- What it describes
- Personal data that has already left your organisation’s control and is now reachable from outside it: leaked credentials tied to customer or staff identities, storage that answers without authentication, documents a search engine has indexed, and source repositories carrying customer records. Each of those is an observable fact about a system on the public internet.
- Where it stops
- This is not legal advice, and it is not a reading of the Digital Personal Data Protection Act, 2023. Nothing here tells you whether a given exposure is a personal data breach under the Act, whether a notification duty arises, who would have to be told, or on what timeline. ShadowMap does not make an organisation DPDP-compliant.
- Where the statutory question belongs
- With your legal counsel and whoever owns data protection in your organisation, with the evidence in front of them. What monitoring contributes is that evidence: specific, attributable and repeatable. Where the readiness work itself needs doing (applicability, consent, rights workflow, processor due-diligence), that is an advisory engagement, and Security Brigade runs it on a separate site under a separate scope.