The Digital Personal Data Protection Act, 2023 — enacted in August 2023 — is India's primary data-protection statute. For an LMS operator and the institutions using it, the most relevant obligations are:
- Lawful basis — consent or one of the listed legitimate uses. For learners, this is typically free and informed consent at sign-up.
- Notice & purpose limitation — what data is collected, for what, and for how long.
- Data Principal rights — access, correction, erasure, grievance redressal.
- Reasonable security safeguards — encryption at rest and in transit, RBAC, audit logs, breach notification.
- Children's data — verifiable parental consent for learners under 18.
- Data Protection Officer (DPO) — required for Significant Data Fiduciaries; recommended for any institution at scale.
DeepTech is engineered with DPDPA in mind — consent capture per data field, learner-initiated access & erasure flows, DPO contact published in each tenant's privacy notice, breach playbook with 72-hour notification windows.