DPDP Act 2023 Compliance

Last Updated: July 30, 2026

PehleVerify was built from the ground up to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). This page explains, in detail, how our platform architecture and processes implement the Act's requirements.

1. Our Compliance Commitment

We are, to our knowledge, among the first consumer-facing background verification platforms in India built with DPDP Act compliance as a foundational design principle rather than a later addition. Every core workflow — consent collection, data processing, notification, retention, and deletion — was designed with the Act's requirements in mind.

2. Lawful Basis for Processing

Under Section 4 of the DPDP Act, personal data may only be processed for a lawful purpose with the consent of the data principal, or for specified legitimate uses. PehleVerify processes data under explicit, purpose-specific consent obtained at two points:

From the Requester: Before any check begins, the requester must affirmatively confirm, through individually checked consent items (not a single bundled checkbox), that they have a legitimate purpose, understand the notification requirement, confirm the subject is an adult, and agree to our data usage terms.

From the Subject (where applicable): In Consent Link Mode, the subject provides explicit consent directly before submitting any of their own information.

3. Notice Requirements (Section 5)

The DPDP Act requires that data principals be given clear notice when their personal data is processed. PehleVerify implements this through automatic SMS notification to every subject when a verification check is initiated about them, informing them that PehleVerify is processing their data using official government databases, and providing a contact channel (privacy@pehleverify.in) for questions.

This notice is sent regardless of which verification mode is used — Requester Mode or Consent Link Mode — ensuring no verification occurs without the subject's knowledge.

4. Purpose Limitation (Section 6)

Data collected for one verification purpose (e.g., domestic help hiring) is not repurposed for another purpose (e.g., matrimonial verification) without fresh consent. Each check is a standalone, purpose-bound transaction.

5. Data Minimization

We collect only the data necessary for the specific checks included in the selected service. Fields not required for the chosen service are not requested. Where a field is optional (such as Aadhaar or PAN number), the corresponding check is simply skipped if the information is not provided, rather than making the field mandatory.

6. Child Data Protection (Section 9)

The DPDP Act imposes strict requirements around processing data of individuals under 18. PehleVerify implements multiple safeguards:

Mandatory age confirmation before any check can proceed. Automatic date-of-birth validation that blocks submission if the subject is calculated to be under 18. An explicit consent checkbox requiring the requester to confirm the subject is 18 or older when date of birth is not collected upfront. Logging of any blocked attempt for compliance audit purposes.

We do not knowingly process data relating to minors under any circumstances.

7. Data Principal Rights (Sections 11–14)

We honour all rights granted under the DPDP Act:

Right to Access: You may request a summary of the personal data we hold about you. Right to Correction: You may request correction of inaccurate data. Right to Erasure: You may request deletion of your data, subject to statutory retention requirements. Right to Grievance Redressal: You may raise concerns with our Data Protection Officer, and escalate unresolved matters to the Data Protection Board of India. Right to Nominate: You may nominate another individual to exercise your rights on your behalf in the event of death or incapacity.

To exercise any of these rights, contact dpo@pehleverify.in. We respond within 30 days.

8. Data Security (Section 8)

We implement reasonable security safeguards including encryption of data in transit and at rest, access restrictions on sensitive identity data, and secure, PIN-protected access to verification reports.

9. Breach Notification

In the unlikely event of a personal data breach, we will notify the Data Protection Board of India and affected data principals in accordance with the timelines and requirements prescribed under the DPDP Act.

10. Cross-Border Data Transfer (Section 16)

Where data is processed by infrastructure providers located outside India, we ensure such transfers comply with the DPDP Act's provisions and occur only to jurisdictions and providers offering adequate data protection standards.

11. Data Protection Officer

In accordance with the DPDP Act, we have designated a Data Protection Officer responsible for overseeing compliance, handling data principal requests, and serving as the primary contact for regulatory matters.

Data Protection Officer: Pranay Mudigonda — dpo@pehleverify.in

12. Our Ongoing Commitment

DPDP Act compliance is not a one-time checklist for PehleVerify — it is an operating principle. As the Act's rules and enforcement guidance continue to develop, we will update our practices and this page accordingly.

13. Contact

For DPDP Act related questions, grievances, or data principal requests:

Email: dpo@pehleverify.in

PehleVerify India Private Limited
Nizamabad, Telangana, India