Compliance at DeepTech
Global data-protection laws, US education law, accessibility standards, and Indian regulatory alignment — under one roof.
Data-protection laws we align with
GDPR (EU 2016/679)
Data minimisation, lawful basis, DPA Article 28 processor terms, sub-processor notification, 72-hour breach reporting, DSR workflows.
DPDPA 2023
Digital Personal Data Protection Act 2023 — consent management, data fiduciary obligations, learner rights, breach notification to DPB, DPO appointed.
Federal Decree-Law 45/2021 (UAE PDPL)
Personal data of UAE residents handled per UAE Personal Data Protection Law. AWS UAE region available for residency.
KSA PDPL (2021)
Saudi Personal Data Protection Law alignment with SDAIA guidance. KSA data residency in AWS Bahrain region.
POPIA (4/2013)
Protection of Personal Information Act — Information Officer designated, processing register maintained, lawful processing per s.11. AWS Cape Town residency.
NDPR (2019)
Nigeria Data Protection Regulation — annual NDPR audit, DPCO engagement, lawful basis, learner rights.
PDPA (SG, MY, TH) + Indonesia UU PDP 2022
Consent management, DPO contact published, data portability, and 72-hour breach notification across ASEAN PDPA regimes.
FERPA (20 U.S.C. § 1232g)
When acting as a school official with a legitimate educational interest, DeepTech maintains FERPA-aligned controls on student records.
COPPA (15 U.S.C. § 6501)
School-consent model for K-12 deployments. No behavioural advertising. Parental consent flows available.
Curriculum frameworks & WCAG
AICTE Model Curriculum alignment
Cybersecurity, AI / ML, and data-science programmes mapped to AICTE model curriculum credits and outcomes.
UGC + NEP 2020
Credit framework, academic bank of credits (ABC), and multi-disciplinary delivery in line with NEP 2020 and UGC online-learning regulations.
WCAG 2.1 AA accessibility
Learner portal and course player tested against WCAG 2.1 AA — keyboard navigation, screen reader (NVDA + JAWS + VoiceOver), captions, transcripts, colour contrast.
Section 508 / ADA-ready
Accessibility features map to Section 508 (US) and ADA Title III online-services guidance.
Available under NDA on request
Data Processing Agreement (DPA)
Standard contractual clauses, sub-processor list, and processor obligations per GDPR Article 28 — available on request.
Standard Contractual Clauses (SCCs)
EU 2021/914 SCCs for international transfers, plus UK IDTA for UK customers.
Sub-processor list
Public list of sub-processors and their roles. Email notification before changes to material sub-processors.
CAIQ / SIG-Lite questionnaire
Pre-completed Cloud Security Alliance CAIQ and Shared Assessments SIG-Lite available under NDA.
Penetration test summary
Annual third-party pentest summary letter available to prospects under NDA.
Insurance certificates
Cyber liability and professional indemnity certificates available on request.
Compliance questions, answered
Are you GDPR compliant?
Yes. DeepTech acts as a data processor for institution customers and as a data controller for direct learners. We sign DPAs with Article 28 processor terms, maintain a sub-processor list, support DSR workflows, and notify breaches within 72 hours.
Are you DPDPA (India) ready?
Yes. We implement consent-management, lawful processing, data minimisation, learner rights workflows, and breach notification per the Digital Personal Data Protection Act 2023. DPO contact published.
Do you support FERPA-protected student records?
Yes. When acting as a school official with a legitimate educational interest, DeepTech maintains FERPA-aligned controls on directory and educational records. FERPA addendum available.
Is the platform accessible (WCAG)?
Yes. Tested against WCAG 2.1 Level AA — keyboard navigation, screen reader compatibility (NVDA, JAWS, VoiceOver), captions, transcripts, colour contrast, and focus management. VPAT available under NDA.
Do you sign DPAs and BAAs?
DPAs: yes, standard. BAAs (HIPAA): on Enterprise plans only — talk to us if you need PHI handling.
Can I get a sub-processor list?
Yes — published publicly and notified before material changes. Email compliance@lmseducation.in for the current list.
Are you SOC 2 / ISO 27001 certified?
ISO 27001 certification is in progress (audit in 2026). SOC 2 Type II is on the roadmap. In the meantime, we provide a completed CAIQ + SIG-Lite, third-party pentest summary, and a security overview under NDA.
Need a compliance pack?
DPA, SCCs, sub-processor list, CAIQ, SIG-Lite, and pentest summary — available under NDA.