Archived analysis

This page is old. Tata Neu was reviewed on 2026-02-22.

This is a historical, policy-only review. Policies, product behavior and source URLs may have changed since this analysis was published.

For current public evidence from website trackers, policy findings and proof samples, go to State of Privacy 2026.

Super App

Tata Neu

Ready Score 44/100
Sushant Pasumarty
ANALYSIS SUPERVISED BY Sushant Pasumarty
πŸ“… 22 Feb 2026

Discuss this page with an LLM

Tata Neu is India's most ambitious data aggregation play β€” combining flights (Air India), hotels (IHCL), groceries (BigBasket), medicines (1mg), luxury (Tanishq), insurance (Tata AIG), and more into one profile via NeuPass. At 44/100, aggregating consumer behavior across 20+ Tata companies under a single privacy policy creates the country's most comprehensive consumer profile.

How To Read This Analysis

This is an archived policy-only review of the company's public privacy policy. It is not a government certification and it is not legal advice.

For current public evidence from website trackers, policy findings and proof samples, see State of Privacy 2026.

We look for:

  • Notice and consent clarity
  • Purpose limitation
  • Data minimization
  • Retention and deletion language
  • Vendor and processor disclosures
  • Data Principal rights
  • Grievance redressal
  • Breach and security posture

Source Check

  • Source policy was reviewed for this archived analysis, but the old policy URL is not linked because public policy locations may have changed.
  • Date reviewed: 2026-02-22
  • Company: Tata Neu
  • Readiness score: 44/100
  • Policies and product behavior may have changed since review
  • Whether the current source policy still matches this archived policy-only review
  • Whether app, web and product flows match the policy

What To Do With This

If your company has a similar data model, use this analysis as a warning map. Do not copy the score. Map your own data flow.

Ask internally:

  • Do we collect similar categories of personal data?
  • Do we share data with the same number or type of vendors?
  • Can users understand why their data is shared?
  • Can we prove deletion, retention and grievance workflows?
  • What evidence would we show if questioned?

If this analysis resembles your business model, the next step is not a better privacy-policy paragraph. It is a data map and gap analysis.

Book a DPDP readiness call

⚠️ Compliance Gaps

  • No DPDP Act 2023 reference
  • Super app aggregates data across 20+ Tata companies
  • NeuPass loyalty data creates cross-conglomerate purchase profiling
  • No granular consent for cross-entity data sharing
  • Data Protection Board not referenced
  • No data retention timelines for loyalty and purchase data
  • Cross-entity profiling consent bundled into single terms acceptance

βœ… Strengths

  • Tata Group brand trust
  • Security measures described
  • Grievance officer designated

Overview

Tata Neu is a super app connecting the entire Tata Group consumer ecosystem through NeuPass loyalty points. A single NeuPass profile links: Air India flights, IHCL hotel stays, BigBasket groceries, 1mg medicines, Croma electronics, Tanishq jewellery, Tata Play entertainment, Tata Capital finances, and more. This is India’s most comprehensive consumer data aggregation attempt.

DPDP Readiness: Section-by-Section Analysis

The super app consent problem: Signing up for Tata Neu consents to data aggregation across potentially 20+ Tata companies. A single β€œI accept” covers:

Tata EntityData CollectedSensitivity
Air IndiaTravel patterns, passport dataHigh
BigBasketGrocery purchases, health productsHigh
1mgMedicine purchases, prescriptionsCritical
IHCL HotelsStay patterns, lifestyleHigh
CromaElectronics, spending capacityMedium
TanishqJewellery spending, occasion dataMedium
Tata CapitalFinancial applications, creditCritical
Tata AIGInsurance claims, health dataCritical

Combined, this creates the most detailed consumer profile in Indian commerce β€” all under one consent.

Section 9 β€” Data Retention πŸ”΄

NeuPass loyalty data aggregates across all entities. No retention timelines defined. A customer’s 10-year Tata purchase history across flights, groceries, medicines, and hotels creates an intimate life record.

Section 11 β€” Rights of Data Principal πŸ”΄

  • Can users participate in NeuPass but exclude specific Tata entities?
  • Can users delete data from 1mg but keep BigBasket?
  • No cross-entity data control mechanism
  • No nomination rights

Risk Assessment

CategoryRisk LevelPotential Impact
Cross-entity profilingCritical20+ entities’ data combined
Health data aggregationCritical1mg + BigBasket + Tata AIG = health profile
Financial data aggregationCriticalTata Capital + spending = complete financial picture
Consent scopeCriticalOne consent for entire conglomerate

The Super App Data Monopoly Problem

Tata Neu’s data combination potential:

Medicine purchases (1mg) + Grocery purchases (BigBasket) + Insurance claims (Tata AIG)
= Complete health profile without explicit health consent

Air India flights + IHCL hotels + Tanishq purchases
= Lifestyle, income, and travel profile

Tata Capital applications + Croma spending + Tanishq
= Complete financial picture

Recommendations

  1. Implement per-entity consent controls β€” Let users choose which Tata entities share data through NeuPass
  2. Create data aggregation transparency β€” Show users what profile NeuPass has built across entities
  3. Establish health data firewalls β€” Prevent 1mg and health-related data from flowing to non-health entities
  4. Define cross-entity retention β€” Clear timelines for how long aggregate profiles are maintained
  5. Build entity-level deletion β€” Allow users to delete data from specific Tata entities independently

Fix these compliance gaps today.

Book 1:1 Consultation >
Book clarity call