Skip to main content
Home Legal
India Privacy and Data Protection

India Privacy and Data Protection

Version 1.0 · Effective 22 August 2026

This supplement states what DECTIFY owes you under Indian data protection law — the Digital Personal Data Protection Act, 2023 above all — and how to make us do it.

Global DPDP Act 2023 IT Act 2000 s.43A SPDI Rules 2011 Data Protection Board

Read this together with the Privacy Policy. Where the two differ for a person in India, this page governs.

1. The legal framework

DECTIFY's handling of personal data in India is governed principally by the Digital Personal Data Protection Act, 2023 and the rules made under it. The following also apply where relevant:

  • Information Technology Act, 2000, section 43A (compensation for failure to protect data) and section 72A (punishment for disclosure in breach of contract).
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — the SPDI Rules — to the extent they continue to operate alongside the DPDP Act.
  • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, for grievance handling and content takedown.
  • CERT-In Directions of 28 April 2022, for incident reporting, log retention and clock synchronisation — dealt with at India Cybersecurity and Technology.
  • Bharatiya Nagarik Suraksha Sanhita, 2023, where a lawful authority compels production — dealt with at Government and Law Enforcement Requests.

2. Who is who under the DPDP Act

Statutory roleWho fills itFor what data
Data FiduciaryDECTIFYWebsite visitors, enquiries, job applicants, and the staff of customers whose accounts we administer
Data ProcessorDECTIFYAll Customer Data — footage, plates, biometric templates, alerts — processed on a customer's documented instructions
Data FiduciaryOur customerAll Customer Data. The customer decides the purpose and means; we do not.
Data PrincipalYouAny personal data relating to you

The distinction decides who you ask. If your question is about the DECTIFY website, our marketing, or your account with us, ask us. If it is about footage of you captured at a shop, campus, factory or road, the operator of those cameras is the Data Fiduciary and the request goes to them — we will route it and assist, but we cannot decide it.

3. Notice and consent

3.1 Notice. Where we rely on your consent, we give a notice meeting section 5 of the DPDP Act before or at the time of collection: what personal data we want, the specified purpose, how to exercise your rights, and how to complain to the Data Protection Board. The notice is available in English and in the languages listed in the Eighth Schedule to the Constitution on request.

3.2 Consent. Consent we rely on is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the personal data necessary for the stated purpose. We do not use pre-ticked boxes, bundled consent, or consent as a condition of providing something that does not need it.

3.3 Withdrawal. You may withdraw consent at any time, and it must be as easy to withdraw as it was to give. Write to privacy@dectify.in or use the in-product control. Withdrawal does not affect processing already lawfully carried out. On withdrawal we, and our processors, cease processing within a reasonable period unless another law requires retention.

3.4 Legitimate uses (section 7). Where we do not rely on consent, we rely on a legitimate use — typically voluntary provision of data for a purpose you asked us to fulfil, compliance with a legal obligation or judgment, or responding to a medical emergency or a threat to public health or safety. We record which limb we rely on and will tell you which it was.

3.5 Consent Managers. Where you choose to give, manage, review or withdraw consent through a Consent Manager registered with the Data Protection Board, we will honour instructions received through it.

4. Your rights as a Data Principal

RightSectionWhat we do
Access information about processings.11Confirm whether we process your data, provide a summary of it and of the processing, and identify the other Data Fiduciaries and Processors we shared it with and what was shared
Correction, completion, updatings.12Correct inaccurate or misleading data, complete incomplete data, update it
Erasures.12Erase data unless retention is necessary for the specified purpose or required by law
Grievance redressals.13Provide a readily available means of registering a grievance, and respond within the prescribed period
Nominates.14Record a nominee who may exercise your rights in the event of your death or incapacity

4.1 How to exercise. Write to privacy@dectify.in, or use the route at Grievance Redressal. Requests are free. We may need to verify your identity, and we will ask for the minimum needed to do that.

4.2 Timelines. We acknowledge within three (3) business days and substantively respond within the period prescribed under the DPDP Rules. If we need longer, we will tell you before the deadline and explain why.

4.3 Your duties. Section 15 of the Act places duties on Data Principals, including not impersonating another person, not suppressing material information, and not raising false or frivolous grievances. We mention this because the Act attaches penalties to it, not because we expect it to arise.

5. Children and persons with disability

Section 9 of the DPDP Act prohibits processing that is likely to cause any detrimental effect on the well-being of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Verifiable consent of a parent or lawful guardian is required before processing a child's personal data, and equivalent consent is required from a lawful guardian of a person with disability who has a guardian appointed.

Our website is directed at businesses and public bodies and we do not knowingly collect children's data through it. In deployed systems, enrolment of a minor into any gallery is restricted as described at Biometric, ANPR and Facial Recognition Policy, clause 9.3.

6. Security safeguards

Section 8(5) requires reasonable security safeguards to prevent a personal data breach. Ours are described at India Cybersecurity and Technology and, in summary, comprise encryption in transit and at rest, least-privilege role-based access control, mandatory multi-factor authentication on privileged accounts, network segregation, append-only audit logging, continuous vulnerability management, annual penetration testing, and personnel training.

We also require equivalent safeguards from every Data Processor we engage, by contract, as listed at Sub-processors.

7. Breach notification

On becoming aware of a personal data breach we will:

  • Notify the Data Protection Board of India and each affected Data Principal in the form and within the time prescribed under section 8(6) and the DPDP Rules.
  • Report to CERT-In within six (6) hours where the incident falls within the Directions of 28 April 2022.
  • Notify affected customers, where the breach concerns Customer Data, without undue delay and in any event within seventy-two (72) hours, with the information they need to meet their own obligations.

Notification describes what happened, the categories and approximate volume of data involved, the likely consequences, the measures taken and proposed, and what you can do to protect yourself. We notify whether or not we are at fault.

8. Retention and erasure

Section 8(7) requires erasure once consent is withdrawn or the specified purpose is no longer served, unless retention is necessary for compliance with a law. Our periods for every data class are at Data Retention Schedule. Where an Indian statute compels retention — company law, tax law, the CERT-In log retention direction — we retain only for that period and only that data.

9. Cross-border transfer

Section 16 of the DPDP Act permits transfer outside India except to countries restricted by notification of the Central Government. DECTIFY hosts Indian Customer Data in an India region by default. Where a sub-processor outside India is engaged, it is listed at Sub-processors with its location and function, it is bound by contract to DPDP-equivalent obligations, and we monitor the restricted-country list and will migrate away from any provider that becomes non-permissible.

Sectoral rules that impose stricter localisation — for example those applying to regulated financial or telecom customers — take precedence, and we will configure a deployment to meet them where a customer identifies the requirement.

10. Significant Data Fiduciary obligations

The Central Government may notify a Data Fiduciary, or a class of them, as a Significant Data Fiduciary under section 10, which brings additional duties: appointing a Data Protection Officer based in India and answerable to the board, appointing an independent data auditor, and conducting periodic Data Protection Impact Assessments and audits.

DECTIFY has not been notified as a Significant Data Fiduciary. We nonetheless already operate a named data protection contact in India, conduct impact assessments before releasing any capability that processes biometric data, and commission independent security assessment. If we are notified, we will publish the fact here and the identity of the appointed officer at Grievance Redressal.

11. Complaints and escalation

  1. Us first. privacy@dectify.in, or the Grievance Officer named at Grievance Redressal.
  2. Then the Board. If we do not respond within the prescribed period, or you are not satisfied, you may complain to the Data Protection Board of India. The Board may impose monetary penalties under the Schedule to the Act.
  3. Appeal. An order of the Board is appealable to the Telecom Disputes Settlement and Appellate Tribunal.

If your question is about footage. The organisation operating the cameras is the Data Fiduciary, not us. Its details should be on the signage at the site. If you cannot identify it, send us the location, date and approximate time and we will route your request or tell you no DECTIFY system operates there.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India