GDPR
The General Data Protection Regulation governs the processing of personal data belonging to people in the EU and the European Economic Area. Any organisation processing that data has to comply, which includes almost every institution of higher education in the EU and the tools they use.
The distinction that matters for an LTI® integration is between a controller, which decides why data is processed, and a processor, which acts on the controller's instructions. The institution is normally the controller and the tool the processor.
LTIAAS acts as a processor. See our data processing addendum and compliance pages.
