Skip to main content
Compliance & Trust

Compliance at DeepTech

Global data-protection laws, US education law, accessibility standards, and Indian regulatory alignment — under one roof.

Regulatory coverage

Data-protection laws we align with

Europe

GDPR (EU 2016/679)

Data minimisation, lawful basis, DPA Article 28 processor terms, sub-processor notification, 72-hour breach reporting, DSR workflows.

India

DPDPA 2023

Digital Personal Data Protection Act 2023 — consent management, data fiduciary obligations, learner rights, breach notification to DPB, DPO appointed.

UAE

Federal Decree-Law 45/2021 (UAE PDPL)

Personal data of UAE residents handled per UAE Personal Data Protection Law. AWS UAE region available for residency.

Saudi Arabia

KSA PDPL (2021)

Saudi Personal Data Protection Law alignment with SDAIA guidance. KSA data residency in AWS Bahrain region.

South Africa

POPIA (4/2013)

Protection of Personal Information Act — Information Officer designated, processing register maintained, lawful processing per s.11. AWS Cape Town residency.

Nigeria

NDPR (2019)

Nigeria Data Protection Regulation — annual NDPR audit, DPCO engagement, lawful basis, learner rights.

Singapore + ASEAN

PDPA (SG, MY, TH) + Indonesia UU PDP 2022

Consent management, DPO contact published, data portability, and 72-hour breach notification across ASEAN PDPA regimes.

USA — Education

FERPA (20 U.S.C. § 1232g)

When acting as a school official with a legitimate educational interest, DeepTech maintains FERPA-aligned controls on student records.

USA — Children

COPPA (15 U.S.C. § 6501)

School-consent model for K-12 deployments. No behavioural advertising. Parental consent flows available.

Education & accessibility

Curriculum frameworks & WCAG

AICTE Model Curriculum alignment

Cybersecurity, AI / ML, and data-science programmes mapped to AICTE model curriculum credits and outcomes.

UGC + NEP 2020

Credit framework, academic bank of credits (ABC), and multi-disciplinary delivery in line with NEP 2020 and UGC online-learning regulations.

WCAG 2.1 AA accessibility

Learner portal and course player tested against WCAG 2.1 AA — keyboard navigation, screen reader (NVDA + JAWS + VoiceOver), captions, transcripts, colour contrast.

Section 508 / ADA-ready

Accessibility features map to Section 508 (US) and ADA Title III online-services guidance.

Documents & artefacts

Available under NDA on request

Data Processing Agreement (DPA)

Standard contractual clauses, sub-processor list, and processor obligations per GDPR Article 28 — available on request.

Standard Contractual Clauses (SCCs)

EU 2021/914 SCCs for international transfers, plus UK IDTA for UK customers.

Sub-processor list

Public list of sub-processors and their roles. Email notification before changes to material sub-processors.

CAIQ / SIG-Lite questionnaire

Pre-completed Cloud Security Alliance CAIQ and Shared Assessments SIG-Lite available under NDA.

Penetration test summary

Annual third-party pentest summary letter available to prospects under NDA.

Insurance certificates

Cyber liability and professional indemnity certificates available on request.

FAQ

Compliance questions, answered

Are you GDPR compliant?

Yes. DeepTech acts as a data processor for institution customers and as a data controller for direct learners. We sign DPAs with Article 28 processor terms, maintain a sub-processor list, support DSR workflows, and notify breaches within 72 hours.

Are you DPDPA (India) ready?

Yes. We implement consent-management, lawful processing, data minimisation, learner rights workflows, and breach notification per the Digital Personal Data Protection Act 2023. DPO contact published.

Do you support FERPA-protected student records?

Yes. When acting as a school official with a legitimate educational interest, DeepTech maintains FERPA-aligned controls on directory and educational records. FERPA addendum available.

Is the platform accessible (WCAG)?

Yes. Tested against WCAG 2.1 Level AA — keyboard navigation, screen reader compatibility (NVDA, JAWS, VoiceOver), captions, transcripts, colour contrast, and focus management. VPAT available under NDA.

Do you sign DPAs and BAAs?

DPAs: yes, standard. BAAs (HIPAA): on Enterprise plans only — talk to us if you need PHI handling.

Can I get a sub-processor list?

Yes — published publicly and notified before material changes. Email compliance@lmseducation.in for the current list.

Are you SOC 2 / ISO 27001 certified?

ISO 27001 certification is in progress (audit in 2026). SOC 2 Type II is on the roadmap. In the meantime, we provide a completed CAIQ + SIG-Lite, third-party pentest summary, and a security overview under NDA.

Need a compliance pack?

DPA, SCCs, sub-processor list, CAIQ, SIG-Lite, and pentest summary — available under NDA.