Is Moodle GDPR compliant? What universities should check
Moodle is the open-source learning management system behind many European university learning platforms. Unlike most LMS vendors, Moodle can be run entirely on a university's own servers, hosted by a Moodle partner, or rented as MoodleCloud from Moodle Pty Ltd in Australia. This page sets out what Moodle documents publicly for each route, including its AI subsystem and learning analytics, and what that means for a university.
Short answer
Moodle LMS is open-source software, so the GDPR picture depends on who runs it. A self-hosted Moodle site keeps data on the university's own or contracted infrastructure, and Moodle HQ is only involved for optional services such as push notifications. MoodleCloud and Moodle's other hosted services are provided by Moodle Pty Ltd (Australia), Moodle US LLC or Moodle India, which publish a pre-signed data processing agreement, name AWS as the main hosting subprocessor and offer standard contractual clauses for transfers. Australia has no EU adequacy decision, so the transfer analysis matters. Moodle's AI features are off by default and use a provider the administrator chooses. A university should know which route it uses before it reads any contract.
Three ways to run Moodle
The same software can sit in very different legal set-ups. That is the most important fact about Moodle and data protection.
- Self-hosted. The university installs Moodle LMS on its own servers or its own cloud tenancy. It is the controller and, apart from any hosting provider it contracts, there may be no processor at all for the core platform. Moodle's documentation says its core privacy plugins ship in the standard distribution but that installing them "will not be enough to meet the GDPR requirements" without proper configuration and procedures [1].
- Hosted by a Moodle partner or certified service provider. Moodle's website refers to certified partners and service providers that offer hosting, support and customisation [2]. The partner is then the university's processor, and its own DPA, hosting region and subprocessors apply. This page does not cover individual partners.
- Hosted by Moodle itself. MoodleCloud and Moodle's hosted LMS and Workplace services are run by Moodle Pty Ltd, Moodle US LLC or Moodle India Information Solutions Pvt Ltd under Moodle's DPA [3].
What Moodle documents publicly
The table summarises Moodle's privacy notice, its 2026 data processing agreement, its GDPR questionnaire and the Moodle LMS documentation, all read on 7 October 2026. Moodle's trust centre at trust.moodle.com did not render any content for us on the check date.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Moodle Pty Ltd, West Perth, Western Australia. The privacy notice was last updated in October 2025 and names an external data protection officer, Data Compliance Europe Ltd, reachable at dpo@moodle.com. | Privacy Notice [2] |
| Data processing agreement | Documented A pre-signed DPA covers Moodle's products and services. It becomes binding when the customer signs and returns it or accepts it with the master agreement. It is governed by Irish law and requires breach notification to the customer within 48 hours of Moodle becoming aware. | Moodle DPA 2026 (PDF) [3] |
| Where data is stored | Partly documented The DPA names AWS as hosting subprocessor for all data uploaded to MoodleCloud and to Moodle-hosted LMS and Workplace sites. The GDPR questionnaire says Moodle hosts in locations closest to customers, usually AWS Ireland for Europe, AWS Sydney for Asia-Pacific and AWS Oregon for the US. A contractual region commitment was not found in public documentation (checked 7 October 2026). | [3], GDPR Questionnaire (PDF) [4] |
| Subprocessors | Documented For MoodleCloud the DPA lists AWS, Blindside Networks (Canada, BigBlueButton, recordings kept up to 365 days), Google Analytics, Google and Apple push servers, LogsHero (Israel, log aggregation), New Relic (US, monitoring) and Intercom (onboarding). Moodle Spain Technologies S.L. supports the branded app service. | [3] |
| International transfers | Partly documented Moodle publishes SCCs for transfers outside the EEA, and the DPA provides for SCCs where data goes to a country without an adequacy decision, including with subprocessors outside the EEA, UK or Switzerland. Australia and India are not on the European Commission's adequacy list; Canada (commercial organisations) and Israel are. DPF participation is not mentioned in the privacy notice; the official DPF list API returned errors on the check date. | [2], [3], EU adequacy decisions [5] |
| Self-hosted sites | Documented The DPA says the only Moodle app function involving processing by Moodle is Airnotifier push notifications, run on AWS servers in Ireland when enabled. It processes the site URL, administrator email, a device token and the notification content. Moodle LMS 4.2 and later support end-to-end encryption for these notifications. | [3] |
| AI and training on customer data | Documented The DPA says the processor shall not "train artificial intelligence models on" customer personal data. In Moodle LMS, AI placements are disabled by default, need a configured provider (OpenAI, Azure AI and Ollama provider plugins are documented, with DeepSeek added in Moodle 5.1), and each user must accept an AI usage policy before first use. | [3], AI placements [6], AI providers [7] |
| Learning analytics | Documented Moodle ships models including "Students at risk of dropping out", "Upcoming activities due" and "No teaching". The documentation says most models are not enabled by default and that machine learning models must be trained on the site's own data. | Analytics [8] |
| Retention and deletion | Documented On termination Moodle will destroy or return customer personal data, except where law requires retention. Backups in AWS are deleted after defined deadlines, "usually 6 months, maximum a year". | [3] |
| Privacy tooling in the software | Documented Moodle LMS includes policy versioning and consent tracking, age and location checks for minors, data subject access and erasure requests, and a data registry. | [1] |
What this means for a university
Validemic's analysis
Self-hosting is a real strength. Few LMS options let a university keep student submissions, grades and messages entirely within infrastructure it controls. The built-in data request and retention tools [1] give a privacy team practical levers that many SaaS products lack. The trade-off is responsibility: patching, backups, access logs, breach detection and plugin vetting all sit with the university or its hosting partner.
Plugins are where data leaves. On a self-hosted site, the risk usually comes from third-party plugins, LTI tools, video services and AI providers rather than Moodle HQ. Each one needs its own assessment, because a plugin that calls an external service usually brings in a new processor.
MoodleCloud means an Australian processor. Hosting in AWS Ireland [4] keeps the stored data in the EU, but Moodle's operating companies sit in Australia, the US and India [3]. Support or administrative access from those countries is a transfer, and Australia and India have no adequacy decision [5]. The SCCs Moodle publishes [2] are the expected tool, together with a transfer impact assessment.
The DPA has useful terms. A 48-hour breach notice, an explicit no-AI-training clause, a ban on solely automated decisions with significant effects and an Irish governing law [3] are all helpful to a European university. The questionnaire describes hosting as "usually" Ireland, so confirm the region for your site.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask before approving or renewing
- Which route do we use: self-hosted, a partner, or Moodle-hosted? Who is our processor, and which DPA applies?
- If Moodle-hosted: which AWS region holds our site, backups and logs, and is that region written into our contract?
- Which Moodle entities and staff locations can access our data for support, and under which transfer mechanism?
- Have we enabled Airnotifier, BigBlueButton or other services that send data to Moodle or its subprocessors, and are they in our records of processing?
- Which AI provider is configured, where does it process prompts, and what retention and training terms apply to it?
- Which learning analytics models are enabled, who sees the predictions, and have students been told?
- Which third-party plugins and LTI tools receive personal data, and does each have a DPA?
The EU AI Act angle
Annex III point 3 of the AI Act covers AI systems intended to evaluate learning outcomes, including when those outcomes steer the learning process, and systems that assess the level of education a person will receive [9]. Moodle's built-in "Students at risk of dropping out" model identifies students it predicts are at risk of dropping out, once trained on the site's own data [8]; whether a given configuration falls under Annex III depends on its intended purpose and use, and Article 6(3) excludes some narrow or preparatory systems unless they profile people [10]. Validemic's analysis Because Moodle ships the model but each site enables it and trains it on its own data, the split between provider and deployer roles is not obvious, and a university that runs it should document its own assessment of its role. The AI placements in core Moodle (text generation, image generation, summaries) are general assistance rather than assessment [6], but a plugin that grades or ranks students needs its own classification. Annex III obligations apply from 2 December 2027 under the amended Article 113 [11]. The duty that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI on their behalf [12].
Sources
- GDPR, Moodle 5.1 documentation, retrieved 7 October 2026
- Moodle Privacy Notice (last updated October 2025), retrieved 7 October 2026
- Moodle Data Processing Agreement, 2026 (PDF), retrieved 7 October 2026
- Moodle GDPR Questionnaire (PDF), retrieved 7 October 2026
- Adequacy decisions, European Commission, retrieved 7 October 2026
- AI placements, Moodle 4.5 documentation, retrieved 7 October 2026
- AI providers, Moodle 5.1 documentation, retrieved 7 October 2026
- Analytics, Moodle 5.1 documentation, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689), retrieved 7 October 2026
- AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Moodle's privacy notice, its 2026 data processing agreement, its GDPR questionnaire, the Moodle LMS documentation on GDPR, AI and analytics, the European Commission's adequacy list and the relevant AI Act texts on 7 October 2026. We did not review individual Moodle partners or plugins. Our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Moodle complies with the GDPR. If you spot an error or Moodle has updated a document, please contact us and we will correct it.
Frequently asked questions
Is Moodle GDPR compliant?
No software is GDPR compliant on its own. Moodle LMS includes privacy tools for policies, consent, data requests and retention, and Moodle offers a standard data processing agreement for its hosted services. Whether a university's use complies depends on who hosts it, the contracts in place, the plugins installed, the configuration and how students are informed.
Does Moodle HQ see our data if we host Moodle ourselves?
For a self-hosted site, the university or its hosting partner runs the servers. Moodle's DPA says the only Moodle mobile app function that involves processing by Moodle itself is the Airnotifier push notification service, which runs on AWS servers in Ireland if the site enables it. Other optional connections, such as AI providers, depend on what the university configures.
Where is MoodleCloud data stored?
Moodle's DPA names Amazon Web Services as the hosting subprocessor for MoodleCloud. Moodle's GDPR questionnaire says it usually hosts customer data in the AWS location closest to the customer, which usually means AWS Ireland for European customers. A university should confirm the region for its own site in writing.
Does Moodle use our data to train AI?
Moodle's 2026 DPA says the processor shall not train artificial intelligence models on customer personal data. In Moodle LMS itself, AI features run through an AI provider that the site administrator chooses and configures, such as OpenAI, Azure AI or a self-hosted Ollama model, so the provider's own terms also matter.
Do we need a DPIA for Moodle?
Usually yes, or at least a documented screening. An LMS holds data about nearly every student, including submissions and grades, and enabling learning analytics models or AI features adds new processing that should be assessed before it is switched on.