Aviso de Privacidad

Last updated: June 2025

Moodle Pty Ltd and its affiliated companies (“Moodle”, “we” or “us”), is the company at the heart of the open source Moodle Project: empowering educators to improve our world. This privacy notice sets out how Moodle collects and uses information about you when you use our products and services (“services”) and why we collect certain personal data. This notice also explains the choices that you can make about the way that we use your information.

Your privacy protection is important to us. This is why we have adopted the following pivotal legislation: EU’s General Data Protection Regulation 2016/679 (“GDPR”), UK General Data Protection Regulation (“UK GDPR”) and the California Consumer Privacy Act 2018 (“CCPA”). This privacy notice relates to all personal data we process and addresses the legislation mentioned.

‘Personal data’, in this privacy notice, means any information that relates to an identified or identifiable natural person, such as a name, an identification number, location data, or online identifiers (including cookies). An identifiable natural person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Useful resources

We remain committed to building a secure LMS that protects the privacy and security of learners' and employees’ data. We provide all users with the tools to ensure that their data, information and operations are secure and protected. Privacy features embedded with Moodle LMS ensure that Moodle is GDPR compliant and adheres to local privacy legislation requirements. However, some responsibility for compliance and safety rests with the organisation that controls each Moodle installation. We encourage institutions and organisations to implement security measures for their Moodle installation and:

  • write multiple policy documents (including site policy for guests) so that they can be completely transparent with their learners, educators and anyone who visits their site on how they collect, use or disclose their data;
  • protect digital minors with age-of-consent checks and manage access for minors who require parental agreement to access their learning management system;
  • handle all data requests from learners and keep track of retention periods in a centralised place; and
  • enable users to easily request access or download their data, to see the policies they’ve agreed to and appoint a Privacy officer role to manage subject access/deletion requests from such users centrally.

We have also included some useful resources for your use in engaging with MoodleHQ:

Why we collect your personal data

In order for us to provide you with our services or for correspondence purposes we need to collect your personal data. We ensure that the information we collect and use is confined to this purpose. We always process your personal data for specific purposes, with the nature of the data collected depending on your interaction with us. We are committed to transparency in this.

Our legal bases for controlling or processing personal data are:

  • Article 6.1(a) GDPR (Consent): You provide informed consent to us or have a reasonable expectation that we will use your information in a certain way – for example, to engage in our community discussions, or to hear about new services or offers. You have the right to withdraw your consent at any time either by selecting ‘delete my data’ within the specific service or by request to privacy@moodle.com;
  • Article 6.1(b) GDPR (Contract): Providing our services and fulfilling our obligations to you, usually relating to a terms of service or partnership agreement;
  • Article 6.1(c) GDPR (Legal Obligation): The necessity to meet compliance with our legal obligations; and/or
  • Article 6.1(f) GDPR (Legitimate Interest): Where it is in our legitimate interests to do so. We only rely on ‘legitimate interests’ as the legal basis for processing by us, or third parties we use, for these purposes:
    • recruitment and induction of new employees, contractors and other people who work with us;
    • emergency contacts for people who work with us, such as employees and contractors for health and safety purposes;
    • business development; or
    • providing login systems to users via their existing social media accounts.

Where we rely on a specific basis for processing your information and you wish to object to that processing, you must be aware that it might not be possible for you to continue using our services.

The special categories of personal data (Article 9 of GDPR) we process are:

  • biometric data in the form of facial images, where you have uploaded and we store your profile picture;
  • health data in respect of employees, contractors and other people who work with us; and/or
  • any special categories of special personal data which any user volunteers while using our services (for example in a forum or submission).

If we need to pass on special category personal data (see Article 9 of GDPR) to a third party, we will only do that in accordance with the legal bases under Article 6 of GDPR as outlined above. This data is processed only in accordance with the legal grounds outlined in GDPR Article 9.

If you would like more details please refer to our Register of GDPR Information.

How we collect personal data

Moodle collects personal data from you when you interact with us. This can be through our websites, over the phone, in person, including, without limitation, when you:

  • create an individual or corporate user account;
  • request support;
  • register for or participate in an online class, exam, certification, training, webcast or other event;
  • request information or materials;
  • participate in surveys or evaluations;
  • participate in promotions, contests or giveaways;
  • make a purchase through our shop or register products;
  • apply for employment;
  • submit questions or comments; or
  • submit content or posts on our forums or other interactive webpages.

How we use personal data

We may need to pass your personal data on to third-party service providers contracted to Moodle in the course of dealing with you. We do this because there are services, such as our video conferencing facility, which will not work unless we are able to make these transfers. Any third parties we share your data with are obliged to keep your personal data secure and use it only for necessary service delivery. When your data is no longer required to fulfil the service, those third parties will be directed to dispose of your data in accordance with our standard procedures.

We seek to enter into Data Processing Agreements with our third party service providers to ensure they only process your data as instructed by us. If you obtain products or services directly from us on behalf of others we will ensure you enter into a Data Processing Agreement (DPA) with us. You will also need to enter into a DPA with your students/employees/customers when using our systems.

How we store personal data

We will process (collect, store and use) the information you provide in a manner compatible with GDPR. We maintain physical, organisational and technical safeguards for all personal data we hold. We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary. We retain personal data for as long as necessary to fulfill the purposes outlined in this privacy notice or as required by law. Retention periods are determined based on the type of data and the purpose for which it was collected.

We will process different forms of personal data for as long as it is necessary and proportionate for the purpose for which it has been supplied and we will store the personal data for the shortest amount of time possible, taking into account legal and service requirements.

Sharing personal data with Third Parties

We do not share with, or receive personal information from, third parties unless it is necessary for the provision of our services and is carried out in accordance with applicable Data Processing Agreements (DPAs) and data protection laws.

Marketing

We have no interest in collecting any data beyond that needed to ensure our services work for you. If we wish to contact you for marketing purposes, we will seek your explicit consent before doing so. You may withdraw your consent to marketing at any time by following the unsubscribe instructions provided in our communications. Moodle does not sell data, and has no intentions in doing so in the future.

Your rights when we process your personal data

At any point while we are in possession of or we process your personal data, you have the following rights:

  • right to withdraw consent;
  • right of access;
  • right of rectification;
  • right to erasure;
  • right of data portability;
  • right to restrict processing;
  • right to object;
  • right to object to automated processing, including profiling;
  • right to know;
  • right to opt out of the sale of your personal information, although we do not sell your data;
  • right to judicial review: in the event that we refuse your request under rights of access, we will provide you with a reason as to why;
  • right to be free of discrimination if you exercise your rights;
  • notification of data breaches; and/or
  • the right to lodge a complaint with a supervisory authority.

Where we are your Data Controller, please make your request directly to the Data Protection Officer at dpo@moodle.com. We will always respond within one month.

However, if we are processing your data on behalf of your Data Controller (your service provider) you should contact them directly.

Privacy notices of other websites

This privacy notice outlines how we manage your personal data. If the website you are using is not hosted by us or you click on a link to another website, we encourage you to read their privacy notice.

Where we are not involved with your personal data, such as where the Moodle software has been self-hosted, you should address your requests to the Data Controller of the website since we have no access to your personal data.

Children and Personal Data

Here at Moodle we understand the importance of protecting the personal data of children under the age of 16. It is not our intention to ever directly collect personal data from a child. If you believe that a child has disclosed personal data to us directly or that we wrongly hold personal information about a child, please email us at privacy@moodle.com. If we become aware that a child under the age of 16 has provided us with personal data, we will take steps to delete that information as soon as possible, unless required to retain it for legal or contractual reasons.

Verification

Before we action a personal data request we need to verify your identity. We accept a request made through your personal Moodle account while you are logged in. We sometimes require additional information such as a colour copy of your passport, driving licence or national ID card.

Amendments to our Privacy Notice

Moodle updates our privacy notice when necessary or in response to:

  • feedback from our community, customers, relevant authority, industry or other stakeholders;
  • changes in our products or services; and/or
  • data processing or policy changes.

The “last updated” date at the top of this privacy notice reflects when the most recent changes were made. If we make significant changes to how we process your personal data, we will notify you directly (e.g., a prominent notice on our website) to ensure you are aware of the updated terms. We encourage you to periodically review this privacy notice for any amendments.

How to contact us

If you have any questions about our privacy notice, please contact us via our Feedback Form, or by email at privacy@moodle.com, or by mail at:

Moodle Pty Ltd
PO Box 303
West Perth WA 6872
Australia

How to contact the appropriate authorities

If you have questions or wish to lodge a complaint about how your personal data is being processed by us (or third parties as described above) you have the right to contact a supervisory authority and also our Data Protection Officer, Data Compliance Europe Ltd.

Our independent Data Protection Officer is:
Data Compliance Europe Ltd.
12 City Gate
Lower Bridge Street, Dublin 8
Ireland
Email: dpo@moodle.com

Our supervisory authority is:
Data Protection Commissioner
21 Fitzwilliam Square S,
Dublin 2,
D02 RD28
Email: info@dataprotection.ie
Phone: +353 57 8684800

Register of GDPR Information

If you would like more details about the types of information we process, please refer to our Register of GDPR Information.