DPDPA Compliance in GCC s in India

Amongst the various sectors which FDPPI is targetting for development of DGPSI sectoral frameworks, “Global Capability Centers” or GCCs present a specific challnge.

DGPSI already have a framework DGPSI-HR for HR operations and DGPSI-DP for Processor platforms which  have some connection with the requirements of GCC. But there are reasons to think of a new framework DGPSI-GCC which is more suitable for the GCCs.

Global Capability Centers (GCCs) are fully owned, internal corporate offices set up by multi national companies in foreign countries to hadle core business operations, technology and innovation. Unlike traditional outsourcing where a third-party vendor is hired to complete repetitive tasks, a GCC is an organic extension of the parent company itself. It operates with the same company culture, protects the same intellectual property, and directly executes strategic goals. 

If a GCC has created a local Indian company and conducts the operations by the Indian Company, the employees may all be employees of the Indian Company while the data processed may actually be of foreigners.

In such cases the Indian Company will be a Data Fiduciary for the employee data while they are Joint Data Fiduciaries for the client data processed by them on behalf of the foreign entity which may be a parent company or subsidiaries of the parent company in other countries.

In case the Indian operations are conducted directly under the MNC, the DPDPA will still be applicable since the processing of personal data occurs in India. There is an exemption clause under Section 17(1)(d) . This section states as follows:

17: Exemptions:

(1) The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where—

(d) personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India;

A close observation of this means that the employees data of a GCC even under a direct operation will come under the jurisdiction of DPDPA and the MNC will become a Data Fiduciary.

Further since the personal data is processed by the MNC directly, there is no contract with any person based in India. Hence the exemption cannot apply even to the personal data of other customers which is processed by the GCC.

It is strategicall imperative that the GCC is established under the name of an Indian company only so that the exemption of Section 17(1)(d) would be available to data other than that of the employees.

DGPSI-GCC will therefore consider this as almost a mandatory suggestion.

In this context the local company will be a Data Fiduciary which will be liable for the employee data processing with all the obligations of DPDPA and limited obligation such as Section 8(1) and 8(5) in respect of other data.

The employee data will be liable for Chapter II, Chapter III as well as Section 16 of the Act which may otherwise be exempted for customer data.

This modified version of DGPSI is the DGPSI-GCC.

 

 

Naavi

Posted in Privacy | Leave a comment

Canara Bank invests over Rs 50 crores for DPDPA Compliance

Today We came across this post in a Linked in account which states that Canara Bank has taken a trend setting decision to start their DPDPA compliance with a Rs 52.19 crore contract to a IT solutions provider along with a Six month contract to an AI platform developer for an additional cost. They have also reportedly contracted with an Audit form for Rs 82 lakhs to provide resources for DPDPA Compliance. (Refer here)  (Also here) All together we can assume that there is an investment of around Rs 60 crores on this exercise.

Since Canara Bank has a market share of around 7% in the Indian Banking sector, this investment of Rs 60 crores represents a possible industry level investment of around Rs 860 crores purely for DPDPA compliance.

We are now getting an idea of the financial impact of DPDPA compliance on the industry.

Canara Bank is still owned by the Government to the extent of Rs 62.93% and essentially a Public sector Bank which is also declared as a Section 70 protected system in parts. Its RFP may indicate more details of what this payment of Rs 52.91 crores represent in terms of delivery.

We also came across an RFP of Nabard Bank for DPDPA contract which we understand has been awarded to another IT company. Some other Banks have gone to the Big4 audit companies to be on the safer side.

We appreciate the ingenuity of IT companies for selling DPDPA compliance as a software project.

These projects will come up for audit after 13th may 2027 and we will know how efficient is the investment made by these Banks.

In the meantime, let us sit back and watch how the other members of the Banking industry respond to the Canara Bank lead.

For curiocity, we visited the website of Kendryl IT solutions and found that it is a company that  designs, build, manage, and modernize the world’s critical, technology systems. Hopefully this includes Privacy related IT systems also.

The PrivaSapien on the other hand declares that it is driven by the singular mission to empoer organizations with cutting-edge privacy management and privacyy enhancing technology products acrss the Data& AI Life cycle.

We presume that both these companies together would make Canara Bank an “AI Driven” Bank in the coming days.

We hope Canara Bank has taken note of the Risks associated with DPDPA compliance in an AI environment.

It would be interesting for shareholders of Canara Bank to know how much of provision has been made in the Books of the bank towards potential penalties under DPDPA for the year 2026-27, 2027-28 and 2028-29. The website of Canara Bank does not have  a contact of the DPO nor a Greivacne officer for the time being and I suppose they will soon update the same.

We wish Canara Bank all the best in this AI driven DPDPA Compliance drive.

Naavi

Posted in Privacy | Leave a comment

The Challenge of Data Processor Contract under DPDPA

The Data Processors under DPDPA are those who process the personal data on behalf of a Data Fiducairy. Such Data Processors are not directly liable under DPDPA for penalties. However Data Fiduciaries are required to execute appropriate contracts so that their responsibilities are adequately transferred to the data processors.

Hence the Data Processor Contract may be drafted as a reflection of DPDPA. In other words the Data Processor Contract is a distillation of DPDPA into the one or more specific purposes for which the processing contract is drafted.

One way this could be achieved in existing contracts is to modify them with a “Notwithstanding” clause  and sign an addendum to include DPDPA related procisions as a development under a change of law.

Such an addendum may contain specific provisions such as

a) Processing shall be only for the authorised purpose which is further clarified in the addendum

b) Drawing attention to the mandatory nature of Section 8(2) which states “A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.

c) Drawing attention to the provisions of Section 72A of Information Technology Act 2000

d) Non appointment of sub contractors or AI without specific consent from the data fiduciary

e) Provision for audit by the data fiducairy

f)Cooperation in meeting the requirements of compliance of DPDPA by the Data Fiduciary including meeting the rights of the data principals, data breach notification, cross border data transfer restrictions if any, reasonable security safeguards to be adopted etc.

Ujvala Consultants had in the past proposed a review of the Standard Contractual Clauses under GDPR and an Audit cum Assurance certification for Data Processors under GDPR. Now Naavi has proposed the DGPSI-DP as a framework of compliance for the “Emancipated Data Processors” as a voiluntary measure which can be audited and certified by the Independent Data Auditors trained by FDPPI.

DGPSI-DP recommends the “Principle of Inheritence” where the Data Processor inherits the obligations of the Data Fiduciary with respect to the specific purpsoe for which the Data Processor is appointed. The contract needs to cature this principle.

This is an interesting professional opportunity for the advocates and more appropriately those who register as “Progationary IDAs” to undertake a one day certification program entirely on Data Processing contracts. Interested persons my contact FDPPI for more details.

Naavi

Posted in Privacy | Leave a comment

The “Quantum” nature of Data, Legal Basis and compliance role: Naavi’s Quantum Theory of DPDPA Compliance

It is interesting to observe how DGPSI (Data Governance and Protection Standard of India) has emerged as an innovative “Standard” for DPDPA compliance distinguishing itself from any other available compliance frameworks.

One of the Cardinal Principles that has driven DGPSI to the front is the concept is a recognition that though DPDPA is about compliance of a Binary system of Data representation and the statutory definition of personal data appears binary, the operational reality of data processing is dynamic and contextual. Many of the compliance activities appear to be more aligned to an “Analog” way of thinking where data does not remain a particular type of data and exhibits a transformation over a life cycle. This was first captured by the undersigned in “Naavi’s Theory of Data” under the second hypothesis which stated  that data life cycle is a “Reversible Lifecycle”.

In this hypothesis, data is recognized as a state which is a function of context, purpose, observer etc and can be mathematically expressed as

DATA STATE = f(data + context + purpose + processing + observer + available knowledge)

[Also refer:  “The New Theory of Data”: October 7 2019 ]

What this theory suggested was that Data Can be non personal to start with and during its lifecycle, may become identifiable, become sensitive, become non identifiable again etc. The “identiifiablity” may be because of the “Processing” or the “Processor” whose prior knowledge may make it identifiable.

The “Identifiability” is therefore a quality that gets assigned either because the data comes as a set of multiple data parameters which together make it identifiable to a particular person or the data element is being observed by a person who with his prior knowledge can identify that the data belongs to a specific person. Hence “Processing” or the “Context of processing” or the “Observer’s knowledge” determines whether a data is  personal or not.

Hence the status of data is not a “Binary” status that it is “Personal” or “Not personal”. It is driven by the Quantum principle of probability that it may be personal or not personal depending on the environment in which it is observed.

The principles of Physics namely the Debroglie principle of matter-wave duality and Heisenberg principle of uncertainty that the act of measurement of one parameter may change another parameter so that position and velocity of a particle cannot be simultanewously determined, aptly represent this status of personal data.

Under the principles of Quantum Physics again applied to this scenario, we can consider that data moves from one qualtum state to another (non-personal, personal, higher-risk or otherwise specially regulated states, and ultimately anonymised/non-personal states) and exists in a continuum of these multiple states which looks like a continuous anolog status.

When we apply “Compliance Controls”, some of which are applicable to personal data and not applicable to non personal data etc., there is a need for the Controls to also adopt to the changing status of the data. Here in lies the challenge of DPDPA Compliance.

This “Continuum” of data state also extends to the state of an organization such as “Data Fiduciary”. The same organisation may occupy different regulatory roles in different processing relationships: it may be a Data Fiduciary for one processing activity and a Data Processor for another. A Data Fiduciary may additionally fall within the Significant Data Fiduciary regime when notified by the Central Government.

Yet another area where this “Naavi’s Quantum Theory of DPDPA Compliance” becomes visible is in the transformaion of Legal Basis of processing as well as Data Valuation.

The legal basis of processing recogniszed is Consent or Legitimate use or Exemption. Hence a Data fiduciary has to first check if the data or its processing is exempt, if not is it covered by legitimate use and if not obtain an appropriate consent. But having determined the purpose as being based on one of these three “Legal Basis”, the data fiduciary cannot consider it as a pemanent tag on the data processing  as the legal basis can transform during the processing.

One example is the data of a person brought to a hospital in an unconcious state by a stranger. At this stage the processing of the data is covered by a “Medical Emergency” which may be a legitimate use. Once the emergency situation ends, the legal basis for subsequent processing must be reassessed. Where no other applicable legitimate use or exemption exists, consent may become necessary for the relevant processing. After a while the hospital may realize that the patient is an accident victim or a terrorist or has a notified decease which requires disclosure to specified authorities. At this stage the processing related to “Disclosure” becomes “Legitimate use” once again.

For compliance, we say every process is to be supported by a policy which states whether the legal basis is either legitimate use or consent or exemption. But this policy support needs to change dynamically during the processsing of the patient data in the above scenario. The legitimate use policy is applicable to the emergency casualty ward but not for the inpatient during a concious state but becomes applicable if the context demands.

Similar changes also affect “Data Valaution” which may be “x” at the time of cretion, “y” after a processing stage and “z” after another processing stage.

In an educational environment data of a Person at the stage of application, admission, examination, qualification, alumni etc is all personal data of one person but at different points of time, it has different purpose of use and is supported by different legal basis.

DGPSI recommends the use of an SSOT (Single Source of Truth) based data inventory and process based system of compliance management both of which are “Quantum Principles”. The Data Inventory consists of one data set for a Data Principal but has multiple groups of data elements linked to different processes. The different processes are themselves part of an Inventory of processes which is a quantum continuum of processes that aggregate to the enterprise processing.

Summarizing, we may state

“The legal status and compliance significance of data cannot always be managed as a static attribute of a data field; they have to be evaluated in relation to the data, purpose, processing operation, context, actor and stage of the data lifecycle.”

Probably this discussion is not meant for every Data Protection Officer for whom Data status is binary and controls are applied either one way or the other. But for those Data Protection Professionals who can think beyond the obvious, this presents an opportunity to find innovative ways of data processing which is both compliant to the DPDPA and also functionally optimal.

Just as the gear systems of Cars evolved from the manual step based system to a continuous variable transmission system, the DPDPA Control mechanism has to also evolve from the current “Binary” system to a “Continuosly Variable” system based on the concept of “Continuum of Quantum States”.

I am aware that I am mixing up the concept of Physics with the Data Protection compliance and probably confusing both audiences. But this confusion would be temporary. From this discussion will emerge a new “Theory of Compliance” that is compatible to the concept of Quantum theory of “State of Matter”.

If we further summarize the concepts for simplification, we can state:

Quantum Principle 1 — State

A data element does not have one immutable compliance identity. Its state depends upon: Data + Context + Processing + Knowledge + Purpose

Quantum Principle 2 — Transition

A processing operation can change the compliance state.

For example:

Collection → enrichment → profiling → pseudonymisation → disclosure → anonymisation

Each transition can alter the applicable controls.

Quantum Principle 3 — Observation

The ability of an observer/processor to identify or derive information from data can alter its practical significance. That connects directly to the first hypothesis of Naavi’s Theory of Data,  “data is in the beholder’s eyes” proposition in the Theory of Data.

P.S: The reference to Quantum Theory in this article is an analogy for state-dependent and context-dependent compliance, and is not intended as a claim that data protection follows the laws of quantum physics

A Word about DGPSI

DGPSI does not merely ask “What data do you have?” It asks “What processing is being performed, for what purpose, under what legal basis, on what data state, by whom, with what controls?”

It also explains why the SSOT + Process Inventory + Data Inventory architecture becomes important.

Instead of:

Employee Data = Personal Data = Apply Controls A, B, C

DGPSI effectively asks:

Employee Data

Recruitment process

Employment process

Payroll process

Benefits process

Performance process

Exit process

Archival/retention

Deletion

The same individual and much of the same dataset can pass through different purposes, processes, users, systems and legal bases.

That is the operational meaning of “continuum”.

AI Challenge

The above discussion presents a real challenge to AI. Because AI systems can dynamically:

  • infer new attributes;
  • combine datasets;
  • create new relationships;
  • identify previously unidentified individuals;
  • generate profiles;
  • transform data;
  • produce new derived data;
  • change the risk associated with an existing dataset.

Therefore, AI can cause state transitions in data without the underlying database being materially changed.

This represents a bridge from

Theory of Data → DGPSI → DGPSI-AI (AIGSI)

Let us expand this thought further in a different article.

To conclude:

The future of DPDPA compliance  cannot be a static checklist applied to static categories of data. It has to become a continuously adaptive control system that recognises changes in data state, processing purpose, legal basis, organisational role and risk.

This is the direction in which DGPSI seeks to take compliance—from a binary, checklist-oriented model towards a process-driven, state-sensitive and continuously variable compliance architecture.

And this is precisely why AI makes the challenge more difficult: AI itself can become the mechanism through which data changes state.

Comments are welcome.

Naavi

Video Overview

Audio Overview (21 mts)

Posted in Privacy | Leave a comment

AI in Data Privacy and AIGSI

On 1st September 2026, FDPPI in association with Consentera, Delhi conducted a one day event at Constitutional Club of India, Delhi as part of the IDPS-2026, (Delhi Leg). IDPS the flagship event of FDPPI was conducted last year in Bengaluru and Chennai. This year it is beign conducted in Delhi and Bengaluru (November 21).

During this event, Naavi presented an Introduction to DGPSI. It was proposed to further discuss AI in Data Privacy which due to paucity of time could not be conducted.

This presentation is discussed here along with AIGSI (AI Governance Standard of India) which is now under public discussion.

Comments are welcome.

The discussion on DGPSI presented at Chennai event on August 28, where FDPPI and MMA conducted an one day workshop on “Beyond the Frontiers of DPDPA” is also available below a.

Naavi

 

 

 

Posted in Privacy | Leave a comment

The Gita of Compliance: Navigating India’s Digital Dharma

The war of Kurukshetra was a war to establish  “Dharma” in the country. If we consider that Building the culture of Data Protection in India is a “Dharma”, FDPPI is in the forefront of establishing the DPDPA Dharma in India.

The chariot of FDPPI driven by the AIDAI carries the flag of DPDPA across the country to build an ecosystem that creates skill sets, establishes standards and provides the manpwer required tobe data auditors in India.

For those of us dedicated to Information Security, Cyber Law, and Data Protection in India, the image of Krishna and Arjuna at Kurukshetra is not merely art; it is a strategic blueprint. It illustrates how various regulations, frameworks, and audits must synchronize to achieve “Victory” (Compliance and Security) in the digital age.

Let us decode this “compliance chariot” to understand the roadmap for Indian organizations.

The Chariot: Powered by FDPPI

At the very foundation of this entire ecosystem is the chariot itself. and it is FDPPI (Foundation of Data Protection Professionals in India).

Before a data fiduciary can dream of galloping toward growth or facing the “battle” of market competition, it must have a robust, legally sound, and technologically secure vehicle. FDPPI represents the foundational capacity building, education, and professional expertise that organizations need. Without the structural integrity provided by FDPPI-certified professionals and methodologies, the entire compliance mechanism is prone to collapse under pressure.

The Flag: Flying High with DPDPA

At the highest point of the chariot, signaling its allegiance and purpose, is the flag flying labeled DPDPA (Digital Personal Data Protection Act).

This symbolizes that the ultimate mandate guiding the organization is the Data Protection law of the land. Every movement, every strategic decision, and every process must serve the ultimate goal flying from the flagpole: compliance with the DPDPA, protection of Data Principal rights, and adherence to obligations of the Data Fiduciary. The DPDPA is the “Dhruva Nakshatra” that defines the direction of the journey.

Arjuna: Armed with DGPSI

Seated within the chariot, poised to act but requiring guidance, is Arjuna. 

Arjuna represents the organizational leadership or the key decision-makers who must fight the daily operational battles. However, a warrior without a reliable guide to the terrain is ineffective. DGPSI (Data Governance and Protection Standard of India) acts as Arjuna’s compass and shield. It is the framework that measures, audits, and guides the organization’s data protection posture. It transforms leadership intent into measurable governance. 

The White Horses: Driven by AIDAI

Finally, we come to the power source—the magnificent four white horses pulling the entire apparatus forward at breakneck speed. They represent AIDAI (Association of Independent Data Auditors of India).

If DPDPA sets the rules, and FDPPI builds the vehicle, AIDAI is the sheer engine power driving modern business. 

Synchronized Dharma

The true genius of this visual is that it demonstrates that compliance is not a static checklist; it is a dynamic, coordinated act.

In this digital Kurukshetra, victory belongs to the organizations that can synchronize these elements into one unified “Digital Dharma.

At Naavi.org, we have always championed this holistic view. Whether you are looking to build your chariot, understand your flag, arm your warriors, or train your steeds, the path to compliance starts with recognizing how these forces intersect.

While FDPPI endeavours to install the DPDPA culture across the county, we rememebr that it is our duty to fulfill our obligations. Success is left to the almighty with power. 

Naavi

Posted in Privacy | Leave a comment