> ## Documentation Index
> Fetch the complete documentation index at: https://faqs.xoxoday.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Xoxoday' With Dpdpa and Global Data Privacy Regulations

> Xoxoday complies with DPDPA, GDPR, CCPA, ISO 27001, and SOC 2, using AES-256 encryption and auditable consent controls for enterprise privacy.

<Note>
  Xoxoday's reward payout platform aligns with the Digital Personal Data Protection Act (DPDPA) and is certified under ISO 27001, SOC 1, SOC 2, GDPR, CCPA, and CRPA, with AES-256 encryption, configurable data retention, auditable consent controls, and a built-in compliance dashboard.
</Note>

Xoxoday supports compliance with the Digital Personal Data Protection Act (DPDPA) and a broad range of global privacy frameworks, including GDPR, CCPA, and CRPA. Data protection is not a bolt-on feature — it is architected into Xoxoday's reward payout infrastructure from the ground up, making it suitable for regulated enterprise environments by design.

## Encryption at Every Layer

Xoxoday protects personal data using AES-256 encryption for data at rest and TLS 1.2/1.3 for data in transit. Whether reward payouts are triggered through a Workday integration, an SAP SuccessFactors workflow, or a Darwinbox HR event, the underlying personal data remains encrypted end to end across every touchpoint.

## Configurable Data Retention and Anonymization

Xoxoday gives enterprise administrators full control over how long personal data is retained. Retention rules are configurable per data type, and administrators can schedule auto-purge or anonymization once data reaches the end of its defined lifecycle. This directly supports DPDPA's right-to-erasure requirements and GDPR's storage limitation principle without requiring manual intervention.

## Consent Management That's Fully Auditable

Consent is captured during user onboarding within Xoxoday and recorded against a timestamped audit log. Users can modify their consent preferences at any time, and every change is tracked in full. For regulated industries such as financial services or healthcare, this creates a defensible consent chain that can be surfaced for regulatory review or internal compliance audits without additional tooling.

## Compliance Dashboard and Exportable Reporting

Xoxoday includes a dedicated compliance dashboard that consolidates audit trails across reward transactions and data access events. Reports are exportable in formats suitable for regulatory submission. When a Data Protection Officer or IT security team needs to demonstrate compliance to an external auditor, Xoxoday's dashboard provides the evidence layer without requiring manual log extraction or custom scripting.

## Certifications

Xoxoday holds certifications under ISO 27001, SOC 1, SOC 2, GDPR, CCPA, and CRPA. SOC 2 Type II independently validates that Xoxoday's security controls operate effectively over time — not just at a single point-in-time snapshot. These certifications support vendor due diligence requirements common in regulated-industry procurement processes.

**Learn more:** [Xoxoday Help Centre — Data, Policy & Privacy](https://www.xoxoday.com/security)

<CardGroup cols={2}>
  <Card title="How does Xoxoday encrypt data at rest and in transit?" href="/xoxoday/compliance/does-xoxoday-support-encryption-for-the-transport-and-storage-of-sensitive-data">
    Learn how Xoxoday applies AES-256 and TLS protocols to protect personal and transactional data across its reward infrastructure.
  </Card>

  <Card title="What security certifications does Xoxoday hold?" href="/xoxoday/compliance/what-security-audit-certifications-has-your-organization-obtained-eg-tx-ramp-fed">
    Review Xoxoday's ISO 27001, SOC 2 Type II, GDPR, CCPA, and CRPA certifications and what they mean for enterprise procurement.
  </Card>
</CardGroup>
