GDPR check

Is Moodle GDPR compliant? What universities should check

Moodle is the open-source learning management system behind many European university learning platforms. Unlike most LMS vendors, Moodle can be run entirely on a university's own servers, hosted by a Moodle partner, or rented as MoodleCloud from Moodle Pty Ltd in Australia. This page sets out what Moodle documents publicly for each route, including its AI subsystem and learning analytics, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Moodle LMS is open-source software, so the GDPR picture depends on who runs it. A self-hosted Moodle site keeps data on the university's own or contracted infrastructure, and Moodle HQ is only involved for optional services such as push notifications. MoodleCloud and Moodle's other hosted services are provided by Moodle Pty Ltd (Australia), Moodle US LLC or Moodle India, which publish a pre-signed data processing agreement, name AWS as the main hosting subprocessor and offer standard contractual clauses for transfers. Australia has no EU adequacy decision, so the transfer analysis matters. Moodle's AI features are off by default and use a provider the administrator chooses. A university should know which route it uses before it reads any contract.

Three ways to run Moodle

The same software can sit in very different legal set-ups. That is the most important fact about Moodle and data protection.

What Moodle documents publicly

The table summarises Moodle's privacy notice, its 2026 data processing agreement, its GDPR questionnaire and the Moodle LMS documentation, all read on 7 October 2026. Moodle's trust centre at trust.moodle.com did not render any content for us on the check date.

TopicWhat the vendor statesSource
Company and establishmentDocumented Moodle Pty Ltd, West Perth, Western Australia. The privacy notice was last updated in October 2025 and names an external data protection officer, Data Compliance Europe Ltd, reachable at dpo@moodle.com.Privacy Notice [2]
Data processing agreementDocumented A pre-signed DPA covers Moodle's products and services. It becomes binding when the customer signs and returns it or accepts it with the master agreement. It is governed by Irish law and requires breach notification to the customer within 48 hours of Moodle becoming aware.Moodle DPA 2026 (PDF) [3]
Where data is storedPartly documented The DPA names AWS as hosting subprocessor for all data uploaded to MoodleCloud and to Moodle-hosted LMS and Workplace sites. The GDPR questionnaire says Moodle hosts in locations closest to customers, usually AWS Ireland for Europe, AWS Sydney for Asia-Pacific and AWS Oregon for the US. A contractual region commitment was not found in public documentation (checked 7 October 2026).[3], GDPR Questionnaire (PDF) [4]
SubprocessorsDocumented For MoodleCloud the DPA lists AWS, Blindside Networks (Canada, BigBlueButton, recordings kept up to 365 days), Google Analytics, Google and Apple push servers, LogsHero (Israel, log aggregation), New Relic (US, monitoring) and Intercom (onboarding). Moodle Spain Technologies S.L. supports the branded app service.[3]
International transfersPartly documented Moodle publishes SCCs for transfers outside the EEA, and the DPA provides for SCCs where data goes to a country without an adequacy decision, including with subprocessors outside the EEA, UK or Switzerland. Australia and India are not on the European Commission's adequacy list; Canada (commercial organisations) and Israel are. DPF participation is not mentioned in the privacy notice; the official DPF list API returned errors on the check date.[2], [3], EU adequacy decisions [5]
Self-hosted sitesDocumented The DPA says the only Moodle app function involving processing by Moodle is Airnotifier push notifications, run on AWS servers in Ireland when enabled. It processes the site URL, administrator email, a device token and the notification content. Moodle LMS 4.2 and later support end-to-end encryption for these notifications.[3]
AI and training on customer dataDocumented The DPA says the processor shall not "train artificial intelligence models on" customer personal data. In Moodle LMS, AI placements are disabled by default, need a configured provider (OpenAI, Azure AI and Ollama provider plugins are documented, with DeepSeek added in Moodle 5.1), and each user must accept an AI usage policy before first use.[3], AI placements [6], AI providers [7]
Learning analyticsDocumented Moodle ships models including "Students at risk of dropping out", "Upcoming activities due" and "No teaching". The documentation says most models are not enabled by default and that machine learning models must be trained on the site's own data.Analytics [8]
Retention and deletionDocumented On termination Moodle will destroy or return customer personal data, except where law requires retention. Backups in AWS are deleted after defined deadlines, "usually 6 months, maximum a year".[3]
Privacy tooling in the softwareDocumented Moodle LMS includes policy versioning and consent tracking, age and location checks for minors, data subject access and erasure requests, and a data registry.[1]

What this means for a university

Validemic's analysis

Self-hosting is a real strength. Few LMS options let a university keep student submissions, grades and messages entirely within infrastructure it controls. The built-in data request and retention tools [1] give a privacy team practical levers that many SaaS products lack. The trade-off is responsibility: patching, backups, access logs, breach detection and plugin vetting all sit with the university or its hosting partner.

Plugins are where data leaves. On a self-hosted site, the risk usually comes from third-party plugins, LTI tools, video services and AI providers rather than Moodle HQ. Each one needs its own assessment, because a plugin that calls an external service usually brings in a new processor.

MoodleCloud means an Australian processor. Hosting in AWS Ireland [4] keeps the stored data in the EU, but Moodle's operating companies sit in Australia, the US and India [3]. Support or administrative access from those countries is a transfer, and Australia and India have no adequacy decision [5]. The SCCs Moodle publishes [2] are the expected tool, together with a transfer impact assessment.

The DPA has useful terms. A 48-hour breach notice, an explicit no-AI-training clause, a ban on solely automated decisions with significant effects and an Irish governing law [3] are all helpful to a European university. The questionnaire describes hosting as "usually" Ireland, so confirm the region for your site.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask before approving or renewing

  1. Which route do we use: self-hosted, a partner, or Moodle-hosted? Who is our processor, and which DPA applies?
  2. If Moodle-hosted: which AWS region holds our site, backups and logs, and is that region written into our contract?
  3. Which Moodle entities and staff locations can access our data for support, and under which transfer mechanism?
  4. Have we enabled Airnotifier, BigBlueButton or other services that send data to Moodle or its subprocessors, and are they in our records of processing?
  5. Which AI provider is configured, where does it process prompts, and what retention and training terms apply to it?
  6. Which learning analytics models are enabled, who sees the predictions, and have students been told?
  7. Which third-party plugins and LTI tools receive personal data, and does each have a DPA?

The EU AI Act angle

Annex III point 3 of the AI Act covers AI systems intended to evaluate learning outcomes, including when those outcomes steer the learning process, and systems that assess the level of education a person will receive [9]. Moodle's built-in "Students at risk of dropping out" model identifies students it predicts are at risk of dropping out, once trained on the site's own data [8]; whether a given configuration falls under Annex III depends on its intended purpose and use, and Article 6(3) excludes some narrow or preparatory systems unless they profile people [10]. Validemic's analysis Because Moodle ships the model but each site enables it and trains it on its own data, the split between provider and deployer roles is not obvious, and a university that runs it should document its own assessment of its role. The AI placements in core Moodle (text generation, image generation, summaries) are general assistance rather than assessment [6], but a plugin that grades or ranks students needs its own classification. Annex III obligations apply from 2 December 2027 under the amended Article 113 [11]. The duty that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI on their behalf [12].

Sources

  1. GDPR, Moodle 5.1 documentation, retrieved 7 October 2026
  2. Moodle Privacy Notice (last updated October 2025), retrieved 7 October 2026
  3. Moodle Data Processing Agreement, 2026 (PDF), retrieved 7 October 2026
  4. Moodle GDPR Questionnaire (PDF), retrieved 7 October 2026
  5. Adequacy decisions, European Commission, retrieved 7 October 2026
  6. AI placements, Moodle 4.5 documentation, retrieved 7 October 2026
  7. AI providers, Moodle 5.1 documentation, retrieved 7 October 2026
  8. Analytics, Moodle 5.1 documentation, retrieved 7 October 2026
  9. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689), retrieved 7 October 2026
  10. AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Moodle's privacy notice, its 2026 data processing agreement, its GDPR questionnaire, the Moodle LMS documentation on GDPR, AI and analytics, the European Commission's adequacy list and the relevant AI Act texts on 7 October 2026. We did not review individual Moodle partners or plugins. Our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Moodle complies with the GDPR. If you spot an error or Moodle has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Moodle GDPR compliant?

No software is GDPR compliant on its own. Moodle LMS includes privacy tools for policies, consent, data requests and retention, and Moodle offers a standard data processing agreement for its hosted services. Whether a university's use complies depends on who hosts it, the contracts in place, the plugins installed, the configuration and how students are informed.

Does Moodle HQ see our data if we host Moodle ourselves?

For a self-hosted site, the university or its hosting partner runs the servers. Moodle's DPA says the only Moodle mobile app function that involves processing by Moodle itself is the Airnotifier push notification service, which runs on AWS servers in Ireland if the site enables it. Other optional connections, such as AI providers, depend on what the university configures.

Where is MoodleCloud data stored?

Moodle's DPA names Amazon Web Services as the hosting subprocessor for MoodleCloud. Moodle's GDPR questionnaire says it usually hosts customer data in the AWS location closest to the customer, which usually means AWS Ireland for European customers. A university should confirm the region for its own site in writing.

Does Moodle use our data to train AI?

Moodle's 2026 DPA says the processor shall not train artificial intelligence models on customer personal data. In Moodle LMS itself, AI features run through an AI provider that the site administrator chooses and configures, such as OpenAI, Azure AI or a self-hosted Ollama model, so the provider's own terms also matter.

Do we need a DPIA for Moodle?

Usually yes, or at least a documented screening. An LMS holds data about nearly every student, including submissions and grades, and enabling learning analytics models or AI features adds new processing that should be assessed before it is switched on.