Personal Data Grievance Redressal Policy
Policy Version: 1.0
Policy Owner: Data Protection Officer
Effective Date: 01st August 2026
Last Reviewed: 01st August 2026
Review Frequency: Annual or upon any material change in applicable data protection law
1. Purpose
Gateway Distriparks Limited (“GDL”, “we”, “us” or “our”) is committed to protecting the privacy and personal data of individuals whose personal data is processed in connection with our business and operations.
GDL has established this Personal Data Grievance Redressal Policy (“Policy”) to provide Data Principals with a readily accessible, transparent and effective mechanism for:
- Raising concerns regarding processing of their personal data
- Exercising applicable rights relating to their personal data
- Reporting suspected misuse, unauthorised disclosure or compromise of personal data
- Obtaining appropriate redressal of privacy-related grievances
This Policy has been prepared considering the requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), and other applicable laws and regulations.
2. Scope
This Policy applies where GDL acts as a Data Fiduciary in relation to digital personal data processed in connection with its operations. It may cover personal data relating to, among others:
- Customers and prospective customers
- Employees and former employees
- Job applicants
- Consultants
- Contractors and contract workers
- Vendors and service providers
- Customs House Agents / Customs Brokers
- Transporters and drivers
- Shipping-line representatives
- Freight-forwarding and logistics partners
- Visitors to GDL premises
- Users of GDL websites, applications and customer portals
- Authorised representatives of customers and vendors
- Shareholders and other stakeholders, where applicable
- Other individuals whose personal data is processed by GDL
The Policy covers personal data processed in connection with GDL’s Inland Container Depots, Container Freight Stations, rail and road logistics operations, corporate offices, websites, digital platforms and other business processes.
3. Role of GDL as Data Fiduciary and Data Processor
Depending upon the processing activity, GDL may act as:
3.1 Data Fiduciary
GDL acts as a Data Fiduciary where it determines the purpose and means of processing personal data.
Examples may include personal data processed for:
- Employee administration
- Recruitment
- Vendor management
- Customer onboarding
- Customer account management
- Visitor management
- Website operation
- Access-control management
- CCTV and physical-security systems
- Customer communication
- Statutory and regulatory compliance
- Safety, security and business administration
3.2 Data Processor
In certain circumstances, GDL may process personal data solely on behalf of and under the instructions of another Data Fiduciary.
Where a grievance concerns personal data for which another organisation is the relevant Data Fiduciary, GDL may:
- Direct the Data Principal to the appropriate Data Fiduciary
- Forward the grievance to the appropriate Data Fiduciary where permitted
- Assist such Data Fiduciary in responding to the grievance in accordance with applicable contractual and legal obligations
4. Grievance Officer / Data Protection Contact
GDL has designated the following officer as the primary contact for matters relating to processing of personal data and privacy grievances:
Data Protection Officer / Grievance Officer
Name: Atul Kumar Bansal
Designation: Data Protection Officer
Company: Gateway Distriparks Limited
Email: dpo@gatewaydistriparks.com
Telephone: +91-11-40554400, Ext. 405
Business Hours: Monday to Friday, 10:00 AM to 6:00 PM IST
Address: 4th Floor, Prius Platinum, Saket District Centre, New Delhi – 110017, India
The Data Protection Officer / Grievance Officer shall act as the principal point of contact for Data Principals seeking information regarding GDL’s processing of their personal data or raising privacy-related grievances.
5. Matters for Which a Grievance May Be Raised
A Data Principal may raise a grievance relating to an act or omission concerning GDL’s processing of their personal data or the exercise of rights available under applicable law.
Grievances may include, but are not limited to:
5.1 Access to Personal Data
A request for information regarding personal data being processed by GDL, including information available to the Data Principal under applicable law.
5.2 Correction of Personal Data
A request to correct inaccurate or misleading personal data maintained by GDL.
5.3 Completion of Personal Data
A request to complete personal data that is incomplete.
5.4 Updating of Personal Data
A request to update personal data maintained by GDL.
5.5 Erasure of Personal Data
A request to erase personal data where such erasure is permissible under applicable law and the information is no longer required to be retained for a lawful purpose.
5.6 Withdrawal of Consent
A grievance concerning:
- Inability to withdraw consent
- Failure to give effect to withdrawal of consent
- Processing continuing after valid withdrawal of consent
- Difficulty accessing the mechanism provided for withdrawing consent
5.7 Unauthorised Processing
A concern that personal data has been collected, used, disclosed or otherwise processed without an appropriate lawful basis.
5.8 Excessive Collection
A concern that GDL has collected personal data that is not necessary for the specified purpose.
5.9 Unauthorised Disclosure or Sharing
A concern relating to unauthorised disclosure, transfer or sharing of personal data with another person or organisation.
5.10 Personal Data Security
A grievance relating to suspected:
- Unauthorised access
- Personal data leakage
- Compromise of personal data
- Loss of personal data
- Accidental disclosure
- Cyber-security incident involving personal data
- Personal data breach
5.11 Retention and Erasure
A concern that personal data is being retained beyond the period required for the specified purpose or applicable legal/regulatory requirements.
5.12 Children’s Personal Data
A grievance concerning processing of personal data relating to a child, including matters concerning verifiable consent of a parent or lawful guardian where required under applicable law.
5.13 Nomination
A request or grievance concerning the exercise of the right of nomination available under the DPDP Act and applicable Rules.
5.14 Other Privacy Concerns
Any other act or omission by GDL concerning processing of personal data or exercise of Data Principal rights.
6. How to Submit a Grievance
A Data Principal may submit a personal-data grievance through one of the following channels:
By Email
dpo@gatewaydistriparks.com
By Post
Data Protection Officer / Grievance Officer
Gateway Distriparks Limited
4th Floor, Prius Platinum
Saket District Centre
New Delhi – 110017 India
Online
Through the GDL Privacy / Data Principal Rights / Grievance Request
Website: www.gatewaydistriparks.com
GDL may implement additional electronic mechanisms, including a privacy request portal or Data Principal Request Management system, for submission and tracking of grievances.
7. Information Required for Raising a Grievance
To enable GDL to identify the Data Principal and investigate the grievance, the Data Principal should provide information reasonably necessary for processing the request.
This may include:
- Full name
- Registered email address
- Registered mobile number
- Employee ID, where applicable
- Customer ID or customer code, where applicable
- Vendor ID, where applicable
- Registered user ID
- Organisation/company represented by the individual
- Location or GDL terminal concerned
- Nature/category of grievance
- Description of the grievance
- Approximate date of the incident
- Relevant reference, ticket, invoice, container, transaction or application number, where applicable
- Details of any earlier communication
- Documents or screenshots supporting the grievance, where relevant
- The remedy or action requested
A Data Principal should not submit passwords, OTPs, PINs, complete banking credentials or personal data that is not reasonably necessary for resolution of the grievance.
8. Identity Verification
GDL may take reasonable and proportionate measures to verify the identity of the Data Principal before disclosing, correcting, updating or erasing personal data.
Depending upon the request, verification may be undertaken through:
- Registered email address
- Registered mobile number
- OTP
- Employee ID
- Customer ID
- Vendor ID
- User/account identifier
- Existing authentication credentials
- Transaction/reference details
- Other reasonable identifiers already associated with the Data Principal
Additional identification documents should be requested only where reasonably necessary.
GDL shall endeavour to avoid collecting additional personal data solely for verification where identity can reasonably be established using information already available with GDL.
9. Grievance Redressal Process
GDL shall follow the process below for handling privacy grievances.
Receipt of Grievance
A grievance received through the designated channel shall be recorded in the privacy grievance management system/register.
Acknowledgement
GDL shall ordinarily acknowledge receipt of a grievance within three working days.
Where technically feasible, a unique grievance or ticket reference number shall be provided to the Data Principal.
Verification
Where required, GDL shall verify the identity and authority of the person submitting the grievance.
Classification
The grievance shall be classified according to its nature, such as:
- Access
- Correction
- Completion
- Updating
- Erasure
- Consent
- Consent Withdrawal
- Unauthorised Processing
- Data Sharing
- Data Retention
- Personal Data Breach
- Children’s Personal Data
- Nomination
- Employee Privacy
- Customer Privacy
- Vendor Privacy
- Other Privacy Matter
Assignment
The grievance shall be assigned to the relevant GDL department or responsible person for investigation.
Depending upon the grievance, this may include:
- Information Technology
- Information Security
- Human Resources
- Customer Service
- Operations
- Commercial
- Finance
- Legal
- Compliance
- Administration
- Procurement
- Vendor Management
- Other relevant functions
The Data Protection Officer / Grievance Officer shall retain oversight of the grievance.
Investigation
The relevant department shall investigate the grievance and may examine, where appropriate:
- Personal data records
- Processing systems
- User-access records
- Consent records
- Privacy notices
- Contractual records
- System logs
- CCTV/access records
- Customer/vendor records
- Communication history
- Data-sharing arrangements
- Retention requirements
- Applicable statutory or regulatory requirements
Corrective Action
Where appropriate, corrective action may include:
- Correcting inaccurate personal data
- Completing incomplete personal data
- Updating personal data
- Erasing personal data
- Recording and implementing withdrawal of consent
- Stopping processing where required
- Correcting access permissions
- Addressing unauthorised disclosure
- Implementing security remediation
- Updating internal procedures
- Providing requested information
- Correcting consent or preference records
- Reviewing processor/vendor arrangements
- Taking other action considered necessary
Response to Data Principal
GDL shall communicate the outcome of the grievance to the Data Principal, including, where appropriate:
- Action taken
- Information requested
- Reasons for not accepting all or part of a request
- Applicable legal or regulatory retention requirement
- Further information required
- Available escalation mechanism
Closure
The grievance shall be closed only after the outcome has been recorded and communicated to the Data Principal.
10. Grievance Resolution Timeline
GDL shall maintain appropriate technical and organisational measures to ensure timely redressal of personal-data grievances.
The following service levels shall normally apply:
| Activity | Target Timeline |
| Acknowledgement of grievance | Within 3 working days |
| Initial review / assignment | Within 7 working days |
| Target resolution for routine grievances | Within 30 calendar days |
| Maximum grievance-redressal period under the applicable DPDP framework | Not exceeding 90 days |
GDL will endeavour to resolve grievances substantially earlier than the maximum permitted period.
Where additional information is required from the Data Principal, GDL shall communicate the requirement promptly.
A complex grievance involving multiple systems, locations, processors, third parties, legal obligations or security investigations may require additional investigation; however, GDL shall manage such grievances within the applicable legally prescribed period.
11. Personal Data Breach or Security Incident Grievances
Where a grievance indicates an actual or suspected personal data breach, it shall receive priority escalation and shall not wait for the ordinary grievance resolution cycle.
The Data Protection Officer / Grievance Officer shall coordinate, as appropriate, with:
- Information Security
- Information Technology
- Legal
- Relevant business functions
- Senior management
- Incident-response teams
The matter shall be handled in accordance with GDL’s Personal Data Breach Response / Incident Response Procedure.
Where required under applicable law, GDL shall provide the prescribed intimation concerning a personal data breach to affected Data Principals and to the Data Protection Board of India within the applicable timelines and in the prescribed manner.
12. Requests for Correction, Completion, Updating and Erasure
Upon receiving a valid request from a Data Principal and after necessary verification, GDL shall take appropriate action in accordance with applicable law.
Correction
Inaccurate or misleading personal data may be corrected.
Completion
Incomplete personal data may be completed.
Updating
Outdated personal data may be updated.
Erasure
Personal data may be erased where the purpose for which it was processed is no longer being served and retention is not required under applicable law.
GDL may continue to retain personal data where retention is necessary for:
- Compliance with applicable laws
- Customs requirements
- Taxation requirements
- Accounting requirements
- Employment laws
- Transportation/logistics regulations
- Contractual obligations
- Legal proceedings
- Establishment, exercise or defence of legal claims
- Fraud prevention
- Security purposes
- Another lawful requirement
Where a request cannot be fully acted upon, GDL shall communicate the applicable reason to the Data Principal.
13. Withdrawal of Consent
Where GDL processes personal data on the basis of consent, a Data Principal shall be provided with a mechanism to withdraw such consent.
The ease of withdrawing consent should be comparable to the ease with which consent was provided.
Following withdrawal of consent, GDL shall cease processing based on that consent within a reasonable time unless processing is otherwise required or permitted by applicable law.
Withdrawal of consent shall not affect processing lawfully undertaken before such withdrawal.
Where GDL has engaged a Data Processor for processing based solely on the withdrawn consent, GDL shall take appropriate steps in accordance with applicable law and contractual arrangements.
14. Grievances Relating to Employees
Employees, former employees and job applicants may raise privacy grievances relating to matters including:
- Employee master data
- Attendance records
- Payroll information
- Biometric/access-control systems
- CCTV
- Recruitment records
- Background verification
- Employee benefits
- Performance records
- Official communication systems
- IT systems
- Employee monitoring where applicable
- Disclosure of employee personal data
A privacy grievance is distinct from a general employment grievance.
Where the matter relates solely to employment conditions, salary, leave, appraisal, workplace conduct or another HR matter without a personal-data issue, it may be handled under GDL’s applicable employee grievance policy.
15. Grievances Relating to Customers, Transporters, Drivers and Business Partners
Considering GDL’s logistics operations, privacy grievances may arise from personal data processed through:
- Customer registration
- Customer portals
- Vehicle and driver registration
- Gate-entry systems
- Transport-management systems
- GPS/vehicle-tracking systems
- Proof-of-delivery records
- Terminal-access systems
- Customs and shipping documentation
- E-invoicing and payment systems
- Customer-service interactions
- CCTV surveillance
- Vendor or contractor management systems
Such grievances shall be handled under this Policy where GDL is responsible as the Data Fiduciary for the relevant processing.
16. Children’s Personal Data
Where GDL processes personal data of a child and the applicable DPDP requirements apply, appropriate measures shall be taken to obtain verifiable consent of the parent or lawful guardian where required.
Privacy grievances involving children’s personal data shall be handled with enhanced care and priority.
GDL may take appropriate steps to verify:
- The age of the child
- The identity of the parent or lawful guardian
- The relationship or authority of the person making the request
17. Nomination
Where applicable under the DPDP Act and DPDP Rules, a Data Principal may nominate one or more individuals who may exercise prescribed rights on their behalf in the event of death or incapacity.
GDL may prescribe an appropriate procedure and verification mechanism for recording and acting upon such nominations.
18. Internal Escalation
Where the Data Principal is dissatisfied with the response provided, the matter may be escalated for further review by the Data Protection Officer.
The escalation request should include:
- Grievance reference number
- Reason for dissatisfaction
- Additional information, if any
- Requested resolution
The DPO may obtain assistance from Legal, Information Security, HR, Compliance, IT or relevant senior management as required.
19. Right to Approach the Data Protection Board of India
Where the applicable provisions of the DPDP Act and DPDP Rules are in force, a Data Principal should first provide GDL an opportunity to redress their grievance through the grievance-redressal mechanism provided under this Policy.
If the Data Principal remains dissatisfied after exhausting GDL’s grievance-redressal mechanism, they may approach the Data Protection Board of India in accordance with the procedure prescribed under applicable law.
GDL shall update its website with the relevant electronic complaint mechanism or official Board details as and when required.
20. Duties of Data Principals
While exercising rights or submitting grievances, Data Principals are expected to comply with their applicable duties under the DPDP Act.
A Data Principal should, among other things:
- Not impersonate another person
- Not suppress material information while providing information for any document, identifier or proof of identity
- Provide authentic information while exercising rights
- Avoid raising false or frivolous grievances
- Comply with applicable law
Nothing in this section is intended to discourage any individual from raising a genuine privacy concern.
21. Confidentiality
GDL shall treat privacy grievances confidentially and restrict access to persons who reasonably require the information for investigation and resolution.
Information submitted as part of a grievance may be used for:
- Identity verification
- Investigation
- Communication with the Data Principal
- Grievance resolution
- Security investigation
- Legal or regulatory compliance
- Audit
- Establishment, exercise or defence of legal claims
- Maintenance of required compliance records
22. Grievance Register and Audit Trail
GDL shall maintain an appropriate Personal Data Grievance Register or electronic case-management record.
The register may record:
- Grievance reference number
- Date and time received
- Data Principal category
- Request/grievance category
- Relevant GDL location/business unit
- Assigned department
- Date of acknowledgement
- Actions taken
- Communication history
- Escalation status
- Date of resolution
- Outcome
- Closure date
- Applicable supporting evidence
Access to the grievance register shall be appropriately controlled.
23. Record Retention
Records relating to grievances shall be retained for a period reasonably necessary for:
- Demonstrating compliance
- Internal and external audits
- Regulatory requirements
- Legal proceedings
- Dispute resolution
- Security purposes
Grievance-related personal data shall not be retained indefinitely unless required by applicable law.
24. Technical and Organisational Measures
GDL shall maintain appropriate technical and organisational measures for effective grievance redressal, which may include:
- Central grievance tracking
- Automated acknowledgement
- Unique ticket numbers
- Role-based access
- SLA monitoring
- Escalation alerts
- Identity verification controls
- Audit logging
- Secure document upload
- Workflow-based assignment
- Overdue grievance alerts
- Reporting dashboards
- Periodic management review
25. Non-Retaliation
No person shall be subjected to retaliation merely for raising a genuine privacy grievance or exercising a right available under applicable data protection law.
26. Relationship With Other GDL Policies
This Policy should be read together with GDL’s applicable:
- Privacy Notice
- Data Privacy Policy
- Information Security Policy
- Personal Data Breach Response Procedure
- Data Retention and Erasure Policy
- Consent Management Policy
- Data Principal Rights Management Procedure
- Children’s Personal Data Policy
- Vendor / Data Processor Management Policy
- Employee Privacy Notice
- Staff Grievance Handling Policy
Where a grievance relates to fraud, whistle-blowing, sexual harassment, employment conditions or other matters governed by a separate GDL policy, the matter may additionally or alternatively be handled under that specific policy.
27. Governance and Review
The Data Protection Officer shall be the owner of this Policy and shall periodically review:
- Number of grievances received
- Categories of grievances
- Average acknowledgement time
- Average resolution time
- Overdue grievances
- Repeat grievances
- Root causes
- Security-related grievances
- Grievances escalated internally
- Regulatory complaints
- Corrective/preventive actions
Material trends and significant privacy risks identified through grievances should be reported to appropriate senior management.
28. Changes to this Policy
GDL may modify this Policy from time to time to reflect:
- Amendments to applicable law
- Notifications under the DPDP Act
- Amendments to the DPDP Rules
- Directions or orders of the Data Protection Board of India
- Changes in GDL’s processing activities
- Changes in technology or security practices
- Improvements to GDL’s privacy governance framework
29. Contact Details
For questions, Data Principal requests or grievances concerning processing of personal data, please contact:
Data Protection Officer / Grievance Officer
Mr. Atul Kumar Bansal
Gateway Distriparks Limited
4th Floor, Prius Platinum
Saket District Centre
New Delhi – 110017, India
Email: dpo@gatewaydistriparks.com
Telephone: +91-11-40554400, Ext. 405
Working Hours: Monday–Friday, 10:00 AM–6:00 PM IST
“Committed to responsible processing of personal data and protection of Data Principal rights.”
Our Vision
Our Mission

Our vision is to render services far more superior than other National and Multinational Operators in the Logistic Industry.

- To provide quality, safety and security, cost effective & reliable service.
- To remain forever committed to excellence.
- To achieve each "END" tempered by "Quality" means.
- To make constructive contribution to the society at large.