All posts
CompliancePrivacy27 June 2026 5 min read

The DPDP Act 2023 and your expense data

Team Reimbilly · Compliance

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data-protection law. If you’re an Indian company processing employee expense data — names, bank details, travel history, medical receipts — it applies to you, and it applies to the tools you use. Here is how Reimbilly is built for it.

Consent that means something

On first launch, Reimbilly asks for specific, informed consent per processing purpose — not a single “I agree to everything” checkbox. Consent records are stored with timestamps, and withdrawing consent is as easy as giving it, straight from the app’s privacy settings.

Your rights as a data principal

  • Access: export every piece of personal data we hold about you from the app.
  • Correction: edit your profile and expense records directly.
  • Erasure: request account deletion; data is removed per our published retention schedule.
  • Grievance: a named Grievance Officer with published contact details and response timelines.

Behind the scenes

We maintain a record of processing activities (ROPA) covering every personal-data field, where it lives, its retention period, and every sub-processor that touches it. A breach-response runbook commits us to notifying the Data Protection Board and affected users within statutory timelines — with roles, templates, and a breach register ready before an incident, not after.

Compliance documents — privacy policy, terms, and security overview — are published on this site and versioned in the open.