Internal governance document — Compliance Manual
DPDP Act 2023 — Implementation & Compliance Manual
VERALIS EVIDENCE PRESS PRIVATE LIMITED — Digital Personal Data Protection Act, 2023
1. Purpose and Scope
This manual sets out how VERALIS EVIDENCE PRESS PRIVATE LIMITED (“VERALIS”, “we”) meets its obligations under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) as a Data Fiduciary. It is the operational counterpart to the public-facing Privacy Policy and DPDP Act Compliance page and is intended for staff, contractors, and our technology developer.
In scope
All digital personal data of Data Principals in India processed through the VERALIS publishing platform — authors, reviewers, editors, institutional users, and website visitors — across account management, manuscript submission and peer review, APC payment, communications, and analytics.
Out of scope
Purely non-personal or fully anonymised data, and personal data governed exclusively by another jurisdiction where the DPDP Act does not apply (GDPR handling is addressed in the Privacy Policy).
2. Key Definitions
| Term | Meaning under the DPDP Act (as applied at VERALIS) |
|---|---|
| Data Principal | The individual to whom the personal data relates (author, reviewer, editor, institutional contact, site visitor). |
| Data Fiduciary | VERALIS — the entity that determines the purpose and means of processing. |
| Data Processor | A third party that processes personal data on VERALIS’s behalf under contract (e.g., cloud host, payment gateway). |
| Personal data | Any data about an individual who is identifiable by or in relation to such data. |
| Processing | Any operation on personal data — collection, storage, use, sharing, erasure, etc. |
| Consent | Free, specific, informed, unconditional, unambiguous agreement, given by a clear affirmative action, for a specified purpose. |
| Grievance Officer | The person designated to receive and resolve Data Principal grievances. |
| Data Protection Board | The Data Protection Board of India, the statutory adjudicatory body. |
3. Roles and Responsibilities
- Data Fiduciary accountability: VERALIS is accountable for compliance regardless of any processing carried out by a Data Processor on its behalf.
- Grievance Officer: VERALIS designates a Grievance Officer, contactable at admin@veralispress.com, responsible for receiving Data Principal requests and grievances, coordinating responses within statutory timelines, and maintaining the registers in this manual.
- Developer / platform team: responsible for implementing consent capture, rights-fulfilment tooling, security controls, logging, and erasure workflows described here.
- Significant Data Fiduciary CONFIRM: if VERALIS is later notified as a Significant Data Fiduciary, additional duties apply — appointing a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments. Status to be reviewed annually.
4. Lawful Basis for Processing
VERALIS processes personal data only on a lawful basis under the DPDP Act — either the Data Principal’s consent or a recognised “legitimate use.” The basis for each activity is recorded in the Record of Processing Activities (Section 5).
- Consent — obtained for marketing communications, non-essential cookies/analytics, and any processing not covered by a legitimate use.
- Legitimate use — voluntary provision of data by the Data Principal for a specified purpose, compliance with legal obligations, and security/fraud prevention, as permitted by the Act.
- Contractual necessity — core publishing services (account, submission, peer review, APC) provided to fulfil the service the Data Principal has requested.
5. Record of Processing Activities (RoPA)
Maintained and reviewed at each review cycle. Columns: purpose, data categories, Data Principals, lawful basis, processors, and retention (detailed in Section 11).
| Purpose | Data categories | Lawful basis | Key processors |
|---|---|---|---|
| Account & identity | Name, email, password hash, ORCID, affiliation | Contract / legitimate use | Cloud host, identity (ORCID) |
| Submission & peer review | Manuscript content, correspondence, reviewer identity | Contract | Cloud host, plagiarism screening |
| APC payment | Billing name, email, transaction refs (card data held by gateway) | Contract / legal obligation | Payment gateway |
| Scholarly metadata | Author/contributor metadata, ORCID, DOI | Legitimate use | Crossref, ORCID, indexers |
| Communications | Email, message content, preferences | Contract / consent (marketing) | Email service provider |
| Analytics & cookies | Usage data, device/IP, cookie IDs | Consent (non-essential) | Analytics provider |
| Security & fraud | Logs, IP, access records | Legitimate use | Cloud host, monitoring |
6. Notice to Data Principals
Before or at the point of collection, VERALIS provides a notice, in clear and plain language, stating the personal data to be collected, the purpose, how the Data Principal may exercise their rights, and how to complain to the Data Protection Board. Where consent was obtained before commencement of the Act for existing users, an updated notice is provided as soon as reasonably practicable.
Implementation: the notice is surfaced at sign-up, at manuscript submission, at payment, and via a persistent link to the Privacy Policy and DPDP Compliance page. A record of the notice version shown is stored against the account.
7. Consent Management and Records
Consent is captured through an affirmative action (e.g., an unticked checkbox the Data Principal selects), is specific to each purpose, and is logged. Each consent record retains the fields below so consent is demonstrable and auditable.
| Consent record field | Example |
|---|---|
| Data Principal ID | Account UUID |
| Purpose | Marketing email / analytics cookies |
| Consent text & version | “v1.0 marketing opt-in” |
| Timestamp & source | 2026-07-25T10:14Z, sign-up form |
| Status | Granted / withdrawn |
| Withdrawal timestamp | If applicable |
Withdrawal: a Data Principal may withdraw consent at any time, as easily as it was given, via account settings or by emailing admin@veralispress.com. On withdrawal, VERALIS ceases the relevant processing and instructs processors to do the same, unless another lawful basis or legal obligation requires retention. Withdrawal does not affect the lawfulness of processing before withdrawal.
Consent Manager CONFIRM: if VERALIS integrates a registered Consent Manager under the Act, requests routed through it are honoured through the same workflow.
8. Data Principal Rights — Fulfilment Procedure
Requests are received at admin@veralispress.com, identity-verified against the account, logged in the Data Subject Request (DSR) register, and actioned within the target timelines below. Final statutory timelines follow the notified DPDP Rules; VERALIS adopts the targets below as internal SLAs.
| Right | What VERALIS does | Target SLA |
|---|---|---|
| Access | Provide a summary of personal data processed and processing activities | 7 working days |
| Correction / completion / update | Amend inaccurate or incomplete data; notify processors | 7 working days |
| Erasure | Delete data no longer needed and not subject to legal retention; instruct processors | 30 days |
| Grievance redressal | Acknowledge, investigate, and respond via Grievance Officer | Acknowledge 48 hrs; resolve ≤ 30 days |
| Nomination | Record a nominee to exercise rights on death/incapacity | On request |
| Withdraw consent | Stop consented processing; confirm to Data Principal | ≤ 72 hrs |
Erasure and the scholarly record: erasure requests are honoured except where data forms part of the permanent version of record (published articles, author/contributor metadata, corrections and retractions) or where law requires retention (e.g., financial records). This limitation is disclosed to the Data Principal in the response.
Duties of Data Principals: we remind requesters that the Act requires them to provide authentic information and not to file false or frivolous grievances.
9. Children’s and Guardianship Data
- The service is directed at researchers and professional users; we do not knowingly process personal data of children (under 18) without verifiable parental/guardian consent.
- We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
- Where a Data Principal has a lawful guardian, verifiable guardian consent is obtained in the manner the Act prescribes.
- If we become aware that a child’s data was collected without valid consent, we erase it promptly.
10. Sub-Processor / Data Processor Register
VERALIS engages Data Processors only under a valid contract requiring DPDP-consistent safeguards, purpose limitation, and deletion on termination. The register below is maintained and reviewed each cycle. CONFIRM vendor names and locations
| Category | Provider | Purpose | Location |
|---|---|---|---|
| Cloud hosting | CONFIRM | Platform & data storage | CONFIRM |
| Payment gateway | CONFIRM | APC processing | CONFIRM |
| Email delivery | CONFIRM | Transactional & notice email | CONFIRM |
| Plagiarism screening | CONFIRM | Integrity checks | CONFIRM |
| Identity / metadata | ORCID, Crossref | Scholarly identifiers & metadata | Global |
| Analytics | CONFIRM | Usage analytics (consented) | CONFIRM |
11. Data Retention and Erasure Schedule
Personal data is retained only as long as necessary for the purpose or as required by law, then erased or anonymised. Automated retention rules are configured in the platform. CONFIRM periods with counsel/finance
| Data set | Retention | Trigger for erasure |
|---|---|---|
| Active account data | Life of account | Account closure + grace period |
| Closed account data | 12 months after closure CONFIRM | End of grace period |
| Submission / review records (unpublished) | 2 years after decision CONFIRM | Elapse of period |
| Published version of record | Permanent | Not erased (scholarly record) |
| Financial / APC records | As required by tax law (e.g., 8 years) CONFIRM | Statutory period elapses |
| Marketing consent data | Until withdrawal + short buffer | Consent withdrawn |
| Server & security logs | 6–12 months CONFIRM | Rolling deletion |
| Analytics / cookie data | Per consent & provider policy | Consent withdrawn / expiry |
12. Security Safeguards
- Encryption of personal data in transit (TLS) and at rest.
- Role-based access control, least privilege, and unique credentials; MFA for administrative access.
- Audit logging and monitoring of access to personal data.
- Segregation of environments; secrets management; regular patching.
- Backups with tested restore, and secure deletion on retirement of media.
- Contractual security obligations flowed down to all processors.
- Periodic access reviews and vulnerability assessment CONFIRM cadence.
13. Personal Data Breach Response
A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. VERALIS follows the steps below and notifies the Data Protection Board of India and affected Data Principals in the manner and timeline required by the DPDP Act and Rules.
| Step | Action | Owner / timing |
|---|---|---|
| 1. Detect & log | Record the incident in the breach register; assign severity | Whoever detects / Grievance Officer — immediately |
| 2. Contain | Isolate systems, revoke credentials, stop the exposure | Developer / platform — immediately |
| 3. Assess | Scope: data, individuals, likely impact | Grievance Officer — within 24 hrs |
| 4. Notify Board | Report to the Data Protection Board of India | Grievance Officer — per Rules timeline |
| 5. Notify Data Principals | Inform affected individuals: nature, consequences, mitigation, contact | Grievance Officer — per Rules timeline |
| 6. Remediate & review | Fix root cause; update controls; post-incident review | Platform + Grievance Officer |
Breach register fields: incident ID, date/time detected, description, data & individuals affected, severity, containment actions, Board notification date, Data Principal notification date, root cause, corrective actions, closure date.
14. Cross-Border Transfers
The DPDP Act permits transfer of personal data outside India except to countries restricted by Government notification. Where processors store or process data outside India (e.g., cloud regions), VERALIS confirms the destination is not restricted, applies contractual safeguards, and records the transfer in the sub-processor register. CONFIRM data-residency choice for hosting
15. Grievance Redressal
- Channel: admin@veralispress.com, monitored by the Grievance Officer.
- Acknowledge within 48 hours; resolve within 30 days (internal SLA, subject to final Rules).
- If unresolved or the Data Principal is dissatisfied, they may approach the Data Protection Board of India.
- All grievances and outcomes are logged for audit.
16. Training, Review, and Accountability
- Staff and contractors with access to personal data receive DPDP awareness briefing at onboarding and annually.
- This manual and all registers are reviewed at least annually and upon notification of the DPDP Rules or material change to processing.
- The Grievance Officer maintains evidence of compliance (RoPA, consent logs, DSR register, breach register, vendor contracts).
- Significant Data Fiduciary duties (DPO, independent audit, DPIA) are activated if VERALIS is so notified.
17. Appendices — Register Templates
A. Data Subject Request (DSR) log
| Field | Notes |
|---|---|
| Request ID / date received | — |
| Data Principal & verification method | — |
| Right requested | Access / correction / erasure / withdrawal / nomination / grievance |
| Action taken & date | — |
| Outcome & closure date | — |
| Within SLA? (Y/N) | — |
B. Consent record (see Section 7)
Fields: Data Principal ID, purpose, consent text & version, timestamp & source, status, withdrawal timestamp.
C. Breach register (see Section 13)
Fields: incident ID, detected date/time, description, data & individuals affected, severity, containment, Board notification date, Data Principal notification date, root cause, corrective actions, closure date.
End of document. This manual is provided for VERALIS internal governance and should be finalised with legal counsel and the notified DPDP Rules.
