DPDP-Compliant LMS in India: Residency, Consent & Vendor Rules

Updated:
August 17, 2026
Skills Caravan
Learning Experience Platform
LinkedIn
August 17, 2026
, updated  
August 17, 2026

This document is written for the person who signs the approval, not the person who wants the platform. If L&D has sent a shortlist and asked for security clearance, the useful question is not whether a vendor calls itself compliant. It is about which obligations under the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025, fall on your organisation, which you can discharge only with the vendor's cooperation, and what must be in the contract to make that cooperation enforceable. Most marketing pages for DPDP-compliant LMS India buyers can shortlist answers to none of the three.

The most common claim you will meet is that a platform is compliant because it sits in an Indian cloud region. That claim is not wrong so much as unrelated.

The direct answer: what DPDP requires of a learning platform

1. A lawful basis, which for employees is usually not consent. Section 7(i) treats processing for employment purposes as a legitimate use. Extended-enterprise learners are a different matter.

2. Reasonable security safeguards under Rule 6 — encryption in transit and at rest, access control, monitoring, and logs retained for at least one year.

3. Working data principal rights — access, correction, erasure, grievance and nomination, with a published channel and a 90-day outer limit.

4. Retention and erasure mechanics that can separate records you must keep by law from records you must delete on request.

5. A processor contract carrying the security, breach, sub-processor, deletion and assistance terms you need — because accountability stays with you.

What it does not require: data residency. Rule 15 permits cross-border transfer except where the Government restricts a specific country. No country has been restricted to date.

13 May 2027
Commencement of the core operational obligations — notice, security, breach, retention, rights and cross-border transfer
Source: MeitY gazette notifications, 13 November 2025
72 hours
Deadline for the detailed breach report to the Data Protection Board, after immediate intimation
Source: DPDP Rules, 2025, Rule 7
₹250 crore
Maximum penalty for failure to take reasonable security safeguards; up to ₹200 crore for breach-notification failure
Source: DPDP Act, 2023, Schedule
1 year
Minimum retention for processing and access logs under the security safeguards rule
Source: DPDP Rules, 2025, Rule 6

Those four numbers frame the review. The deadline means a platform bought this quarter will still be running when the obligations bite. The breach clock means the vendor's notification SLA must be shorter than yours. The penalty is why the security schedule is not boilerplate. The log retention tells you to ask where logs live, for how long, and how you obtain them mid-investigation.

Not legal advice. This is a technical and procurement reference prepared from the published Act, the notified Rules and the gazette commencement notifications. It is not a legal opinion and does not account for sector-specific regulation that may apply to your organisation. Have your counsel review any contractual position before you rely on it.

Where does the law actually stand today?

Vendor material treats the Act as either fully in force or years away. Neither is accurate, and the distinction changes what you can demand at contract stage. The Act received assent in August 2023 but was not operational until the Rules arrived. MeitY notified the DPDP Rules, 2025 on 13-14 November 2025, alongside gazette notifications setting staggered commencement across eighteen months and establishing the Data Protection Board of India.

PhaseDateWhat commencesWhat it means for procurement
Phase 113 Nov 2025Data Protection Board of India constituted; definitions; transitional and miscellaneous provisionsThe adjudicating body exists and can receive complaints. Definitions of Data Fiduciary, Data Processor and Significant Data Fiduciary are legally operative
Phase 213 Nov 2026Consent Manager regime under Rule 4 — registration, governance and obligationsRelevant if any part of your learner population is served through a consent-based flow rather than the employment basis
Phase 313 May 2027Notice, security safeguards, breach reporting, retention and erasure, data principal rights, Significant Data Fiduciary duties, cross-border transferThe obligations your review is actually about. A platform contracted today will be mid-term on this date

You are inside the preparation window, not outside the law: the Board is live and can take complaints now, while the substantive duties switch on later. On a three-year term, what matters is not the vendor's posture today but what the contract obliges them to deliver by May 2027 — a contracting problem, not a product-feature problem.

Who is the Data Fiduciary — and why it is not your vendor

Settle this before anything else. The entity determining the purpose and means of processing is the Data Fiduciary. In a standard enterprise deployment that is you: you decide who is trained, on what, and what records are kept. The vendor processes on your instructions and is a Data Processor.

You — Data Fiduciary

Accountable for lawful basis, notice, security, rights, retention and breach reporting. Accountability is not discharged by outsourcing the processing.

LMS vendor — Data Processor

Processes on documented instructions. Owes you contractual duties, but the Board's enforcement attention falls on the fiduciary.

Content and analytics partners — sub-processors

Course libraries, proctoring, video hosting, email and analytics tools all touch learner data. Each needs to be named and flowed down.

The exception to watch

If a vendor uses learner data for its own purposes — product analytics, benchmarking, model training — it is a fiduciary for that processing, not your processor.

Nothing you sign moves liability to the vendor. The contract only determines whether you can meet obligations that remain yours either way.

Press the last card hardest. Ask whether learner data trains models, generates cross-customer benchmarks, or improves recommendations for other tenants. If yes in any form, that processing needs its own lawful basis and its own line in the notice, and is no longer covered by the instruction-only framing of a processor relationship. For the wider selection framework, our guide to evaluating an enterprise LMS platform covers the non-security criteria this document deliberately leaves out.

Does DPDP actually require learner data to stay in India?

No — and this is where most vendor claims fall apart under questioning. Rule 15 provides that a Data Fiduciary may transfer personal data outside India except where the Central Government restricts transfer to a particular country or territory. India adopted a negative-list model, permitted by default and restricted by exception, which is the opposite of an adequacy regime. No country has been placed on that list to date. A vendor pitching a DPDP compliant LMS India deployment on the strength of an Indian cloud region is describing an architectural choice, not a legal requirement.

Not accurate

"The Act mandates data localisation, so learner data must be stored in India." The Rules contain no general localisation mandate. Transfers are permitted unless restricted by notification.

Accurate

Transfers are permitted, but the Government retains discretion to restrict specific countries and to impose conditions when data is made available to a foreign State or its agencies.

Not accurate

"Indian hosting means we are compliant." Hosting location has no bearing on lawful basis, notice, rights workflows, retention mechanics or breach reporting — which is where most gaps sit.

Accurate

Rights follow the data. Access, correction, erasure, and grievance obligations apply identically wherever processing physically occurs, so offshore storage raises operational difficulty, not legality.

Four situations where residency genuinely becomes mandatory

Dismissing the myth is not the same as saying location does not matter. It matters in four circumstances, and the review should establish which apply before you write a requirement into an RFP.

  1. Significant Data Fiduciary designationWhere the Government notifies an entity or class as an SDF, Rule 13 adds duties: a DPIA, annual audit, an India-based Data Protection Officer, algorithmic due diligence, and possible restrictions on transferring specified categories outside India. If you are a plausible SDF candidate, treat residency as a forward requirement.
  2. Sectoral regulation that predates DPDPFinancial-sector localisation comes from regulators, not the DPDP Act. Banks, NBFCs, insurers and payment entities carry storage requirements that bind regardless of what the Rules permit — the most common real reason an Indian enterprise needs an Indian region.
  3. Government access conditionsRule 15 also lets the Government specify requirements where data is made available to a foreign State or its agencies. Where a vendor's parent or infrastructure provider is subject to foreign disclosure regimes, that belongs on your transfer risk register.
  4. Your own contractual commitmentsCustomer contracts, tender conditions and group security policies routinely impose residency independently of statute. Check them first — they are often stricter than the law and are what you will be audited against.

How to phrase the requirement. Rather than asking "is data stored in India", ask the vendor to state the primary hosting region, disaster-recovery region, and the location of every sub-processor, backup, log store, and support-access path. Offshore support tooling is the most commonly missed transfer: the database can sit in Mumbai while a support engineer views learner records from another jurisdiction through a screen-sharing session that leaves no record in your architecture diagram.

Residency claims are usually made about the production database and are usually accurate about it. The gaps sit in backups, log aggregation, email delivery, analytics pipelines and the support desk — absent from the architecture slide, and all processing personal data. If your sector carries its own storage rules, our overview of learning platforms in banking and financial services covers the additional constraints those environments impose.

Do you need employee consent to run a corporate LMS?

Usually not — and this single point invalidates much of the consent-management tooling marketed alongside learning platforms. Section 7 sets out legitimate uses for which personal data may be processed without consent. Clause (i) covers processing for employment, for safeguarding the employer from loss or liability, and for providing any service or benefit sought by an employee. Neither the Act nor the Rules narrow that ground further.

Role-based assignment, completion and assessment records, statutory training evidence, manager visibility and competency records all sit inside employment purposes. A consent gate in front of mandatory compliance training is not merely unnecessary — it creates a right to refuse you never intended to grant and cannot honour.

If a learner can withdraw consent to safety training, you have designed the wrong lawful basis into the system.

Where consent is still required

The ground is narrower than it looks, because it is tied to the employment relationship itself. Several categories fall outside it, and most enterprise deployments contain at least one.

Learner or processing typeConsent needed?Reasoning and what to configure
Employees — mandatory compliance and safety trainingNoEmployment purpose under Section 7(i). Provide notice; do not build a consent gate
Employees — role-based skilling, assessments, competency recordsNoEmployment purpose. Keep processing limited to what is relevant and reasonably necessary
Channel partners, franchisee staff, dealer networksYesNot your employees. Needs a consent flow, its own notice, and withdrawal handling in the portal
Customers on an extended-enterprise or academy portalYesConsent-based, and the platform must support withdrawal without breaking access records
Contractors engaged directly rather than through a vendorDependsAssess against the employment relationship; where absent, treat as consent-based and document the reasoning
Marketing to learners, alumni outreach, publishing photosYesOutside employment purposes even for employees. Needs separate, specific consent
Vendor's use of learner data for benchmarking or model trainingYesSeparate purpose requiring its own basis and notice. Most reviewers should simply prohibit it
Learners under 18 — apprentices, trainees, internsYesVerifiable parental or guardian consent; no tracking, behavioural monitoring or targeted advertising

The last row catches organisations by surprise. Apprentice schemes, ITI-linked programmes and structured internships routinely include learners under 18, and the Act treats anyone under 18 as a child with heightened protections. If any such cohort will use the platform, establish whether it can capture verifiable guardian consent and suppress behavioural tracking for those accounts specifically — a capability most corporate platforms were never built to provide.

Three drafting errors to catch in the notice

Notice obligations remain even where consent is not required, and notices are where imported templates cause damage. First, there is no general legitimate-interest basis of the European kind — Section 7 lists specific grounds with no balancing test to fall back on, so do not import that language. Second, the Act does not carry forward the separate sensitive-personal-data category from the 2011 rules it replaces: all digital personal data is treated alike, so a training-records table attracts the same expectations as a payroll file. Third, a notice must be understandable on its own rather than buried inside broader terms.

The instruction to give L&D. The employment ground changes the consent question, not the accountability question. Transparency, purpose limitation, security, rights handling, grievance redressal and retention all still apply. Keep a short written legal-basis record per processing activity, so that if asked why data was processed without consent, the answer is a document rather than a recollection.

Scope non-employee audiences at the requirements stage rather than discovering them at launch. Our overviews of partner training and customer training set out how those populations are typically structured, which determines how many separate consent flows you end up having to support.

What security controls must the platform evidence?

Rule 6 is the part your review can test directly, because unlike the Act's general "reasonable security safeguards" language, the Rules name specific measures. Any DPDP compliant LMS India evaluation should treat these as the minimum control set and demand evidence rather than assertion for each. They cover encryption, obfuscation, masking or tokenisation; access controls over the computer resources where processing happens; logging and monitoring sufficient to detect and investigate unauthorised access; measures for continued processing such as backups; and appropriate security provisions in the processor contract.

Encryption in transit and at rest

Named explicitly in the Rules alongside masking, obfuscation and tokenisation. Applies to the database, object storage, backups and exports — not just the connection.

Ask: cipher suites, key management, who holds the keys, whether backups and CSV exports are encrypted

Access control over the resource

Role-based access, least privilege, SSO with your identity provider, MFA for administrators, and joiner-mover-leaver deprovisioning that actually fires.

Ask: can an admin export the full learner table, and is that export logged and alertable

Logging with one-year retention

The Rules set a minimum one-year retention for processing and access logs. Most platforms retain admin audit trails far longer than they retain learner-record access logs.

Ask: which events are logged, retention per log type, and how you obtain them mid-incident

Monitoring and detection

Detection of unauthorised access is a named purpose of the logging obligation, which implies review rather than storage alone.

Ask: is there alerting on anomalous bulk access, and can logs be streamed to your SIEM

Continuity measures

Backups and measures for continued processing in the event of loss of availability are part of the safeguard set, not a separate commercial nicety.

Ask: RPO, RTO, backup region, restore test date, and backup encryption and retention

Contractual security terms

The Rules require appropriate security provisions in the agreement with the processor. This is a control, and a missing schedule is a finding.

Ask: for the security schedule itself, not a summary of it, before technical sign-off

Turning the control set into an evidence pack

Vendors answer questionnaires; reviewers need artefacts. The difference is what a Board inquiry would accept. Below is the shape of the evidence register worth maintaining — each line a document you either hold or do not, with an owner and a review date.

LMS vendor evidence register — pre-approval status
Illustrative view · artefacts held versus artefacts claimed
18
Artefacts requested
11
Received and reviewed
3
Blocking gaps
Certifications with scope statement attachedComplete
Encryption and key-management descriptionComplete
Log inventory with retention per log typePartial
Named sub-processor list with locationsPartial
Breach notification SLA in the contractMissing
Deletion certificate process on terminationMissing

That pattern is the normal one. Vendors are well prepared on certifications and encryption because those questions are asked constantly, and weakest on log-retention detail, sub-processor transparency, contractual breach timelines and end-of-contract deletion — precisely the four areas where the Rules create obligations you cannot discharge alone.

On certifications. ISO 27001 and SOC 2 Type II evidence an audited security programme and map onto much of Rule 6. They do not evidence purpose limitation, notice content, rights workflows, retention mechanics, breach reporting in the prescribed form, or the fiduciary-processor terms. Always request the scope statement: a certificate covering a data centre or one product line may not cover the service you are buying.

Position in the wider stack changes the control surface. A platform provisioning users from the HR system inherits that integration's authentication and data-flow risks, as our explainer on LMS and HRMS integration sets out in operational terms.

Rights, retention and the erasure problem

Rights test a learning platform's architecture hardest, because learner records are unusually distributed. One employee's data typically sits in the platform database, the identity provider, the HR system that provisioned the account, a third-party course library, a video host, an email service and a reporting warehouse. The rights request lands on you, not on any one of them.

RightWhat it means in a learning platformQuestion for the vendor
AccessA summary of the personal data being processed and the processing activities, plus identities of others it has been shared withCan the platform produce a per-learner data export covering every table, not just the profile record?
Correction and updatingCorrecting inaccurate profile, role, manager or completion data — including in downstream reporting copiesDoes correcting a record propagate to reports and certificates already issued?
ErasureDeletion where the purpose no longer applies and no legal retention obligation existsIs there a hard-delete function distinct from deactivation, and does it reach backups on a stated cycle?
Grievance redressalA published channel and a defined response period, with the Board as escalationWho is the vendor's named contact and what is their response commitment?
NominationA nominee may exercise rights in the event of death or incapacityRarely platform-implemented; confirm whether it is handled by process instead

All carry a published response period with an outer limit of 90 days. Generous, until you account for discovery — locating every copy across integrations — which is why the sub-processor list is not a formality. You cannot honour erasure against a system you did not know was holding data.

Why erasure and training records collide

The hardest question is what happens when a former employee requests erasure and you hold statutory training evidence about them. Erasure is not absolute: where another law requires retention, that obligation continues. Safety training under industrial legislation, POSH records and sector-mandated certification evidence generally fall on the retain side.

The failure mode is not refusing an erasure request. It is being unable to explain which fields were kept, under which law, and where the copies live.

The erasure workflow that survives scrutiny

  1. Classify before you delete. Split the record into fields held under a statutory obligation and fields held for operational convenience. Do this once as policy, not per request.
  2. Erase the operational remainder. Behavioural data, recommendation signals, engagement analytics, marketing preferences and free-text feedback rarely carry a retention obligation and should go.
  3. Minimise what is retained. A statutory training record generally needs identity, course, date and outcome. It does not need device history, login IP or session recordings.
  4. Propagate to processors. Erasure extends to data held by your processors. Issue the instruction in writing, require confirmation, and get a stated backup-expiry window rather than an implied one.
  5. Record the decision. Log what was erased, what was retained, the legal basis for retention, and the date the retained portion becomes deletable. This record is the deliverable if the Board ever asks.

A schedule that does not apply to you. The Third Schedule sets three-year inactivity-based erasure defaults for specified classes — large e-commerce, online gaming and social media intermediaries above stated thresholds — with 48-hour advance notice. A corporate learning platform is not in those classes. Vendors occasionally quote it as though it governs learner records; it does not, and your retention periods should come from your own statutory obligations.

Set the retention schedule during implementation, not after the first request arrives — retrofitting field-level classification into a live platform holding three years of records is materially harder. Our guide to LMS implementation strategies covers where this fits in the rollout sequence, and the record-keeping expectations for statutory programmes are set out in our overview of POSH training certification.

Breach notification: whose clock is running?

Rule 7 creates a dual obligation, and both halves land on the Data Fiduciary rather than the vendor whose system was compromised. On becoming aware of a breach, you must inform each affected data principal without delay through their registered channel, describing its nature and extent, likely consequences, mitigation taken, and steps the individual should take. Separately, you must intimate the Data Protection Board, then file a detailed report within 72 hours.

Vendor to you
Contractual

Not set by the Rules. This is the number you negotiate, and everything downstream depends on it being short.

You to affected learners
Without delay

Registered channel, plain description of nature, extent, consequences, mitigation and recommended steps.

You to the Board
Immediate + 72 hrs

Initial intimation, then a detailed report. Extensions are possible on written request but should not be assumed.

Exposure
₹200 crore

Maximum penalty for failure to notify, separate from the ₹250 crore ceiling for absent security safeguards.

The asymmetry in the first card is the point. The regulatory clock starts when you become aware, and you become aware when the vendor tells you. A contract with no notification SLA, or one saying "promptly", hands the vendor unilateral control over when your 72-hour obligation begins.

Your regulatory deadline is fixed at 72 hours. If the vendor's notification commitment is undefined, so is your ability to meet it.

What the detailed report has to contain

The 72-hour filing is not an acknowledgement. The Rules prescribe its contents, and each element implies a capability the vendor must supply, since you have no direct access to their infrastructure. Reading those contents as a capability checklist is the fastest route to a defensible breach clause.

  1. Nature, extent, timing and location of the breachRequires log fidelity and retention on the vendor side, plus an extract rather than a summary. Ties back to the one-year log retention requirement.
  2. The circumstances that led to itRoot-cause analysis within three days is possible only where the vendor has an incident-response function and has agreed to share findings, not a sanitised statement.
  3. Impact assessment — who and what was affectedNeeds a per-record view of which learners and fields were exposed. Ask whether the platform can scope exposure to a learner list — "the tenant database" is not an impact assessment.
  4. Mitigation and remedial measures takenContractual obligation to act, not merely to report. Include evidence preservation so remediation does not destroy the forensic record you need.
  5. Who or what caused the breachWhere a sub-processor is involved, your right to that information has to flow down the chain, or it stops at your vendor's own supplier boundary.
  6. Confirmation of how and when data principals were notifiedYou issue those notifications, so the vendor must supply the affected-learner list in a usable format fast enough for you to act before the report is due.

The clause to negotiate. Notification within 24 hours of vendor awareness, in writing, to named contacts, with a defined minimum content set; preservation of logs and forensic evidence; cooperation with your investigation and any Board inquiry; provision of the affected-record list; and no restriction on your ability to report to the regulator. Vendors resist the 24-hour figure more than any other term in a security schedule, and that resistance is informative.

Run the timeline as a tabletop exercise before signing. Give the vendor a scenario — unauthorised bulk export of learner records from one tenant on a Friday evening — and ask who is called, in what order, and at what hour you would be told. That answer reveals more than any certificate. For the broader operating model, our overview of compliance training in the AI era covers how audit expectations are shifting alongside the data rules.

What the data processing agreement must actually say

Everything above converges here. Accountability stays with the Data Fiduciary, and the Rules expressly require appropriate security provisions in the agreement with a processor, so the contract is the only instrument converting a vendor's intentions into something you can rely on at a Board inquiry. When people call a DPDP compliant LMS India procurement a legal exercise rather than a technical one, this is what they mean. A separate DPA is not mandatory provided a data-protection schedule inside the master agreement covers the same ground.

ClauseWhat it must commit the vendor toWhy it matters to you
Roles and instructionsVendor acts as Data Processor on your documented instructions only; no processing for its own purposesPrevents silent repurposing for analytics, benchmarking or model training
Scope and purposeCategories of data principals, data types, processing operations and duration, listed specificallyDefines the boundary you are entitled to enforce; vague scope is unenforceable scope
Security scheduleNamed Rule 6 measures: encryption in transit and at rest, access control, logging with one-year retention, monitoring, backupsRequired by the Rules to be in the contract; a summary paragraph is not a schedule
Breach notificationWritten notice within 24 hours to named contacts, defined content, evidence preservation, affected-record list, cooperation with the BoardYour 72-hour clock cannot start later than the vendor chooses
Sub-processorsNamed list with locations and functions, prior notice of changes, right to object, flow-down of equivalent termsYou cannot honour rights or scope a breach against systems you were never told about
Rights assistanceSupport for access, correction and erasure requests within a window that fits inside your 90-day limitTurns a platform capability into an enforceable service commitment
Retention and erasureConfigurable retention aligned to your statutory obligations; hard delete distinct from deactivation; stated backup-expiry windowEnables the classify-then-erase workflow rather than an all-or-nothing choice
Location and transferPrimary and DR hosting regions, backup and log-store locations, support-access jurisdictions, notice before any changeSupport tooling is the most commonly missed cross-border transfer path
Audit and evidenceAnnual evidence pack, certification scope statements, penetration-test summaries, and a right to audit or an agreed substituteCompliance is a continuing state, not a state at signature
Exit and deletionExport in a documented open format on request, deletion of all copies within a stated period, written certificate of destructionThe clause with the least leverage at renewal and the most value at exit
Liability and indemnityIndemnity for penalties and losses arising from the vendor's breach of the schedule, with a proportionate capStatutory liability stays with you; recovery has to be contractual

Five contractual positions to reject

"We will notify you promptly"

Undefined, therefore unenforceable against a fixed 72-hour deadline. Replace with a stated number of hours from vendor awareness, and define awareness.

"Sub-processors are listed on our website and may change"

A unilateral right to add processors, including in new jurisdictions, without notice. Ask for a contract-annexed list with prior notice and a right to object.

"Aggregated and anonymised data may be used to improve our services"

The clause worth the most scrutiny. Ask how anonymisation is performed and verified; if it is de-identification rather than true anonymisation, this is processing for the vendor's own purpose.

"Data will be deleted in accordance with our retention policy"

Their policy, changeable by them. Retention periods must be yours, configurable, and derived from your statutory obligations.

"We are ISO 27001 certified" offered in place of a security schedule

A certification is evidence, not a commitment. It gives you no remedy, and its scope may exclude the service you are buying.

Sequencing note. Ask for the DPA and security schedule during evaluation, not after commercial terms are agreed. Once price is settled and a go-live date published, leverage on contractual language drops sharply — and the clauses that matter most here, 24-hour notification, sub-processor objection rights and exit deletion certificates, are exactly the ones vendors concede early and resist late.

If you are assembling a full requirements document rather than reviewing one vendor, this section sits alongside functional and commercial criteria deliberately excluded here. Our guide to choosing the right learning management system covers those, and the compliance training software overview sets out the record-keeping capabilities a regulated programme depends on.

The questionnaire: what to send, and how to read the answers

Send these fifteen before the demo, not after. Written answers given ahead of a sales conversation are markedly more accurate than live ones, and the pattern of which come back vague shows where the gaps are. The third column is what most questionnaires omit: a stated expectation of a satisfactory answer, so the review does not rest on the reviewer's memory of the last vendor.

#QuestionReading the answer
1Confirm your role as Data Processor and that you process only on our documented instructions.Good: unqualified confirmation in the contract. Flag: "we may also act as a fiduciary for certain data"
2List every location where learner data is stored, backed up, logged or accessed, including support.Good: a table with regions per function. Flag: a single "hosted in India" line
3Provide your named sub-processor list with function and jurisdiction.Good: annexed list, prior-notice commitment. Flag: a website URL that may change
4Is learner data used for product analytics, cross-customer benchmarking or model training?Good: a clear no, contractually. Flag: "only in aggregated and anonymised form"
5Describe encryption at rest and in transit, including backups and exports, and who holds the keys.Good: named algorithms and key custody. Flag: "industry-standard encryption"
6Provide a log inventory with retention period per log type.Good: access logs retained at least a year. Flag: admin audit only, 30–90 days
7Can logs be exported or streamed to our SIEM, and how quickly during an incident?Good: documented export or streaming. Flag: "raise a support ticket"
8State your breach notification commitment in hours from your awareness.Good: 24 hours or better, in writing. Flag: "promptly" or "without undue delay"
9Can you produce a list of affected learners and fields within 24 hours of detection?Good: yes, with a described method. Flag: tenant-level scoping only
10Describe the per-learner data export used to answer an access request.Good: covers all tables including activity. Flag: profile fields only
11Is there a hard delete distinct from deactivation, and when do backups expire?Good: hard delete plus a stated backup window. Flag: deactivation described as deletion
12Can retention be configured per record type so statutory records are kept while others are erased?Good: field or record-type granularity. Flag: one global retention setting
13Can the platform capture verifiable guardian consent and suppress tracking for under-18 learners?Good: a described mechanism. Flag: "we do not have minors on the platform"
14Provide certification scope statements and the most recent penetration-test summary.Good: scope covers this service. Flag: a certificate image with no scope
15Describe the exit process: export format, deletion timeline, certificate of destruction.Good: documented open format and a certificate. Flag: "contact your account manager"

Question four changes recommendations most often: rarely asked, evasively answered, and decisive on whether the vendor is genuinely your processor. Question thirteen is most often answered incorrectly rather than evasively, because vendors assume corporate platforms carry no minors — an assumption that fails the moment an apprentice cohort is enrolled.

Where Skills Caravan sits on these questions

Skills Caravan operates as a Data Processor for enterprise deployments, supports Indian-region hosting, SSO and role-based access, configurable retention, and an open API with native connectors to the Indian HR systems most enterprises already run. Learner data is not used to train models for other customers.

Stated plainly, because this document is only useful if it applies to us too: none of that substitutes for reading our security schedule and DPA against the fifteen questions above. Ask us for scope statements, a log inventory, and a written notification SLA exactly as you would any other vendor. Our privacy policy is the public starting point; the contractual detail is supplied on request during evaluation.

On scoring. Do not score all fifteen and take the highest total. Questions 1, 4, 8 and 15 are gates, not scores — failing any is a structural problem that strong answers elsewhere do not offset. Score the remaining eleven if you need a comparison matrix.

If an incumbent cannot meet these commitments, the migration question follows immediately, and it is more tractable than most teams assume. Our guide on switching LMS platforms covers the sequencing, and the current Indian market is surveyed in our roundup of the top learning management systems in India.

Six mistakes that show up in learning-platform reviews

1. Treating hosting location as the compliance question

An Indian region answers a requirement the law does not currently impose, while leaving lawful basis, rights workflows, retention mechanics, and breach terms unexamined. Establish whether residency is genuinely mandatory for you before it becomes an RFP line.

2. Building consent gates in front of mandatory training

Employment-purpose processing needs no consent. Asking for it creates a right of refusal you cannot honour on statutory training, and makes the completion record harder to defend.

3. Scoping the review to the platform and stopping there

Course libraries, video hosts, proctoring tools, email services, and analytics warehouses all process learner data. A review covering the platform but not its sub-processors has assessed a fraction of the data flow.

4. Accepting a certificate in place of a schedule

ISO 27001 and SOC 2 evidence a security programme. They create no obligation for you, carry no remedy, and may exclude the service being purchased. Always read the scope statement.

5. Leaving breach notification undefined

Your 72-hour obligation begins when you become aware, and you become aware when the vendor tells you. A contract with no hours-based commitment surrenders control of a statutory deadline.

6. Negotiating exit terms at renewal

Export format, deletion timeline, and certificate of destruction cost nothing to agree during evaluation, and are near-unobtainable once the platform is embedded and renewal is three weeks away.

The bottom line for the reviewer

The framework is neither as restrictive nor as vague as the marketing around it suggests. It does not mandate localisation, and it does not require employee consent for training delivered as part of the employment relationship. It does require a named lawful basis, a specific set of security safeguards with one-year log retention, working rights workflows within a 90-day limit, retention mechanics that separate statutory records from operational ones, and a processor contract carrying all of it.

Only the first two are decided by the platform. The rest are decided by the contract, which is why a security review ending at a product demo has not finished. Ask for the security schedule and sub-processor list on day one, treat notification hours and exit deletion as gates rather than preferences, and note that the obligations commence on 13 May 2027 — comfortably inside the term of anything signed this year.

DPDP Act 2023 DPDP Rules 2025 LMS data residency data processing agreement learner data governance Data Protection Board breach notification Significant Data Fiduciary vendor security review employee data India

Frequently asked questions

Does the DPDP Act require LMS learner data to be stored in India?
No. Rule 15 of the DPDP Rules, 2025 permits transfer of personal data outside India except where the Central Government restricts transfer to a specified country, and no country has been restricted to date. India adopted a negative-list model, not a localisation mandate. Residency becomes mandatory in three other situations: designation as a Significant Data Fiduciary where the Government specifies categories that may not be transferred out, a sectoral regulator such as the RBI imposing localisation on your industry, or your own contracts committing you to it. A Mumbai region alone does not make a platform compliant.
Do we need employee consent to process learner data in a corporate LMS?
Generally no. Section 7(i) recognises processing for employment as a legitimate use that does not require consent, and neither the Act nor the Rules narrow that ground further. Role-based training assignment, completion tracking and statutory training records sit inside it. Consent is still required for processing outside employment purposes, and for learners who are not your employees — channel partners, franchisees, contractors engaged directly, and customers on extended-enterprise portals. Notice, security, rights, and retention obligations apply whichever basis you rely on.
Is our LMS vendor a Data Fiduciary or a Data Processor?
In a standard enterprise deployment, the employer is the Data Fiduciary, because it determines the purpose and means of processing, and the vendor is a Data Processor acting on the employer's instructions. This matters because liability does not transfer with the data: the Data Fiduciary remains accountable for processing carried out by its processors, so a vendor's certifications do not discharge your obligation. Confirm the classification in writing, because a vendor using learner data for its own product analytics or model training is acting as a fiduciary for that processing.
What must a DPDP-ready LMS data processing agreement contain?
At minimum: scope and purpose with an instruction-only clause; the Rule 6 security safeguards, including encryption in transit and at rest, access control and one-year log retention; a breach notification SLA short enough for you to meet the 72-hour Board deadline; rights assistance inside your 90-day limit; a named sub-processor list with prior-notice rights; hosting regions and any cross-border transfer; deletion and return of data on termination with a certificate of destruction; audit or evidence rights; and retention periods aligned to your statutory obligations.
How do we handle an erasure request when training records must be retained?
Erasure is not absolute. Where another law requires retention, that obligation continues, so statutory safety, POSH, and sector-regulated training evidence is generally retained rather than deleted. The correct response is a documented split: identify which records are held under a legal retention obligation, erase the remainder across the platform and every processor holding copies, and record the legal basis for whatever is kept. The failure mode is not refusing erasure — it is being unable to show which fields were kept, why, and where the copies were.
What breach notification timeline applies, and what should the LMS vendor commit to?
Rule 7 creates a dual obligation on the Data Fiduciary: inform affected data principals without delay through their registered channel, and intimate the Data Protection Board, followed by a detailed report within 72 hours covering nature, extent, timing, location, circumstances, impact, remedial steps, and confirmation that principals were told. Your vendor does not file that report — you do. Their contractual notification SLA must therefore be materially shorter than 72 hours, with 24 hours a defensible target, and must include preservation of forensic evidence and named escalation contacts.
Does ISO 27001 certification mean an LMS is DPDP compliant?
No. ISO 27001 and SOC 2 are strong evidence that an information security management system exists and is audited, and they map usefully onto the Rule 6 safeguards. They are not evidence of DPDP-specific obligations: purpose limitation, notice content, rights workflows, retention and erasure mechanics, breach reporting in the prescribed form, or the contractual terms between fiduciary and processor. Treat a certificate as an input, request the scope statement and Statement of Applicability, and verify the DPDP-specific controls separately.
When do DPDP obligations actually become enforceable?
The DPDP Rules, 2025 were notified on 13-14 November 2025 with staggered commencement across eighteen months. The Data Protection Board of India and the definitional provisions took effect immediately. The Consent Manager regime under Rule 4 commences on 13 November 2026. The core operational obligations — notice, security safeguards, breach reporting, retention and erasure, data principal rights, Significant Data Fiduciary duties and cross-border transfer — commence on 13 May 2027. Decisions made now will still be running on that date, which is why the contract matters more than the current state.

For the functional side deliberately excluded here, our overview of what a corporate LMS includes sets out the baseline capability set, and the Skills Caravan platform page covers architecture and integrations in more detail.

Send us the questionnaire

If Skills Caravan is on your shortlist, request the security schedule, sub-processor list, and DPA before the demo. We will answer all fifteen in writing, including the ones where the answer is a qualified yes.

About the author

Shreya Verma is the VP of Product and Customer Success at Skills Caravan, where she leverages her decade-long expertise in learning & development (L&D) and human resources to shape an impactful, learner-centric platform. Her deep understanding of user needs, honed through hands-on L&D roles in leading companies, empowers her to translate insights into high-engagement interventions. At Skills Caravan, she bridges the gap between technology and people, ensuring learning experiences are not only effective but genuinely meaningful.

Trusted by Leaders
Book a Demo

Our Learning Partners

Skillsoft

Skillsoft is a global leader in corporate learning, providing digital training and education solutions to help businesses improve workforce productivity, reduce risk, and increase innovation.

Finshiksha

FinShiksha provides a practical and industry-relevant approach to finance education, with courses designed by industry experts and delivered through interactive and engaging methods.

Wallstreet Prep

Wall Street Prep offers best-in-class financial training for aspiring finance professionals and corporate clients.

Udemy Business

Udemy Business offers an unparalleled learning experience for organizations looking to upskill their workforce with over 155,000 courses taught by expert instructors.