Effective Date: March 11, 2026
Last Updated: March 11, 2026
1. Preamble and Interpretation of the Policy
This extensive Privacy Notice, Data Protection Policy, and Global Governance Framework (hereinafter referred to as the “Policy”) dictates the rigorous data collection methodologies, processing activities, third-party sharing protocols, and operational retention safeguards implemented by 24hoursnews.in (hereinafter referred to interchangeably as the “Company,” “We,” “Us,” or “Our”). Recognizing the profound transformation of the digital media landscape into a complex data processing ecosystem, this Policy has been architected to achieve absolute harmonization with the most stringent global data protection regimes.
This document serves as our binding declaration of compliance with the Digital Personal Data Protection (DPDP) Act 2023 of India, the European Union’s General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the California Privacy Rights Act (CPRA) amending the CCPA, the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and all other emerging comprehensive state privacy statutes enacted through 2026, including those in Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Nebraska, and Rhode Island. Furthermore, this Policy is specifically tailored to satisfy the exhaustive transparency requirements mandated by Google AdSense Publisher Policies, ensuring our continued eligibility for programmatic advertising monetization.
1.1. Detailed Glossary of Technical and Legal Definitions
To eliminate ambiguity and ensure that our readers can make informed decisions regarding their privacy, the following terms, utilized throughout this extensive document2. Exhaustive Taxonomy of Data Collection
The operation of a modern, algorithmically optimized digital news portal necessitates the continuous ingesting and processing of diverse data streams. We employ both active collection mechanisms (data voluntarily supplied by the user) and passive collection frameworks (data harvested autonomously via tracking technologies and network telemetry). Over the preceding twelve (12) months, we have collected, and will continue to collect, the following expansive categories of personal information.
2.1. Categories of Information Collected
2.2. Sources of Personal Data
We do not operate in a vacuum; our data ecosystem is enriched by multiple sources. We acquire the aforementioned categories of personal information from the following origins.
- Directly from the Data Principal: Information supplied directly through form submissions, account creation, newsletter opt-ins, and direct correspondence with our editorial or support teams.
- Automatically from User Devices: Data autonomously transmitted by the user’s web browser, mobile device, or network router when accessing 24hoursnews.in, facilitated by HTTP protocols and client-side scripting.
- From Third-Party Service Providers: Aggregated demographic insights and behavioral analytics supplied by entities such as Google Analytics, reinforcing our understanding of audience engagement.
- From Advertising Networks and Data Brokers: Cross-site behavioral data fed back into our systems via programmatic networks (e.g., Google AdSense) to evaluate the efficacy of ad placements and optimize yield management.
3. Lawful Basis and Purpose Limitation of Processing
Under Article 6 of the GDPR, Section 4 of the Indian DPDP Act 2023, and the data minimization principles of the CPRA, personal data must only be processed for specified, explicit, and legitimate purposes [19, 36, 43]. We strictly prohibit the processing of data for reasons incompatible with these original purposes.
3.1. Extensive Purposes for Processing Data
Our processing activities are systematically mapped to the following operational, commercial, and legal imperatives.
- Delivery of Digital Journalism and Core Platform Functionality (Contractual Necessity & Legitimate Interest): To render web pages efficiently, optimize content delivery networks (CDNs), adapt article layouts to specific device dimensions, and provide unhindered access to our news repositories.
- Programmatic Advertising Monetization (Consent & Legitimate Interest): As a free-to-access news portal, we rely entirely on ad revenue. We process tracking data to auction ad space via Real-Time Bidding (RTB) environments, specifically utilizing Google AdSense, to display targeted, contextually relevant, and cross-context behavioral advertisements. This ensures the economic viability of our journalistic endeavors.
- Audience Analytics and Content Optimization (Consent & Legitimate Interest): To measure article performance, understand reader demographics, evaluate traffic sources, and identify trending topics. This enables our editorial team to curate content that resonates with our audience.
- Fraud Detection and Network Security (Legal Obligation & Legitimate Interest): To identify and mitigate distributed denial-of-service (DDoS) attacks, detect malicious bot networks attempting click fraud on ad units, and maintain the absolute integrity of our server architecture.
- Regulatory Compliance and Law Enforcement (Legal Obligation): To comply with binding court orders, lawful requests from state authorities, and statutory data retention mandates stipulated by the DPDP Act 2023.
3.2. Lawful Grounds Matrix
- Consent: Where mandated by the DPDP Act 2023 (for Indian residents) and the GDPR/ePrivacy Directive (for EEA residents), we rely on explicitly acquired, verifiable consent prior to deploying non-essential tracking cookies or processing data for targeted advertising.
- Legitimate Interests: For fraud prevention, cybersecurity threat mitigation, and basic analytics, we rely on our legitimate business interests, provided these do not override the fundamental rights and freedoms of the Data Principal.
- Legal Obligation: When retaining access logs to comply with government intelligence or cybersecurity directives.
4. Google AdSense, DoubleClick DART, and Comprehensive Cookie Policy
To sustain the high-quality journalism provided by 24hoursnews.in without erecting a paywall, we extensively utilize Google’s advertising infrastructure. This integration necessitates full transparency regarding how Google and its partners deploy tracking technologies on our platform, satisfying the specific disclosure mandates of the Google Publisher Policies.
4.1. The Mechanics of Google AdSense and DoubleClick
When a user visits 24hoursnews.in, the page contains embedded ad tags that instruct the user’s browser to request advertising content directly from Google’s servers. Simultaneously, Google servers transmit an advertising cookie to the user’s browser.
- Targeted Advertising: Third-party vendors, most notably Google, use these cookies to serve highly personalized advertisements based on the user’s prior visits to 24hoursnews.in and other diverse websites across the internet ecosystem.
- The DoubleClick DART Cookie: Google’s use of the DoubleClick DART cookie, alongside other proprietary tracking tokens originating from domains such as doubleclick.net, googlesyndication.com, and googleadservices.com, enables Google and its vast network of partners to analyze a user’s cross-site browsing behavior and serve ads reflective of those inferred interests.
- Attribution Reporting: Beyond simple cookies, Google’s ad services may also leverage Attribution Reporting APIs, which store encrypted measurement data directly within the user’s browser or mobile device, allowing advertisers to measure ad conversions without relying on traditional third-party cookies, aligning with the evolving Privacy Sandbox initiatives.
4.2. Log Data Anonymization by Google
Google stores a permanent record of the ads served on our platform in its server logs. These logs typically capture the user’s web request, IP address, browser type, and cookie identifiers. To address privacy concerns, Google employs automated anonymization protocols, truncating IP addresses after a period of 9 months and anonymizing cookie information after 18 months.
4.3. Managing Preferences and Opting Out of Google Tracking
Users retain absolute control over their advertising experience.
- Google Ad Settings: Users may voluntarily opt out of the use of the DoubleClick cookie for interest-based advertising by visiting the Google Ads Settings page (adssettings.google.com).
- Third-Party Opt-Out: Alternatively, users can opt out of a wide array of third-party vendor’s use of cookies for personalized advertising by visiting the Network Advertising Initiative (NAI) opt-out page or the Digital Advertising Alliance (DAA) WebChoices tool.
4.4. General Cookie Taxonomy on 24hoursnews.in
Beyond Google AdSense, our portal utilizes a stratified approach to cookie deployment.
- Strictly Necessary Cookies: Essential for page navigation, load balancing, and access to secure areas. These cannot be disabled as the system cannot function without them.
- Performance and Analytics Cookies: Utilized to understand how visitors interact with the website, reporting on metrics such as bounce rate and traffic sources anonymously.
- Targeting and Advertising Cookies: Set by our advertising partners (including Google) to build a profile of interests and show relevant adverts on other sites.
5. Sub-Processors, Third-Party Sharing, and Cross-Border Transfers
We do not operate our infrastructure in isolation. 24hoursnews.in relies on an enterprise-grade stack of third-party vendors. Under the GDPR and DPDP Act, these entities act as Data Processors or Sub-Processors. While we do not “sell” data for direct monetary gain, transmitting personal information to advertising networks constitutes a “sale” or “sharing” under the CPRA and other US state laws.
5.1. Verified List of Third-Party Sub-Processors
We mandate that all downstream vendors adhere to strict Technical and Organizational Measures (TOMs) and sign binding Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) to guarantee the secure handling of our users’ data.
5.2. International Data Transfers
The internet is inherently borderless. Personal data collected from users residing in the European Economic Area (EEA) or India may be transferred to, and processed in, the United States or other third countries where our Sub-Processors maintain server infrastructure.
- For EU Residents: We ensure that such international transfers are executed relying on adequacy decisions by the European Commission, or through the implementation of Standard Contractual Clauses (SCCs) as prescribed by Article 46 of the GDPR, ensuring an equivalent level of data protection.
- For Indian Residents: In compliance with Chapter IV, Clause 16 of the DPDP Act 2023, data may be processed outside India pursuant to valid contracts, provided the central government has not explicitly restricted transfers to the target territory.
6. Comprehensive User Rights Framework
Recognizing the fundamental right to privacy, 24hoursnews.in has engineered mechanisms to allow users to exercise profound control over their digital footprint. Our platform honors rights granted by the CPRA/CCPA, the GDPR, the Indian DPDP Act, and other emerging comprehensive privacy legislation.
6.1. Privacy Rights for California and US State Residents (CPRA, VCDPA, CPA, CTDPA)
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or any state with an enacted comprehensive privacy law as of 2026 [23, 24], you are entitled to the following expansive consumer rights.
- The Right to Know and Access: You have the absolute right to request that we disclose the specific pieces and categories of personal information we have collected about you over the past 12 months, the categories of sources from which it was collected, the business or commercial purpose for collecting, selling, or sharing it, and the categories of third parties to whom we disclosed it. You may make this request up to twice within a 12-month period, entirely free of charge.
- The Right to Delete: You maintain the right to request the permanent deletion of personal information we have collected from you, and to demand that we direct our service providers to do the same, subject to statutory exceptions such as completing a transaction, detecting security incidents, or complying with a legal obligation.
- The Right to Opt-Out of Sale or Sharing (Do Not Sell or Share My Personal Information): Because our use of third-party advertising cookies (like Google AdSense) constitutes a “sale” or “sharing” under the CPRA, you have the right to direct us to cease this activity [26, 38]. We facilitate this via a clear hyperlink on our homepage and by technically recognizing user-enabled Global Privacy Control (GPC) signals—a browser-level switch that acts as a universal opt-out mechanism [26]. Once opted out, we will wait at least 12 months before requesting re-authorization.
- The Right to Correct Inaccurate Information: You may request that we rectify any inaccurate personal information maintained in our databases, taking into account the nature and purpose of the processing.
- The Right to Limit Use of Sensitive Personal Information: You hold the right to direct us to restrict the use and disclosure of your sensitive personal information (such as precise geolocation) exclusively to the necessary purposes required to provide the digital news services you expect.
- The Right to Non-Discrimination: We are strictly prohibited from discriminating against you for exercising your privacy rights. We will never deny you access to news content, charge different rates, or provide a degraded user experience as retaliation for your choices.
6.2. Privacy Rights for Residents of the European Economic Area (GDPR)
If you are located within the EEA, your rights under Chapter 3 (Articles 12-23) of the GDPR are fully supported.
- Right of Access and Rectification: The right to obtain copies of your personal data and mandate the correction of inaccuracies.
- Right to Erasure (‘Right to be Forgotten’): The right to request the erasure of your personal data without undue delay when the data is no longer necessary for the purposes for which it was collected, or upon the withdrawal of consent.
- Right to Restriction of Processing and Right to Object: The right to halt specific processing activities, particularly those predicated on legitimate interest, and the absolute right to object to processing for direct marketing and automated individual decision-making (profiling).
- Right to Data Portability: The right to receive your data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller seamlessly.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.
- Right to Lodge a Complaint: You retain the right to lodge a formal complaint with the relevant Data Protection Supervisory Authority in your member state.
6.3. Privacy Rights for Residents of India (DPDP Act 2023)
For citizens residing in India, 24hoursnews.in acts as a Data Fiduciary and fully enforces the rights granted by the groundbreaking Digital Personal Data Protection Act of 2023.
- Right to Information about Personal Data: The ability to request a detailed summary of the personal data being processed, the underlying processing activities, and the specific identities of all Data Fiduciaries and Data Processors with whom your data has been shared.
- Right to Correction, Completion, Updating, and Erasure: You can demand the rectification of misleading data and the immediate deletion of personal data once the specified purpose for processing is no longer being served.
- Right of Grievance Redressal: A statutorily protected right to register complaints regarding any act or omission by the Company regarding the performance of its obligations under the Act.
- Right to Nominate: The unique right to nominate another individual who shall, in the event of your death or physical/mental incapacity, exercise your rights under the DPDP Act on your behalf.
Crucial Note on Duties of the Data Principal under the DPDP Act: The law places corresponding obligations upon you. Under Section 15, you are legally obligated to ensure you do not impersonate another person, suppress material information while providing personal data, or register false and frivolous grievances with our Data Protection Officer or the Data Protection Board [22]. We reserve the right to report severe violations of these duties to the regulatory authorities.
7. Operationalizing Privacy: Technical and Organizational Measures (TOMs)
A privacy policy is merely a theoretical document without the rigorous implementation of protective security architecture. To ensure the ongoing confidentiality, integrity, availability, and resilience of our processing systems against cyber threats and unauthorized data exfiltration, 24hoursnews.in deploys an exhaustive array of Technical and Organizational Measures (TOMs) in alignment with GDPR Article 32, ISO/IEC 27701 frameworks, and the DPDP Act’s mandate for “reasonable security safeguards”.
7.1. Technical Security Measures
- Cryptographic Data Protection: All data transmitted between the user’s browser and our server infrastructure is secured using Transport Layer Security (TLS 1.3) cryptographic protocols. Data resting in our databases is protected utilizing AES-256 encryption standards.
- Pseudonymization and Anonymization: We actively pseudonymize personal datasets, stripping direct identifiers and replacing them with hashed tokens to ensure data cannot be attributed to a specific individual without isolated supplementary keys.
- Perimeter Defense and Threat Detection: Implementation of stateful firewalls, Web Application Firewalls (WAF), distributed denial-of-service (DDoS) mitigation through Cloudflare, and automated malware detection heuristics [40, 41, 64].
- Access Control: Strict enforcement of the Principle of Least Privilege (PoLP). Administrative access to our backend databases containing personal information is restricted via Multi-Factor Authentication (MFA), FIDO-2 complex password requirements, and cryptographic VPN tunnels.
7.2. Organizational Security Framework
- Information Security Governance: We maintain formalized, overarching information security policies that dictate consistent data handling procedures across all hierarchical levels of the organization.
- Employee Awareness Training: Mandatory, recurring data protection training for all personnel handling personal data, ensuring they understand the gravity of GDPR, CPRA, and DPDP compliance, as well as the methodology for spotting phishing and social engineering attacks.
- Data Destruction Protocols: When data reaches the end of its retention lifecycle, it is not merely deleted but cryptographically wiped. Any physical storage media is destroyed in compliance with DIN 66399 standards to prevent forensic recovery.
- Incident Response and Business Continuity: In the unlikely event of a data breach, we have established rapid-response continuity plans to contain the threat, preserve system integrity, and notify the relevant regulatory boards (e.g., Data Protection Board of India, EU Supervisory Authorities) and affected Data Principals within legally mandated timelines (e.g., 72 hours under GDPR).
8. Data Retention Dynamics and Storage Limitation
The Company adheres rigidly to the principle of storage limitation. We do not hoard personal data indefinitely. Information is retained solely for the period necessary to fulfill the operational purposes detailed in Section 3 of this Policy, or as legally mandated by overlapping regulatory regimes.
- Programmatic and Telemetry Data: As previously stated, Google AdSense and Analytics logs containing partially truncated IPs and cookie metadata are retained on Google’s servers for periods ranging from 9 to 18 months before automated anonymization.
- Consent and Preference Records: Records of user consent, opt-out requests, and CPRA/GDPR rights executions are retained for up to three (3) years to demonstrate verifiable compliance to auditors and regulatory agencies.
- DPDP Act Specific Retention Paradigms: In accordance with the DPDP Act 2023 rules governing platforms, 24hoursnews.in implements a dual-layered retention strategy. To comply with lawful government access requests or investigative mandates, specific traffic data and connection logs must be retained for a mandatory minimum of one (1) year [18]. Conversely, to prevent indefinite surveillance, if the platform is categorized under rules for large entities, we are strictly prohibited from retaining personal data for more than three (3) years following the user’s last verifiable interaction with the website, after which it undergoes automated erasure unless an extended legal hold applies.
9. Notice of Financial Incentives and Non-Discrimination
Under the CPRA, businesses that offer financial incentives, price differences, or service level disparities in exchange for the retention or sale of a consumer’s personal data must provide a explicit “Notice of Financial Incentive”.
Currently, 24hoursnews.in does not operate any financial incentive programs, loyalty schemes, or premium paywalls predicated on the collection or sale of personal information. The delivery of our journalistic content is uniformly free and unhindered for all users. Consequently, exercising your right to opt-out of cross-context behavioral advertising (via the “Do Not Sell or Share My Personal Information” link or GPC signal) will absolutely not result in diminished access, throttled load speeds, or discriminatory treatment of any kind.
10. Protection of Minors and Children’s Data
The digital landscape poses unique threats to vulnerable demographics. 24hoursnews.in is a general audience news platform and is not directed at, nor do we knowingly collect personal information from, children.
- Under US COPPA and CTDPA: We do not knowingly collect, sell, or share the personal information of consumers under 13 (or under 16 without explicit opt-in consent).
- Under the Indian DPDP Act 2023: Processing the personal data of children (defined as individuals under 18) requires “verifiable parental consent.” Furthermore, we are strictly prohibited from undertaking behavioral monitoring of children or targeting advertisements directly at them.
If we discover that a minor has transmitted personal data without verified parental authorization, we will initiate immediate protocols to purge the data from our active databases and alert our Sub-Processors to execute corresponding erasures.
11. Procedures for Submitting Verifiable Consumer Requests
To execute any of the rights enumerated in Section 6 (such as a Request to Know, Request to Delete, or DPDP Grievance), the Data Principal must submit a verifiable request.
11.1. Submission Channels
Users may submit their requests through the following designated mechanisms :
- Electronic Mail: By emailing our dedicated compliance team at info@24hoursnews.in .
- Interactive Web Form: By utilizing the automated “Privacy Rights Request” portal linked in the footer of our homepage (for Opt-Outs and access requests).
11.2. The Verification Mechanism
To prevent unauthorized access to personal data and protect against identity spoofing, we are legally mandated to verify the identity of the individual submitting the request.
- We will attempt to match the identifying information provided in the request (e.g., email address, device IP, recent browsing context) against the data already maintained in our systems.
- We may require additional information solely for the purpose of identity verification.
- Authorized Agents: Under the CPRA, users may designate an Authorized Agent (a person or business entity registered with the Secretary of State) to submit requests on their behalf. We will require the agent to provide proof of signed permission and may require the consumer to verify their own identity directly with us.
11.3. Response Timelines
- CPRA/US Laws: We will acknowledge receipt of the request within 10 days and provide a substantive response within 45 calendar days. This deadline may be extended by an additional 45 days (totaling 90 days) if necessary, accompanied by a notification of the extension.
- GDPR: Responses to Data Subject Access Requests (DSARs) will be provided without undue delay and in any event within one month of receipt.
- DPDP Act: Grievances will be addressed within the specific timelines notified by the Central Government and the Data Protection Board of India.
12. Contact Information and Data Protection Officer (DPO)
Accountability is the cornerstone of effective privacy architecture. To facilitate seamless communication with regulatory authorities (such as the Data Protection Board of India or EU Supervisory Authorities) and to manage the daily execution of consumer rights, 24hoursnews.in has appointed a formalized Data Protection Officer (DPO) and Grievance Officer.
For all matters concerning this Privacy Policy, the withdrawal of consent, the execution of Data Principal rights, or the reporting of a potential data breach, please direct your correspondence to:
Data Protection and Grievance Officer
Entity: 24hoursnews.in
Email Address: news24in7h@gmail.com , info@24hoursnews.in
We are committed to resolving all data protection inquiries with the utmost urgency, transparency, and legal precision. By continuing to navigate and consume the journalistic content provided by 24hoursnews.in, you acknowledge that you have read, understood, and accept the expansive data processing mechanics detailed within this exhaustive master document.