
Skillsoft
Skillsoft is a global leader in corporate learning, providing digital training and education solutions to help businesses improve workforce productivity, reduce risk, and increase innovation.






.webp)
This document is written for the person who signs the approval, not the person who wants the platform. If L&D has sent a shortlist and asked for security clearance, the useful question is not whether a vendor calls itself compliant. It is about which obligations under the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025, fall on your organisation, which you can discharge only with the vendor's cooperation, and what must be in the contract to make that cooperation enforceable. Most marketing pages for DPDP-compliant LMS India buyers can shortlist answers to none of the three.
The most common claim you will meet is that a platform is compliant because it sits in an Indian cloud region. That claim is not wrong so much as unrelated.
1. A lawful basis, which for employees is usually not consent. Section 7(i) treats processing for employment purposes as a legitimate use. Extended-enterprise learners are a different matter.
2. Reasonable security safeguards under Rule 6 — encryption in transit and at rest, access control, monitoring, and logs retained for at least one year.
3. Working data principal rights — access, correction, erasure, grievance and nomination, with a published channel and a 90-day outer limit.
4. Retention and erasure mechanics that can separate records you must keep by law from records you must delete on request.
5. A processor contract carrying the security, breach, sub-processor, deletion and assistance terms you need — because accountability stays with you.
What it does not require: data residency. Rule 15 permits cross-border transfer except where the Government restricts a specific country. No country has been restricted to date.
Those four numbers frame the review. The deadline means a platform bought this quarter will still be running when the obligations bite. The breach clock means the vendor's notification SLA must be shorter than yours. The penalty is why the security schedule is not boilerplate. The log retention tells you to ask where logs live, for how long, and how you obtain them mid-investigation.
Not legal advice. This is a technical and procurement reference prepared from the published Act, the notified Rules and the gazette commencement notifications. It is not a legal opinion and does not account for sector-specific regulation that may apply to your organisation. Have your counsel review any contractual position before you rely on it.
Vendor material treats the Act as either fully in force or years away. Neither is accurate, and the distinction changes what you can demand at contract stage. The Act received assent in August 2023 but was not operational until the Rules arrived. MeitY notified the DPDP Rules, 2025 on 13-14 November 2025, alongside gazette notifications setting staggered commencement across eighteen months and establishing the Data Protection Board of India.
| Phase | Date | What commences | What it means for procurement |
|---|---|---|---|
| Phase 1 | 13 Nov 2025 | Data Protection Board of India constituted; definitions; transitional and miscellaneous provisions | The adjudicating body exists and can receive complaints. Definitions of Data Fiduciary, Data Processor and Significant Data Fiduciary are legally operative |
| Phase 2 | 13 Nov 2026 | Consent Manager regime under Rule 4 — registration, governance and obligations | Relevant if any part of your learner population is served through a consent-based flow rather than the employment basis |
| Phase 3 | 13 May 2027 | Notice, security safeguards, breach reporting, retention and erasure, data principal rights, Significant Data Fiduciary duties, cross-border transfer | The obligations your review is actually about. A platform contracted today will be mid-term on this date |
You are inside the preparation window, not outside the law: the Board is live and can take complaints now, while the substantive duties switch on later. On a three-year term, what matters is not the vendor's posture today but what the contract obliges them to deliver by May 2027 — a contracting problem, not a product-feature problem.
Settle this before anything else. The entity determining the purpose and means of processing is the Data Fiduciary. In a standard enterprise deployment that is you: you decide who is trained, on what, and what records are kept. The vendor processes on your instructions and is a Data Processor.
Accountable for lawful basis, notice, security, rights, retention and breach reporting. Accountability is not discharged by outsourcing the processing.
Processes on documented instructions. Owes you contractual duties, but the Board's enforcement attention falls on the fiduciary.
Course libraries, proctoring, video hosting, email and analytics tools all touch learner data. Each needs to be named and flowed down.
If a vendor uses learner data for its own purposes — product analytics, benchmarking, model training — it is a fiduciary for that processing, not your processor.
Nothing you sign moves liability to the vendor. The contract only determines whether you can meet obligations that remain yours either way.
Press the last card hardest. Ask whether learner data trains models, generates cross-customer benchmarks, or improves recommendations for other tenants. If yes in any form, that processing needs its own lawful basis and its own line in the notice, and is no longer covered by the instruction-only framing of a processor relationship. For the wider selection framework, our guide to evaluating an enterprise LMS platform covers the non-security criteria this document deliberately leaves out.
No — and this is where most vendor claims fall apart under questioning. Rule 15 provides that a Data Fiduciary may transfer personal data outside India except where the Central Government restricts transfer to a particular country or territory. India adopted a negative-list model, permitted by default and restricted by exception, which is the opposite of an adequacy regime. No country has been placed on that list to date. A vendor pitching a DPDP compliant LMS India deployment on the strength of an Indian cloud region is describing an architectural choice, not a legal requirement.
"The Act mandates data localisation, so learner data must be stored in India." The Rules contain no general localisation mandate. Transfers are permitted unless restricted by notification.
Transfers are permitted, but the Government retains discretion to restrict specific countries and to impose conditions when data is made available to a foreign State or its agencies.
"Indian hosting means we are compliant." Hosting location has no bearing on lawful basis, notice, rights workflows, retention mechanics or breach reporting — which is where most gaps sit.
Rights follow the data. Access, correction, erasure, and grievance obligations apply identically wherever processing physically occurs, so offshore storage raises operational difficulty, not legality.
Dismissing the myth is not the same as saying location does not matter. It matters in four circumstances, and the review should establish which apply before you write a requirement into an RFP.
How to phrase the requirement. Rather than asking "is data stored in India", ask the vendor to state the primary hosting region, disaster-recovery region, and the location of every sub-processor, backup, log store, and support-access path. Offshore support tooling is the most commonly missed transfer: the database can sit in Mumbai while a support engineer views learner records from another jurisdiction through a screen-sharing session that leaves no record in your architecture diagram.
Residency claims are usually made about the production database and are usually accurate about it. The gaps sit in backups, log aggregation, email delivery, analytics pipelines and the support desk — absent from the architecture slide, and all processing personal data. If your sector carries its own storage rules, our overview of learning platforms in banking and financial services covers the additional constraints those environments impose.
Usually not — and this single point invalidates much of the consent-management tooling marketed alongside learning platforms. Section 7 sets out legitimate uses for which personal data may be processed without consent. Clause (i) covers processing for employment, for safeguarding the employer from loss or liability, and for providing any service or benefit sought by an employee. Neither the Act nor the Rules narrow that ground further.
Role-based assignment, completion and assessment records, statutory training evidence, manager visibility and competency records all sit inside employment purposes. A consent gate in front of mandatory compliance training is not merely unnecessary — it creates a right to refuse you never intended to grant and cannot honour.
If a learner can withdraw consent to safety training, you have designed the wrong lawful basis into the system.
The ground is narrower than it looks, because it is tied to the employment relationship itself. Several categories fall outside it, and most enterprise deployments contain at least one.
| Learner or processing type | Consent needed? | Reasoning and what to configure |
|---|---|---|
| Employees — mandatory compliance and safety training | No | Employment purpose under Section 7(i). Provide notice; do not build a consent gate |
| Employees — role-based skilling, assessments, competency records | No | Employment purpose. Keep processing limited to what is relevant and reasonably necessary |
| Channel partners, franchisee staff, dealer networks | Yes | Not your employees. Needs a consent flow, its own notice, and withdrawal handling in the portal |
| Customers on an extended-enterprise or academy portal | Yes | Consent-based, and the platform must support withdrawal without breaking access records |
| Contractors engaged directly rather than through a vendor | Depends | Assess against the employment relationship; where absent, treat as consent-based and document the reasoning |
| Marketing to learners, alumni outreach, publishing photos | Yes | Outside employment purposes even for employees. Needs separate, specific consent |
| Vendor's use of learner data for benchmarking or model training | Yes | Separate purpose requiring its own basis and notice. Most reviewers should simply prohibit it |
| Learners under 18 — apprentices, trainees, interns | Yes | Verifiable parental or guardian consent; no tracking, behavioural monitoring or targeted advertising |
The last row catches organisations by surprise. Apprentice schemes, ITI-linked programmes and structured internships routinely include learners under 18, and the Act treats anyone under 18 as a child with heightened protections. If any such cohort will use the platform, establish whether it can capture verifiable guardian consent and suppress behavioural tracking for those accounts specifically — a capability most corporate platforms were never built to provide.
Notice obligations remain even where consent is not required, and notices are where imported templates cause damage. First, there is no general legitimate-interest basis of the European kind — Section 7 lists specific grounds with no balancing test to fall back on, so do not import that language. Second, the Act does not carry forward the separate sensitive-personal-data category from the 2011 rules it replaces: all digital personal data is treated alike, so a training-records table attracts the same expectations as a payroll file. Third, a notice must be understandable on its own rather than buried inside broader terms.
The instruction to give L&D. The employment ground changes the consent question, not the accountability question. Transparency, purpose limitation, security, rights handling, grievance redressal and retention all still apply. Keep a short written legal-basis record per processing activity, so that if asked why data was processed without consent, the answer is a document rather than a recollection.
Scope non-employee audiences at the requirements stage rather than discovering them at launch. Our overviews of partner training and customer training set out how those populations are typically structured, which determines how many separate consent flows you end up having to support.
Rule 6 is the part your review can test directly, because unlike the Act's general "reasonable security safeguards" language, the Rules name specific measures. Any DPDP compliant LMS India evaluation should treat these as the minimum control set and demand evidence rather than assertion for each. They cover encryption, obfuscation, masking or tokenisation; access controls over the computer resources where processing happens; logging and monitoring sufficient to detect and investigate unauthorised access; measures for continued processing such as backups; and appropriate security provisions in the processor contract.
Named explicitly in the Rules alongside masking, obfuscation and tokenisation. Applies to the database, object storage, backups and exports — not just the connection.
Ask: cipher suites, key management, who holds the keys, whether backups and CSV exports are encryptedRole-based access, least privilege, SSO with your identity provider, MFA for administrators, and joiner-mover-leaver deprovisioning that actually fires.
Ask: can an admin export the full learner table, and is that export logged and alertableThe Rules set a minimum one-year retention for processing and access logs. Most platforms retain admin audit trails far longer than they retain learner-record access logs.
Ask: which events are logged, retention per log type, and how you obtain them mid-incidentDetection of unauthorised access is a named purpose of the logging obligation, which implies review rather than storage alone.
Ask: is there alerting on anomalous bulk access, and can logs be streamed to your SIEMBackups and measures for continued processing in the event of loss of availability are part of the safeguard set, not a separate commercial nicety.
Ask: RPO, RTO, backup region, restore test date, and backup encryption and retentionThe Rules require appropriate security provisions in the agreement with the processor. This is a control, and a missing schedule is a finding.
Ask: for the security schedule itself, not a summary of it, before technical sign-offVendors answer questionnaires; reviewers need artefacts. The difference is what a Board inquiry would accept. Below is the shape of the evidence register worth maintaining — each line a document you either hold or do not, with an owner and a review date.
That pattern is the normal one. Vendors are well prepared on certifications and encryption because those questions are asked constantly, and weakest on log-retention detail, sub-processor transparency, contractual breach timelines and end-of-contract deletion — precisely the four areas where the Rules create obligations you cannot discharge alone.
On certifications. ISO 27001 and SOC 2 Type II evidence an audited security programme and map onto much of Rule 6. They do not evidence purpose limitation, notice content, rights workflows, retention mechanics, breach reporting in the prescribed form, or the fiduciary-processor terms. Always request the scope statement: a certificate covering a data centre or one product line may not cover the service you are buying.
Position in the wider stack changes the control surface. A platform provisioning users from the HR system inherits that integration's authentication and data-flow risks, as our explainer on LMS and HRMS integration sets out in operational terms.
Rights test a learning platform's architecture hardest, because learner records are unusually distributed. One employee's data typically sits in the platform database, the identity provider, the HR system that provisioned the account, a third-party course library, a video host, an email service and a reporting warehouse. The rights request lands on you, not on any one of them.
| Right | What it means in a learning platform | Question for the vendor |
|---|---|---|
| Access | A summary of the personal data being processed and the processing activities, plus identities of others it has been shared with | Can the platform produce a per-learner data export covering every table, not just the profile record? |
| Correction and updating | Correcting inaccurate profile, role, manager or completion data — including in downstream reporting copies | Does correcting a record propagate to reports and certificates already issued? |
| Erasure | Deletion where the purpose no longer applies and no legal retention obligation exists | Is there a hard-delete function distinct from deactivation, and does it reach backups on a stated cycle? |
| Grievance redressal | A published channel and a defined response period, with the Board as escalation | Who is the vendor's named contact and what is their response commitment? |
| Nomination | A nominee may exercise rights in the event of death or incapacity | Rarely platform-implemented; confirm whether it is handled by process instead |
All carry a published response period with an outer limit of 90 days. Generous, until you account for discovery — locating every copy across integrations — which is why the sub-processor list is not a formality. You cannot honour erasure against a system you did not know was holding data.
The hardest question is what happens when a former employee requests erasure and you hold statutory training evidence about them. Erasure is not absolute: where another law requires retention, that obligation continues. Safety training under industrial legislation, POSH records and sector-mandated certification evidence generally fall on the retain side.
The failure mode is not refusing an erasure request. It is being unable to explain which fields were kept, under which law, and where the copies live.
A schedule that does not apply to you. The Third Schedule sets three-year inactivity-based erasure defaults for specified classes — large e-commerce, online gaming and social media intermediaries above stated thresholds — with 48-hour advance notice. A corporate learning platform is not in those classes. Vendors occasionally quote it as though it governs learner records; it does not, and your retention periods should come from your own statutory obligations.
Set the retention schedule during implementation, not after the first request arrives — retrofitting field-level classification into a live platform holding three years of records is materially harder. Our guide to LMS implementation strategies covers where this fits in the rollout sequence, and the record-keeping expectations for statutory programmes are set out in our overview of POSH training certification.
Rule 7 creates a dual obligation, and both halves land on the Data Fiduciary rather than the vendor whose system was compromised. On becoming aware of a breach, you must inform each affected data principal without delay through their registered channel, describing its nature and extent, likely consequences, mitigation taken, and steps the individual should take. Separately, you must intimate the Data Protection Board, then file a detailed report within 72 hours.
Not set by the Rules. This is the number you negotiate, and everything downstream depends on it being short.
Registered channel, plain description of nature, extent, consequences, mitigation and recommended steps.
Initial intimation, then a detailed report. Extensions are possible on written request but should not be assumed.
Maximum penalty for failure to notify, separate from the ₹250 crore ceiling for absent security safeguards.
The asymmetry in the first card is the point. The regulatory clock starts when you become aware, and you become aware when the vendor tells you. A contract with no notification SLA, or one saying "promptly", hands the vendor unilateral control over when your 72-hour obligation begins.
Your regulatory deadline is fixed at 72 hours. If the vendor's notification commitment is undefined, so is your ability to meet it.
The 72-hour filing is not an acknowledgement. The Rules prescribe its contents, and each element implies a capability the vendor must supply, since you have no direct access to their infrastructure. Reading those contents as a capability checklist is the fastest route to a defensible breach clause.
The clause to negotiate. Notification within 24 hours of vendor awareness, in writing, to named contacts, with a defined minimum content set; preservation of logs and forensic evidence; cooperation with your investigation and any Board inquiry; provision of the affected-record list; and no restriction on your ability to report to the regulator. Vendors resist the 24-hour figure more than any other term in a security schedule, and that resistance is informative.
Run the timeline as a tabletop exercise before signing. Give the vendor a scenario — unauthorised bulk export of learner records from one tenant on a Friday evening — and ask who is called, in what order, and at what hour you would be told. That answer reveals more than any certificate. For the broader operating model, our overview of compliance training in the AI era covers how audit expectations are shifting alongside the data rules.
Everything above converges here. Accountability stays with the Data Fiduciary, and the Rules expressly require appropriate security provisions in the agreement with a processor, so the contract is the only instrument converting a vendor's intentions into something you can rely on at a Board inquiry. When people call a DPDP compliant LMS India procurement a legal exercise rather than a technical one, this is what they mean. A separate DPA is not mandatory provided a data-protection schedule inside the master agreement covers the same ground.
| Clause | What it must commit the vendor to | Why it matters to you |
|---|---|---|
| Roles and instructions | Vendor acts as Data Processor on your documented instructions only; no processing for its own purposes | Prevents silent repurposing for analytics, benchmarking or model training |
| Scope and purpose | Categories of data principals, data types, processing operations and duration, listed specifically | Defines the boundary you are entitled to enforce; vague scope is unenforceable scope |
| Security schedule | Named Rule 6 measures: encryption in transit and at rest, access control, logging with one-year retention, monitoring, backups | Required by the Rules to be in the contract; a summary paragraph is not a schedule |
| Breach notification | Written notice within 24 hours to named contacts, defined content, evidence preservation, affected-record list, cooperation with the Board | Your 72-hour clock cannot start later than the vendor chooses |
| Sub-processors | Named list with locations and functions, prior notice of changes, right to object, flow-down of equivalent terms | You cannot honour rights or scope a breach against systems you were never told about |
| Rights assistance | Support for access, correction and erasure requests within a window that fits inside your 90-day limit | Turns a platform capability into an enforceable service commitment |
| Retention and erasure | Configurable retention aligned to your statutory obligations; hard delete distinct from deactivation; stated backup-expiry window | Enables the classify-then-erase workflow rather than an all-or-nothing choice |
| Location and transfer | Primary and DR hosting regions, backup and log-store locations, support-access jurisdictions, notice before any change | Support tooling is the most commonly missed cross-border transfer path |
| Audit and evidence | Annual evidence pack, certification scope statements, penetration-test summaries, and a right to audit or an agreed substitute | Compliance is a continuing state, not a state at signature |
| Exit and deletion | Export in a documented open format on request, deletion of all copies within a stated period, written certificate of destruction | The clause with the least leverage at renewal and the most value at exit |
| Liability and indemnity | Indemnity for penalties and losses arising from the vendor's breach of the schedule, with a proportionate cap | Statutory liability stays with you; recovery has to be contractual |
Undefined, therefore unenforceable against a fixed 72-hour deadline. Replace with a stated number of hours from vendor awareness, and define awareness.
A unilateral right to add processors, including in new jurisdictions, without notice. Ask for a contract-annexed list with prior notice and a right to object.
The clause worth the most scrutiny. Ask how anonymisation is performed and verified; if it is de-identification rather than true anonymisation, this is processing for the vendor's own purpose.
Their policy, changeable by them. Retention periods must be yours, configurable, and derived from your statutory obligations.
A certification is evidence, not a commitment. It gives you no remedy, and its scope may exclude the service you are buying.
Sequencing note. Ask for the DPA and security schedule during evaluation, not after commercial terms are agreed. Once price is settled and a go-live date published, leverage on contractual language drops sharply — and the clauses that matter most here, 24-hour notification, sub-processor objection rights and exit deletion certificates, are exactly the ones vendors concede early and resist late.
If you are assembling a full requirements document rather than reviewing one vendor, this section sits alongside functional and commercial criteria deliberately excluded here. Our guide to choosing the right learning management system covers those, and the compliance training software overview sets out the record-keeping capabilities a regulated programme depends on.
Send these fifteen before the demo, not after. Written answers given ahead of a sales conversation are markedly more accurate than live ones, and the pattern of which come back vague shows where the gaps are. The third column is what most questionnaires omit: a stated expectation of a satisfactory answer, so the review does not rest on the reviewer's memory of the last vendor.
| # | Question | Reading the answer |
|---|---|---|
| 1 | Confirm your role as Data Processor and that you process only on our documented instructions. | Good: unqualified confirmation in the contract. Flag: "we may also act as a fiduciary for certain data" |
| 2 | List every location where learner data is stored, backed up, logged or accessed, including support. | Good: a table with regions per function. Flag: a single "hosted in India" line |
| 3 | Provide your named sub-processor list with function and jurisdiction. | Good: annexed list, prior-notice commitment. Flag: a website URL that may change |
| 4 | Is learner data used for product analytics, cross-customer benchmarking or model training? | Good: a clear no, contractually. Flag: "only in aggregated and anonymised form" |
| 5 | Describe encryption at rest and in transit, including backups and exports, and who holds the keys. | Good: named algorithms and key custody. Flag: "industry-standard encryption" |
| 6 | Provide a log inventory with retention period per log type. | Good: access logs retained at least a year. Flag: admin audit only, 30–90 days |
| 7 | Can logs be exported or streamed to our SIEM, and how quickly during an incident? | Good: documented export or streaming. Flag: "raise a support ticket" |
| 8 | State your breach notification commitment in hours from your awareness. | Good: 24 hours or better, in writing. Flag: "promptly" or "without undue delay" |
| 9 | Can you produce a list of affected learners and fields within 24 hours of detection? | Good: yes, with a described method. Flag: tenant-level scoping only |
| 10 | Describe the per-learner data export used to answer an access request. | Good: covers all tables including activity. Flag: profile fields only |
| 11 | Is there a hard delete distinct from deactivation, and when do backups expire? | Good: hard delete plus a stated backup window. Flag: deactivation described as deletion |
| 12 | Can retention be configured per record type so statutory records are kept while others are erased? | Good: field or record-type granularity. Flag: one global retention setting |
| 13 | Can the platform capture verifiable guardian consent and suppress tracking for under-18 learners? | Good: a described mechanism. Flag: "we do not have minors on the platform" |
| 14 | Provide certification scope statements and the most recent penetration-test summary. | Good: scope covers this service. Flag: a certificate image with no scope |
| 15 | Describe the exit process: export format, deletion timeline, certificate of destruction. | Good: documented open format and a certificate. Flag: "contact your account manager" |
Question four changes recommendations most often: rarely asked, evasively answered, and decisive on whether the vendor is genuinely your processor. Question thirteen is most often answered incorrectly rather than evasively, because vendors assume corporate platforms carry no minors — an assumption that fails the moment an apprentice cohort is enrolled.
Skills Caravan operates as a Data Processor for enterprise deployments, supports Indian-region hosting, SSO and role-based access, configurable retention, and an open API with native connectors to the Indian HR systems most enterprises already run. Learner data is not used to train models for other customers.
Stated plainly, because this document is only useful if it applies to us too: none of that substitutes for reading our security schedule and DPA against the fifteen questions above. Ask us for scope statements, a log inventory, and a written notification SLA exactly as you would any other vendor. Our privacy policy is the public starting point; the contractual detail is supplied on request during evaluation.
On scoring. Do not score all fifteen and take the highest total. Questions 1, 4, 8 and 15 are gates, not scores — failing any is a structural problem that strong answers elsewhere do not offset. Score the remaining eleven if you need a comparison matrix.
If an incumbent cannot meet these commitments, the migration question follows immediately, and it is more tractable than most teams assume. Our guide on switching LMS platforms covers the sequencing, and the current Indian market is surveyed in our roundup of the top learning management systems in India.
An Indian region answers a requirement the law does not currently impose, while leaving lawful basis, rights workflows, retention mechanics, and breach terms unexamined. Establish whether residency is genuinely mandatory for you before it becomes an RFP line.
Employment-purpose processing needs no consent. Asking for it creates a right of refusal you cannot honour on statutory training, and makes the completion record harder to defend.
Course libraries, video hosts, proctoring tools, email services, and analytics warehouses all process learner data. A review covering the platform but not its sub-processors has assessed a fraction of the data flow.
ISO 27001 and SOC 2 evidence a security programme. They create no obligation for you, carry no remedy, and may exclude the service being purchased. Always read the scope statement.
Your 72-hour obligation begins when you become aware, and you become aware when the vendor tells you. A contract with no hours-based commitment surrenders control of a statutory deadline.
Export format, deletion timeline, and certificate of destruction cost nothing to agree during evaluation, and are near-unobtainable once the platform is embedded and renewal is three weeks away.
The framework is neither as restrictive nor as vague as the marketing around it suggests. It does not mandate localisation, and it does not require employee consent for training delivered as part of the employment relationship. It does require a named lawful basis, a specific set of security safeguards with one-year log retention, working rights workflows within a 90-day limit, retention mechanics that separate statutory records from operational ones, and a processor contract carrying all of it.
Only the first two are decided by the platform. The rest are decided by the contract, which is why a security review ending at a product demo has not finished. Ask for the security schedule and sub-processor list on day one, treat notification hours and exit deletion as gates rather than preferences, and note that the obligations commence on 13 May 2027 — comfortably inside the term of anything signed this year.
For the functional side deliberately excluded here, our overview of what a corporate LMS includes sets out the baseline capability set, and the Skills Caravan platform page covers architecture and integrations in more detail.
If Skills Caravan is on your shortlist, request the security schedule, sub-processor list, and DPA before the demo. We will answer all fifteen in writing, including the ones where the answer is a qualified yes.
Shreya Verma is the VP of Product and Customer Success at Skills Caravan, where she leverages her decade-long expertise in learning & development (L&D) and human resources to shape an impactful, learner-centric platform. Her deep understanding of user needs, honed through hands-on L&D roles in leading companies, empowers her to translate insights into high-engagement interventions. At Skills Caravan, she bridges the gap between technology and people, ensuring learning experiences are not only effective but genuinely meaningful.
See how enterprises close skill gaps with AI. We'll email your brochure instantly.
Please enter your name, a valid email, and your phone number.
We respect your privacy. No spam — unsubscribe anytime.
Your platform overview is on its way. You can also download it right now.
Download Brochure











.png)
.png)
.png)
%20(1).png)
.png)







.webp)











.png)
.png)
.png)
%20(1).png)
.png)















Skillsoft is a global leader in corporate learning, providing digital training and education solutions to help businesses improve workforce productivity, reduce risk, and increase innovation.

FinShiksha provides a practical and industry-relevant approach to finance education, with courses designed by industry experts and delivered through interactive and engaging methods.

Wall Street Prep offers best-in-class financial training for aspiring finance professionals and corporate clients.

Udemy Business offers an unparalleled learning experience for organizations looking to upskill their workforce with over 155,000 courses taught by expert instructors.







.webp)








