DPDP Act compliance for Indian data principals.
ShadowMap is operated from India by an Indian company, and most of the estates it monitors sit under Indian regulators. This page sets out how we meet our obligations under the Digital Personal Data Protection Act, 2023 — as a Data Fiduciary for our own processing, and as a Data Processor for everything inside a customer tenant.
1. About the DPDP Act
The Digital Personal Data Protection Act, 2023 ("DPDP Act", Act No. 22 of 2023, enacted 11 August 2023) is India's data protection legislation. It establishes the framework for processing digital personal data, defines the rights of Data Principals, sets out the obligations of Data Fiduciaries, and creates the Data Protection Board of India as the enforcement authority.
Security Brigade InfoSec Private Limited ("Security Brigade"), the company that builds and operates ShadowMap, is incorporated in India with its registered office in Mumbai, Maharashtra. We comply with the DPDP Act and with the subordinate rules as they are notified by the Central Government.
This page supplements our Privacy Policy and should be read alongside it. Where your organisation is also subject to the GDPR, see the GDPR page.
2. Our roles: Data Fiduciary and Data Processor
We are a Data Fiduciary when we determine the purpose and means of processing ourselves: website visitors, enquiry and demo submissions, prospective and existing customer contacts, platform user accounts, billing records, and our own employees and applicants.
We are a Data Processor for everything inside a customer's ShadowMap tenant — discovered assets, exposed services, leaked code and secrets, brand-abuse cases, credential and dark-web exposure attributed to that customer, vendor exposure, validation evidence and workflow history. That material is processed on the customer's instructions, against a scope the customer authorises, under the Data Processing Agreement in Section 10. The customer organisation is the Data Fiduciary for it.
Because ShadowMap runs continuously rather than as a discrete engagement, our processor obligations run for the whole subscription, and our erasure obligations are calendar-bound to termination rather than to the close of a project.
3. Lawful grounds for processing (Section 4)
Under the DPDP Act, personal data may be processed for a lawful purpose with consent, or for a certain legitimate use specified in the Act. We rely on:
- Consent (Sec. 6). Where we collect personal data directly from you — a demo request, a newsletter subscription, a non-essential cookie — we obtain free, specific, informed, unconditional and unambiguous consent by clear affirmative action, with the purpose stated in plain language at the point of collection.
- Voluntary provision for a specified purpose (Sec. 7(a)). Where you give us your details for a stated purpose — asking for a proposal, submitting a security report, requesting documentation — we process them for that purpose.
- Compliance with a judgment or order (Sec. 7(d)). Where processing is necessary to comply with any judgment, decree or order issued under Indian law.
- Employment purposes (Sec. 7(i)). For processing employee data necessary to safeguard the employer from loss or liability, to prevent corporate espionage, and to protect trade secrets and confidential information.
4. Consent management (Section 6)
- Notice before consent. Before collection we give an itemised notice describing the personal data collected, the purpose of processing, how to exercise your rights, how to withdraw consent, and how to file a grievance.
- Specific and informed. Consent is sought separately for each distinct purpose. We do not bundle unrelated purposes into a single acceptance.
- Plain language. Consent requests and privacy notices are presented in clear, plain English, and in Hindi where applicable, so that they can actually be understood.
- Easy withdrawal. Withdraw at any time by writing to dpo@securitybrigade.com or by using the unsubscribe link in any marketing email. We stop the relevant processing as soon as practicable. Withdrawal does not affect the lawfulness of processing carried out before it.
- Record keeping. We keep auditable records of consent — the notice given, the time and manner of consent, and any later modification or withdrawal.
5. Rights of Data Principals (Sections 11-14)
- Right to access information (Sec. 11). A summary of the personal data we process about you, the processing activities undertaken, and the identities of Data Fiduciaries and Data Processors with whom it has been shared.
- Right to correction and erasure (Sec. 12). Correction of inaccurate or misleading data, completion of incomplete data, updating, and erasure of data no longer necessary for the purpose for which it was collected. On a valid request we act and notify any Data Processor acting on our behalf.
- Right to grievance redressal (Sec. 13). Registering a grievance with our Grievance Officer, with acknowledgement and resolution within the prescribed periods, and escalation to the Data Protection Board of India if you are not satisfied.
- Right to nominate (Sec. 14). Nominating another individual to exercise your rights in the event of death or incapacity. We honour validly executed nominations.
Write to the Grievance Officer in Section 11. We verify identity before acting. Where we hold the data as a Data Processor on a customer's behalf, we forward the request to that customer as Data Fiduciary and tell you we have done so.
6. Our obligations as Data Fiduciary (Section 8)
- Purpose limitation. We process personal data only for the specific lawful purpose notified to you, and not for purposes beyond what is necessary and consented to.
- Data minimisation. We collect only what the purpose requires. The enquiry form on this site asks for a work email, a company and — optionally — an apex domain, because that is genuinely all that is needed to start an evaluation.
- Accuracy. We take reasonable steps to keep data complete, accurate and not misleading, and provide mechanisms to update it.
- Storage limitation. Data is retained only as long as the purpose requires or the law demands, then securely erased. Retention periods are set out in the Privacy Policy.
- Reasonable security safeguards (Sec. 8(4)). Encryption at rest using AES-256 or equivalent and in transit using TLS 1.2 or higher, role-based least-privilege access, mandatory multi-factor authentication for production systems, privileged-access logging and review, centralised logging and monitoring, and a documented secure development lifecycle for the platform. Detail is on the security page.
- Erasure on purpose fulfilment (Sec. 8(7)). When the purpose is fulfilled and retention is not required by law, we erase the data.
- Processor obligations under Sec. 8(2). Where we engage sub-processors, they are bound by written contract to obligations no less protective than our own, and we remain accountable for their performance.
7. Breach reporting
In the event of a personal data breach we notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under Section 8(6) and the rules made under the Act. Where we are acting as Data Processor, we notify the customer as Data Fiduciary without undue delay and in any event within seventy-two hours of becoming aware, providing what they need to discharge their own obligations.
We separately comply with CERT-In's mandatory incident reporting requirements under the Information Technology Act, 2000, including the six-hour reporting window in the directive of 28 April 2022 where an incident falls within its scope.
8. Personal data inside exposure intelligence
This is the section that differs most from a consulting firm's DPDP page, and it deserves a direct answer rather than a general one.
ShadowMap continuously collects material that is already exposed outside the customer's perimeter: discovered assets and services, publicly reachable documents, code and secrets in repositories the customer does not control, brand impersonation, and dark-web and infostealer material. Infostealer output is device-level — credentials, session cookies and tokens, autofill entries, browser history, payment and wallet artefacts, and machine information — and it can therefore contain the personal data of Indian Data Principals who have no relationship with us or with our customer.
How that processing is constrained:
- Security purpose only. The material is processed to detect, evidence and help remediate exposure affecting a monitored estate. It is not sold, licensed as a data product, used for profiling or marketing, or used to enrich a contact database.
- Attribution gates disclosure. A customer tenant surfaces only material correlated to that customer's identities and assets. The platform is not a searchable index over the corpus and cannot be used to look up an arbitrary individual or an unrelated organisation.
- Credentials are for revocation. Recovered credentials are treated as compromised regardless of how briefly they were exposed, and are reported so that they can be rotated or revoked. They are tested only against a customer's own authorised in-scope estate, never against a third party.
- Access control and audit. The material is held under role-based access control with logging of access, and every workflow decision taken on a finding is recorded.
- No transmission to model providers. Customer personal data is not transmitted to third-party large language model providers. That is a contractual commitment in our Data Processing Agreement, not merely a practice.
The output of an exposure investigation is an input to a regulatory decision, not the decision itself. Where an exposure investigation is relevant to a Data Fiduciary's notification obligation under Section 8(6), we supply the evidence — what was exposed, when it was first observed, what it reaches — so that the Data Fiduciary can scope its own decision. We do not make that decision, and nothing in the platform constitutes legal or regulatory advice.
If your personal data appears in this material, write to dpo@securitybrigade.com and we will deal with it under Section 5, routing the request to the relevant Data Fiduciary where we hold the material as a Processor.
9. Residency and cross-border transfer (Section 16)
Section 16 of the DPDP Act permits transfer of personal data outside India except to countries specifically restricted by the Central Government by notification. As at the date of this page no such restriction affects the jurisdictions in which we operate; we monitor notifications and will change our practice immediately if one is issued.
Independently of that permissive position, residency is configurable. Where you elect data localisation, we configure storage and backup locations accordingly. Regions currently available are Mumbai, Paris, Singapore and Dubai, with further regions on request, and a customer-specific private-cloud deployment is available where region-level separation is not enough. Indian regulated entities that require data to remain in India can be provisioned entirely on the Mumbai region, and the arrangement is recorded in the order form rather than left to assurance.
Where your organisation is also subject to the GDPR, the transfer safeguards on our GDPR page apply in addition.
10. Data Processing Agreement
Where we process personal data on your behalf as a Data Processor, our standard Data Processing Agreement governs how we handle it — including instructions, confidentiality, security measures, sub-processors, assistance with Data Principal requests, breach notification and destruction on termination. It is published in full: read or download the DPA. We also accept customer-provided DPAs — send redlines or your draft to privacy@securitybrigade.com.
11. Grievance Officer
In compliance with Section 13 of the DPDP Act and Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have designated a Grievance Officer:
Grievance Officer
Security Brigade InfoSec Private Limited
Registered Office: Mumbai, Maharashtra, India
Email: dpo@securitybrigade.com
Acknowledgement within 48 hours; resolution within the period prescribed by law
If you are not satisfied with our response, you may escalate to the Data Protection Board of India, once constituted and operational under the DPDP Act.
12. Duties of Data Principals (Section 15)
The Act also places duties on Data Principals. When dealing with us you are expected to:
- comply with applicable law when exercising your rights under the Act;
- not impersonate another person when providing personal data;
- not suppress material information when providing personal data for a specified purpose;
- not file a false or frivolous grievance or complaint;
- furnish verifiably authentic information where it is required for the purpose of processing.
13. Relationship with other laws
Our DPDP obligations operate alongside:
- the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures) Rules, 2011;
- CERT-In directions dated 28 April 2022 on the reporting of cyber security incidents;
- sector-specific requirements from RBI, SEBI, IRDAI and TRAI as they apply to our customers and, where relevant, to us as their service provider;
- the Indian Contract Act, 1872 and the Companies Act, 2013.
ShadowMap produces the dated, timestamped, auditable record of continuous external monitoring that regulated entities use to evidence that a monitoring control actually operated — over what scope, on what date, with what result. That is evidence generation, not compliance advisory. For advisory work on RBI, SEBI CSCRF, IRDAI and related frameworks, see securitybrigade.com.
14. Updates to this page
The DPDP framework is still filling in: the Central Government continues to notify subordinate rules, and the Data Protection Board is being operationalised. We update this page as rules, notifications and guidance are issued, and the "last updated" date changes with it.
15. Contact
Grievance Officer / Data Protection Officer
Security Brigade InfoSec Private Limited
Registered Office: Mumbai, Maharashtra, India
Email: dpo@securitybrigade.com
Privacy enquiries: privacy@securitybrigade.com
Contractual and legal enquiries: legal@securitybrigade.com
Security reports: security@shadowmap.com
Data stays in India if you need it to.
Mumbai-region provisioning, private-cloud deployment and a published DPA — the three things Indian regulated buyers ask for before anything else. Bring your apex domain and we will show you the platform in 30 minutes.