Who Owns Your Exam Data? The Coempt Takedown and the Case for Institutional Data Control
When CBSE shifted 1.6 lakh students' evaluation records off a private vendor's servers onto government infrastructure in June 2026, it exposed a vulnerability that every Indian university shares.

A Transfer That Should Never Have Been Necessary
On June 6, 2026, CBSE engineers began migrating all Class 12 on-screen marking evaluation records off Coempt Edu Teck's servers and onto government-controlled infrastructure. The operation took days. It required coordination between CBSE officials, Coempt's technical team, and the Ministry of Education's technology department. It involved moving evaluation data for 1.6 lakh students — marked answer sheets, evaluator annotations, moderation logs, and marks records — under conditions of an active Supreme Court case and public scrutiny.
The migration succeeded. But the fact that it had to happen at all — that the government discovered, mid-controversy, that national examination data was sitting on a private vendor's infrastructure without adequate institutional oversight — exposes a structural vulnerability in how Indian institutions procure and deploy examination technology.
Most Indian universities that use third-party examination software face a version of the same situation CBSE found itself in. The question worth asking now, before a crisis forces the answer, is simple: who actually owns your examination data?
The Anatomy of the Coempt Data Problem
Coempt Edu Teck was contracted to provide the technology platform for CBSE's on-screen marking system. The contract, awarded in December 2025, made Coempt responsible for the scanning infrastructure, the examiner portal, and the backend systems where marked answer sheets and evaluation records resided.
Three interconnected data problems emerged once the controversy became public.
Problem one: data residence. Evaluation records — including scanned answer sheets, evaluator identities linked to specific scripts, marks at the question level, and moderation decisions — were stored on infrastructure that Coempt operated and controlled. CBSE's access to its own examination data required Coempt's cooperation.
Problem two: security architecture. Ethical hacker Nisarga Adhikary publicly demonstrated access to a live Coempt production server and an unauthenticated AWS storage bucket containing student evaluation data. The exposure was not the result of a sophisticated attack. An unauthenticated storage bucket is a misconfiguration — a failure to set a basic access control on a cloud storage resource. This means student data had been sitting in that state for an unknown period, accessible to anyone who knew where to look.
Problem three: portability friction. When CBSE decided to move data off Coempt's infrastructure, the process was not a simple export. It required active engagement with the vendor during a period when the vendor was under investigation and facing potential liability. The lack of clear data portability provisions in the original contract created leverage — or at minimum, friction — at precisely the moment when smooth data transfer was most important.
These three problems are distinct but connected. Each would have been addressable through contractual and technical provisions that a more thorough procurement process would have required.
Why This Is Not Just CBSE's Problem
The CBSE-Coempt data episode attracted national coverage because of its scale. But the underlying situation — examination data residing with a vendor under contractual terms that give the institution limited control — is common across India's higher education sector.
When a university contracts a third-party examination management platform, the data generated by that platform — answer book scans, evaluator identities and performance metrics, question-level marks, moderation logs, student grievance records, result audit trails — is typically stored on infrastructure that the vendor controls. The institution accesses this data through the vendor's portal. The institution's technical team rarely has direct database access. The data's physical location (which data centre, which jurisdiction, which cloud provider) is often unspecified in the contract.
Under normal operating conditions, this arrangement is invisible. The university uses the platform, results are produced, and examination cycles proceed. The vendor's infrastructure never becomes a concern.
The visibility problem is that the arrangement's vulnerability only becomes apparent when something goes wrong: a vendor dispute, a financial failure, a regulatory investigation, a security breach, or an end-of-contract transition. At those moments, institutions discover what they should have established at the outset — whether they can access and export their own data, on their own terms, without the vendor's cooperation.
India's DPDP Act and Examination Records
The Digital Personal Data Protection Act, which came into force progressively through 2024 and 2025, adds a regulatory dimension to the data ownership question. Under the DPDP framework, universities act as Data Fiduciaries — they are responsible for the processing of students' personal data, including examination records, regardless of whether that processing is done by the university's own systems or by a contracted Data Processor.
The distinction matters practically. If a vendor experiences a data breach and student examination records are exposed, the university — not the vendor — is the party that bears primary accountability to the Data Protection Board. The university must issue the breach notification. The university faces the regulatory scrutiny.
This accountability structure makes the question of vendor data governance a compliance matter, not merely a procurement preference. A university that cannot demonstrate, in a DPDP audit, that it has contractual and technical mechanisms to ensure its examination data processors meet adequate security standards is exposed to regulatory liability.
The specific provisions relevant to examination data procurement include:
None of these requirements are onerous. But they do require that examination technology contracts are reviewed by personnel with DPDP awareness — not just by finance and IT departments operating under pre-DPDP procurement norms.
What Institutional Data Control Actually Looks Like
Data sovereignty in examination systems is not an argument against cloud infrastructure or third-party platforms. It is an argument for specific contractual and technical provisions that protect institutional interests regardless of what happens with the vendor.
Data portability provisions. The contract should specify the format in which data can be exported, the timeline within which an export must be completed on request, and the completeness of the export — including not just marks records but scan images, evaluator logs, moderation records, and audit trails.
Data residency requirements. Where is the data physically stored? In which country's jurisdiction? For public universities, data residency requirements may be implicit in government data localisation guidelines. For private institutions, the question should still be explicitly answered in the contract.
Security audit rights. The institution should have a contractual right to audit the vendor's security practices, or to require the vendor to produce third-party security audit reports on a defined schedule. This is standard in enterprise technology contracts and should be standard in examination technology contracts.
Breach notification timelines. The contract should specify the maximum time within which the vendor must notify the institution of a security incident affecting examination data. Under the DPDP framework, notification obligations run on tight timelines — a vendor who discovers a breach on a Friday evening and notifies the institution on Monday morning may already have triggered the institution's regulatory clock.
Escrow or backup provisions. For institutions using platforms where examination records are critical to result declaration, arrangements should exist for the institution to obtain a backup of current examination data at regular intervals during active examination periods — not just at contract end.
The Government Cloud Question
One response to data sovereignty concerns is to prefer platforms that deploy on government-certified cloud infrastructure — typically the MeitY-empanelled cloud service providers in India. This approach has genuine merit: government-empanelled providers have met baseline security and data localisation standards that a DPDP-compliant institution should require in any case.
However, government cloud residency does not substitute for the contractual provisions described above. Data can reside on a government cloud and still be inaccessible to the institution if the vendor controls the application layer and has not agreed to data portability terms.
The Coempt migration — the transfer of data from Coempt's infrastructure to government-controlled servers — illustrates this point. The destination was more appropriate than the origin. But the difficulty of the transfer was a contractual and technical problem, not primarily a hosting question. If Coempt had stored data on a government cloud but retained exclusive application-layer control, the migration would have been equally difficult.
The right answer is both: government-appropriate hosting standards and clear institutional data rights.
Recommendations for Examination Controllers and Registrars
For institutions that are currently under contract with an examination technology vendor, a practical first step is to review the existing contract against the following questions:
If the answer to any of these questions is no or unclear, the next contract renewal is an opportunity to correct it. If the next renewal is distant, it may be worth initiating a contract amendment discussion now — particularly in light of DPDP obligations that now apply regardless of when the contract was originally signed.
For institutions that are in the process of selecting a new examination platform, these questions should be part of the vendor evaluation process, weighted alongside technical capability and price. The CBSE-Coempt episode demonstrated that data governance questions, which are easy to defer during procurement, become impossible to defer during a crisis.
The examination record is one of the most sensitive data assets an institution holds. It connects a student's identity to their academic performance at a specific moment, evaluated by specific faculty, through a specific process. Institutions that treat that data as casually as they treat administrative email are taking on risks they have not adequately examined.
---
Related Reading
Ready to digitize your evaluation process?
See how MAPLES OSM can transform exam evaluation at your institution.