Official Compliance Statement • Republic of India

Digital Personal Data Protection (DPDP) Act, 2023

How Flurid empowers schools, colleges, and universities to meet statutory data protection compliance under Indian law.

Flurid DPDP Act Compliance Guarantee

The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) passed by the Parliament of India establishes a strict legal framework for processing digital personal data. Flurid Education Operating System (EduOS) has been built from the ground up to ensure complete technical, operational, and structural alignment with all DPDP Act mandates.

1. Technical Implementation of DPDP Principles

Notice & Consent Architecture

Automated consent notices rendered in clear language across onboarding portals, with itemized purpose specification for students and parents.

Purpose Limitation

Data is processed exclusively for school operations, attendance, academics, and fee collection—never repurposed for external marketing.

Data Minimization

Only data essential to providing educational services is collected. Custom fields are strictly governed by institutional Super Admins.

Storage Limitation

Automated archival and deletion workflows when a student graduates or transfers, adhering to institutional data retention policies.

2. Special Obligations for Children's Personal Data (Section 9)

Recognizing that educational institutions handle data of minors under 18 years of age, Flurid enforces statutory safeguards mandated by Section 9 of the DPDP Act:

  • Verifiable Parental Consent: Digital consent workflows built into the Parent Portal before minor student records are processed.
  • No Behavioral Tracking: Zero behavioral tracking, profiling, or monitoring of minor students' online activity.
  • No Targeted Advertisements: Flurid guarantees zero commercial advertisements across student and parent interfaces.

3. Indian Data Sovereignty & Localization

Flurid complies with Indian data residency mandates. All primary databases, daily encrypted backups, media attachments, and logs are hosted within Tier-IV MeitY-empaneled Indian Data Centers:

📍 Primary Cloud Region: AWS Asia Pacific (Mumbai) / GCP (Delhi NCR)
🔐 Encryption Standard: AES-256 at rest, TLS 1.3 in transit
⚡ Backup Failover: Encrypted Indian Disaster Recovery Center (Hyderabad)

4. Data Protection Officer (DPO) Contact

Institutions, Data Principals, or regulatory authorities seeking information regarding DPDP compliance may contact our Data Protection Office:

Office: Data Protection & Regulatory Compliance Cell
Legal Entity: Flurid Technologies India Private Limited