Readiness assessment
EdTech · LMS

The DPDP Act for LMS Platforms

An LMS is usually a Processor for the institution that deploys it, and a Fiduciary for its own accounts.

In short

Where children are the end users, Section 9 flows through the LMS: verifiable consent, no behavioural monitoring, and airtight processor terms. Children-data penalties reach ₹200 crore.

Core impacts

What changes for this sub-sector.

Processor vs Fiduciary

Map where you are a processor for an institution and where you are a fiduciary for your own users.

Children flow through

If pupils use the LMS, the Section 9 protections apply; build them in, do not assume the client handles it.

Learning-analytics grey zone

Behavioural learning analytics on minors sits in a grey area the Board is expected to test; be conservative.

Consent pass-through

Give institutions the tools and records to obtain and evidence verifiable parental consent.

Security and access

Protect pupil data with strong access control and encryption.

Sub-processors

Disclose and control the vendors your LMS relies on.

Check your LMS obligations.

The readiness check maps role, consent-passthrough and analytics gaps.

Take the readiness check