Skip to main content
DPDPA 2023 Aligned

DPDPA 2023-Aligned LMS for Indian Institutions

India-resident data on AWS Mumbai, granular consent capture, data-principal-rights workflows, written data-fiduciary obligations, and breach-response playbooks — built around the Digital Personal Data Protection Act 2023.

TL;DR

Quick answers

Is DeepTech DPDPA-compliant?
DPDPA 2023 does not include a formal product-certification scheme. DeepTech publishes its DPDPA-alignment posture, contractual data-processor commitments, and supporting technical controls. The institution remains the data fiduciary and performs its own assessment.
Where is learner data stored?
Default Indian deployments run on AWS Mumbai (ap-south-1) with multi-AZ replication, AES-256 at rest, and TLS 1.2+ in transit. The institution authorises any cross-border transfer.
How are data-principal rights served?
Learners raise access, correction, completion, erasure, nomination, and grievance requests inside the LMS; the institutional admin acts within DPDPA-aligned timelines, with auditable evidence.
Are children's accounts supported?
Yes, with verifiable parental-consent capture. Behavioural tracking, profiling, and targeted advertising aimed at children are restricted, in line with DPDPA expectations.
What DPDPA alignment looks like

Six pillars of privacy-readiness

India-resident data by default

Default Indian deployments run on AWS Mumbai (ap-south-1) with multi-AZ replication, AES-256 at rest, and TLS 1.2+ in transit. The institution retains learner-data ownership; cross-border transfer is only allowed when the institution explicitly authorises it.

Granular consent capture

Each purpose for which learner personal data is processed (course delivery, assessment, proctoring, marketing, third-party integrations) is captured with a separate, revocable consent record. Consent receipts are timestamped and exportable.

Data-principal rights workflows

Access, correction, completion, erasure, nomination, and grievance workflows are built in. Learners (the data principal) raise a request inside the LMS; the institutional admin (data fiduciary) reviews and acts within the DPDPA-aligned timelines.

Data fiduciary obligations

The institution is the data fiduciary; DeepTech is the data processor under a written agreement. Processing purposes, retention periods, breach-notification flows, and grievance officer contact are documented in the standard institutional agreement.

Children's data safeguards

DPDPA 2023 requires verifiable parental consent for processing personal data of children (under 18). Where the institution authorises children's accounts, the LMS supports verifiable parental-consent capture and restricts processing accordingly.

Audit, breach response, and DPIA support

Access logs, admin-action audit trail, automated weekly back-ups, and a documented breach-notification playbook. Significant Data Fiduciary obligations (DPO appointment, DPIA, independent data audit) are supported where the institution is so classified.

Frequently asked questions

DPDPA 2023 FAQs

Is DeepTech officially certified for DPDPA 2023?+

DPDPA 2023 does not include a formal product-certification scheme. DeepTech publishes its DPDPA-alignment posture, contractual data-processor commitments, and supporting technical controls. Institutions perform their own data-protection impact assessment as part of onboarding.

Who is the data fiduciary and who is the data processor?+

The institution that decides why and how learner personal data is processed is the data fiduciary. DeepTech operates the platform on the institution's behalf and is the data processor under a written agreement that mirrors DPDPA's data-processor obligations.

Where is learner data stored?+

Default Indian deployments run on AWS Mumbai (ap-south-1). Cross-border transfer is restricted to countries the Central Government has not negatively listed, and any such transfer is only enabled when the institution explicitly authorises it.

How are data-principal rights served?+

Learners raise access, correction, completion, erasure, nomination, or grievance requests inside the LMS. The institutional admin reviews and acts; the system enforces the DPDPA-aligned response timeline and produces an auditable trail.

How are children's accounts handled?+

Where the institution authorises children's accounts (under 18 in India), verifiable parental-consent capture is required. The system restricts behavioural tracking, profiling, and targeted advertising aimed at children, in line with DPDPA expectations.

Is a DPIA required before onboarding?+

DPDPA expects a Data Protection Impact Assessment for high-risk processing. Higher-education and corporate L&D processing through DeepTech is typically not high-risk, but the institution should document its assessment. DeepTech provides the technical-control inventory needed to complete a DPIA.