Loading

Government of India · CRIMSON System

Privacy Policy

This document describes how CRIMSON collects, processes, stores, and protects information relating to officers, case subjects, and complainants. All processing is performed under the authority of applicable Indian law.

DPDPA 2023 Compliant AES-256 Encrypted Sovereign Infrastructure Last Updated: 1 September 2026

Sovereign Data Commitment

All data processed by CRIMSON remains within the Government of India's sovereign infrastructure. No case intelligence, suspect profile, or officer data is ever transmitted to commercial cloud services or foreign servers.

1. Overview

This Privacy Policy governs the collection, storage, processing, and disclosure of information within the CRIMSON Criminal Intelligence Management System ("System"). It applies to all authorised users including officers, administrators, and supervisory personnel.

CRIMSON operates exclusively on government-controlled, sovereign infrastructure. No personal data, case intelligence, or investigative information is transferred to commercial cloud providers, foreign entities, or any third party outside the authorised law enforcement ecosystem.

This Policy is issued in compliance with the Information Technology Act 2000, the CCTNS Framework, applicable State Police Acts, and the principles established under the Digital Personal Data Protection Act 2023.

2. Information Collected

Officer Identity Data: Name, service number, badge number, official email address, rank, unit, and biometric verification data used during system enrolment and authentication.

Session & Access Logs: IP address, device fingerprint, browser/client agent, timestamps of login and logout, geographic location of access (where available), and duration of session.

Operational Data: Every record created, modified, queried, or deleted by an officer — including FIRs, accused profiles, entity nodes, case notes, evidence uploads, and intelligence reports.

Communication Data: Internal system messages, case assignment notifications, alert acknowledgements, and access request communications transmitted through the System's messaging layer.

System Telemetry: Error logs, performance metrics, and anomaly detection signals generated by the System's automated monitoring infrastructure.

3. Purpose of Processing

Authentication & Access Control: To verify the identity and clearance level of each officer at every session and enforce role-based access boundaries.

Operational Intelligence: To construct, maintain, and analyse case records, criminal network graphs, entity relationship maps, and intelligence summaries in support of active investigations.

Audit & Accountability: To produce immutable, court-admissible records of every system action for use in departmental enquiries, judicial proceedings, and compliance audits.

Security & Integrity: To detect, investigate, and respond to unauthorised access attempts, data exfiltration, insider threats, and system anomalies.

System Improvement: Anonymised, aggregated usage telemetry may be used to improve system performance, reliability, and analytical accuracy, subject to the approval of the National Operations Cell.

4. Data Subjects & Their Information

The System holds information about three categories of individuals: (a) Officers — authorised users of the System, (b) Accused / Suspects — individuals named in FIRs or linked through investigation, and (c) Complainants / Witnesses — parties recorded in case documentation.

Information about accused and suspect individuals is processed strictly under the authority of the Code of Criminal Procedure 1973, applicable State Police Acts, and court orders. Such processing is necessary for the performance of public law enforcement functions.

Complainant and witness data is handled with heightened sensitivity. Officers are required to apply the Witness Protection Scheme protocols and minimise exposure of witness identity within investigation records.

Minors (persons under 18 years) identified in case records are subject to additional access restrictions. Records involving minors are accessible only to officers with juvenile justice clearance, in compliance with the Juvenile Justice Act 2015.

5. Data Sharing & Disclosure

Data within CRIMSON is shared only on a strict need-to-know basis. Inter-agency data sharing requires a formal request lodged through the System, approval from a Superintendent-level officer, and is logged for audit purposes.

CRIMSON may share information with the National Crime Records Bureau (NCRB), Central Bureau of Investigation (CBI), Interpol National Central Bureau (NCB), and the Financial Intelligence Unit (FIU) when required by law or court direction.

No case data, suspect profile, or intelligence report may be shared with media organisations, political bodies, private entities, or foreign governments without explicit written authorisation from the Director General of Police and, where applicable, the Ministry of Home Affairs.

In the event of a data breach or unauthorised disclosure, the affected unit's administrator must notify the CRIMSON National Operations Cell within 6 hours. Affected individuals will be notified in accordance with the DPDPA 2023 requirements.

6. Data Retention

Active Case Records: Retained for the duration of the investigation plus 10 years after final court disposal, or as directed by the relevant court.

Closed / Undetected Cases: Retained for a minimum of 7 years from the date of closure, subject to annual review by the unit's Records Officer.

Officer Session Logs: Retained for 5 years. Access logs for sensitive operations (e.g., accessing a Top Secret case, bulk data exports) are retained for 10 years.

Biometric & Identity Data of Officers: Retained for the duration of service plus 3 years after separation or retirement, after which it is purged following dual authorisation.

Permanent Preservation: Records forming part of a conviction, acquittal, or landmark legal precedent may be preserved indefinitely by order of the Records Preservation Committee.

7. Security Measures

Authentication: Multi-factor authentication is mandatory for all officer accounts. Session tokens are short-lived (4 hours) and rotate on each request. Passwords are hashed using bcrypt with a cost factor of 14.

Encryption: All data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256. Encryption keys are managed by a dedicated Hardware Security Module (HSM) with quarterly key rotation.

Network Security: The System is accessible only through approved government networks or via authorised VPN endpoints. All external access is proxied through an Application-Layer Firewall with deep packet inspection.

Physical Security: Servers are located in Tier-IV government data centres with 24×7 physical surveillance, biometric access control, and redundant power and cooling systems.

Penetration Testing: The System undergoes bi-annual penetration testing by CERT-In empanelled security auditors. Critical vulnerabilities are remediated within 72 hours of identification.

8. Rights & Requests

Accused individuals have the right to request, through their legal representative, a summary of information held about them in active case records, subject to the limitations prescribed under the CrPC and Evidence Act. Requests must be addressed to the court of competent jurisdiction.

Officers may request a copy of their own session and access logs by submitting a formal written request to their unit's System Administrator. Such requests will be fulfilled within 15 working days.

Correction requests for officer profile data (e.g., rank, unit) must be submitted through the official service record amendment process and cannot be self-modified.

Deletion of case records is not available to individual officers. Requests for expungement of records must be made to a court of competent jurisdiction or the State's Legal Metrology Authority as appropriate.

9. Policy Updates & Contact

This Privacy Policy is reviewed and updated annually or upon significant changes to applicable law, system architecture, or operational requirements.

Officers will be notified of material changes via the System's internal notification channel and must acknowledge the updated policy within 14 days of notification.

For privacy-related queries, data breach reports, or requests, contact the CRIMSON Data Protection Officer at: dpo@crimson-intel.gov.in or through the secure internal ticketing system.

Complaints regarding privacy violations may also be escalated to the National Data Protection Board under the DPDPA 2023, or to the State Human Rights Commission as appropriate.

© 2026 CRIMSON · Criminal Intelligence Management System

Government of India · All rights reserved · DPDPA 2023 Compliant