websites, applications or services linked from our website. Such services may have their own privacy policies.
For the purposes of this Policy, personal data generally means information about an identifiable individual.
Examples may include:
Name;
Email address;
Telephone or mobile number;
Designation;
Organisation or school affiliation;
Professional information;
Communication records;
Photographs or videos where an individual is identifiable;
IP address and certain device information;
Information contained in enquiries or submissions that identifies an individual;
Transaction-related information;
Any other information that is personal data under applicable law.
Institutional information relating solely to a school or organisation may not itself constitute personal data. However, information relating to identifiable principals, trustees, teachers, staff, students, parents or other individuals may constitute personal data.
We collect only information that is reasonably necessary for specified purposes.
4.1 Institutional Information
Depending on the programme, we may collect:
School/institution name;
Address and location;
Board or affiliation;
School category;
Institutional contact details;
Institutional policies and processes;
Governance information;
Safety infrastructure information;
Training and implementation records;
Assessment evidence;
Programme participation information;
Institutional impact information.
4.2 Professional and Contact Information
We may collect:
Name;
Designation;
Official email;
Phone/mobile number;
Organisation/school;
Professional role;
Communication preferences;
Information contained in correspondence or enquiries.
4.3 Assessment and Benchmarking Information
For participating institutions, NCSS may collect information necessary to conduct or facilitate:
NSSB assessment;
4P assessment;
Policy review;
Process review;
People and training review;
Practice and implementation review;
Institutional benchmarking;
Gap analysis;
Improvement planning;
National School Safety Index processes.
Assessment submissions should be limited to information necessary for the applicable assessment.
Schools should not voluntarily submit student-identifiable information, medical information, safeguarding case files, photographs of children or other sensitive personal information unless specifically requested through an approved process and appropriate safeguards have been established.
We may process personal data for the following specified purposes:
A. Programme Administration
To:
Register institutions;
Manage Founding Cohort participation;
Respond to enquiries;
Communicate programme information;
Administer events and activities;
Maintain institutional records.
B. Assessment and Benchmarking
To:
Conduct NSSB assessments;
Assess institutional readiness and practices;
Generate benchmarking and gap-analysis reports;
Support improvement planning;
Maintain assessment records;
Administer the National School Safety Index.
C. Research, Reporting and Impact
To:
Prepare anonymised or aggregated research;
Measure programme impact;
Develop school safety frameworks;
Prepare Mission reports;
Document institutional learning;
Develop future programmes and tools.
D. Publications and Communications
Where appropriate permissions and approvals exist, to:
Publish institutional stories;
Produce the Mission Safe Schools Magazine;
Publish event and programme material;
Produce case studies;
Communicate programme outcomes;
Promote school-safety awareness.
E. Donations and Financial Administration
To:
Process and reconcile donations;
Maintain financial records;
Issue acknowledgements or receipts where applicable;
Prevent fraud and misuse;
Meet accounting, tax and legal requirements.
F. Security and Legal Compliance
To:
Maintain website and system security;
Detect and prevent misuse;
Investigate suspected fraud or abuse;
Respond to legal requirements;
Comply with applicable law, regulatory requirements or lawful requests.
We will process personal data only where permitted under applicable law.
Depending on the circumstances, processing may be based on:
Consent;
Voluntary provision of information for a specified purpose where permitted under applicable law;
Performance of a requested service or activity;
Compliance with applicable legal obligations;
Legitimate organisational or other permitted purposes recognised under applicable law;
Other grounds permitted under the DPDP Act and applicable rules.
Where consent is required, we will seek consent in an appropriate manner and will not treat consent as having been given merely because a person has visited the website.
Where personal data is collected directly from an individual, we will endeavour to provide appropriate notice describing:
The personal data being collected;
The purpose for which it is processed;
How the individual may exercise applicable rights;
How consent may be withdrawn where consent is the basis of processing;
How a grievance may be raised;
Relevant contact details.
Where required under applicable law, such notice may be provided separately at the point of data collection.
Where processing is based on consent:
Consent will be sought for specified purposes;
Consent will be presented in a clear and understandable manner;
Consent will not be bundled with unrelated purposes where prohibited or inappropriate;
Withdrawal of consent will be made reasonably accessible;
Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
If withdrawal of consent means that NCSS can no longer provide a particular service, assessment, publication or programme activity, we will communicate the relevant consequence.
9.1 Our Commitment
Mission Safe Schools places the highest importance on the privacy, dignity and safety of children.
For the purposes of applicable Indian data-protection law, a child is an individual who has not completed eighteen years of age.
NCSS will adopt heightened safeguards for children's personal data and will comply with applicable requirements relating to children's data.
9.2 Collection of Student Information
The general Mission Safe Schools website is not intended to collect personal information directly from children.
Schools, institutions, partners and other organisations must not provide NCSS with personally identifiable student information unless:
the information is genuinely necessary for a defined programme purpose;
the disclosure is legally permissible;
the required parental/guardian consent or other lawful basis has been obtained, where applicable;
the institution has complied with its own legal and safeguarding obligations; and
the information is transferred through an approved and secure mechanism.
9.3 Photographs and Videos of Children
Photographs and videos in which children are identifiable will be treated with particular care.
Before using identifiable child photographs, videos, testimonials or similar material for public-facing purposes, NCSS will require appropriate permissions and safeguards consistent with applicable law and its child-protection protocols.
Where appropriate, NCSS may use:
Anonymisation;
Blurring;
De-identification;
Group images where individuals are not readily identifiable;
Institutional rather than individual references.
9.4 Child Safety and Safeguarding Information
Schools must not submit identifiable safeguarding case records, allegations, medical information, counselling records or other sensitive student information through general website forms.
Where such information is genuinely required for a specific safeguarding or assessment purpose, NCSS will use a separate controlled process and applicable safeguarding/data-protection protocol.
Mission Safe Schools may document the work undertaken by participating institutions.
Institutional stories may be used for:
Mission Safe Schools Magazine;
Mission reports;
Research and impact documentation;
NCSS publications;
Conclave materials;
Website content;
Social media;
Awareness campaigns;
Case studies;
National advocacy and policy discussions.
Where an institutional story identifies a school or individual, NCSS will obtain appropriate institutional permission and/or individual consent where required.
Schools should clearly identify any information provided to NCSS that is confidential, commercially sensitive, legally privileged or otherwise restricted from publication.
NCSS will not knowingly publish confidential student safeguarding records or personally identifiable child case information as part of a public institutional story.
Mission Safe Schools may prepare national-level reports, recommendations, research and impact documentation.
Such materials may be intended for presentation or submission to relevant stakeholders, including:
Ministry of Education (MoE);
Prime Minister’s Office (PMO);
National Commission for Protection of Child Rights (NCPCR);
Ministry of Women and Child Development (MWCD);
Other government departments, statutory bodies, regulators or institutional stakeholders, where relevant.
Where practicable and appropriate, reports will prioritise:
Aggregated data;
Anonymised information;
Institutional-level information;
De-identified case studies.
Personal data will be shared only where necessary, legally permissible and subject to appropriate safeguards.
Participation in Mission Safe Schools does not constitute an assurance that any government authority will adopt, endorse or act upon a particular recommendation or report.
Where institutional information is used for the National School Safety Index, NCSS may process relevant institutional and assessment information for:
Benchmarking;
Analysis;
Research;
Reporting;
Impact measurement;
Public or restricted reporting, depending on the applicable Index methodology.
NCSS will communicate the relevant publication and visibility framework to participating institutions.
Personal data relating to identifiable individuals will not be included in public Index outputs unless there is an appropriate legal basis and, where required, consent.
NCSS may share personal data where reasonably necessary and legally permitted with:
13.1 Service Providers
Technology, hosting, communications, analytics, event management, assessment, payment and other service providers that support Mission activities.
13.2 Professional Advisers
Legal advisers, auditors, accountants, consultants and other professional advisers where necessary.
13.3 Government and Regulatory Authorities
Where required by law, lawful direction, regulatory requirement, court order or other legally recognised authority.
13.4 Programme and Research Partners
Where necessary for an approved Mission activity and subject to appropriate contractual, confidentiality and data-protection safeguards.
13.5 Payment Service Providers
Payment transactions may be processed through third-party providers such as Razorpay.
NCSS does not sell personal data.
Where third parties process personal data on behalf of NCSS, NCSS will seek to implement appropriate contractual and operational safeguards proportionate to the nature and sensitivity of the data.
Such safeguards may address:
Purpose limitation;
Confidentiality;
Security;
Access control;
Data retention;
Deletion or return of data;
Incident reporting;
Restrictions on further use.
Where required by applicable law, NCSS will maintain appropriate records and arrangements relating to such processing.
Mission Safe Schools may use Razorpay or another authorised payment service provider to process donations.
When a donor makes a payment:
Payment credentials may be processed directly by the payment service provider;
NCSS may receive transaction-related information required to administer and reconcile the donation;
Such information may include donor/institution name, transaction reference, amount, date, status and other information made available by the payment provider;
NCSS does not intentionally store complete card numbers, CVV information, banking passwords, PINs or payment authentication credentials on its own systems.
Payment processing is also subject to the payment provider’s applicable terms and privacy practices.
Donors should review the relevant payment provider's privacy documentation before completing a transaction.
The website may use cookies and similar technologies for:
Essential website functionality;
Security;
Session management;
Analytics;
Performance monitoring;
Improving user experience.
Where consent is required for a particular category of cookie or technology, appropriate consent mechanisms may be used.
Users may control cookies through browser settings, although disabling certain cookies may affect website functionality.
We may use analytics tools to understand:
Website traffic;
Page usage;
General visitor behaviour;
Technical performance;
Website effectiveness.
Where third-party analytics providers are used, the applicable provider may process technical information subject to its own terms and privacy practices.
Where reasonably possible, analytics will be configured to minimise unnecessary collection of identifiable information.
NCSS will implement reasonable security safeguards appropriate to the nature and volume of personal data processed and the risks associated with the processing.
Depending on the system and processing activity, safeguards may include:
Access controls;
Role-based permissions;
Authentication;
Secure transmission;
Encryption or equivalent protections where appropriate;
Secure hosting;
Logging and monitoring;
Vendor controls;
Backup and recovery measures;
Confidentiality obligations;
Periodic review of security practices.
Access to personal data will be limited to authorised persons who require access for legitimate organisational purposes.
No internet transmission or electronic storage system can be guaranteed to be completely secure.
NCSS will maintain reasonable processes for identifying, assessing, containing, responding to and documenting personal-data security incidents.
Where a personal data breach occurs, NCSS will take steps required under applicable law, including notification to relevant authorities and affected Data Principals where required.
NCSS may also take measures such as:
Containing the incident;
Securing affected systems;
Investigating the cause;
Assessing the categories of data affected;
Taking remedial measures;
Preventing recurrence.
NCSS will retain personal data only for as long as reasonably necessary for:
The purpose for which it was collected;
Programme administration;
Assessment and benchmarking;
Financial and accounting records;
Legal and regulatory obligations;
Dispute resolution;
Audit requirements;
Legitimate organisational requirements.
Retention periods may differ depending on the category of data.
Where personal data is no longer required and there is no legal or legitimate reason to retain it, NCSS will take reasonable steps to delete, anonymise or otherwise dispose of it securely.
Specific retention schedules may be established for different categories of data.
Subject to applicable law and the provisions in force at the relevant time, individuals may have rights including:
The right to obtain information about processing of their personal data;
The right to correction of inaccurate or incomplete personal data;
The right to erasure where applicable;
The right to withdraw consent where processing is based on consent;
The right to raise a grievance;
The right to nominate another individual to exercise rights in accordance with applicable law;
Other rights available under applicable law.
Requests should be directed to:
Vrinda Sareen
Privacy / Grievance Contact
National Council for School Safety
Email: missionsafeschools@ncss.org.in
NCSS may require reasonable information to verify the identity and authority of a requester before processing a request.
Where personal data relating to a child is processed, a parent or lawful guardian may exercise applicable rights in accordance with the DPDP Act and applicable rules.
NCSS may require appropriate verification of:
Identity;
Parental or guardian status;
Authority to make the request.
Requests relating to child data will be handled with heightened care and in accordance with applicable child-protection requirements.
Where processing is based on consent, a Data Principal may withdraw consent through the mechanism provided by NCSS.
Withdrawal of consent:
Will not affect the legality of processing carried out before withdrawal;
May affect NCSS's ability to continue providing a particular service or activity where the relevant data is necessary for that purpose;
May not require deletion where NCSS is legally required or otherwise lawfully permitted to retain the data.
Where possible, NCSS will explain the consequences of withdrawal before or at the time the withdrawal is processed.
Any person who believes that their personal data has been processed inappropriately may contact:
Grievance / Privacy Contact:
Vrinda Sareen
National Council for School Safety
Email: missionsafeschools@ncss.org.in
The complaint should, where possible, include:
Name of the complainant;
Contact details;
Nature of the concern;
Relevant dates;
Applicable communication or transaction reference;
Supporting information.
NCSS will review and address grievances in accordance with applicable law and its internal grievance process.
Where a person remains dissatisfied, they may have recourse to the applicable statutory mechanism, including the Data Protection Board of India, where available and applicable.
Where personal data is processed or stored outside India through a third-party service provider, NCSS will implement such processing in accordance with applicable Indian law and any restrictions, directions or requirements applicable to cross-border processing.
NCSS will take reasonable steps to ensure that service providers handling personal data maintain appropriate safeguards.
The Mission Safe Schools website may contain links to third-party websites, platforms or services.
Examples may include:
Payment platforms;
Social media platforms;
Partner websites;
Registration platforms;
Event platforms;
Government websites.
NCSS is not responsible for the privacy practices, security or content of third-party websites.
Users should review the privacy policies of third-party services before providing personal information.
NCSS may send programme-related communications to participating institutions and individuals, including:
Programme updates;
Event information;
Assessment communications;
Mission updates;
Publications;
Relevant school-safety resources.
Where communications constitute direct marketing and consent is required, NCSS will obtain and manage consent in accordance with applicable law.
Recipients may opt out of non-essential promotional communications through the mechanism provided in the relevant communication.
Essential programme, transaction, assessment or legal communications may continue where necessary.
Schools participating in Mission Safe Schools may provide information relating to their internal systems, policies, processes and practices.
NCSS will treat information identified as confidential in accordance with applicable agreements and internal controls.
However, information may be disclosed where:
Required by law;
Required by a lawful authority;
Necessary to protect rights, safety or security;
Required to administer the Mission;
The institution has authorised disclosure;
The information is already lawfully public;
Disclosure is otherwise permitted under applicable law.
Schools should not submit information that they are legally prohibited from disclosing.
NCSS does not sell personal data to third parties.
Personal data may be shared with service providers or other parties only where reasonably necessary for specified purposes, legally permitted, appropriately authorised or required by law.
NCSS may update this Policy from time to time to reflect:
Changes in applicable law;
Changes in the DPDP framework;
Changes in Mission Safe Schools activities;
Changes in technology;
Changes in data-processing practices;
Security or operational requirements.
The updated Policy will be published on this website with a revised “Last Updated” date.
Where a material change requires additional notice or consent under applicable law, NCSS will take appropriate steps to provide it.
This Policy shall be governed by the laws of India.
Nothing in this Policy limits any mandatory rights or remedies available to an individual under applicable law.
Any dispute arising in relation to this Policy shall be subject to the jurisdiction and dispute-resolution mechanisms applicable under Indian law.
For questions relating to privacy, personal data, consent, data requests or grievances:
Vrinda Sareen
National Council for School Safety (NCSS)
Email: missionsafeschools@ncss.org.in
Phone: +91 9354101121
Address: C2, Sector 1, Block C, Sector 1, Noida, Uttar Pradesh 201301, India
Schools and institutions participating in Mission Safe Schools are responsible for ensuring that information submitted to NCSS is:
Accurate and relevant;
Lawfully collected;
Necessary for the stated purpose;
Shared through approved channels;
Accompanied by required permissions or consents;
Free from unnecessary student-identifiable information;
Handled in accordance with applicable child-protection and data-protection requirements.
Do not upload student case files, medical records, counselling records, identifiable safeguarding complaints, Aadhaar numbers, financial credentials or other sensitive personal information through general Mission Safe Schools forms unless specifically requested through an approved and secure process.
National Council for School Safety (NCSS)
Mission Safe Schools
Policy Version: 1.0
Effective Date: 31 August 2026
Next Review: On or before 31 August 2027, or earlier where required by law or material changes in processing.