Regulatory Status

Last updated 5 August 2026

This page sets out Dunime's legal standing, the law our work sits under, and, just as importantly, what we do not claim. Security firms are easy to overstate credentials for, so nothing is asserted here until it can be evidenced on request.

1. Legal entity

Dunime Technologies Private Limited is a private limited company incorporated in India in 2026, CIN U62020DC2026PTC473332, operating from Delhi NCR and serving client organisations in India, Hong Kong, Singapore and Germany.

Where a document, an invoice or a contract needs the registered name, it is the name above. Anything signed on behalf of Dunime is signed in that name.

2. What we are

A private technology services company providing custom software development, business automation, cybersecurity and cyber audit work, and technology systems delivery, to client organisations.

We serve clients in India, Hong Kong, Singapore and Germany. Those are the places our clients are, not places we have offices.

3. The law we work under

Being subject to a law is not a credential. This section is here because clients ask what rules apply to a technology supplier in India, and the honest answer is more useful than a logo.

  • Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The Rules were notified on 13 November 2025 as G.S.R. 846(E) and commence in stages. The Data Protection Board of India was constituted on notification; Consent Manager registration follows on 13 November 2026; and the substantive duties, covering notice, consent, security safeguards, breach reporting, data principal rights and cross-border transfer, take effect on 13 May 2027. In client work we are usually the Data Processor and the client is the Data Fiduciary.
  • Information Technology Act 2000. Section 43A and the Sensitive Personal Data or Information Rules 2011 remain in force during the transition. Section 44(2) of the DPDP Act will omit section 43A when it commences, currently expected alongside the May 2027 phase, so for now both regimes run in parallel.
  • CERT-In Directions of 28 April 2022, issued under section 70B(6) of the IT Act. These apply to service providers, intermediaries, data centres, body corporates and government organisations, which includes us. Section 7 sets out what they require.
  • The GDPR, Regulation (EU) 2016/679, where we process personal data for a client established in the European Union.
  • Client-side obligations under the laws of Hong Kong and Singapore reach us through the contract, principally as a duty on the client to bind us to a comparable standard of protection.

4. Standards our work references

There is a real difference between being certified to a standard, being audited against one, and aligning your practice with one. The first two are held by an accredited body and can be checked; the third is a description of how you work. This page will only ever use the wording that is true.

Three words get used interchangeably and should not be. Certified means an accredited body has audited an organisation and issued a certificate that can be checked with that body. Audited against means an assessment was carried out using a standard as the yardstick, producing findings mapped to its controls, without a certificate being issued. Aligned with is a description of how an organisation works, claimed by itself. Our engagements are scoped and reported against whichever framework a client names, so that every finding traces to a numbered control rather than to an opinion. Where a certificate carrying accreditation is needed, we prepare the evidence and work alongside the body entitled to issue it.

5. Authorisation for security testing

All testing is performed strictly under written authorisation defining the scope, the systems, the testing window and the escalation contacts. We decline work where the requesting party cannot demonstrate authority over the target, and we stop if that authority turns out not to hold.

This is not caution for its own sake. Under sections 43 and 66 of the IT Act 2000, the same technical act is lawful testing or a civil wrong and a criminal offence depending entirely on whether authorisation exists. A firm that is casual about the paperwork is telling you something about how it will treat your systems. Section 5 of the Terms of Service lists exactly what we need before a test begins.

6. Incident reporting duties we are subject to

Two separate clocks can run at once, and clients are entitled to know that before they engage us.

  • CERT-In, within six hours. The 2022 Directions require the cyber incident types they list to be reported to CERT-In within six hours of being noticed or notified. They also require logs of ICT systems to be maintained for 180 days and held within India, and system clocks to be synchronised to the national time servers. Non-compliance carries criminal liability under section 70B(7) of the IT Act.
  • The Data Protection Board, without delay, then 72 hours. For a personal data breach, section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025 require the Board and every affected person to be told without delay, followed by a fuller report to the Board within 72 hours.

Where an engagement makes the client the Data Fiduciary, the notification duty is theirs, and our job is to give them what they need fast enough for them to meet it.

7. Data handling and location

India does not impose a general data localisation requirement on personal data. Rule 15 of the DPDP Rules 2025 works the other way round: transfer outside India is permitted unless the Central Government restricts a country or territory by order, and no such order has been made as at the date on this page. Sector regulators can impose their own stricter rules, and CERT-In's 180-day log retention must be met within India.

For clients in the European Union, India holds no adequacy decision, so transfers to us rely on Standard Contractual Clauses with a transfer impact assessment, alongside an Article 28 data processing agreement.

8. Verifying any of this

Write to director@dunime.com before contracting and we will send the underlying documents. If a claim on this page cannot be evidenced on request, treat that as a reason not to engage us. That test should be applied to every supplier, including us.

9. Raising a concern about our conduct

If you believe testing has been carried out against a system without proper authority, or that someone has claimed Dunime credentials it does not hold, tell us at director@dunime.com. Privacy complaints are covered by section 14 of the Privacy Policy, which also explains the route to the Data Protection Board of India.

This page is written from the primary sources and states the position as at the date above. Where the law changes, this page changes with it.

Privacy policy Terms of service Regulatory status