GDPR check

Is D2L Brightspace GDPR compliant? What universities should check

D2L Brightspace is the learning management system at many European universities, including Utrecht University and Aarhus University. It holds course work, submissions, grades and messages for most students. This page sets out what D2L's own documentation and its university customers publicly say about hosting, deletion, transfers and the D2L Lumi AI features, including AI-assisted grading, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

D2L's documentation says Brightspace data platform services run on AWS in the same region as the institution's LMS, with Europe among the available hosting areas. Universities such as Aarhus and Utrecht state that they have data processing arrangements with D2L, and Utrecht notes D2L offices in the UK, Canada and Australia. Brightspace has strong built-in tools for data portability and erasure. D2L Lumi uses Anthropic's Claude models through AWS Bedrock, and D2L says customer data is not used for training. Lumi Feedback produces draft scores on student work and can grade automatically, which brings the AI Act's education rules into view. D2L's main website blocked automated access on the check date, so its privacy notice and subprocessor list are not summarised here.

Source limitation. On 7 October 2026 the pages on www.d2l.com, including its privacy notice, GDPR page and subprocessor list, returned a bot challenge to our automated retrieval, and we do not bypass such checks. This page therefore relies on D2L's documentation site (community.d2l.com) and on university customers' privacy statements. Statements below that are not sourced to D2L are marked as customer-documented.

What is publicly documented

The table summarises D2L's Brightspace documentation and Lumi FAQ, plus privacy statements from Utrecht University and Aarhus University, all read on 7 October 2026.

TopicWhat the sources stateSource
Contract and roleCustomer-documented Aarhus University says it has "entered into a data processing agreement" with D2L and that D2L uses subcontractors for operation and support. Utrecht says data is shared with D2L as the supplier of Brightspace. D2L's own DPA terms could not be read on the check date.Aarhus University [1], Utrecht University [2]
Where data is storedPartly documented D2L says the Brightspace Data Platform uses AWS and that data is hosted in the same region as the LMS. D2L Link is limited to the Australia, Europe and US-East hosting areas. The European AWS region used for Brightspace was not found in the documentation we could read (checked 7 October 2026).Insights dashboards [3], D2L Link [4]
International transfersCustomer-documented Utrecht says D2L has offices in the UK, Canada and Australia and that it has taken appropriate contractual measures for data outside the EU. The UK and Canada (commercial organisations) have EU adequacy decisions; Australia does not. DPF participation could not be checked: D2L's site was unavailable to us and the official DPF list API returned errors.[2], EU adequacy decisions [5]
Deletion and data subject rightsDocumented The Data Purge tool removes user data. After a purge, session history and enrolment records are deleted from Brightspace Data Sets, quiz IP addresses are anonymised, and the user is anonymised in other data sets such as assignment submissions. D2L also documents data portability under the GDPR.Data Purge tool [6], Data portability [7]
RetentionCustomer-documented Utrecht deletes data linked to a Brightspace account after two years of inactivity and keeps official results in its student system. Aarhus keeps data as long as needed and longer where examination rules require. D2L's own post-contract deletion terms were not read.[2], [1]
AI models and trainingDocumented D2L Lumi Pro uses LLMs through AWS Bedrock, including Anthropic's Claude Sonnet and Claude Haiku. "No. Customer data is not used to train the AI models used by D2L Lumi." D2L does not fine-tune the models with customer data.D2L Lumi FAQs [8]
AI controlsDocumented Administrators control where Lumi Pro is available through configuration settings and tool permissions, at organisation and course level. Autograde "can be enabled or disabled".[8]
Lumi FeedbackDocumented Lumi Feedback can draw on learning outcomes, rubrics, course content, assignment submissions and instructor annotations. It analyses student work against rubrics and gives "a draft score and personalized feedback" for the instructor to review, edit and approve. An automated grading option can grade submissions immediately on submission and give learners instant feedback.[8], Lumi Chat, Tutor and Feedback [9]
AI processing locationNot found The AWS Bedrock region used for Lumi for European customers was not found in the documentation we could read (checked 7 October 2026).[8]

What this means for a university

Validemic's analysis

Good tools for data subject rights. The Data Purge tool, with documented effects on each data set [6], and the portability guidance [7] are practical strengths. Few vendors describe so precisely which records are deleted and which are anonymised. Universities that export Brightspace Data Sets to their own warehouse should mirror the purge there, as D2L itself recommends updating local copies.

Customers publish more than we could read from D2L. Utrecht and Aarhus show that Brightspace can be documented clearly for students [1][2]. Their statements are not a substitute for your own contract: confirm the AWS region, the D2L entity and the support locations in writing, and include Australian support access in a transfer impact assessment.

Lumi Feedback changes the risk profile. Most LMS AI features generate course material. Lumi Feedback reads submissions and proposes scores [9], and D2L describes an automated grading option that grades submissions on submission and gives learners instant feedback [9]. The documentation we could read does not say whether an instructor reviews automated grades before learners see them (checked 7 October 2026), so this should be confirmed with D2L. Either way, grading data, rubric logic and model output come into the same flow. It needs its own DPIA section, a decision on whether autograde is used at all, and clear information for students. The configurable switch [8] is the control to use.

AI processing region matters. D2L's public FAQ names the models and the platform but does not say in which region prompts and outputs are processed for EU customers [8]. Ask before enabling.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask D2L before approving or renewing

  1. Which D2L entity signs our DPA, and which AWS region holds our Brightspace instance, backups and Brightspace Data Platform data?
  2. From which countries can D2L staff access our data for support, and under which transfer mechanism for Australia?
  3. Can we receive the current subprocessor list and subscribe to change notices?
  4. In which AWS Bedrock region are Lumi prompts and outputs processed for our tenant, and what retention applies?
  5. Is autograde enabled anywhere in our tenant, does an instructor review automated grades before learners see them, and can it be disabled at organisation level until reviewed?
  6. What does Lumi Feedback send to the model for each submission, and is the draft score logged so that a student can see how it was reached?
  7. How long does D2L keep our data after the contract ends, and how is deletion confirmed?

The EU AI Act angle

Annex III point 3(b) of the AI Act covers AI systems "intended to be used to evaluate learning outcomes", including when those outcomes steer the learning process [10]. Validemic's analysis A feature that analyses submissions against a rubric and proposes a score [9] fits that description closely. Article 6(3) lets a provider conclude that an Annex III system is not high-risk if, for example, it only performs a preparatory task for a human assessment, but that exception does not apply where the system profiles people [11]. If an automated grading mode released results to learners without instructor review, it would be harder to describe as preparatory; D2L's public documentation does not say how review works in that mode. D2L, as provider, makes the first classification; the university, as deployer, decides how the feature is used and should document that decision. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [12]. Article 4, in force now, requires deployers to take measures to support the AI literacy of staff who use these features [13].

Sources

  1. Brightspace privacy policy, Aarhus University (updated 9 February 2026), retrieved 7 October 2026
  2. Brightspace privacy statement, Utrecht University (last modified 19 June 2025), retrieved 7 October 2026
  3. Set up Insights Dashboards, D2L Brightspace documentation, retrieved 7 October 2026
  4. About D2L Link, D2L Brightspace documentation, retrieved 7 October 2026
  5. Adequacy decisions, European Commission, retrieved 7 October 2026
  6. Brightspace Data Sets and the Data Purge tool, D2L Brightspace documentation, retrieved 7 October 2026
  7. Data Portability and the GDPR, D2L Brightspace documentation, retrieved 7 October 2026
  8. D2L Lumi FAQs, D2L Brightspace documentation, retrieved 7 October 2026
  9. About D2L Lumi Chat, Tutor and Feedback, D2L Brightspace documentation, retrieved 7 October 2026
  10. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689), retrieved 7 October 2026
  11. AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read D2L's Brightspace documentation on hosting, data sets, data portability and D2L Lumi, privacy statements from Aarhus University and Utrecht University, the European Commission's adequacy list and the relevant AI Act texts on 7 October 2026. D2L's main website, including its privacy notice and subprocessor list, was not available to our automated retrieval on that date, and we will update this page when we can read those documents. Our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Brightspace complies with the GDPR. If you spot an error or can point us to an updated D2L document, please contact us and we will correct it.

Frequently asked questions

Is Brightspace GDPR compliant?

No tool is GDPR compliant on its own. University customers such as Aarhus University state that they have a data processing agreement with D2L, and Brightspace includes tools for data portability and erasure. Whether a university's use complies depends on its contract, configuration, retention rules and how it informs students and staff.

Where is Brightspace data stored?

D2L's documentation says the Brightspace Data Platform uses Amazon Web Services and that data is hosted in the same region as the institution's LMS. D2L Link is offered in Australia, Europe and US-East hosting areas. The specific region for a university's instance should be confirmed in its contract.

Does D2L Lumi grade student work?

D2L describes Lumi Feedback as an assistant that analyses student work against rubrics or grading criteria and gives the instructor a draft score and feedback to review, edit and approve. It also lists an automated grading option that can grade submissions on submission and give instant feedback, and says autograde can be enabled or disabled.

Does D2L use customer data to train AI?

D2L's Lumi FAQ says customer data is not used to train the AI models used by D2L Lumi, and that D2L does not fine-tune the third-party models with customer data. Lumi Pro uses Anthropic's Claude models through AWS Bedrock.

Can Brightspace delete a student's data on request?

Brightspace has a Data Purge tool. D2L documents that purging a user deletes some records from Brightspace Data Sets, such as session history and enrolments, and anonymises the user in others, such as assignment submissions and quiz attempts. Universities should check copies held in their own data warehouse as well.