It is interesting to observe how DGPSI (Data Governance and Protection Standard of India) has emerged as an innovative “Standard” for DPDPA compliance distinguishing itself from any other available compliance frameworks.
One of the Cardinal Principles that has driven DGPSI to the front is the concept is a recognition that though DPDPA is about compliance of a Binary system of Data representation and the statutory definition of personal data appears binary, the operational reality of data processing is dynamic and contextual. Many of the compliance activities appear to be more aligned to an “Analog” way of thinking where data does not remain a particular type of data and exhibits a transformation over a life cycle. This was first captured by the undersigned in “Naavi’s Theory of Data” under the second hypothesis which stated that data life cycle is a “Reversible Lifecycle”.
In this hypothesis, data is recognized as a state which is a function of context, purpose, observer etc and can be mathematically expressed as
DATA STATE = f(data + context + purpose + processing + observer + available knowledge)
[Also refer: “The New Theory of Data”: October 7 2019 ]
What this theory suggested was that Data Can be non personal to start with and during its lifecycle, may become identifiable, become sensitive, become non identifiable again etc. The “identiifiablity” may be because of the “Processing” or the “Processor” whose prior knowledge may make it identifiable.
The “Identifiability” is therefore a quality that gets assigned either because the data comes as a set of multiple data parameters which together make it identifiable to a particular person or the data element is being observed by a person who with his prior knowledge can identify that the data belongs to a specific person. Hence “Processing” or the “Context of processing” or the “Observer’s knowledge” determines whether a data is personal or not.
Hence the status of data is not a “Binary” status that it is “Personal” or “Not personal”. It is driven by the Quantum principle of probability that it may be personal or not personal depending on the environment in which it is observed.
The principles of Physics namely the Debroglie principle of matter-wave duality and Heisenberg principle of uncertainty that the act of measurement of one parameter may change another parameter so that position and velocity of a particle cannot be simultanewously determined, aptly represent this status of personal data.
Under the principles of Quantum Physics again applied to this scenario, we can consider that data moves from one qualtum state to another (non-personal, personal, higher-risk or otherwise specially regulated states, and ultimately anonymised/non-personal states) and exists in a continuum of these multiple states which looks like a continuous anolog status.
When we apply “Compliance Controls”, some of which are applicable to personal data and not applicable to non personal data etc., there is a need for the Controls to also adopt to the changing status of the data. Here in lies the challenge of DPDPA Compliance.
This “Continuum” of data state also extends to the state of an organization such as “Data Fiduciary”. The same organisation may occupy different regulatory roles in different processing relationships: it may be a Data Fiduciary for one processing activity and a Data Processor for another. A Data Fiduciary may additionally fall within the Significant Data Fiduciary regime when notified by the Central Government.
Yet another area where this “Naavi’s Quantum Theory of DPDPA Compliance” becomes visible is in the transformaion of Legal Basis of processing as well as Data Valuation.
The legal basis of processing recogniszed is Consent or Legitimate use or Exemption. Hence a Data fiduciary has to first check if the data or its processing is exempt, if not is it covered by legitimate use and if not obtain an appropriate consent. But having determined the purpose as being based on one of these three “Legal Basis”, the data fiduciary cannot consider it as a pemanent tag on the data processing as the legal basis can transform during the processing.
One example is the data of a person brought to a hospital in an unconcious state by a stranger. At this stage the processing of the data is covered by a “Medical Emergency” which may be a legitimate use. Once the emergency situation ends, the legal basis for subsequent processing must be reassessed. Where no other applicable legitimate use or exemption exists, consent may become necessary for the relevant processing. After a while the hospital may realize that the patient is an accident victim or a terrorist or has a notified decease which requires disclosure to specified authorities. At this stage the processing related to “Disclosure” becomes “Legitimate use” once again.
For compliance, we say every process is to be supported by a policy which states whether the legal basis is either legitimate use or consent or exemption. But this policy support needs to change dynamically during the processsing of the patient data in the above scenario. The legitimate use policy is applicable to the emergency casualty ward but not for the inpatient during a concious state but becomes applicable if the context demands.
Similar changes also affect “Data Valaution” which may be “x” at the time of cretion, “y” after a processing stage and “z” after another processing stage.
In an educational environment data of a Person at the stage of application, admission, examination, qualification, alumni etc is all personal data of one person but at different points of time, it has different purpose of use and is supported by different legal basis.
DGPSI recommends the use of an SSOT (Single Source of Truth) based data inventory and process based system of compliance management both of which are “Quantum Principles”. The Data Inventory consists of one data set for a Data Principal but has multiple groups of data elements linked to different processes. The different processes are themselves part of an Inventory of processes which is a quantum continuum of processes that aggregate to the enterprise processing.
Summarizing, we may state
“The legal status and compliance significance of data cannot always be managed as a static attribute of a data field; they have to be evaluated in relation to the data, purpose, processing operation, context, actor and stage of the data lifecycle.”
Probably this discussion is not meant for every Data Protection Officer for whom Data status is binary and controls are applied either one way or the other. But for those Data Protection Professionals who can think beyond the obvious, this presents an opportunity to find innovative ways of data processing which is both compliant to the DPDPA and also functionally optimal.
Just as the gear systems of Cars evolved from the manual step based system to a continuous variable transmission system, the DPDPA Control mechanism has to also evolve from the current “Binary” system to a “Continuosly Variable” system based on the concept of “Continuum of Quantum States”.
I am aware that I am mixing up the concept of Physics with the Data Protection compliance and probably confusing both audiences. But this confusion would be temporary. From this discussion will emerge a new “Theory of Compliance” that is compatible to the concept of Quantum theory of “State of Matter”.
If we further summarize the concepts for simplification, we can state:
Quantum Principle 1 — State
A data element does not have one immutable compliance identity. Its state depends upon: Data + Context + Processing + Knowledge + Purpose
Quantum Principle 2 — Transition
A processing operation can change the compliance state.
For example:
Collection → enrichment → profiling → pseudonymisation → disclosure → anonymisation
Each transition can alter the applicable controls.
Quantum Principle 3 — Observation
The ability of an observer/processor to identify or derive information from data can alter its practical significance. That connects directly to the first hypothesis of Naavi’s Theory of Data, “data is in the beholder’s eyes” proposition in the Theory of Data.
P.S: The reference to Quantum Theory in this article is an analogy for state-dependent and context-dependent compliance, and is not intended as a claim that data protection follows the laws of quantum physics
A Word about DGPSI
DGPSI does not merely ask “What data do you have?” It asks “What processing is being performed, for what purpose, under what legal basis, on what data state, by whom, with what controls?”
It also explains why the SSOT + Process Inventory + Data Inventory architecture becomes important.
Instead of:
Employee Data = Personal Data = Apply Controls A, B, C
DGPSI effectively asks:
Employee Data
↓
Recruitment process
↓
Employment process
↓
Payroll process
↓
Benefits process
↓
Performance process
↓
Exit process
↓
Archival/retention
↓
Deletion
The same individual and much of the same dataset can pass through different purposes, processes, users, systems and legal bases.
That is the operational meaning of “continuum”.
AI Challenge
The above discussion presents a real challenge to AI. Because AI systems can dynamically:
- infer new attributes;
- combine datasets;
- create new relationships;
- identify previously unidentified individuals;
- generate profiles;
- transform data;
- produce new derived data;
- change the risk associated with an existing dataset.
Therefore, AI can cause state transitions in data without the underlying database being materially changed.
This represents a bridge from
Theory of Data → DGPSI → DGPSI-AI (AIGSI)
Let us expand this thought further in a different article.
To conclude:
The future of DPDPA compliance cannot be a static checklist applied to static categories of data. It has to become a continuously adaptive control system that recognises changes in data state, processing purpose, legal basis, organisational role and risk.
This is the direction in which DGPSI seeks to take compliance—from a binary, checklist-oriented model towards a process-driven, state-sensitive and continuously variable compliance architecture.
And this is precisely why AI makes the challenge more difficult: AI itself can become the mechanism through which data changes state.
Comments are welcome.
Naavi
Video Overview
Audio Overview (21 mts)



enquiry@consentera.com






