Digital Personal Data Protection Act, 2023 (DPDP)
How 20X approaches the India DPDP Act, 2023 and its rules, which govern the processing of digital personal data in India.
Data Fiduciary and Data Processor
When customers use 20X to process personal data of their users or employees, the customer is the Data Fiduciary and Setoo Solutions Pvt Ltd is a Data Processor acting under the customer's instructions. For our own business processing (billing, security, marketing to prospects), Setoo Solutions Pvt Ltd is the Data Fiduciary.
Notice and consent (Section 5-6)
Data Fiduciaries must give Data Principals clear notice about the personal data being processed, the purpose, how to exercise rights, and how to complain to the Data Protection Board of India. Consent must be free, specific, informed, unconditional, unambiguous, and revocable. 20X provides configurable notice and consent surfaces (forms, chat prompts, workflow gates) so customers can meet these obligations.
Certain processing may proceed on "legitimate uses" listed in Section 7 (voluntary provision of data, employment, medical emergencies, disasters, and specified public-interest functions). Customers determine which basis applies to their use case.
Rights of Data Principals (Section 11-14)
- Right to access a summary of personal data being processed.
- Right to correction, completion, updating, and erasure.
- Right to grievance redressal from the Data Fiduciary.
- Right to nominate an individual to exercise rights in the event of death or incapacity.
- Right to withdraw consent as easily as it was given.
If your data is processed by 20X on behalf of a customer, contact that customer first as the Data Fiduciary. For data Setoo Solutions Pvt Ltd holds as a Data Fiduciary, contact our grievance channel below.
Children's data and persons with disabilities
Processing of personal data of children (under 18) and of persons with disabilities under lawful guardianship requires verifiable parental or guardian consent, and behavioural tracking or targeted advertising directed at children is prohibited under Section 9. Customers configuring 20X for audiences that may include children are responsible for meeting these requirements.
Reasonable security safeguards (Section 8(5))
- Encryption in transit for customer traffic.
- Access controls and audit logging.
- Backups and disaster-recovery procedures.
- Written contracts with sub-processors handling personal data.
- Deletion of personal data when the purpose is served or consent is withdrawn, subject to legal retention obligations.
Breach notification (Section 8(6))
If 20X becomes aware of a personal-data breach affecting customer data, we will notify the affected customer without undue delay so they can notify the Data Protection Board of India and affected Data Principals as required by the Act and its rules.
Cross-border transfers (Section 16)
The DPDP Act permits transfers of personal data outside India except to countries the Central Government notifies as restricted. Where the Government of India issues such notifications, 20X will honour them for the affected data flows.
Grievance officer
Complaints about our processing of personal data as a Data Fiduciary can be sent to the grievance channel below. We will acknowledge and respond within the timelines prescribed by the DPDP rules.
Grievance channel: privacy@20x.business
Operator: Setoo Solutions Pvt Ltd
If unresolved, Data Principals may raise the complaint with the Data Protection Board of India in accordance with the Act.