Effective from: 14-08-2026
Indus Towers Limited (“ITL” or “the Company”) is committed to ensuring the lawful and transparent processing of personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDPA”). This Privacy Notice sets forth the Company’s approach to the collection, use, disclosure, storage, and protection of personal data processed in the course of its business operations.
This Notice applies to personal data collected by the Company from natural persons, including but not limited to landlords, business partners, service providers, employees, and other stakeholders whose personal data is processed in connection with ITL’s functions, services, or regulatory obligations.
Where-ever personal data is collected indirectly through third parties, such parties shall bear the responsibility of ensuring that all requisite notices have been duly provided to the data principals and that any necessary consents have been lawfully obtained prior to the disclosure of such data. ITL disclaims all liability arising from the failure of any third party to obtain valid authorization or consent. This Privacy notice is applicable to any personal data that data principals may provide to third parties via other sites linked to the company’s website.
This Privacy Notice is limited to the scope of personal data processed by ITL in its capacity as a data fiduciary under the DPDPA and does not extend to anonymized data or data that no longer qualifies as personal data under applicable law. Personal data shall be processed strictly for specified, clear, and lawful purposes, and shall be retained only for as long as is necessary to fulfil such purposes or as required under applicable legal or regulatory obligations.
ITL may engage third-party processors or service providers to act on its behalf in processing personal data. Such processing shall be governed by binding contractual arrangements that impose obligations equivalent to those set forth under this Privacy Notice and the DPDPA.
Requests, complaints, or inquiries concerning the Company’s data processing practices may be directed to the designated Grievance officer/Privacy Officer via the communication channels specified herein.
Whose Personal Data does ITL collect?
Indus Towers Limited (“ITL”) may collect or receive personal data from a range of identifiable natural persons in accordance with the nature of its operational and contractual relationships. The categories of data principals include, but are not limited to, the following:
Categories of Personal Data Collected
Why is personal data collected?
Personal data may be processed pursuant to contractual obligations, including the provision of products and services, handling of requests (such as inquiries or complaints), marketing of ITL’s services, business communications, and execution of business activities with partners.
| Data Principal | Personal Data Collected |
| Landlords | Name, address, contact details, ownership documents, bank details, PAN, tax records |
| Candidates | Resume, qualifications, employment history, references |
| Employees | Employee ID, contact details, payroll data, attendance, access logs |
| Visitors | Name, mobile number, organization, ID details, CCTV images |
| Vendors/Partners | Contact details, KYC details, payment information |
The purpose of collection and use of personal data is directly related to the nature of the data principal’s relationship with ITL and may include, inter alia, the following:
a) For Partners and Third Parties (including prospective parties):
b) Visitors to any of our premises or events:
c) Candidates (including prospective):
d) Landlords (including prospective):
e) General Purposes
How do we collect your personal data?
ITL may collect personal data through both direct and indirect means, as may be appropriate to the nature of interaction. The collection mechanisms may include the following (but not limited to):
Data is collected automatically pursuant to visit to our website
As part of its digital operations, Indus Towers Limited (“ITL”) automatically collects certain categories of personal data from individuals who access or interact with its websites, applications, or digital interfaces (“the Platforms”). This data collection is undertaken to enhance platform functionality, optimize user experience, and ensure compliance with security protocols.
The categories of data collected through automated means may include:
The categories of location data may include:
Purpose of processing location data:
Legal basis and consent:
Sharing and retention:
Sharing of Personal data amongst Indus Towers Limited Partners
Personal data may be shared internally within Indus Towers Limited (“ITL”) where such sharing is necessary for the continuity of business operations, provision of services, or to meet compliance requirements.
Data Sharing
To facilitate the delivery of services and to enhance operational efficiency, ITL may engage external service providers, vendors, and business associates who may be required to process personal data on behalf of ITL. Any such engagement shall be subject to formal contractual arrangements mandating that the third party implements appropriate technical and organizational security measures to ensure confidentiality, integrity, and availability of the data and to prevent unauthorized access, alteration, disclosure, or destruction.
ITL ensures that such third parties process personal data strictly for the purposes specified in the contract and in accordance with applicable data protection laws. No personal data shall be sold or disclosed to third parties for marketing or unrelated commercial purposes
Data Security
ITL is committed to maintaining the security of personal data and ensures that it is stored and processed in secure environments, whether on ITL’s own infrastructure or within third-party facilities under ITL’s contractual agreement. Depending on the nature of the data, storage may occur within encrypted systems, databases, document repositories, email archives, external hard drives, or cloud-based environments, subject to relevant technical controls.
Robust physical, administrative, and technical safeguards will be implemented to prevent unauthorized or unlawful processing, accidental loss, destruction, or alteration of personal data. These measures include (but are not limited to):
Personal Data Breach
In the event of a personal data breach, ITL shall take appropriate measures to investigate, contain, mitigate and remediate the incident. Where required under applicable law, ITL shall notify affected Data Principals and competent authorities in accordance with applicable statutory requirements.
Security Practices and Procedures
We are committed to safeguarding your Personal Information and implementing appropriate security measures to protect it against unauthorized access, use, disclosure, alteration, loss, or destruction. We maintain reasonable security practices and procedures that are aligned with recognized information security standards including ISO/IEC 27001 and other applicable industry best practices. These measures include technical, operational, administrative, and physical safeguards designed to ensure the confidentiality, integrity, and security of Personal Information under our control.
We also take reasonable steps to ensure that third-party service providers and business partners who process Personal Information on our behalf maintain appropriate security standards and implement adequate safeguards consistent with applicable legal and contractual requirements.
While we strive to protect Personal Information through robust security controls across our systems, applications, websites, and network infrastructure, no method of transmission over the internet or electronic storage is completely secure. Accordingly, despite our efforts, we cannot guarantee absolute security of Personal Information against all risks, including those arising from events beyond our reasonable control, such as cyberattacks, unauthorized access, malware, system vulnerabilities, failures of communication networks, or force majeure events.
Data retention policy
Indus Towers Limited (“ITL”) shall retain personal data only for the duration necessary to fulfil the specific purposes for which such data was originally collected, or as required to comply with applicable legal, regulatory, or contractual obligations.
The applicable retention period may vary depending on statutory requirements or legitimate business needs. In certain cases, ITL may be legally obligated to retain personal data for extended periods, particularly where necessary to establish, exercise, or defend legal claims, or to comply with audit, tax, or other regulatory mandates.
Upon expiry of the retention period, or once the data is no longer required for the stated purposes, ITL shall take appropriate steps to securely delete, anonymize, or destroy the data. This obligation also extends to data processed by third-party processors acting on behalf of ITL, ensuring such data is not retained beyond the authorized duration.
Data principal rights
In accordance with the Digital Personal Data Protection Act, 2023, individuals whose personal data is collected and processed by ITL (“data principals”) are entitled to exercise specific rights with respect to their personal data. These rights are subject to applicable exemptions and procedural validations as prescribed under the law.
1. Right to Access Information
Data principals have the right to request access to personal data processed by ITL, including:
2. Right to Correction and Erasure
Data principals have the right to request correction or deletion of their personal data in the following scenarios:
3. Right to withdraw consent
Data principals shall have the right to withdraw their consent at any time with respect to any processing activity previously authorized. Upon such withdrawal, ITL shall cease the processing of the relevant personal data, unless such processing is required to comply with legal or contractual obligations. Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to such withdrawal.
Data principals may withdraw the consent through the dedicated privacy email ID
4. Right of grievance redressal
Data principals shall have access to designated grievance redressal mechanisms established by ITL for the resolution of complaints arising from any act or omission relating to personal data processing or the exercise of data rights under this Policy. Grievances must be submitted in good faith, supported by relevant facts and documentation, and must not be frivolous or malicious in nature.
ITL shall acknowledge the grievance within the timelines prescribed under applicable laws and shall make reasonable efforts to address and resolve such grievances in a prompt and effective manner. In the event that a grievance remains unresolved to the satisfaction of the data principal, the individual may escalate the matter to the appropriate regulatory authority.
5. Right to nominate
A data principal shall have the right to nominate an alternate individual to exercise data protection rights on their behalf in the event of incapacitation or death. Such nomination shall be made in the manner prescribed by law and shall be recorded by ITL subject to verification of the nominee’s identity and authority.
To exercise the rights outlined under this Privacy Notice, including access, correction, erasure, consent withdrawal, nomination, and grievance redressal, data principals may submit a formal request using the Data Principal Rights Request Form available on ITL’s official website. The form shall require the individual to provide accurate identification details, specify the right being exercised, and include any supporting documents as necessary to enable verification and processing.
ITL shall acknowledge receipt of such requests within the prescribed legal timeframe and shall make reasonable efforts to respond substantively in accordance with applicable regulatory requirements. All responses shall include a summary of the actions taken or the reasons for any delay or rejection, as permitted under law.
For any questions related to the exercise of rights under this Privacy Notice, or for concerns regarding the manner in which personal data is handled by ITL, data principals may contact the Company’s designated Privacy Officer/Grievance Officer at COMPLIANCE.OFFICER@INDUSTOWERS.COM.
In the event that a data principal believes their request has not been addressed satisfactorily, they may escalate the matter to the appropriate Data Protection Board or regulatory authority in accordance with the provisions of the DPDPA.
Notification of changes
ITL reserves the right to modify, update, or amend this Privacy Notice at its discretion, in order to reflect changes in applicable law, regulatory guidance, or operational practices. Any material changes shall be duly notified, and the revised version shall be published on ITL’s official website.
The most recent and publicly available version of this Privacy Notice shall be deemed authoritative and shall supersede all prior versions. Data principals are encouraged to review this Notice periodically to remain informed of any updates affecting the handling of their personal data.
Disclaimer
Indus Towers Limited (“ITL”) is committed to protecting personal data by following industry best practices and applying reasonable security measures. However, due to the nature of the Internet and digital systems, it is important to understand that no system can be completely secure.
While ITL takes all necessary steps to keep your personal data safe, it cannot guarantee protection against every possible risk, such as cyberattacks or incidents beyond our control. While ITL implements reasonable security safeguards to protect personal data, no electronic transmission or storage mechanism can be guaranteed to be completely secure that occurs due to reasons outside its control, including any negligence on the part of the individual sharing the data.
ITL appreciates your cooperation in keeping information secure and acting responsibly when handling personal data.
Privacy Notice
Submission of personal data shall be deemed to constitute the data principal’s acknowledgment of the following:
Questions and updates
Any queries or requests relating to the contents of this Privacy Notice or the processing of personal data may be addressed at COMPLIANCE.OFFICER@INDUSTOWERS.COM