Privacy Policy — Cyber Rapid Action Unit (CRAU)
1. Introduction
This Privacy Policy governs the operations of the Cyber Rapid Action Unit (CRAU), functioning under the Ministry of Home Affairs (MHA), in coordination with the Indian Cyber Crime Coordination Centre (I4C) and the Central Bureau of Investigation (CBI).
CRAU respects the privacy of citizens, organizations, and institutions, and ensures that all data collected, analyzed, or processed during cybercrime investigations is handled with confidentiality, legality, and accountability.
2. Scope of Operation
CRAU does not engage in broad public data collection.
Its operations are limited to cases formally assigned or escalated by authorized agencies such as MHA, I4C, or CBI.
It handles only high-priority, complex, or large-scale cybercrime investigations, ensuring a selective and secure approach to data handling.
3. Nature of Data Collected
Data processed by CRAU may include:
-
Digital forensic evidence and logs relevant to active cases.
-
Communication metadata for investigation and tracing.
-
Cyber threat indicators and network signatures.
-
Operational records shared by central and state cyber enforcement units.
CRAU does not store or process personal data unrelated to official investigations.
4. Purpose of Data Usage
The information collected or processed by CRAU is used strictly for:
-
Investigating and mitigating major cyber threats.
-
Supporting coordinated enforcement with MHA, I4C, CBI, and CERT-In.
-
Preserving digital evidence for lawful prosecution.
-
Conducting post-incident reviews and preventive policy development.
No data is shared outside authorized government channels.
5. Data Security and Retention
CRAU employs robust security protocols including:
-
End-to-end encryption for all transmitted data.
-
Restricted access control with role-based permissions.
-
Multi-factor authentication for authorized personnel.
-
Tamper-proof audit trails for every data access instance.
All data is stored within secure Government of India data centers and retained only as per the directives of MHA and I4C.
6. Data Confidentiality and Oversight
Access to sensitive information is governed by strict internal policies. Only authorized officers deputed from MHA, I4C, or CBI may review, process, or disseminate case-related information.
Every operation is subject to oversight, auditing, and accountability mechanisms ensuring compliance with national cybersecurity and privacy frameworks.
7. Third-Party Access
No external or private entity is permitted to access CRAU systems, databases, or intelligence reports.
All information sharing is done exclusively with government agencies on a need-to-know basis.
8. Transparency and Legal Compliance
CRAU operates within the framework of the Information Technology Act, 2000, and the associated rules, directives, and advisories issued by the Government of India.
All actions are undertaken with full adherence to national data privacy and information security laws.
9. Contact Information
Cyber Rapid Action Unit (CRAU)
Ministry of Home Affairs, Government of India
In coordination with the Indian Cyber Crime Coordination Centre (I4C) and the Central Bureau of Investigation (CBI)
Email: info@crau.gov.in (illustrative)
Headquarters: 5th Floor, NDCC Building, Jai Singh Road, New Delhi – 110001