Skip to main content
GDPRLiving document

GDPR Compliance Mapping

How DevAcademia is designed to meet its GDPR processor obligations and support every data-subject right.

Reference: Regulation (EU) 2016/679Effective: Reviewed annually

Scope: how DevAcademia satisfies the EU General Data Protection Regulation (Regulation (EU) 2016/679), and the UK GDPR, when providing services to institutions in the EU, EEA, and UK.

Audience: data-protection officers, EU/UK institution legal counsel, and security auditors performing vendor due diligence.


About this document. This is a transparent description of
how DevAcademia is built to meet its GDPR processor obligations
and support every data-subject right — what we collect, what we
preserve, and what we do with data. It is reviewed periodically
and updated as our services and applicable law evolve. The
specific processor terms are set out in the Data Processing
Agreement entered into with each institution.

#Executive summary

When engaged by an institution, DevAcademia is designed to act as a data processor under Article 4(8), processing personal data only on the documented instructions of that institution, which is the data controller. DevAcademia provides an Article 28 Data Processing Agreement (DPA) to every institution it works with and supports the full set of data-subject rights directly in the product.


#What GDPR protects

Personal data (Article 4(1)): any information relating to an identified or identifiable person. For DevAcademia this includes:

  • User account data (name, email, institution membership)
  • Coursework metadata (submissions, attempts, grades)
  • Communications data (notifications, feedback)
  • Audit metadata (who did what, when)
  • Usage/behavioural data (login times, usage patterns) —

minimised by design

Special categories (Article 9) are NOT processed. DevAcademia does not process health data, biometric identifiers, or data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation. Any future change here would require a fresh assessment, an updated DPA, and explicit consent.

Children (Article 8). DevAcademia does not process the personal data of children below the applicable member-state digital-consent age without parental consent obtained by the subscribing institution. Institutions using DevAcademia with under-age learners are contractually responsible, as controllers, for securing that consent, and attest to it in the product.


#DevAcademia's role and lawful basis

DevAcademia acts as a processor, not a controller, and does not decide the purposes of processing on its own account. Every institution DPA:

  1. Names DevAcademia as processor under Article 28.
  2. Sets out the documented instructions for processing.
  3. Prohibits processing for any other purpose.
  4. Requires compliance with the Article 5 principles: lawfulness,

fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

The lawful basis for processing is the institution's contract (Article 6(1)(b) and Article 28). DevAcademia does not process personal data for advertising, resale, or profiling, and does not use personal data to train external AI models.


#Data-subject rights on the platform

DevAcademia supports the following rights directly in the product, so an institution can honor a data subject's request without a custom engineering effort. Institutions remain the controller and make the final decision on each request.

RightArticleHow it works on DevAcademia
AccessArt. 15Signed-in users can download a machine-readable copy of their own data from their dashboard.
Data portabilityArt. 20The same export is a structured, commonly-used, machine-readable format the subject can hand to another provider.
RectificationArt. 16Users can file a request to correct inaccurate records; the institution reviews and resolves it.
Erasure ("right to be forgotten")Art. 17Users can request erasure of their data; the institution reviews and, unless a legal exception applies, schedules deletion.
Restriction of processingArt. 18When filing a rectification request, a user can also ask that the disputed data be restricted while the request is pending.
ObjectionArt. 21Objections are handled by the institution as controller; DevAcademia provides the tools to give effect to the decision.
Not to be subject to solely-automated decisionsArt. 22Grading and scoring always allow human review (instructor override and a grade-dispute path), so no decision producing legal or similarly significant effects is made on a solely-automated basis.

Every rights request and its resolution is recorded in the institution's compliance audit trail. Where a statutory deadline applies, the platform surfaces a countdown to the reviewing administrator. Access requests return in seconds — well within the one-month Article 12(3) response window.


#Security of processing (Article 32)

  • Data is encrypted in transit (TLS) and at rest (provider-managed,

block-level encryption on our hosted database and backups).

  • Access is gated by role and institution membership; one

institution's data is never visible to another.

  • Sensitive integration secrets are additionally encrypted at the

application layer, with keys rotated at least annually.

  • The platform includes protections against common web attacks and

applies rate limits to sensitive operations.

  • Every administrative action is recorded in an append-only,

tamper-evident audit trail.


#International data transfers (Articles 44–49)

Some of DevAcademia's sub-processors are located in the United States and some in the EU. Transfers to the US rely on the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback. EU-region processing is available on request for institutions that require their data to stay within the EU/EEA. Each sub-processor's transfer mechanism is listed in the public sub-processor list.


#Records, assessments, and accountability

  • Records of processing (Article 30): DevAcademia maintains a

processor register of its processing activities and makes it available to a supervisory authority on request.

  • Data Protection Impact Assessments (Article 35): a DPIA is

the controller's responsibility. DevAcademia provides the technical detail an institution needs to complete its own DPIA under Article 28(3)(g).

  • Cookies / e-Privacy: DevAcademia uses only strictly-necessary

cookies (for signing in and keeping you signed in). It sets no advertising, analytics, or tracking cookies, so no consent banner is required.


#Breach notification (Articles 33 and 34)

DevAcademia notifies an affected institution within 72 hours of confirming an unauthorized disclosure and provides the information the institution needs to meet its own Article 33 (supervisory- authority) and Article 34 (data-subject) obligations. DevAcademia does not notify a supervisory authority on the institution's behalf — that decision belongs to the controller. Full details are in the incident & breach notification policy, which covers the GDPR alignment for EU/EEA/UK institutions.


#Data protection officer and contact

DevAcademia's security lead is the accountable point of contact for data-protection matters, and a formal DPO designation is kept under review as the platform grows and as member-state law requires. Data-protection questions, DPA requests, and rights requests that need DevAcademia's help go to compliance@devacademia.com.


#Change history

DateChange
2026-07-12Initial public version.