Legal
DPDP Act 2023 Compliance
Last updated June 1, 2026.
This statement describes how Sema aligns with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). It explains the roles, principles, and rights that govern our processing of digital personal data of individuals ("Data Principals") in India.
1. Roles under the DPDP Act
- For personal data you provide to Sema directly (account, billing, support), Sema is the Data Fiduciary and determines the purpose and means of processing.
- For personal data contained in the sources you connect, you are the Data Fiduciary and Sema acts as a Data Processor processing such data only on your documented instructions.
2. Lawful processing & notice
- We process personal data only for lawful purposes for which the Data Principal has given consent or for certain legitimate uses permitted by the DPDP Act.
- Before or at the time of requesting consent, we provide a clear notice describing the personal data collected, the purpose, how rights may be exercised, and how to complain to the Data Protection Board of India.
3. Consent management
- Consent is obtained through a free, specific, informed, unconditional, and unambiguous affirmative action, limited to the personal data necessary for the stated purpose.
- Data Principals may withdraw consent at any time with ease comparable to giving it; upon withdrawal we cease processing within a reasonable time unless another lawful basis applies.
4. Purpose & data minimisation
- We limit collection to personal data necessary for the specified purpose and retain it only for as long as necessary to serve that purpose or to meet legal obligations, after which it is erased.
5. Rights of Data Principals
- Right to access a summary of personal data being processed and the processing activities.
- Right to correction, completion, updating, and erasure of personal data.
- Right to grievance redressal through the Data Fiduciary before approaching the Board.
- Right to nominate another individual to exercise rights in the event of death or incapacity.
6. Reasonable security safeguards
- We implement technical and organisational measures to prevent personal-data breaches, including encryption, access control, pseudonymisation where appropriate, logging, and regular review.
- In the event of a personal-data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and timelines prescribed under the DPDP Act.
7. Children's data
- We do not process children's personal data in a manner likely to cause detrimental effect and will obtain verifiable parental consent where the DPDP Act requires it. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
8. Processing on behalf of customers
- Where Sema acts as a Data Processor, we process personal data only under a valid contract, assist the customer with Data Principal requests and breach notifications, and engage subprocessors only under equivalent obligations.
9. Grievance Officer
- Our Grievance Officer for DPDP matters can be reached at grievance@semalayer.com. We acknowledge and resolve grievances within the timelines prescribed by law.
10. Contact
- For DPDP-related queries, email privacy@semalayer.com or the Grievance Officer at grievance@semalayer.com.

