DPDP disclosures

The Digital Personal Data Protection Act, 2023 sets out how personal data must be handled in India. This page states how VerifyBG meets it, and is honest about what is still in progress.

Our role

For subject data, the requester who raises a check is the Data Fiduciary deciding the purpose. VerifyBG acts as a Data Processor executing that check, and as a Data Fiduciary in its own right for the account data of requesters.

Lawful basis

We rely on consent, and only consent. There is no legitimate-interest processing of subject data on this platform. See the consent framework for exactly how it is obtained and recorded.

Notice

Subjects are shown an itemised, plain-language notice of every check category before they sign, along with the retention period and their rights. The notice is not buried in a link or a scrollbox.

Data principal rights, and how to use them

Cross-border transfer

Sanctions, PEP and adverse-media screening is performed by Didit, a provider based outside India. Performing that check necessarily transfers the subject's name, and where supplied their date of birth and an identifier, outside the country. We send only the fields required to perform the match, and never the results of other checks, the stated purpose, or the requester's identity.

This transfer happens under the same consent that authorises the check itself. A subject who does not consent has nothing transferred, because no check runs at all. The provider is named here rather than described generically so that a data principal can look them up and make their own judgement.

Corporate registry verification queries GLEIF, an international register, which likewise involves sending the supplied identifier or company name outside India. All other checks, including identifier structural validation and the locally held sanctions lists, run entirely on our own servers.

Data minimisation in practice

We collect only the fields a requester enters, and only the checks the chosen tier includes. A subject's PAN is used to perform the identity check but is never sent back to the requester's browser. Data exports exclude raw third-party responses, because those can contain information about people other than the person exporting.

Retention

A fixed 30 day clock starts when a request is created. An automated sweep purges subject identifiers, check results and raw source responses once it expires, and anonymises the consent record while keeping proof that consent existed.

Security measures

What is not yet in place

We would rather state this than imply completeness we have not reached:

Grievance officer

The grievance officer for Bitola Industries Pvt Ltd can be reached through our contact page. We aim to acknowledge within 72 hours.