- What it describes
- Personal data that has already left your organisation’s control and is now reachable from outside it — leaked credentials tied to customer or staff identities, storage that answers without authentication, documents a search engine has indexed, and source repositories carrying customer records. Each of those is an observable fact about a system on the public internet.
- What it is not
- It is not legal advice and it is not a reading of the Digital Personal Data Protection Act, 2023. Nothing here tells you whether a given exposure is a personal data breach under the Act, whether a notification duty arises, who would have to be told, or on what timeline. ShadowMap does not make an organisation DPDP-compliant, and no finding should be read as saying that it does.
- Where the statutory question belongs
- With your legal counsel and whoever owns data protection in your organisation, with the evidence in front of them. What monitoring contributes is that evidence — specific, attributable and repeatable. Where the readiness work itself needs doing — applicability, consent, rights workflow, processor due-diligence — that is an advisory engagement, and Security Brigade runs it on a separate site under a separate scope.