Digital Personal Data Protection Policy

Version 1.3. Effective 14 August 2026.

Who we are

EnAble India, Survey No. 9, ‘Purva Gainz’, Second Floor, Beratana Agrahara, Lavakusha Nagar, Hosur Main Road, Bengaluru – 560100, Karnataka, India, is the Data Fiduciary responsible for the personal data described in this policy. This policy is issued in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.

Whose personal data this covers

Personal data of the persons we serve and their families and guardians, job seekers and candidates, employees and interns, volunteers and trainers, donors, partner and client organisations, and visitors to our websites and applications.

Why we collect personal data

We collect personal data to deliver our programmes, services and employment support to persons with disabilities, to run our organisation, to meet our obligations to funders and regulators, and to comply with law.

How we collect personal data

We collect personal data through our websites, applications and online forms, and in person and on paper at job fairs, melas, camps, training centres and partner-led events. Some collection at joint events is carried out by partner organisations.

How we use personal data

We use personal data for the purposes set out in this policy.

Who we share personal data with

Where the purpose of a programme or event is to connect candidates with employment or training, we share candidate details with prospective employers and training partners.

Our programmes are supported by companies, foundations, government bodies and individual donors, and we report to them on the work they fund. Reports to funders are based on aggregated and anonymised data wherever possible. Where a funder, or an agency appointed by a funder, needs to verify our work directly, this may involve sharing identifying details of the people we serve, or those representatives contacting them.

We use photographs, video and case studies in our reports to funders and in public material about our work. Some of these identify the individuals concerned.

We share personal data where we are required to by law, including reporting to government and regulatory authorities.

We do not sell personal data. Apart from the sharing described above, we share personal data only where it is needed to deliver our services, where the individual has consented, or where the law requires it.

Some of the systems we use are operated by service providers whose infrastructure may be located outside India.

Retention

We retain personal data for as long as it is needed for the purpose for which it was collected, and for as long as required under applicable law and our audit, statutory and funder record-keeping obligations.

Security

Access to the systems in which we hold personal data is restricted to those who need it for their work. We are reviewing and strengthening our technical and organisational security measures.

Aggregated and anonymised data

We may use aggregated and anonymised data for internal analysis, reporting and programme improvement. Such data does not identify individuals.

Personal data breach

If a personal data breach occurs, we will inform affected individuals and notify the Data Protection Board of India within the timelines set out under the Act and the Rules.

Your rights

You may write to us to confirm what personal data of yours we hold and how we use it, to correct or complete inaccurate or incomplete data, to request erasure of your personal data, to withdraw consent, and to nominate another person to exercise these rights on your behalf.

If you do not wish your photograph, video or story to be used, or you want us to stop using material already published, write to us and we will act on it.

Where we are unable to act on a request because the law, an audit requirement or a funder obligation requires us to retain the data, we will tell you the reason.

If you need this policy in another format or in another language, write to us and we will provide it.

How to contact us or raise a grievance

Shiva Kumar B R, Director IT, EnAble India

Email: privacy@enableindia.org

Address: EnAble India, Survey No. 9, ‘Purva Gainz’, Second Floor, Beratana Agrahara, Lavakusha Nagar, Hosur Main Road, Bengaluru – 560100, Karnataka, India

We acknowledge requests and grievances within five working days and resolve them within ninety days. If you are not satisfied with our response, or do not receive one within this period, you may make a complaint to the Data Protection Board of India.

Compliance status

The Digital Personal Data Protection Rules, 2025 provide for phased compliance, with full compliance required by 13 May 2027.
 
EnAble India is engaging external data protection expertise and will meet all requirements of the Act and the Rules within that timeline. This includes notices and consent processes at our collection points, verifiable consent for children and for persons with disability who have a lawful guardian, records of the personal data we
hold, defined retention periods, and agreements with our partners and service providers.
 
Until these are in place, the rights and the contact route set out above apply, and any individual may write to us to ask what data we hold, to correct it, or to have it deleted.

Changes to this policy

We update this policy as our systems and processes develop. The current version and effective date are shown at the top.

Revision History

Version Date Description of Revision
1 24-Nov-2025 Initial publication.
1.1 20-Aug-2026 Revised in line with the Digital Personal Data Protection Rules, 2025. Grievance officer contact, individual rights, wider scope, data sharing sections and compliance timeline added.