ScreenJournal

India — Digital Personal Data Protection Act 2023

Version 2.0 · Effective 5 October 2026

This page explains how ScreenJournal, operated by Cyberinfra Limited (Isle of Man) ("we", "us"), and the employers who use it handle personal data under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "Rules"). It is written for our customers, for the people whose work activity they monitor, and for anyone reviewing how the product treats personal data from India.

This is a plain-language explainer and is not legal advice. Our Privacy Policy describes in full what we collect and why; this page adds what is specific to Indian law.

1. When it applies

The DPDP Act governs the processing of digital personal data in India, and of personal data processed outside India in connection with offering goods or services to people in India. The people the data is about are called Data Principals. The Act is enforced by the Data Protection Board of India (the "Board").

The Rules were published in the Official Gazette on 13 November 2025 and announced by the Government on 14 November 2025. As at October 2026, they commence in three stages:

  • 13 November 2025: the provisions constituting the Board and governing how it works took effect immediately.
  • 13 November 2026: the provisions on registered consent managers take effect.
  • 13 May 2027: the substantive duties take effect, including the itemised notice, Data Principal rights and the grievance timeline, security safeguards, breach intimation, erasure, cross-border transfer and the duties of significant data fiduciaries.

The Board's chairperson and members were reported appointed in mid-2026. As far as we know, it is not yet accepting complaints from individuals about their rights. We describe below how we work today, ahead of May 2027, and we will update this page as the timetable moves.

2. Who plays which role

  • Your employer is the Data Fiduciary for the monitoring of your work. It decides whether to use ScreenJournal, which features to turn on, what to monitor and why, and what to do with the results. It is accountable to you and to the Board, and it is your first point of contact.
  • Cyberinfra Limited is a Data Processor. We process monitoring data on the employer's behalf, under contract and on its instructions. We do not use monitoring data for our own purposes, and we do not use it to train AI models.
  • We are a Data Fiduciary only for the data we control directly, such as customer account, billing, sign-in security and website data, as described in our Privacy Policy.

Grievance Officer. Our Grievance Officer for India is a role, not yet a named individual. Until an officer is appointed, the role is reached through support@screenjournal.ai with the subject line "Data protection request". See our Data Protection Contacts page.

3. What the product does

The ScreenJournal desktop app runs on Windows and macOS and is visible in the menu bar or system tray while it runs. While tracking is on it records each connected display as short video segments, by default at one frame per second. The app paints the cursor position and clicks into the recording as markers. Applications and sites on the organisation's exclusion list are not captured. The app also records application names, window titles, browser addresses, and presence and idle signals.

  • Default mode. Screen video is uploaded for analysis and deleted after analysis; any temporary copy is removed by a storage lifecycle rule we configure on the bucket. The desktop app keeps its own copies on the member's device for the period the organisation sets, up to three months.
  • Record + Save (employer-elected). If the organisation enables it, screen video is stored on our servers so managers can play it back.
  • Alert evidence clips (employer-elected). Where the organisation's alert rules call for it, a short clip is kept as evidence for a flagged event.
  • Audio is off by default. If the organisation turns it on, the app records listed meeting and calling applications, including the other people on the call.
  • Connected AI tools. If the organisation connects its own AI tool through our integration feature, that tool can read the organisation's data within the connecting user's permissions.
  • Sign-in region. At desktop sign-in we derive a country or region from the network address, using a local database, and store it on the user record.

At every desktop sign-in the app shows a notice that it may record the screen and, where the organisation turns it on, meeting audio. That acknowledgment is not yet recorded.

4. Notice

Under section 5 and Rule 3, a Data Fiduciary that asks for consent must give each Data Principal an itemised notice, in clear and plain language, setting out the personal data and the specific purposes of processing, how consent can be withdrawn, how rights can be exercised and how to complain to the Board. For monitoring data, telling people what is processed and why is your employer's duty, whichever basis it relies on.

We provide inputs for it: our Privacy Policy, which lists every data category and purpose, and the documents on our Legal page. An employer should not rely on our pages alone; its own notice should describe its programme, its purposes and its own contact for grievances.

5. Lawful basis

The DPDP Act permits processing either with the Data Principal's consent (section 6) or for a legitimate use (section 7). Section 7 includes processing for the purposes of employment, or to safeguard the employer from loss or liability, for example to prevent corporate espionage or to protect confidential information. Which basis applies is the employer's decision as Data Fiduciary.

A caveat about consent at work: consent under the Act must be free, specific, informed, unconditional and unambiguous. Consent asked of an employee as a condition of the job may not meet that standard. Employers usually do better to identify the employment purpose they rely on under section 7 and to keep monitoring within it, using consent only where it can genuinely be refused. This is not legal advice; employers should confirm their position with Indian counsel.

6. Automated processing

The service draws five kinds of automated inference about the people it monitors:

  1. an activity score from 1 to 5 for each recorded segment of screen activity;
  2. a productivity percentage, measured against the working day;
  3. a position in a weekly ranking of the organisation's members;
  4. flags that activity may be simulated, for example by a mouse-jiggling device;
  5. matches against alert rules written by the organisation.

Segment scores and descriptions are produced by a Google Gemini model accessed through Google Vertex AI, and alert evaluations by a Google Gemini model accessed through Google's Gemini API, from screen content and activity signals such as presence and idle time. The productivity percentage and the weekly ranking are calculated from those scores. Simulated-activity flags come from the same model reviewing the segment's screen recording, on which the desktop app marks the cursor position and clicks; fixed checks in our code then discount the device's own idle periods and apply minimum thresholds before a flag is set. These outputs are probabilistic. They can be wrong, and they describe what was on screen, not the quality or value of anyone's work.

ScreenJournal makes no employment decision. Any decision about a person, whether on pay, performance, discipline or anything else, is made by your employer's managers, who are responsible for it.

The following human-review surfaces exist today:

  • the Review page, where managers can examine flagged segments, and the alerts inbox, where a manager approves or rejects a member's explanation;
  • corrections, where the organisation's administrators change a segment's score;
  • Add a reason, where a member, or a manager on the member's timeline, explains a paused, offline or away stretch (when the organisation's policy allows manual entries);
  • the member's own Activity timeline, which shows their segments, descriptions and scores.

If you disagree with a score, flag or ranking, ask your employer first. Your employer can correct the record or redact a time range. If your employer does not respond, contact support@screenjournal.ai.

A flag that activity may be simulated is an indicator that calls for human judgement. It is never proof of misconduct, and it should not be relied on without a person reviewing the underlying activity.

An employer's notice purposes must cover scoring, rankings and activity flags, and any alert rules the employer writes, because these are purposes of processing in their own right.

7. Your rights

Once the substantive duties commence, the DPDP Act gives Data Principals the right to:

  • access a summary of the personal data processed and the processing carried out;
  • correct, complete, update or erase personal data, where the Act allows;
  • grievance redressal from the Data Fiduciary and, after that, from the Board;
  • nominate someone to exercise these rights on their behalf on death or incapacity; and
  • withdraw consent, where processing relies on consent, as easily as it was given.

Your employer is the Data Fiduciary, so raise requests about monitoring data with your employer first. If you write to us, we pass the request to your employer and help it respond.

How requests are fulfilled today. We honour access, correction and erasure requests manually, on a verified request; there is no self-service export. Where your employer has enabled it, you can redact a time range from your own timeline; a redaction removes the activity data for that range, including any Record + Save video. Alert evidence clips are not removed by a member's redaction request. Our Retention & Deletion Protocol describes how deletion is carried out.

8. Grievance redressal

  • Write to support@screenjournal.ai with the subject line "Data protection request". Say whether you are a monitored employee, a customer or someone else, and what you are asking for.
  • We acknowledge every request. We verify who you are through the sign-in email on your account, or through your employer's administrator.
  • Under the Rules, Data Fiduciaries must respond to rights requests and grievances within ninety days once the substantive duties commence. We aim to respond well within that.
  • Escalation to the Data Protection Board becomes available as its complaint provisions commence. Until then, raise a grievance with your employer and with us.

9. How we assist our customers

As Data Processor we help the employer meet its own duties:

  • Safeguards (Rule 6). The Rules require reasonable security safeguards, including access control, encryption, logging and measures for continued processing. Our Security page describes the measures in place and what is not yet built. We do not currently keep database backups.
  • Breach intimation (Rule 7). A Data Fiduciary must inform affected Data Principals and the Board of a personal data breach without delay, and give the Board a detailed report within 72 hours. We notify the affected customer without undue delay after confirming a breach and give the facts it needs for its own intimation. We do this manually; there is no automated notification.
  • Erasure (Rule 8). When an employer instructs us to erase data, or its subscription ends, we delete it by our operational procedure.

10. Cross-border transfers

The service is hosted in Germany. Activity time-series data is stored in India, in Amazon Web Services' Mumbai region. Some data is transferred onward to the vendors listed on our Subprocessors page, including AI processing through Google Vertex AI and Google's Gemini API. These transfers take place under each vendor's standard terms.

The DPDP Act allows transfers outside India except to countries the central government restricts by notification. We are not aware of any such restriction affecting our vendors. The Act does not override stricter sectoral rules: customers in banking, payments, insurance or securities should check any localisation requirements from their own regulators before deploying.

11. Significant data fiduciaries

The central government may designate a Data Fiduciary as a significant data fiduciary, based on factors such as the volume and sensitivity of the data and the risk to Data Principals. A designated customer must appoint a Data Protection Officer based in India, carry out periodic data protection impact assessments and audits, and meet any further duties the Rules set.

These duties apply only if a designation is made; we are not aware of any designation affecting us or our customers. We do not have an India-based Data Protection Officer. If a customer is designated, we will give it the processing facts it needs for its assessments.

12. Retention

Data is retained for the term of your employer's subscription unless it is deleted earlier on a verified request or by your employer. Where Record + Save is enabled, stored screen video is kept for up to three months by policy. Automated expiry is not yet built; deletion is carried out by our operational procedure.

Our Retention & Deletion Protocol sets out how long each kind of data is kept.

13. Translations

This page is in English. If you need a version in a language listed in the Eighth Schedule to the Constitution of India, ask us; we will discuss what we can provide.

We list every change on the Legal page with its effective date and, where practicable, post material changes before they take effect.

Related: Privacy Policy, Subprocessors, Security, Retention & Deletion Protocol, Data Protection Contacts, Vulnerability Disclosure Policy, Cookie Policy and Terms of Use.

Contact: support@screenjournal.ai (subject "Data protection request"). Post: Cyberinfra Limited, 50 Athol Street, Douglas, Isle of Man IM1 1JB.

This page is for information and is not legal advice. Employers remain responsible, as Data Fiduciary, for the lawfulness of their own monitoring.

Changes and previous versions

  • 5 October 2026v2.0: current stack; Rules commencement dates; Board timing; automated-processing and redaction wording.

Questions about this document: support@screenjournal.ai. Canonical URL: /legal/india-dpdp.