The Digital Personal Data Protection Act 2023 (DPDPA) is now binding on Indian universities and the EdTech vendors they use. Most institutions still treat it as a checklist exercise. It isn't. DPDPA fundamentally reshapes consent, processing, breach notification, and the rights learners have over their data.
The five things every Indian university must do
- Appoint a Data Protection Officer (DPO) and publish the contact
- Map every learner data flow — source, processor, retention period
- Capture explicit consent at enrolment, with the ability to withdraw
- Implement Data Subject Request workflows (access, correction, erasure)
- Have a breach notification plan that can move within 72 hours
Your LMS vendor is a Data Processor
Sign a Data Processing Agreement with every EdTech vendor, including your LMS, proctoring, and lab providers. Ask for the sub-processor list, AWS region for data residency, and a CAIQ-style security questionnaire response. See DeepTech compliance for our approach.
Indian data should stay in India
Pick LMS hosting in AWS Mumbai (ap-south-1) as your default. Anything else creates avoidable cross-border transfer risk. See our security overview for encryption and access controls.