1. Purpose:
1.1.To establish a formal mechanism for external stakeholders (clients, vendors, visitors) to lodge and
resolve grievances related to data protection, privacy practices, or service delivery, ensuring
transparency, consistency, and compliance with ISO 27001:2022 and the Digital Personal Data
Protection Act (DPDPA) 2023.
2. Scope:
2.1 This procedure applies to all grievances raised by external parties regarding IDA Analytics’ products,
services, website privacy notice, consent mechanisms, or data handling.
3. References:
3.1 ISO/IEC 27001:2022 – Information Security, Cyber security, and Privacy Protection-Information
Security Management System- Requirements.
3.2.Digital Personal Data Protection Act, 2023 (DPDPA)
4. Acronyms:
4.1 HR: Human Resource
4.2 DPDPA – Digital Personal Data Protection Act, 2023
4.3 DGC – Data Governance Committee
4.4 COO – Chief Operating Officer
4.5 EGRC – External Grievance Redressal Committee
5. Definitions:
5.1 Data Principal: The natural person to whom the personal data relates.
5.2 Data Fiduciary: Any person, including the State, who alone or in conjunction with others
determines the purpose and means of processing personal data.
5.3 Data Processor: Any person who processes personal data on behalf of the Data Fiduciary.
5.4 Consent: Free, informed, specific, clear, and capable of being withdrawn agreement by the Data
Principal for processing their personal data.
5.5 Personal Data: Any data about an individual who is identifiable by or in relation to such data.
5.6 Processing: A wholly or partly automated operation or set of operations performed on digital
personal data, including collection, recording, organization, storage, use, sharing, disclosure,
retrieval, alignment, combination, indexing, erasure or destruction.
5.7 Personal Data Breach: Any unauthorized processing of personal data or accidental disclosure,
acquisition, sharing, use, alteration, destruction or loss of access to personal data that
compromises the confidentiality, integrity or availability of personal data.
5.8 External Stakeholder: Any client, customer, vendor, service provider, visitor, Data Principal or
other external party interacting with IDA.
5.9 Grievance: Any expression of dissatisfaction or concern raised by an external stakeholder
relating to IDA’s services, data protection, privacy practices, information security, processing of
personal data or other matters falling within the scope of this procedure
6. Roles and Responsibilities:
| External Stakeholder | Submit grievance with sufficient details and supporting evidence, where available, and provide additional information reasonably required for investigation |
| EGRC Chairperson | Provide oversight of the grievance redressal process, lead committee deliberations, ensure appropriate resolution and adherence to defined timelines |
| Committee Secretary | Acknowledge grievances, maintain the Grievance Register, coordinate investigation and committee communication, track timelines, maintain records and facilitate closure. |
| EGRC Members | Review and investigate assigned grievances, obtain relevant information, participate in deliberations and recommend corrective/remedial actions. |
| Risk & Compliance | Provide oversight for grievances relating to privacy, personal data, information security, regulatory or compliance matters and coordinate necessary escalation. |
| Relevant Department / Process Owner |
Support investigation, provide required information/evidence and implement approved corrective or preventive actions within agreed timelines. |
| Appellate Authority – COO |
Independently review escalated/appealed grievances and communicate the final internal decision. |
6.1.1 The External Grievance Redressal Committee (EGRC) shall comprise representatives from
relevant business and support functions to ensure appropriate review, investigation and
resolution of external grievances.
6.1.2 The EGRC shall have representation from the following functions:
| Committee Role | Functional Representation |
| Chairperson | Chief Operating Officer (COO) |
| Member | Service Operations |
| Member | IT & Compliance / Technical |
| Member | Human Resources |
| Member / Committee Coordinator | Risk & Compliance |
| Member | Legal |
| Member | Location Representative |
6.1.3 The names of the nominated EGRC members shall be maintained separately through an
approved EGRC Committee Member Register/List and updated whenever there is a
change in committee membership.
6.1.4 Any addition, replacement or change in EGRC membership shall be approved by the
appropriate Management Authority. Changes to individual members shall not require
revision of this procedure, provided that the required functional representation is
maintained.
7. Procedure Steps:
7.1 Lodging a Grievance: External stakeholders may submit grievances to the External Grievance
Redressal Committee through the dedicated email address: [email protected]
The grievance should contain the following information, where applicable:
7.1.1. Description of the grievance, including relevant date(s), event(s), affected service, process
or personal data.
7.1.2 Full name and contact details of the complainant.
7.1.3 Relevant client, vendor, transaction, service or other reference details, where applicable.
7.1.4 Preferred resolution or expected outcome, if any.
7.1.5 Supporting documents or evidence, if available.
7.1.6. Personal data submitted as part of a grievance shall be processed only to the extent
necessary for investigating, resolving, documenting and complying with applicable legal,
regulatory or contractual requirements relating to the grievance, in accordance with
applicable data protection requirements and IDA’s Privacy Policy.
7.2.Acknowledgement – The Committee Secretary/Coordinator shall acknowledge receipt of the
grievance within 3 business days of receipt. The acknowledgement shall, where applicable, include
the grievance reference number, date of receipt, next steps and expected resolution timeline.
7.3.Review & Investigation – The External Grievance Redressal Committee will convene to:
7.3.1 Upon receipt, the grievance shall be reviewed and classified based on its nature, including
where applicable:
7.3.1.1. Service Delivery
7.3.1.2. Data Protection / Privacy
7.3.1.3. Information Security
7.3.1.4. Data Principal Rights
7.3.1.5. Contractual / Client-related
7.3.1.6. Vendor-related
7.3.1.7. Website / Privacy Notice / Consent-related
7.3.1.8. Other External Grievance
7.3.2 Grievance shall be assigned an appropriate severity of High, Medium or Low based on its
impact, urgency, sensitivity of information involved, number of affected individuals,
contractual implications and regulatory/compliance risk.
7.3.3 Appropriate EGRC members, department(s) or process owner(s) shall be assigned to
investigate the grievance and gather relevant information and evidence.
7.3.4 Relevant business functions, vendors, service providers, clients or other third parties may
be consulted where necessary for investigation, subject to applicable confidentiality and
need-to-know requirements.
Any EGRC member having an actual or potential conflict of interest in relation to
grievance shall disclose the conflict and shall not participate in the investigation or
decision-making for that grievance.
7.3.5. Grievances relating to personal data, privacy, regulatory compliance or information
security shall be escalated to Risk & Compliance and/or the Data Governance Committee,
as applicable, for assessment and necessary action.
7.3.6. Where a grievance indicates or is suspected of involve an information security incident or
personal data breach, the matter shall be immediately escalated and handled in
accordance with IDA’s applicable Information Security Incident Management and Data
Breach Management procedures. The grievance process shall not delay any required
containment, investigation, notification, regulatory or contractual action.
7.4 Decision & Communication – Within 30 calendar days of the acknowledgement, the Committee
will:
7.4.1 The EGRC shall review the investigation findings and determine the appropriate response,
corrective action, preventive action or other remedial measures, as applicable.
7.4.2 The outcome and applicable remedial measures shall be communicated in writing to the
complainant within 30 calendar days from receipt of the grievance, subject to the nature
and complexity of the matter.
7.4.3 Where resolution within the defined timeline is not reasonably possible due to
complexity, dependency on the complainant, third-party involvement or other justified
reasons, the complainant shall be informed of the status and revised expected resolution
timeline.
7.4.4 Where corrective or preventive actions are identified, the responsible
department/process owner shall implement the actions within agreed timelines and
provide appropriate evidence of closure.
7.4.5 Significant findings may be considered for risk assessment, process improvement,
policy/procedure changes, training or other appropriate corrective measures.
7.5 Appeal Process – If the complainant is dissatisfied with the resolution, they may request an
internal review by the Appellate Authority (COO) by responding to the decision communication
within 15 calendar days of receiving the outcome.
7.5.1. The Appellate Authority shall review the grievance, investigation findings, decision and
any additional information submitted by the complainant.
7.5.2. The final internal decision shall ordinarily be communicated within 15 calendar days from
receipt of the appeal.
7.6 Closure – Grievance shall be considered closed when the resolution has been communicated to
the complainant and all applicable corrective/remedial actions have been completed or appropriately
tracked.
7.6.1. Where an appeal has been raised, the grievance shall be closed following communication
of the Appellate Authority’s final internal decision and completion/tracking of applicable
actions.
7.6.2. The closure status, closure date, outcome, supporting evidence and applicable
CAPA/reference numbers shall be recorded in the Grievance Register.
7.7 Confidentiality:
7.7.1. All grievances, supporting evidence, investigation records and communications shall be
treated as confidential and shall be accessible only to personnel having a legitimate
business need.
7.7.2. Personal data collected or generated during the grievance process shall be limited to what
is reasonably necessary for investigation, resolution, documentation and compliance
purposes.
7.7.3. Grievance records shall be appropriately protected against unauthorized access,
disclosure, alteration, loss or destruction in accordance with IDA’s information security
and data protection requirements.
7.7.4. Information relating to grievance only is shared internally or externally where necessary
for investigation, resolution, legal/regulatory compliance or contractual requirements
and subject to appropriate confidentiality controls.
8. Contact Us:
8.1 If you have any concerns or complaints related to our services, data processing practices, or any
conduct pertaining to IDA Analytics Pvt Ltd, you may contact our External Grievance Redressal
Committee by emailing: [email protected] All submissions will be treated
confidentially and addressed within 30 working days as per IDA’s grievance resolution guidelines.
9. Non-Compliance:
9.1 Failure to comply with the External Redressal procedure may result in disciplinary action as per
IDA Policy.