Grievance Policy

Personal Data Grievance Redressal Policy

Policy Version: 1.0

Policy Owner: Data Protection Officer

Effective Date: 01st August 2026

Last Reviewed: 01st August 2026

Review Frequency: Annual or upon any material change in applicable data protection law

1. Purpose

Gateway Distriparks Limited (“GDL”, “we”, “us” or “our”) is committed to protecting the privacy and personal data of individuals whose personal data is processed in connection with our business and operations.

GDL has established this Personal Data Grievance Redressal Policy (“Policy”) to provide Data Principals with a readily accessible, transparent and effective mechanism for:

  • Raising concerns regarding processing of their personal data
  • Exercising applicable rights relating to their personal data
  • Reporting suspected misuse, unauthorised disclosure or compromise of personal data
  • Obtaining appropriate redressal of privacy-related grievances

This Policy has been prepared considering the requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), and other applicable laws and regulations.

2. Scope

This Policy applies where GDL acts as a Data Fiduciary in relation to digital personal data processed in connection with its operations. It may cover personal data relating to, among others:

  • Customers and prospective customers
  • Employees and former employees
  • Job applicants
  • Consultants
  • Contractors and contract workers
  • Vendors and service providers
  • Customs House Agents / Customs Brokers
  • Transporters and drivers
  • Shipping-line representatives
  • Freight-forwarding and logistics partners
  • Visitors to GDL premises
  • Users of GDL websites, applications and customer portals
  • Authorised representatives of customers and vendors
  • Shareholders and other stakeholders, where applicable
  • Other individuals whose personal data is processed by GDL

The Policy covers personal data processed in connection with GDL’s Inland Container Depots, Container Freight Stations, rail and road logistics operations, corporate offices, websites, digital platforms and other business processes.

3. Role of GDL as Data Fiduciary and Data Processor

Depending upon the processing activity, GDL may act as:

3.1 Data Fiduciary

GDL acts as a Data Fiduciary where it determines the purpose and means of processing personal data.

Examples may include personal data processed for:

  • Employee administration
  • Recruitment
  • Vendor management
  • Customer onboarding
  • Customer account management
  • Visitor management
  • Website operation
  • Access-control management
  • CCTV and physical-security systems
  • Customer communication
  • Statutory and regulatory compliance
  • Safety, security and business administration

3.2 Data Processor

In certain circumstances, GDL may process personal data solely on behalf of and under the instructions of another Data Fiduciary.

Where a grievance concerns personal data for which another organisation is the relevant Data Fiduciary, GDL may:

  • Direct the Data Principal to the appropriate Data Fiduciary
  • Forward the grievance to the appropriate Data Fiduciary where permitted
  • Assist such Data Fiduciary in responding to the grievance in accordance with applicable contractual and legal obligations
4. Grievance Officer / Data Protection Contact

GDL has designated the following officer as the primary contact for matters relating to processing of personal data and privacy grievances:

Data Protection Officer / Grievance Officer

Name: Atul Kumar Bansal

Designation: Data Protection Officer

Company: Gateway Distriparks Limited

Email: dpo@gatewaydistriparks.com

Telephone: +91-11-40554400, Ext. 405

Business Hours: Monday to Friday, 10:00 AM to 6:00 PM IST

Address: 4th Floor, Prius Platinum, Saket District Centre, New Delhi – 110017, India

The Data Protection Officer / Grievance Officer shall act as the principal point of contact for Data Principals seeking information regarding GDL’s processing of their personal data or raising privacy-related grievances.

5. Matters for Which a Grievance May Be Raised

A Data Principal may raise a grievance relating to an act or omission concerning GDL’s processing of their personal data or the exercise of rights available under applicable law.

Grievances may include, but are not limited to:

5.1 Access to Personal Data

A request for information regarding personal data being processed by GDL, including information available to the Data Principal under applicable law.

5.2 Correction of Personal Data

A request to correct inaccurate or misleading personal data maintained by GDL.

5.3 Completion of Personal Data

A request to complete personal data that is incomplete.

5.4 Updating of Personal Data

A request to update personal data maintained by GDL.

5.5 Erasure of Personal Data

A request to erase personal data where such erasure is permissible under applicable law and the information is no longer required to be retained for a lawful purpose.

5.6 Withdrawal of Consent

A grievance concerning:

  • Inability to withdraw consent
  • Failure to give effect to withdrawal of consent
  • Processing continuing after valid withdrawal of consent
  • Difficulty accessing the mechanism provided for withdrawing consent

5.7 Unauthorised Processing

A concern that personal data has been collected, used, disclosed or otherwise processed without an appropriate lawful basis.

5.8 Excessive Collection

A concern that GDL has collected personal data that is not necessary for the specified purpose.

5.9 Unauthorised Disclosure or Sharing

A concern relating to unauthorised disclosure, transfer or sharing of personal data with another person or organisation.

5.10 Personal Data Security

A grievance relating to suspected:

  • Unauthorised access
  • Personal data leakage
  • Compromise of personal data
  • Loss of personal data
  • Accidental disclosure
  • Cyber-security incident involving personal data
  • Personal data breach

5.11 Retention and Erasure

A concern that personal data is being retained beyond the period required for the specified purpose or applicable legal/regulatory requirements.

5.12 Children’s Personal Data

A grievance concerning processing of personal data relating to a child, including matters concerning verifiable consent of a parent or lawful guardian where required under applicable law.

5.13 Nomination

A request or grievance concerning the exercise of the right of nomination available under the DPDP Act and applicable Rules.

5.14 Other Privacy Concerns

Any other act or omission by GDL concerning processing of personal data or exercise of Data Principal rights.

6. How to Submit a Grievance

A Data Principal may submit a personal-data grievance through one of the following channels:

By Email
dpo@gatewaydistriparks.com

By Post
Data Protection Officer / Grievance Officer
Gateway Distriparks Limited
4th Floor, Prius Platinum
Saket District Centre
New Delhi – 110017 India

Online
Through the GDL Privacy / Data Principal Rights / Grievance Request
Website: www.gatewaydistriparks.com

GDL may implement additional electronic mechanisms, including a privacy request portal or Data Principal Request Management system, for submission and tracking of grievances.

7. Information Required for Raising a Grievance

To enable GDL to identify the Data Principal and investigate the grievance, the Data Principal should provide information reasonably necessary for processing the request.

This may include:

  • Full name
  • Registered email address
  • Registered mobile number
  • Employee ID, where applicable
  • Customer ID or customer code, where applicable
  • Vendor ID, where applicable
  • Registered user ID
  • Organisation/company represented by the individual
  • Location or GDL terminal concerned
  • Nature/category of grievance
  • Description of the grievance
  • Approximate date of the incident
  • Relevant reference, ticket, invoice, container, transaction or application number, where applicable
  • Details of any earlier communication
  • Documents or screenshots supporting the grievance, where relevant
  • The remedy or action requested

A Data Principal should not submit passwords, OTPs, PINs, complete banking credentials or personal data that is not reasonably necessary for resolution of the grievance.

8. Identity Verification

GDL may take reasonable and proportionate measures to verify the identity of the Data Principal before disclosing, correcting, updating or erasing personal data.

Depending upon the request, verification may be undertaken through:

  • Registered email address
  • Registered mobile number
  • OTP
  • Employee ID
  • Customer ID
  • Vendor ID
  • User/account identifier
  • Existing authentication credentials
  • Transaction/reference details
  • Other reasonable identifiers already associated with the Data Principal

Additional identification documents should be requested only where reasonably necessary.

GDL shall endeavour to avoid collecting additional personal data solely for verification where identity can reasonably be established using information already available with GDL.

9. Grievance Redressal Process

GDL shall follow the process below for handling privacy grievances.

01
Receipt of Grievance

A grievance received through the designated channel shall be recorded in the privacy grievance management system/register.

02
Acknowledgement

GDL shall ordinarily acknowledge receipt of a grievance within three working days.

Where technically feasible, a unique grievance or ticket reference number shall be provided to the Data Principal.

03
Verification

Where required, GDL shall verify the identity and authority of the person submitting the grievance.

04
Classification

The grievance shall be classified according to its nature, such as:

  • Access
  • Correction
  • Completion
  • Updating
  • Erasure
  • Consent
  • Consent Withdrawal
  • Unauthorised Processing
  • Data Sharing
  • Data Retention
  • Personal Data Breach
  • Children’s Personal Data
  • Nomination
  • Employee Privacy
  • Customer Privacy
  • Vendor Privacy
  • Other Privacy Matter
05
Assignment

The grievance shall be assigned to the relevant GDL department or responsible person for investigation.

Depending upon the grievance, this may include:

  • Information Technology
  • Information Security
  • Human Resources
  • Customer Service
  • Operations
  • Commercial
  • Finance
  • Legal
  • Compliance
  • Administration
  • Procurement
  • Vendor Management
  • Other relevant functions

The Data Protection Officer / Grievance Officer shall retain oversight of the grievance.

06
Investigation

The relevant department shall investigate the grievance and may examine, where appropriate:

  • Personal data records
  • Processing systems
  • User-access records
  • Consent records
  • Privacy notices
  • Contractual records
  • System logs
  • CCTV/access records
  • Customer/vendor records
  • Communication history
  • Data-sharing arrangements
  • Retention requirements
  • Applicable statutory or regulatory requirements
07
Corrective Action

Where appropriate, corrective action may include:

  • Correcting inaccurate personal data
  • Completing incomplete personal data
  • Updating personal data
  • Erasing personal data
  • Recording and implementing withdrawal of consent
  • Stopping processing where required
  • Correcting access permissions
  • Addressing unauthorised disclosure
  • Implementing security remediation
  • Updating internal procedures
  • Providing requested information
  • Correcting consent or preference records
  • Reviewing processor/vendor arrangements
  • Taking other action considered necessary
08
Response to Data Principal

GDL shall communicate the outcome of the grievance to the Data Principal, including, where appropriate:

  • Action taken
  • Information requested
  • Reasons for not accepting all or part of a request
  • Applicable legal or regulatory retention requirement
  • Further information required
  • Available escalation mechanism
09
Closure

The grievance shall be closed only after the outcome has been recorded and communicated to the Data Principal.

10. Grievance Resolution Timeline

GDL shall maintain appropriate technical and organisational measures to ensure timely redressal of personal-data grievances.

The following service levels shall normally apply:

Activity Target Timeline
Acknowledgement of grievance Within 3 working days
Initial review / assignment Within 7 working days
Target resolution for routine grievances Within 30 calendar days
Maximum grievance-redressal period under the applicable DPDP framework Not exceeding 90 days

GDL will endeavour to resolve grievances substantially earlier than the maximum permitted period.

Where additional information is required from the Data Principal, GDL shall communicate the requirement promptly.

A complex grievance involving multiple systems, locations, processors, third parties, legal obligations or security investigations may require additional investigation; however, GDL shall manage such grievances within the applicable legally prescribed period.

11. Personal Data Breach or Security Incident Grievances

Where a grievance indicates an actual or suspected personal data breach, it shall receive priority escalation and shall not wait for the ordinary grievance resolution cycle.

The Data Protection Officer / Grievance Officer shall coordinate, as appropriate, with:

  • Information Security
  • Information Technology
  • Legal
  • Relevant business functions
  • Senior management
  • Incident-response teams

The matter shall be handled in accordance with GDL’s Personal Data Breach Response / Incident Response Procedure.

Where required under applicable law, GDL shall provide the prescribed intimation concerning a personal data breach to affected Data Principals and to the Data Protection Board of India within the applicable timelines and in the prescribed manner.

12. Requests for Correction, Completion, Updating and Erasure

Upon receiving a valid request from a Data Principal and after necessary verification, GDL shall take appropriate action in accordance with applicable law.

Correction

Inaccurate or misleading personal data may be corrected.

Completion

Incomplete personal data may be completed.

Updating

Outdated personal data may be updated.

Erasure

Personal data may be erased where the purpose for which it was processed is no longer being served and retention is not required under applicable law.

GDL may continue to retain personal data where retention is necessary for:

  • Compliance with applicable laws
  • Customs requirements
  • Taxation requirements
  • Accounting requirements
  • Employment laws
  • Transportation/logistics regulations
  • Contractual obligations
  • Legal proceedings
  • Establishment, exercise or defence of legal claims
  • Fraud prevention
  • Security purposes
  • Another lawful requirement

Where a request cannot be fully acted upon, GDL shall communicate the applicable reason to the Data Principal.

13. Withdrawal of Consent

Where GDL processes personal data on the basis of consent, a Data Principal shall be provided with a mechanism to withdraw such consent.

The ease of withdrawing consent should be comparable to the ease with which consent was provided.

Following withdrawal of consent, GDL shall cease processing based on that consent within a reasonable time unless processing is otherwise required or permitted by applicable law.

Withdrawal of consent shall not affect processing lawfully undertaken before such withdrawal.

Where GDL has engaged a Data Processor for processing based solely on the withdrawn consent, GDL shall take appropriate steps in accordance with applicable law and contractual arrangements.

14. Grievances Relating to Employees

Employees, former employees and job applicants may raise privacy grievances relating to matters including:

  • Employee master data
  • Attendance records
  • Payroll information
  • Biometric/access-control systems
  • CCTV
  • Recruitment records
  • Background verification
  • Employee benefits
  • Performance records
  • Official communication systems
  • IT systems
  • Employee monitoring where applicable
  • Disclosure of employee personal data

A privacy grievance is distinct from a general employment grievance.

Where the matter relates solely to employment conditions, salary, leave, appraisal, workplace conduct or another HR matter without a personal-data issue, it may be handled under GDL’s applicable employee grievance policy.

15. Grievances Relating to Customers, Transporters, Drivers and Business Partners

Considering GDL’s logistics operations, privacy grievances may arise from personal data processed through:

  • Customer registration
  • Customer portals
  • Vehicle and driver registration
  • Gate-entry systems
  • Transport-management systems
  • GPS/vehicle-tracking systems
  • Proof-of-delivery records
  • Terminal-access systems
  • Customs and shipping documentation
  • E-invoicing and payment systems
  • Customer-service interactions
  • CCTV surveillance
  • Vendor or contractor management systems

Such grievances shall be handled under this Policy where GDL is responsible as the Data Fiduciary for the relevant processing.

16. Children’s Personal Data

Where GDL processes personal data of a child and the applicable DPDP requirements apply, appropriate measures shall be taken to obtain verifiable consent of the parent or lawful guardian where required.

Privacy grievances involving children’s personal data shall be handled with enhanced care and priority.

GDL may take appropriate steps to verify:

  • The age of the child
  • The identity of the parent or lawful guardian
  • The relationship or authority of the person making the request
17. Nomination

Where applicable under the DPDP Act and DPDP Rules, a Data Principal may nominate one or more individuals who may exercise prescribed rights on their behalf in the event of death or incapacity.

GDL may prescribe an appropriate procedure and verification mechanism for recording and acting upon such nominations.

18. Internal Escalation

Where the Data Principal is dissatisfied with the response provided, the matter may be escalated for further review by the Data Protection Officer.

The escalation request should include:

  • Grievance reference number
  • Reason for dissatisfaction
  • Additional information, if any
  • Requested resolution

The DPO may obtain assistance from Legal, Information Security, HR, Compliance, IT or relevant senior management as required.

19. Right to Approach the Data Protection Board of India

Where the applicable provisions of the DPDP Act and DPDP Rules are in force, a Data Principal should first provide GDL an opportunity to redress their grievance through the grievance-redressal mechanism provided under this Policy.

If the Data Principal remains dissatisfied after exhausting GDL’s grievance-redressal mechanism, they may approach the Data Protection Board of India in accordance with the procedure prescribed under applicable law.

GDL shall update its website with the relevant electronic complaint mechanism or official Board details as and when required.

20. Duties of Data Principals

While exercising rights or submitting grievances, Data Principals are expected to comply with their applicable duties under the DPDP Act.

A Data Principal should, among other things:

  • Not impersonate another person
  • Not suppress material information while providing information for any document, identifier or proof of identity
  • Provide authentic information while exercising rights
  • Avoid raising false or frivolous grievances
  • Comply with applicable law

Nothing in this section is intended to discourage any individual from raising a genuine privacy concern.

21. Confidentiality

GDL shall treat privacy grievances confidentially and restrict access to persons who reasonably require the information for investigation and resolution.

Information submitted as part of a grievance may be used for:

  • Identity verification
  • Investigation
  • Communication with the Data Principal
  • Grievance resolution
  • Security investigation
  • Legal or regulatory compliance
  • Audit
  • Establishment, exercise or defence of legal claims
  • Maintenance of required compliance records
22. Grievance Register and Audit Trail

GDL shall maintain an appropriate Personal Data Grievance Register or electronic case-management record.

The register may record:

  • Grievance reference number
  • Date and time received
  • Data Principal category
  • Request/grievance category
  • Relevant GDL location/business unit
  • Assigned department
  • Date of acknowledgement
  • Actions taken
  • Communication history
  • Escalation status
  • Date of resolution
  • Outcome
  • Closure date
  • Applicable supporting evidence

Access to the grievance register shall be appropriately controlled.

23. Record Retention

Records relating to grievances shall be retained for a period reasonably necessary for:

  • Demonstrating compliance
  • Internal and external audits
  • Regulatory requirements
  • Legal proceedings
  • Dispute resolution
  • Security purposes

Grievance-related personal data shall not be retained indefinitely unless required by applicable law.

24. Technical and Organisational Measures

GDL shall maintain appropriate technical and organisational measures for effective grievance redressal, which may include:

  • Central grievance tracking
  • Automated acknowledgement
  • Unique ticket numbers
  • Role-based access
  • SLA monitoring
  • Escalation alerts
  • Identity verification controls
  • Audit logging
  • Secure document upload
  • Workflow-based assignment
  • Overdue grievance alerts
  • Reporting dashboards
  • Periodic management review
25. Non-Retaliation

No person shall be subjected to retaliation merely for raising a genuine privacy grievance or exercising a right available under applicable data protection law.

26. Relationship With Other GDL Policies

This Policy should be read together with GDL’s applicable:

  • Privacy Notice
  • Data Privacy Policy
  • Information Security Policy
  • Personal Data Breach Response Procedure
  • Data Retention and Erasure Policy
  • Consent Management Policy
  • Data Principal Rights Management Procedure
  • Children’s Personal Data Policy
  • Vendor / Data Processor Management Policy
  • Employee Privacy Notice
  • Staff Grievance Handling Policy

Where a grievance relates to fraud, whistle-blowing, sexual harassment, employment conditions or other matters governed by a separate GDL policy, the matter may additionally or alternatively be handled under that specific policy.

27. Governance and Review

The Data Protection Officer shall be the owner of this Policy and shall periodically review:

  • Number of grievances received
  • Categories of grievances
  • Average acknowledgement time
  • Average resolution time
  • Overdue grievances
  • Repeat grievances
  • Root causes
  • Security-related grievances
  • Grievances escalated internally
  • Regulatory complaints
  • Corrective/preventive actions

Material trends and significant privacy risks identified through grievances should be reported to appropriate senior management.

28. Changes to this Policy

GDL may modify this Policy from time to time to reflect:

  • Amendments to applicable law
  • Notifications under the DPDP Act
  • Amendments to the DPDP Rules
  • Directions or orders of the Data Protection Board of India
  • Changes in GDL’s processing activities
  • Changes in technology or security practices
  • Improvements to GDL’s privacy governance framework
29. Contact Details

For questions, Data Principal requests or grievances concerning processing of personal data, please contact:

Data Protection Officer / Grievance Officer

Mr. Atul Kumar Bansal
Gateway Distriparks Limited
4th Floor, Prius Platinum
Saket District Centre
New Delhi – 110017, India

Email: dpo@gatewaydistriparks.com

Telephone: +91-11-40554400, Ext. 405

Working Hours: Monday–Friday, 10:00 AM–6:00 PM IST

“Committed to responsible processing of personal data and protection of Data Principal rights.”