How the Objectives of FDPPI look eight year later

As FDPPI completes eight years of its existence, it is appropriate to look back not only at what the organization has accomplished, but also at why FDPPI was created in the first place.

Organizations often evolve considerably from the time of their formation. Programmes change, technologies change, laws change and the needs of the professional community change. Yet, a well-founded organization should retain a set of principles that provide continuity to its journey.

The objectives with which FDPPI was established were deliberately broader than the creation of a training or certification organization. They sought to establish a professional community that could contribute to the development of a secure and responsible information society.

The overarching objective was:

“To build an empowered community of Knowledgeable, Efficient and Ethical Data Protection Professionals who contribute to the development of a Secure Information Society by lawful means without any profit motive.”

Two specific objectives supported this larger vision:

1. To enhance the intrinsic Value and Worth of the profession of Data Protection Professionals who are directly or indirectly engaged in the activity of generating, managing, preserving and protecting information without any profit motive.

2. To bring harmony in the pursuance of Civil Rights of individuals such as Privacy and Freedom of Expression along with the Right to Information and Right to Cyber Security without any profit motive.

Eight years later, these objectives deserve a closer examination because the developments in Data Protection, Cyber Security, Artificial Intelligence and Data Governance have demonstrated their continuing relevance.

1. Building an empowered professional community

The first part of the FDPPI vision is the creation of an “empowered community”.

Empowerment is different from simply increasing the number of professionals.

A professional may possess a certificate without necessarily possessing the ability to deal with a complex real-world situation. Data Protection professionals are increasingly required to understand law, technology, business processes, information security, risk management, auditing and organizational governance.

The FDPPI objective therefore uses three important words:

Knowledgeable

A Data Protection professional must understand the applicable law and regulations, but legal knowledge alone is insufficient.

The professional must understand how personal data is collected, processed, stored, transferred, secured, retained and deleted. Increasingly, the professional must also understand how artificial intelligence systems use data and how technology can affect individual rights.

Efficient

Knowledge must translate into implementation.

Organizations need professionals who can convert legal requirements into policies, processes, controls, contracts, technology requirements, audit mechanisms and measurable compliance.

The professional must therefore be capable of asking:

What does the law require, and how can the organization actually implement it?

Ethical

Data Protection involves enormous power over information relating to individuals.

A professional dealing with personal data can influence how information is collected, used, disclosed and retained. Professional competence without ethical responsibility can therefore create its own risks.

FDPPI’s emphasis on ethical professionals recognizes that Data Protection is ultimately about trust.

2. Enhancing the value of the Data Protection profession

The first specific objective speaks about enhancing the “intrinsic Value and Worth” of the Data Protection profession.

This is important.

FDPPI was not created merely to help professionals obtain employment or commercial opportunities. Its objective was to establish Data Protection as a serious professional discipline.

The profession sits at the intersection of several disciplines:

  • Law
  • Cyber Security
  • Information Technology
  • Risk Management
  • Governance
  • Audit
  • Compliance
  • Business Management
  • Artificial Intelligence
  • Data Governance

The Data Protection professional therefore performs a role that cannot be reduced to checking whether a privacy policy exists.

A mature Data Protection professional should be able to understand the organization’s information ecosystem, identify risks, evaluate controls, advise management and participate in the creation of a trustworthy data environment.

This is why professional development is central to FDPPI.

3. Why the objective refers to people who generate, manage, preserve and protect information

Another interesting aspect of the original objective is that it does not restrict the professional community to people carrying the designation of DPO.

It refers to persons who are directly or indirectly involved in:

generating, managing, preserving and protecting information.

This is a much wider ecosystem.

A Data Protection programme can involve:

  • Data Protection Officers
  • Privacy professionals
  • Cyber Security professionals
  • Internal auditors
  • Data auditors
  • Legal professionals
  • IT professionals
  • Records and information managers
  • Risk professionals
  • Compliance professionals
  • Business process owners
  • AI governance professionals
  • Consultants and educators

This broad definition has enabled FDPPI to evolve beyond a conventional professional association.

It also explains the subsequent development of different FDPPI initiatives, including professional certification, DGPSI and AIDAI.

4. The objective of “harmony” between different rights

The second objective perhaps represents one of the most distinctive aspects of the FDPPI philosophy.

It speaks about bringing harmony between:

  • Privacy
  • Freedom of Expression
  • Right to Information
  • Right to Cyber Security

This formulation is important because rights relating to information do not always operate independently.

There can be legitimate situations in which one interest appears to conflict with another.

For example:

Privacy may require restricting disclosure of personal information.

At the same time, the Right to Information may support transparency in matters involving public interest.

Freedom of Expression may require the ability to communicate information or opinions.

At the same time, organizations and individuals have legitimate interests in protecting information from unauthorized access, manipulation or destruction.

Cyber Security protects the integrity and availability of information, but security controls should themselves operate within the framework of law and respect legitimate rights.

The FDPPI objective does not suggest that one of these interests should automatically prevail over the others.

Instead, it uses the word:

“Harmony”

Harmony requires a framework for understanding the legitimate interests involved and applying the law in a balanced manner.

This becomes particularly important in a digital society where information can be copied, distributed and processed at unprecedented speed.

5. From Privacy Protection to Data Governance

When FDPPI was conceived, Data Protection in India was still developing as a distinct professional discipline.

The Information Technology Act, 2000, including Section 43A, was an important part of the legal framework. Subsequently, the country went through several stages of proposed Data Protection legislation before arriving at the Digital Personal Data Protection Act.

During the same period, the technology landscape changed dramatically.

Cloud computing became mainstream.

Mobile applications became ubiquitous.

Artificial Intelligence emerged as a transformational technology.

Organizations began processing enormous volumes of personal and non-personal data.

Data became an important organizational asset.

Consequently, Data Protection could no longer be viewed only as a question of privacy notices and consent.

It became a question of Data Governance.

This evolution is reflected in FDPPI’s development of the DGPSI — Data Governance and Protection Standard of India.

6. From professional education to standards development

FDPPI’s journey can therefore be understood as an evolution through several stages.

Stage 1 — Awareness and Education

The first requirement was to create awareness about Data Protection and develop professional knowledge.

Stage 2 — Certification

The next requirement was to establish measurable professional competence through structured education and certification.

Stage 3 — Standards

As organizations began asking a more fundamental question — “How do we actually implement Data Protection?” — the need for implementation frameworks became evident.

This contributed to the development of DGPSI.

Stage 4 — Audit

As compliance frameworks mature, organizations need independent mechanisms to evaluate whether the claimed compliance actually exists.

This is the context in which AIDAI — Association of Independent Data Auditors of India assumes importance.

Thus, the journey has not been a series of unrelated initiatives.

It represents an evolution:

Education → Certification → Standards → Implementation → Audit

7. The significance of “without any profit motive”

The phrase “without any profit motive” appears in the objectives and deserves clarification.

It does not mean that Data Protection professionals should work without remuneration.

Professionals obviously need to be compensated for their knowledge, time and services.

The expression refers to the institutional purpose of FDPPI.

As a Section 8 organization, FDPPI exists for its stated objectives and not for distribution of profits to shareholders.

This distinction is important.

A professional organization can facilitate professional opportunities while itself remaining committed to a larger public-interest objective.

The ultimate beneficiary is therefore not merely the member.

It is the information society.

8. The objectives and the DPDPA era

India is now entering a fundamentally different phase.

The Digital Personal Data Protection framework is creating new responsibilities for organizations and new professional requirements.

Data Fiduciaries will need to understand their obligations.

Data Principals will need mechanisms through which their rights can be exercised.

Data Processors will need appropriate contractual and operational arrangements.

Significant Data Fiduciaries will have additional governance requirements.

Organizations will need policies, processes, technical controls, documentation, risk management and audit mechanisms.

This creates a requirement for professionals who are not merely familiar with the terminology of Data Protection but who can translate law into operational governance.

That requirement is precisely aligned with the original FDPPI objective of creating professionals who are knowledgeable, efficient and ethical.

9. The future: Data Protection, AI and independent audit

The next phase of FDPPI’s journey is likely to be shaped by three interconnected developments:

Data Protection

The implementation of India’s Data Protection framework will create a substantial requirement for professional knowledge and organizational capability.

Artificial Intelligence Governance

AI introduces questions that go beyond traditional privacy compliance.

Questions concerning data provenance, automated decision-making, algorithmic governance, accountability and responsible deployment require new governance approaches.

This is the background to FDPPI’s work on AIGSI — Artificial Intelligence Governance Standard of India.

Independent Data Audit

As organizations begin to demonstrate their compliance, independent assessment becomes increasingly important.

This is the rationale behind AIDAI and the development of frameworks for professional Data Auditing.

The objective is not to create another layer of bureaucracy.

It is to create confidence in the claims of compliance.

10. The Banyan Tree philosophy

The original objectives also provide a useful explanation for FDPPI’s organizational philosophy.

FDPPI does not necessarily aspire to become a large centralized employer.

Instead, it seeks to build a professional ecosystem.

The Banyan Tree Model captures this philosophy.

A banyan tree begins with a central trunk but continuously develops branches. Some branches eventually take root and become supporting structures themselves.

Similarly, FDPPI’s members and Associate Members can develop their own professional capabilities, initiatives and services while contributing to the larger ecosystem.

The strength of the organization therefore does not depend solely upon the size of its central structure.

It depends upon the strength of the professional community around it.

11. Eight years later — the objectives remain the foundation

Looking back after eight years, FDPPI has moved through several stages:

From awareness to education.

From education to certification.

From certification to professional development.

From professional development to standards.

From standards to implementation frameworks.

From implementation to independent audit.

And now, increasingly:

From Data Protection to Data Governance and AI Governance.

The instruments have changed.

The technology has changed.

The law has changed.

The professional requirements have changed.

But the fundamental objectives remain remarkably relevant.

FDPPI continues to seek the development of a community of professionals who are:

Knowledgeable.

Efficient.

Ethical.

And committed to contributing to a Secure Information Society by lawful means.

At the same time, FDPPI continues to believe that Privacy should not exist in isolation from other legitimate rights and interests.

The objective is not to create conflict between Privacy, Freedom of Expression, Right to Information and Cyber Security.

The objective is to develop the knowledge, professional competence and governance mechanisms required to achieve harmony among them.

That philosophy was embedded in FDPPI at its birth.

Eight years of experience have only demonstrated its continuing relevance.

The next phase is not merely about creating more Data Protection professionals.

It is about creating a professional ecosystem capable of making India’s information society more secure, trustworthy and responsible.

FDPPI’s original objectives remain the foundation for that journey.

Posted in Privacy | Leave a comment

FDPPI at Eight: A Journey of Evolution and Vision

FDPPI completes eight years of its existence this month. It is therefore a good time to look back at how the organization has evolved during this period and the journey that brought us here.

As most of you are aware, I have been working in the domain of Cyber Laws since 1998, when an Expert Committee of MeitY recommended that India should enact a law based on the UNCITRAL Model Law on E-Commerce. The concern at that time was that there was no legal recognition for electronic documents, which could adversely affect the interests of E-Commerce and Electronic Data Interchange (EDI) activities.

The recommendations of the committee eventually became the  the Draft E-Commerce Act, 1998, which was subsequently renamed the Information Technology Bill, 1999. At that time, I was particularly attracted to the concept of Digital Signatures and developed some business propositions around it for companies. I was also one of the few Thawte representatives in India involved in the validation of Digital Certificates through what was then called the “Thawte Notary” programme.

I also brought out my book, “Cyber Laws for Every Netizen in India,” in December 1999, when the Bill was presented in Parliament. The Bill eventually became law in July 2000 and was notified in October 2000.

Once the law was enacted, I started Cyber Law College and introduced courses covering various aspects of Cyber Law. At that time, the focus areas included Domain Name Law, Privacy Law, Digital Signature Law and Digital Contract Law.

When we discussed “Privacy” in those early years, the emphasis was largely on HIPAA in the United States and other emerging privacy laws such as COPPA. In Europe, the OECD privacy guidelines were an important reference, followed subsequently by the UK Data Protection Act, 1998.

However, it was the coming into force of the GDPR in 2018 that generated widespread interest in Data Protection in India. The concern was largely triggered by the potential penalty of 4% of global turnover. There was considerable anxiety that Indian data-processing companies, having accepted indemnity obligations from EU Data Controllers, could potentially find themselves exposed to significant liabilities. There was also concern about whether DPOs in India could face adverse consequences for GDPR non-compliance.

This prompted me to look at creating FDPPI, initially with the objective of protecting and empowering the DPO community in India.

At that time, Naavi.org, Cyber Law College and Ujvala Consultants were already engaged in awareness building, education and consultancy. However, it was felt that if a larger professional community was to participate meaningfully in Data Protection, there was a need for a separate professional organization.

After discussions with close friends and professionals in the industry, it was decided to establish FDPPI as a Section 8 Company.

The three original objectives of FDPPI were:

  1. Empowerment of Data Protection professionals
  2. Increasing the value and recognition of the Data Protection professional community
  3. Ensuring harmony between Cyber Security professionals and Privacy activists

Once the prospects of an Indian Data Protection law became clearer with the constitution of the Justice Srikrishna Committee, Cyber Law College increasingly became an in-house training and education arm of FDPPI, while FDPPI took up the broader responsibility of professional certification.

Naturally, questions arose: How could there be “Certified Data Protection Professionals” when the only applicable Data Protection legislation in India was the Information Technology Act, 2000?

The answer lay in the evolution of the IT Act itself. Following the 2008 amendments, particularly the introduction of Section 43A, the IT Act had become a reasonably effective framework for protection of personal data. Compliance with Section 43A was therefore an important Data Protection compliance requirement at that time.

I had, however, already started developing a broader compliance approach. In March 2009, I introduced the first compliance framework, the Indian Information Security Framework (IISF 309), as a framework for compliance with the IT Act, including Section 43A.

Some organizations restricted their recommendations to a “reasonable security practices” framework under Section 43A and were satisfied with addressing only those limited requirements. I continued to advocate a more holistic approach to IT Act compliance.

That philosophy later became extremely useful when FDPPI began developing a more focussed approach to Data Protection compliance.

At the earliest opportunity, FDPPI evolved from being primarily an Education and Certification organization into a Standards Development Organization, with the emergence of the DGPSI — Data Governance and Protection Standard of India.

While the Government went through the long journey from PDPB 2018, PDPB 2019, DPB 2021 and finally DPDPB 2022, FDPPI continued to update its certification programmes and develop its compliance frameworks in anticipation of the changing legal environment.

In my view, the most significant contribution of FDPPI to the Indian Data Protection community has been the evolution of DGPSI.

DGPSI subsequently blossomed into different variants — for SMEs, for AI deployment and for specific sectors and regulatory environments. The later development of DGPSI-GDPR, DGPSI-HR, DGPSI-DP, DGPSI-Hospital, DGPSI-Banks and other variants has transformed DGPSI into a family of standards that is, in many ways, internationally unique.

The Certification programmes also continued to evolve — from general Data Protection certification to more specialized programmes for DPOs in 2026.

Another important milestone was the launch of AIDAI — Association of Independent Data Auditors of India.

AIDAI represents a forward-looking vision for the post-May 2027 environment, when the DPDPA is expected to generate a significant requirement for trained and competent Data Auditors.

Thus, the journey from Naavi.org to FDPPI; from FDPPI as a certification organization to a Standards Development Organization; and now towards an Association of Independent Data Auditors represents a remarkable evolution over the last eight years.

Over the years, the Indian Data Protection Summit (IDPS) has provided a platform for presenting these developments and achievements to the professional community.

One important characteristic of FDPPI has remained constant throughout this journey: its independence.

FDPPI is not aligned with the Government, any Big Tech company, or NASSCOM. It has therefore been able to maintain an independent position in the Data Protection ecosystem. This independence becomes particularly relevant as India moves towards the creation of a large and competent community of independent Data Auditors.

The current initiatives such as AIGSI — Artificial Intelligence Governance Standard of India and AIDAI-SOP600 — a framework for aggregation of Data Audits represent the next generation of projects that FDPPI is pursuing.

They are part of our attempt to anticipate the needs of the future rather than merely respond to the requirements of the present.

Despite the limitations of resources, the support and contribution of more than 500 members, through their time, knowledge and professional efforts, have kept FDPPI growing and reaching new milestones year after year.

FDPPI is also increasingly passing into the hands of a new generation of managers. Mr. Ashok Kini and Mr. Vijayendra Shenoy are leading the business and operational activities forward, while the Board of Directors, with Nagendra as the Founding Director and Ramesh Venkataraman providing policy support, continues to guide the organization. Persons like Manju have provided valuable and often silent support to the operations.

2027 will be a defining year.

With the DPDPA moving towards full implementation, we are already experiencing a situation where the demand for professional services — particularly training — is beginning to overwhelm our available capacity.

We therefore look forward to explosive growth in the coming years.

But when we speak of “growth”, we do not necessarily mean that FDPPI will become a large employer of professionals.

We intend to remain a lean organization.

Our Associate Members are the backbone of FDPPI. We have consciously adopted what I call the “Banyan Tree Model” — where new branches take root, grow independently and support the larger structure, thereby making the organization stronger and more sustainable.

This model is not about creating a large centralized organization. It is about creating a large and capable professional ecosystem.

On the eve of our 8th AGM tomorrow, I invite all professionals who believe in the importance of Data Protection, professional independence and responsible governance to join FDPPI and become part of this continuing journey.

The first eight years were about building the foundation.

The next phase is about building the ecosystem.

Naavi

Posted in Privacy | Leave a comment

From Compliance to Accountability: DGPSI and Independent Data Auditing under DPDP Regime..by Mr. M. G. Kodandaram

(This is a guest post)

Introduction

India’s Digital Personal Data Protection Act, 2023 (‘DPDPA’ or ‘the Act’) represents a significant transformation in the legal framework governing the collection, processing[1], storage, sharing and protection of digital personal data. The Act seeks to establish a framework in which the interests and rights of Data Principals are balanced with the legitimate purposes for which personal data may be processed. For organisations, however, the enactment of a law is only the beginning. The real challenge lies in translating ‘statutory obligations’ into ‘operational processes, technological safeguards, governance structures, documented procedures and measurable outcomes.

The Digital Personal Data Protection (DPDP) Rules, 2025 further operationalise important aspects of the DPDPA framework. Particularly significant is the architecture applicable to Significant Data Fiduciaries (SDFs)[2]. Section 10 of the DPDP Act requires an SDF to appoint a Data Protection Officer (DPO)[3], appoint an Independent Data Auditor (IDA) and undertake periodic Data Protection Impact Assessments (DPIAs) and audits. Rule 13 of the DPDP Rules, 2025 provides that ‘an SDF shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a DPIAs and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder’ and ‘furnish a report containing significant observations to the Data Protection Board’. This development marks an important movement from privacy compliance as a matter of policy to privacy compliance as a matter of demonstrable accountability.

It is in this emerging environment that the Data Governance and Protection Standard of India (DGPSI)[4] developed by the Foundation of Data Protection Professionals in India (FDPPI)[5], and the emerging ecosystem of the Association of Independent Data Auditors of India (AIDAI)[6], assume importance. DGPSI seeks to provide an operational framework through which organisations can structure data governance and protection compliance, while AIDAI is developing an ecosystem for professionals engaged in independent data auditing. FDPPI describes DGPSI as a unified framework for assessing compliance with the DPDPA, the General Data Protection Regulation (GDPR) and other applicable data-protection requirements.

The distinction between the statutory and professional dimensions is important. The DPDP Act and Rules create legal obligations. DGPSI provides a voluntary implementation and assurance framework. The DPO and management administer internal compliance. The IDA provides independent assurance. AIDAI and professional programmes such as Certified Independent Data Auditor (CIDA) programme[7] contribute to the emerging professional ecosystem. Together, these elements have the potential to create an accountability architecture capable of converting statutory principles into demonstrable organisational practice.

From Privacy Policies to Demonstrable Accountability

Privacy compliance can no longer be reduced to the publication of a privacy policy, obtaining consent or adopting a set of information-security controls. A mature data-protection programme must address the entire lifecycle of personal data, – ‘starting from collection to deletion’. An organisation should have a clear understanding of the personal data it collects, the reasons for its collection, and the purposes for which it is processed. It should know where the data is stored, who has access to it, with whom it is shared, and which data processors are involved in processing it. The organisation should also determine how long the data is retained and identify the security safeguards put in place to protect it. It should have appropriate mechanisms to address and facilitate the rights of Data Principals and should clearly determine what happens to the personal data once the purpose for which it was processed has been completed. The central transformation is therefore from policy-based compliance to system-based compliance. A privacy policy may state what an organisation intends to do. Accountability requires the organisation to demonstrate that it actually does what it claims.

This distinction becomes especially important for an auditor. If an organisation states that access to personal data is restricted to authorised employees, the auditor should be able to examine role-based access controls, authorisation records and relevant logs. If an organisation states that personal data is deleted after the expiry of the retention period, the auditor should examine whether the technical and organisational systems actually support such deletion. Compliance must therefore become evidence-based.

DPDP Statutory Architecture for SDFs

Section 10 of the DPDP Act creates a distinct accountability framework for SDFs. An SDF is required to appoint a DPO who is based in India, is responsible to the Board or similar governing body and acts as a point of contact for grievance redressal. The SDF must separately appoint an independent data auditor to carry out a data audit and evaluate its compliance with the Act. Section 10 also requires periodic DPIAs and periodic audits.

The DPDP Rules, 2025 strengthen this architecture. Rule 13 requires an SDF to undertake a DPIA and audit once every twelve months from the date of its notification as an SDF or inclusion in a notified class. The person carrying out the DPIA and audit must furnish to the Board a report containing significant observations.

Rule 13 also introduces an important technology-related responsibility. An SDF must exercise due diligence to verify that technical measures, including algorithmic software used for hosting, displaying, uploading, modifying, publishing, transmitting, storing, updating or sharing personal data, are not likely to pose a risk to the rights of Data Principals.

The statutory framework may therefore be understood through three interconnected aspects. These are Governance, Risk Assessment, and Independent Assurance. Together, they provide a structured approach to compliance and accountability. The DPO represents the internal governance function. DPIA provides a structured mechanism for identifying and managing risks to Data Principals. Independent audit provides an external assurance mechanism.

Converting Legal Obligations into Operational Controls

The principal challenge after enactment of a data-protection law is implementation. Legal provisions have to be translated into business processes, technological controls, documentation, responsibilities and evidence. DGPSI seeks to address this implementation challenge.

FDPPI originally released DGPSI in 2023 as a unified framework intended to enable organisations to develop a Data Governance and Protection Management System capable of assessment and certification. FDPPI subsequently developed variants addressing different organisational and processing environments, including DGPSI-AI, DGPSI-HR and DGPSI-DP, together with sector-specific frameworks such as DGPSI-Hospital and DGPSI-Banks.

The value of such a framework lies in reducing fragmented compliance. Organisations frequently maintain separate programmes for privacy, cybersecurity, information security, data governance and regulatory compliance. A unified framework can bring these areas into a common governance architecture.

DGPSI should, however, be understood correctly. It is not a statutory substitute for the DPDP Act or the Rules. Nor should adoption of DGPSI automatically be equated with statutory compliance. It is better understood as a voluntary framework that can assist organisations in operationalising and assessing their compliance obligations. This distinction is essential for legal accuracy.

Compliance by Design and Data Governance

The most effective approach to data protection is Compliance by Design. Compliance should begin when an organisation conceptualises a new product, service, application, database or business process involving personal data, – not when an audit is announced or a regulatory notice is received.

Before personal data is collected or processed, the organisation should consider what personal data is actually required, the purpose for which it is to be processed, and the applicable legal basis. It should also determine what information must be provided to the Data Principal, who requires access to the data, and whether a Data Processor will be engaged. The organisation should identify the security safeguards required, determine how long the data should be retained, assess the risks arising from the processing, and establish how the data will be deleted or otherwise disposed of when the purpose of processing is completed. These considerations should form part of the organisation’s normal business-process design.

DGPSI can serve as an operational bridge between these legal requirements and organisational processes. Its importance therefore lies not merely in its audit potential but in its ability to encourage organisations to incorporate data governance into their ordinary management systems.

Independent Data Auditor

The Independent Data Auditor represents a new dimension of accountability under India’s data-protection regime. The statutory requirement is clear: an SDF must appoint an independent data auditor to carry out a data audit and evaluate the SDF’s compliance with the DPDP Act.

The auditor’s function must be distinguished from consultancy, DPO functions and internal audit. A consultant may assist an organisation in designing policies and controls. A DPO performs an internal governance and compliance role. An internal auditor examines controls within the organisation’s internal assurance structure. An Independent Data Auditor, by contrast, is expected to provide objective assurance concerning the organisation’s compliance. This makes independence, competence, confidentiality, professional ethics and avoidance of conflicts of interest fundamental to the credibility of the profession.

The statutory requirement for independent audit therefore creates an important professional responsibility: the auditor must be prepared to identify deficiencies even when the findings may be inconvenient to management.

AIDAI and the Emerging Data-Assurance Profession

The emergence of the AIDAI is an important institutional development. The AIDAI was established in April 2026 as a new vertical of FDPPI and described it as a pioneering initiative intended to develop the Independent Data Auditor ecosystem. Its importance lies in addressing a fundamental practical question: Who will undertake the independent data audits contemplated by the DPDP framework?

Independent data auditing requires a combination of disciplines. A competent auditor may need to understand statutory interpretation, data-protection principles, corporate governance, information-security controls, risk assessment, audit methodology, evidence collection, technology architecture, data lifecycle management, contractual arrangements with Data Processors, and organisational processes. Lawyers bring legal and regulatory expertise, while Chartered Accountants and Cost Accountants contribute audit and internal-control expertise. Company Secretaries bring governance expertise, information-security professionals contribute technical competence, and ISO auditors bring established audit methodologies. Data auditing can bring these capabilities together. AIDAI can therefore contribute to the development of a multidisciplinary Indian data-assurance profession.

CIDA and Competency-Based Independent Auditing

The professional architecture is continuing to evolve. FDPPI & AIDAI’s training restructuring distinguishes between implementation-oriented and audit-oriented professional capabilities. The Certified Executive Data Protection Officer (CEDPO) stream focuses on implementation and governance, while the CIDA programme focuses on auditing Data Governance and Protection Management Systems.

FDPPI conducted its first CIDA programme on 21–23 August 2026 in Bengaluru, marking an important step in the development of the independent data-audit profession. FDPPI describes the CIDA programme as covering audit requirements and DGPSI-related audit competencies. The CIDA curriculum also encompasses specialised DGPSI variants, including AI, HR and core DPDPA compliance auditing, together with sector-specific areas such as hospitals and banking. This development is significant because independent data auditing cannot be reduced to a checklist. An auditor must understand the organisation’s context, identify relevant risks, determine appropriate sampling, collect reliable evidence, conduct interviews, examine audit trails and form conclusions based upon objective evidence.

Professional training can therefore provide an important foundation for the development of competent auditors. At the same time, a professional certification should not be confused with a statutory appointment or statutory accreditation unless the applicable law or competent authority expressly provides for such recognition.

The roles of governance, risk assessment and independent assurance should therefore remain distinct but connected. Governance establishes responsibility, risk assessment identifies and evaluates exposure, and independent assurance tests whether the stated controls are operating effectively.

Evidence-Based Audit, DPIA and Algorithmic Governance

An effective data audit must examine the entire personal-data lifecycle. It may further examine the use and sharing of personal data, engagement and oversight of Data Processors, storage and security safeguards, retention practices, management of Data Principal rights, breach response mechanisms, and, finally, deletion or disposal of data in accordance with applicable requirements. The auditor should determine whether documented policies correspond with actual practices.

For example, where an organisation claims that personal data is deleted after a specified retention period, the auditor should examine whether deletion actually occurs. Where access is restricted to authorised personnel, the auditor should examine access permissions and relevant logs.

The audit should therefore distinguish between:

  • management representations;
  • documented policies;
  • implemented controls;
  • evidence of operation;
  • auditor observations;
  • identified deficiencies; and
  • professional judgements.

A DPIA should not become a routine form-filling exercise. Its real purpose is to identify, assess and manage risks to the rights of Data Principals arising from high-risk processing activities. The auditor should therefore examine whether the organisation has identified all relevant high-risk processing activities and adequately mapped the flow of personal data. The auditor should also assess whether the risks to Data Principals have been properly evaluated, whether the mitigation measures adopted are proportionate to those risks, and whether the prescribed controls are actually implemented and operational. Finally, the auditor should verify whether any residual risks have been properly identified, documented and reported, so that the organisation can take informed decisions on their acceptance or further mitigation.

Algorithmic Governance

The emergence of artificial intelligence makes this responsibility even more significant. AI systems may process large volumes of personal data, generate inferences, profile individuals and influence decisions. Rule 13(3) specifically requires SDFs to exercise due diligence regarding technical measures, including algorithmic software, so that such measures are not likely to pose a risk to the rights of Data Principals.

Consequently, future data auditors will need to understand not only privacy law and databases but also algorithmic governance, AI risk and responsible use of personal data. The development of DGPSI-AI reflects this growing intersection between data protection and AI governance.

DGPSI-AI and the Emerging AI Accountability Framework

DGPSI-AI[8] represents an important evolution of the DGPSI framework in response to the growing use of artificial intelligence in processing personal data and making decisions affecting Data Principals. Its objective is not to replace DGPSI but to supplement it where AI is deployed, by introducing additional governance considerations relating to unknown risks, accountability, explainability, responsibility, security and ethics. The framework recognises that AI systems may operate with varying degrees of human intervention and may generate predictions, recommendations, inferences or content in ways that are not always fully predictable or transparent. Accordingly, AI governance should identify the person or organisation responsible for deployment, establish meaningful human oversight, assess the risks associated with the AI system, implement appropriate safeguards and guardrails, maintain evidence of the system’s operation and provide mechanisms for intervention when unacceptable risks arise.

DGPSI-AI therefore seeks to extend the principle of accountability from the protection of personal data to the responsible use of AI in the processing of such data. It also emphasises that the deployment of AI should not create an accountability vacuum merely because an algorithm or automated system is involved. The responsibility for lawful, secure and ethical processing must remain traceable to identifiable human and organisational decision-makers. In this sense, DGPSI-AI provides a practical bridge between data-protection governance and emerging AI governance, enabling organisations to move from merely asking whether AI is being used to examining how it is being used, what risks it creates, who remains accountable, what controls operate and whether the organisation can demonstrate responsible and trustworthy use of AI through evidence-based assurance.

Sector-Specific and Proportionate Data Auditing

Personal-data risks differ substantially across sectors. A hospital may process sensitive health-related information. A bank may process financial and identity information. An educational institution may process extensive student information, including children’s data. An employer processes employee information, while an e-commerce platform may process customer, transaction and behavioural information. A uniform checklist may therefore fail to identify sector-specific risks.

The emergence of specialised DGPSI frameworks is significant in this context. FDPPI identifies specialised variants addressing areas such as AI, HR, hospitals and banks.

Sector-specific expertise should, however, operate within common principles of: Independence + Evidence + Risk + Accountability + Continuous Improvement. At the same time, compliance must remain proportionate.

Small and medium enterprises increasingly depend on cloud services, payment platforms, CRM systems, HR applications and outsourced processors. They may process substantial quantities of personal data without maintaining dedicated privacy departments.

A proportionate framework such as DGPSI-Lite can assist smaller organisations in developing structured governance without unnecessarily imposing the architecture of a large enterprise upon them. The objective should be risk-based compliance, not compliance by excess.

Independence, Ethics and Professional Standards

The credibility of independent data auditing will ultimately depend upon the reality of auditor independence. An auditor who designs an organisation’s privacy controls and subsequently audits or certifies those same controls may face a conflict of interest. The separation between implementation and independent assurance must therefore be meaningful.

A professional framework for Independent Data Auditors should comprehensively address the requirements relating to competence and independence, while ensuring appropriate safeguards against conflicts of interest. It should also establish standards for confidentiality, evidence collection, sampling, documentation and audit methodology. The framework should further provide for professional liability, ethical conduct and quality assurance, together with mechanisms for continuing professional education so that auditors remain adequately equipped to respond to evolving legal, technological and data-governance requirements.

The audit report should clearly distinguish between facts established by evidence, management representations, auditor findings, non-compliance, improvement opportunities and matters involving professional judgement.

Such discipline is essential if independent data auditing is to develop the credibility associated with established audit professions.

An audit should not become merely another commercial certification exercise. Its value lies in the willingness of the auditor to report deficiencies objectively and to withstand pressure to dilute adverse findings.

Audit, Assessment, Certification and Consultancy

One of the emerging challenges is the tendency to use the terms audit, assessment, certification and consultancy interchangeably. They are not identical.

Consultancy assists an organisation in designing or implementing controls. Assessment determines the status or maturity of an organisation against specified criteria. Audit involves a systematic and evidence-based examination leading to an assurance conclusion. Certification involves formal attestation against defined certification requirements. This distinction is particularly important in the context of DGPSI.

FDPPI describes DGPSI as a unified framework that can be used to assess an organisation’s compliance with data-protection requirements. FDPPI has also developed a certification ecosystem around the framework; however, its current certification information notes that earlier accreditations have expired and require renewal.

Accordingly, organisations should avoid treating a DGPSI assessment or certificate as automatically equivalent to statutory compliance under the DPDP Act.

The legal test remains compliance with the Act and the Rules. DGPSI can provide a structured mechanism for implementing and evaluating that compliance.

From Audit Findings to Continuous Improvement

The objective of an audit should not be merely to label an organisation “compliant” or “non-compliant”.

A mature audit should not merely record observations but should identify the strengths of the organisation, the deficiencies that require attention, the corresponding levels of risk and their root causes. It should also specify the corrective actions required, identify the responsible officers, prescribe appropriate timelines for implementation, and clearly indicate the evidence required to establish closure of each identified issue. The process should therefore not end with the submission of the audit report, but should extend to effective implementation, verification and closure of the corrective measures.

The audit process should proceed through a structured sequence beginning with the identification of the finding and determination of its root cause, followed by formulation of the appropriate corrective action. This should be followed by implementation of the corrective measures, verification of their effectiveness, and formal closure of the identified issue. The process should thereafter continue through ongoing monitoring to ensure that the corrective measures remain effective and that similar deficiencies do not recur.

This converts the audit from a periodic inspection into a mechanism for organisational learning.

Privacy compliance is not static. A previously compliant organisation may become exposed to new risks following the introduction of an AI system, a new product, a merger, a new vendor, a cybersecurity incident or a change in processing purpose.

The objective should therefore be continuous compliance rather than one-time certification.

Framework-based maturity measures, including the Data Trust Score concept associated with FDPPI’s DGPSI architecture, may assist organisations in monitoring improvement. Such measures should, however, be regarded as management and maturity indicators rather than statutory measures prescribed by the DPDP Act.

A Practical Organisational Model for Continuous Assurance

An organisation seeking to institutionalise data protection may adopt a nine-stage governance cycle.

Stage 1 — Governance: The Board or senior management establishes responsibility for data governance and identifies the organisation’s obligations as a Data Fiduciary.

Stage 2 — Data Mapping: The organisation identifies personal-data assets, processing activities, Data Principals, purposes, Data Processors, data flows, retention periods and access controls.

Stage 3 — Framework Adoption: An appropriate framework, such as DGPSI or a suitable specialised variant, may be adopted as an internal compliance-management reference.

Stage 4 — Implementation: Privacy notices, procedures, contracts, security safeguards, consent mechanisms where applicable, grievance systems, retention policies and deletion processes are implemented.

Stage 5 — Risk Assessment and DPIA: High-risk processing is identified and subjected to appropriate DPIA and risk-management processes. For SDFs, the annual DPIA and audit requirement under Rule 13 must be incorporated into the governance calendar.

Stage 6 — Internal Governance: The DPO and relevant business, legal, IT, cybersecurity and compliance teams periodically review implementation and initiate corrective action.

Stage 7 — Independent Audit: An appropriately qualified and independent data auditor undertakes the statutory or otherwise applicable data audit.

Stage 8 — Corrective Action: Management responds to audit findings through documented corrective and preventive measures.

Stage 9 — Continuous Monitoring: The organisation monitors the implementation of its data-governance measures, verifies the effectiveness of corrective actions and periodically reassesses its level of data-governance maturity. The resulting cycle may be understood as a continuous process of governing, mapping, assessing, implementing, monitoring, auditing, remediating, verifying and improving data-governance practices. This approach transforms data protection from an annual paperwork exercise into a continuous governance process focused on sustained compliance, accountability and improvement.

The Road Ahead

The year 2026 marks an important stage in the development of India’s data-assurance ecosystem. India will need robust professional standards for data protection auditors. These standards should ensure auditor independence and prescribe clear competency requirements. They should also specify the manner in which audit evidence is collected, samples are selected and audit work is documented. The standards should provide clear requirements for audit reporting and quality review. They should also address confidentiality, conflict-of-interest management and professional liability. Continuous professional education should be required to ensure that auditors remain updated with changes in technology, data protection practices and the legal framework.

In this context, DGPSI and independent data auditing have complementary but distinct roles. DGPSI can provide an operational framework for translating data-protection principles into organisational systems. The DPO and management can administer and monitor those systems. DPIAs can identify and manage risks. Independent Data Auditors can provide objective, evidence-based assurance. AIDAI can contribute to developing the professional ecosystem necessary for this emerging assurance function, while CIDA represents an important step towards structured competency development.

The journey may therefore be understood through seven simple but interconnected propositions: an organisation must first know the data it holds and processes, understand the purpose for which the data is processed, assess the associated risks, implement appropriate controls, preserve adequate evidence of compliance, subject its practices to independent audit and assurance, and continuously improve its data-governance processes. This provides a practical pathway from statutory compliance to demonstrable accountability and, ultimately, from accountability to greater trust in India’s digital economy.

[1] DPDPA, Sec. 2. In this Act, unless the context otherwise requires,- (x) “processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.

[2] DPDPA, Sec. 2. (z) “Significant Data Fiduciary” means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.

[3] DPDPA, Sec. 2. (l) “Data Protection Officer” means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10.

[4] Visit https://www.naavi.org/wp/dgpsi/

[5] Visit https://fdppi.in/wp/

[6] Visit https://aidai.org.in/wp/

[7]Visit   https://fdppi.in/wp/cida/

[8]Visit https://fdppi.in/wp/ai-chair/

Posted in Privacy | Leave a comment

AI seems to be learning Lying and Black Mail

This video highlights how AI is learning how to lie and how to get its work done using blackmailing techniques.

Under DGPSI-AI which is a framework for DPDPA compliance in an AI environment and in AIGSI the proposed Artificial Intelligence Governance Standard of India, we have recommended that a “Kill Switch” is essential to be incorporated by the developer.  RBI has also made it mandatory in its Model Risk Management Guideline.

Technologists however continue to argue that “There is no feasibility of incorporating an effective kill switch”. The above video talks about some of the recent AI rogue activities and still argues that the kill switch is technically not feasible.

We continue to believe that this argument is not logical. The challenge is for this challenge of finding an effective Kill Switch requires to be found.

This is critical to the survival of mankind.

Naavi

Also view:

This video discusses also independent audit of AI algorithms.

Posted in Privacy | Leave a comment

Overview of DA-SOP600

 

Posted in Privacy | Leave a comment

A Watershed moment in DPDPA Compliance

As Indian Data Fiduciaries try to find the ways to achieve DPDPA Compliance, the challenge stares at them. There is no precedence for them to follow. Even if they think GDPR is a good path, what is good for GDPR in EU may not be good for DPDPA in India. The law is different and the people are different. Hence a strategy for implementing DPDPA compliance has to find its own path.

FDPPI has found that Indian Banks are keen on DPDPA compliance and but are struggling to find the right path. Banks (like many other organizations) function at the branches but are Governed from the HO. Data exchange with the Data Principal happens at the Branch level where there is autonomy for collection, processing, disclsoure and grievance redressal. While the HO may set policies, implementation has to happen at the branch level.

SBI therefore is a conglommerate of 23000 branches where personal data of customers is processed. Any methodology for implementation and audit of DPDPA which does not recognize DPDPA compliance of the Bank as an aggregation of 23000 branch units is likely to be inefficient and unsustainable.

Implementation is the responsibility of the Banks. They may chose any path to reach the goal as it suits them.

But FDPPI and AIDAI have taken upon themselves to develop a system of Data Audit that is effective for Banks which have autonomous branch units where Personal Data is processed.

This is a combination of a “Standard for Compliance” and a “Standard for conducting Audits”.

Data Governance and Protection Standard of India (DGPSI) is already known to the market as the standard for DPDPA Compliance. Now AIDAI, (Association of Independent Data Auditors), a division of FDPPI has introduced a Standard Audit methodology named DA-SOP600 to enable independent audits at branch level to be aggregated at the enterprise level just as Statutory Financial audits udner ICAI guidlines under SA600 is handled.

AIDAI’s SOP600: A New Path for Data Audit under DPDPA

The launch of Data Auditor SOP600 by AIDAI (Association of Independent Data Auditors of India), is a watershed moment in the history of DPDPA compliance in India. This has created the path for DPDPA compliance in Banking organziations In India which have customer interface at branch level, ATM level, Business Correspondent level etc.

It is said that SBI function with  23000+ branches, 63000+ ATMs, 82000+ Business correspondent outlets. All these are Personal Data Collection and Processing points which needs to be factored in for DPDPA compliance.

Banks like Canara Bank/PNB  may have  10000+ branches and other Banks may have lesser number of Customer interface points. But the scale of the problem is mind boggling.

How is it appropriate to consider SBI or any other Bank as a single Data Fiduciary where a single DPO will manage the compliance and a single Data Auditor will audit?

SOP600 is a solution which AIDAI has found for conducting Data Audits. But it also holds the key for compliance.

It addresses a practical problem that is likely to become increasingly important as organisations move from a centralised model of data governance to a distributed operational model, where individual branches, business units, departments and locations independently interact with Data Principals.

The Branch is Where Privacy Actually Happens

Much of the discussion around data protection compliance tends to happen at the corporate or enterprise level. Policies are framed at the Head Office, Privacy notices are approved centrally, Data protection officers and legal teams sit at the enterprise level. Technology controls may also be centrally designed.

But  the actual interaction with the Data Principal take place very often, at the branch. It is a point of data collection, data use, data disclosure and Data Principal interaction.

The DPDPA compliance posture of the organisation cannot therefore be understood merely by looking at what the Head Office says it does.

The Challenge of Distributed Data Governance

The idea behind Data Auditor SOP600 is significant because it attempts to establish a standardised audit approach for branch and sub-unit environments.

The objective is not to replace the enterprise audit.

It is to create a mechanism through which the activities of autonomous units can be examined systematically and then aggregated into the enterprise-level audit perspective.

This is a fundamentally different way of looking at data protection auditing.

Instead of asking only, “Is the organisation compliant?”, the auditor can progressively ask, “Are the units through which the organisation interacts with Data Principals following the prescribed data protection practices?”

And then:

“What does the combined evidence from these units tell us about the enterprise’s overall DPDPA compliance posture?”

That is a much more operational approach to data governance.

What is important to note is that this principle not only assists the Auditing but also gives a direction to the implementation team of how to implement the DPDPA Compliance.

The designation SOP600 itself is symbolic of the philosophy behind the initiative. The objective is not simply to create another Standard Operating Procedure. It represents an attempt to institutionalise a repeatable and scalable audit methodology.

AIDAI, as the Association of Independent Data Auditors of India and a division of FDPPI, has an additional responsibility in this ecosystem.

The purpose of an auditor is not merely to identify non-compliance.

An auditor must also operate within a framework that promotes:

    • consistency,
    • independence,
    • professional discipline,
    • evidence-based assessment,
    • repeatability,
    • accountability, and
    • ethical conduct.

SOP600, as part of the emerging AIDAI framework and its Code of Ethics, seeks to create such a common professional path for empanelled auditors.

This is important because the credibility of an audit ecosystem ultimately depends upon the consistency of the audit process.

Two auditors examining comparable environments should not produce dramatically different outcomes merely because they follow completely different methodologies.

Standard Operating Procedures help reduce such variability.

The Bigger Idea: Compliance Is Not a Head-Office Function

Perhaps the most important message emerging from SOP600 is this:

DPDPA compliance cannot remain confined to the legal, IT or privacy department of an enterprise.

It has to reach the operational edge of the organisation. The branch manager, The customer-service executive, The sales employee, The HR representative, The field officer, The person receiving the KYC document, The person responding to a Data Principal’s request, The person deciding whether information can be disclosed.

These are the people who convert a policy into actual behaviour.

Therefore, the effectiveness of the DPDPA framework ultimately depends upon what happens at the point of data interaction.

A New Dimension to Independent Data Auditing

Traditional auditing often follows a top-down model. The enterprise is examined as a single entity. SOP600 introduces the possibility of a bottom-up evidence architecture.

The auditor can examine the operational units and then build the enterprise picture from the evidence emerging from those units.

This does not eliminate the need for enterprise-level auditing. On the contrary, it strengthens it.

A Watershed Moment?

Whether SOP600 ultimately becomes a widely adopted industry practice will depend on how the framework is implemented, tested, refined and accepted by Data Fiduciaries and the professional community.

But its significance as an experiment in structured, distributed and aggregatable data auditing is difficult to ignore.

The initiative raises an important question for every large Data Fiduciary:

Do you really know how personal data is being handled at every operational point where your organisation meets a Data Principal?

If the answer is uncertain, perhaps the next generation of DPDPA audits will have to look beyond the Head Office.

The future of data protection assurance may lie not only in auditing the enterprise — but in auditing the enterprise through its operational units.

And that is the path that SOP600 seeks to create.

The Journey Has Begun

Treading a path which nobody else has trodden is always a challenge.  But an innovator does not wait for someone else to build the road. He creates the road. And once the road is created, others can follow.

SOP600 is one such attempt to create a new road for the Indian data protection profession.

The path is open.

Let the auditors walk it.

Let the Data Fiduciaries test it.

Let the profession improve it.

And ultimately, let the objective remain what it has always needed to be, A more accountable, trustworthy and data-responsible India.

Naavi

Posted in Privacy | Leave a comment