Summary: Privacy-First, Zero Behavioral Tracking
The Compliance Ledger does not deploy third-party advertising cookies, behavioral trackers, or biometric telemetry. We operate under strict data minimization in full compliance with India's Digital Personal Data Protection Act (DPDPA 2023).
1. Introduction & Institutional Scope
The Compliance Ledger ("we," "our," or "the publication"), accessible at complianceledger.in, is an independent, public-interest research publication providing evidence-qualified gap analysis of automated decision systems operating in sensitive Indian sectors.
This Privacy Policy explains how personal data is handled when you visit our website, communicate with our editorial team, or voluntarily submit an automated system for an opt-in review under our Feature 5 program. We are committed to upholding the rights of Data Principals as defined under the Digital Personal Data Protection Act, 2023 (DPDPA 2023) and the Information Technology Act, 2000.
2. Zero-Cookie Architecture & Local Storage
We fundamentally reject invasive tracking infrastructure:
- No Commercial Tracking or Ad Pixels: We do not load Meta Pixels, Google Analytics retargeting tags, or commercial ad networks.
- Zero Tracking Cookies: The website does not set non-essential persistent cookies on your device.
- Client-Side Local Storage: The only persistent state saved in your browser is a single key (
theme: 'light' | 'dark') within your browser’slocalStorage, used strictly to maintain your visual display preference across visits. This data never leaves your device and is not transmitted to our servers.
3. Personal Data We Collect
In accordance with Section 6 of DPDPA 2023 (Purpose Limitation), we collect only the personal data strictly required to fulfill specific, legitimate interactions:
A. Voluntarily Submitted Inquiries (Contact & Feature 5 Reviews)
When you contact our editorial team or submit an organization for an opt-in evaluation via our contact or review forms, we collect:
- Full name and professional affiliation (organization/entity name).
- Work email address and official contact details.
- Subject line, message content, and submitted documentation (e.g., published URLs, policy links, right-of-reply clarifications).
This information is processed exclusively to respond to your inquiry, facilitate pre-publication right-of-reply communications, or process audit requests.
B. Technical Server Telemetry
When you browse the website, standard edge web servers temporarily record ephemeral technical requests:
- IP address (anonymized/truncated where feasible).
- Timestamp and HTTP request method / response status code.
- User-agent string and referring URL.
This telemetry is collected solely under legitimate system administration purposes (preventing Distributed Denial of Service [DDoS] attacks, maintaining server availability, and diagnosing routing errors). Logs are automatically purged within 30 days.
4. Treatment of Third-Party Entities Evaluated in Reports
The Public Evidentiary Boundary
The Compliance Ledger’s gap analysis reports investigate algorithmic decision systems based strictly on publicly accessible, verifiable documentation—including published terms of service, public privacy notices, regulatory filings, job requisitions, and technical whitepapers.
We do not access, purchase, scrape, or process non-public databases, end-user personal records, private customer transaction logs, or confidential employee communications.
5. Legal Grounds for Processing (DPDPA 2023)
Under DPDPA 2023, personal data is processed under the following lawful bases:
- Specified Purpose & Consent (Section 6): For inquiries and Feature 5 review submissions, your submission constitutes clear affirmative action for the specific purpose of corresponding regarding your submission.
- Legitimate Uses (Section 7): Technical telemetry is processed for the legitimate interest of cybersecurity, fraud prevention, and maintaining website operational integrity.
6. Data Retention & Deletion
We retain personal data only for as long as necessary to satisfy the purpose for which it was collected:
- Inquiries & Correspondence: Retained for the duration of the communication cycle and archived for up to 24 months for audit defensibility, unless an earlier erasure request is submitted.
- Technical Edge Logs: Automatically rotated and purged after 30 days.
- Public Reports: Evaluated organizational disclosures are preserved as permanent historical records of public corporate disclosures as of their evaluation date.
7. Rights of Data Principals under DPDPA 2023
As a Data Principal under Indian law, you are entitled to exercise the following rights regarding any personal data we hold about you:
Right to Access
Obtain confirmation of whether your personal data is being processed, and access a summary of data held along with processing activities.
Right to Correction & Erasure
Request correction of inaccurate or misleading personal data, completion of incomplete data, or erasure of data no longer required for processing.
Right to Grievance Redressal
Have your complaints reviewed and resolved expeditiously by our designated Grievance Redressal Officer.
Right to Nominate
Designate another individual who shall exercise your rights in the event of death or incapacity.
8. Grievance Redressal Officer (DPDPA Section 8 Mandate)
In compliance with Section 8(10) of the DPDPA 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have designated a Grievance Redressal Officer to handle data protection inquiries and complaints:
Attention: Data Protection & Grievance Redressal Desk
Publication: The Compliance Ledger (complianceledger.in)
Jurisdiction: Bengaluru, Karnataka / New Delhi, India
Direct Redressal Email: grievance@complianceledger.in
Response Commitment: Initial acknowledgment within 48 hours; substantive resolution within 30 days as mandated by law.
9. Changes to this Policy
We may periodically update this policy to reflect statutory developments under DPDPA subordinate rules or modifications to publication workflows. All updates will be published on this page with an updated "Effective Date" and recorded in our public Changelog.