DPDPA 2023-Aligned LMS for Indian Institutions
India-resident data on AWS Mumbai, granular consent capture, data-principal-rights workflows, written data-fiduciary obligations, and breach-response playbooks — built around the Digital Personal Data Protection Act 2023.
Quick answers
- Is DeepTech DPDPA-compliant?
- DPDPA 2023 does not include a formal product-certification scheme. DeepTech publishes its DPDPA-alignment posture, contractual data-processor commitments, and supporting technical controls. The institution remains the data fiduciary and performs its own assessment.
- Where is learner data stored?
- Default Indian deployments run on AWS Mumbai (ap-south-1) with multi-AZ replication, AES-256 at rest, and TLS 1.2+ in transit. The institution authorises any cross-border transfer.
- How are data-principal rights served?
- Learners raise access, correction, completion, erasure, nomination, and grievance requests inside the LMS; the institutional admin acts within DPDPA-aligned timelines, with auditable evidence.
- Are children's accounts supported?
- Yes, with verifiable parental-consent capture. Behavioural tracking, profiling, and targeted advertising aimed at children are restricted, in line with DPDPA expectations.
Six pillars of privacy-readiness
India-resident data by default
Default Indian deployments run on AWS Mumbai (ap-south-1) with multi-AZ replication, AES-256 at rest, and TLS 1.2+ in transit. The institution retains learner-data ownership; cross-border transfer is only allowed when the institution explicitly authorises it.
Granular consent capture
Each purpose for which learner personal data is processed (course delivery, assessment, proctoring, marketing, third-party integrations) is captured with a separate, revocable consent record. Consent receipts are timestamped and exportable.
Data-principal rights workflows
Access, correction, completion, erasure, nomination, and grievance workflows are built in. Learners (the data principal) raise a request inside the LMS; the institutional admin (data fiduciary) reviews and acts within the DPDPA-aligned timelines.
Data fiduciary obligations
The institution is the data fiduciary; DeepTech is the data processor under a written agreement. Processing purposes, retention periods, breach-notification flows, and grievance officer contact are documented in the standard institutional agreement.
Children's data safeguards
DPDPA 2023 requires verifiable parental consent for processing personal data of children (under 18). Where the institution authorises children's accounts, the LMS supports verifiable parental-consent capture and restricts processing accordingly.
Audit, breach response, and DPIA support
Access logs, admin-action audit trail, automated weekly back-ups, and a documented breach-notification playbook. Significant Data Fiduciary obligations (DPO appointment, DPIA, independent data audit) are supported where the institution is so classified.
DPDPA 2023 FAQs
Is DeepTech officially certified for DPDPA 2023?+
DPDPA 2023 does not include a formal product-certification scheme. DeepTech publishes its DPDPA-alignment posture, contractual data-processor commitments, and supporting technical controls. Institutions perform their own data-protection impact assessment as part of onboarding.
Who is the data fiduciary and who is the data processor?+
The institution that decides why and how learner personal data is processed is the data fiduciary. DeepTech operates the platform on the institution's behalf and is the data processor under a written agreement that mirrors DPDPA's data-processor obligations.
Where is learner data stored?+
Default Indian deployments run on AWS Mumbai (ap-south-1). Cross-border transfer is restricted to countries the Central Government has not negatively listed, and any such transfer is only enabled when the institution explicitly authorises it.
How are data-principal rights served?+
Learners raise access, correction, completion, erasure, nomination, or grievance requests inside the LMS. The institutional admin reviews and acts; the system enforces the DPDPA-aligned response timeline and produces an auditable trail.
How are children's accounts handled?+
Where the institution authorises children's accounts (under 18 in India), verifiable parental-consent capture is required. The system restricts behavioural tracking, profiling, and targeted advertising aimed at children, in line with DPDPA expectations.
Is a DPIA required before onboarding?+
DPDPA expects a Data Protection Impact Assessment for high-risk processing. Higher-education and corporate L&D processing through DeepTech is typically not high-risk, but the institution should document its assessment. DeepTech provides the technical-control inventory needed to complete a DPIA.
Related solution pages
Security Posture →
AWS Mumbai, AES-256, TLS 1.2+, multi-AZ replication, automated back-ups.
Compliance →
DPDPA, ISO 27001 controls, learner-data ownership.
UGC-Compliant LMS →
Online-degree framework alignment.
Privacy Policy →
Our published privacy and data-handling commitments.
SAML SSO →
Let IT own identity; we don't see passwords.
Contact / DPO →
Reach our grievance officer / DPO for privacy queries.
From the DeepTech blog
Practical guides, comparisons, and playbooks for university and training-institute teams.
How to Choose an LMS for Universities in 2026: A Decision Framework
A practical decision framework for choosing a university LMS in 2026 — covering AI features, multilingual delivery, proctoring, data residency, and accreditation reporting.
9 min read →White-Label LMS vs Open Source LMS: A 2026 Buyer's Guide
When to pick a white-label hosted LMS vs an open-source LMS like Moodle — TCO, control, AI features, and the engineering team you actually need.
8 min read →Real Cyber Labs vs. Simulations: Why Hands-On Environments Win
Simulated security exercises feel safe, but they don't build real skills. Here's why practising in genuine, isolated cyber labs makes you job-ready — and how DeepTech delivers them in your browser.
9 min read →