Free online DPIA offer for Corporate Members

We are now around 213 days from 13th May 2027 when DPDPA will be fully effective. Many organizations have already started implementation. Action has started on three fronts

  1. Engagement of consultants for implementation
  2. Conducting Awareness Training
  3. Create a Governance Structure for implementation
  4. Create Policy documents at all levels
  5. Software for Compliance management mainly for “Consent Management”

Some organizations have followed the above order of implementation. Some have also used the reverse order believing that software will do the trick and achieve the compliance.

While one can argue which is the correct order in which Compliance drive should be approached, everybody agrees that there has to be a synchronization of the elements.

Since many organizations have already jumped in with the impolementation in some fashion based on their current understanding of the requirements, they are now wondering if they are in the right track.

As the festival of Dussehra symbolizes the triumph of good over evil, righteousness over discord, and clarity over ignorance, it is the perfect time for organizations to strengthen their digital trust and overcome compliance hurdles.

In today’s evolving regulatory landscape, with the Digital Personal Data Protection Act (DPDPA) ensuring robust Data Protection Impact Assessments (DPIA) is no longer optional; it is essential.

To mark this auspicious season, FDPPI (Foundation of Data Protection Professionals in India) is excited to announce a special Dussehra Offer for businesses looking to elevate their data governance framework.

To assist companies re-visit their current approach to DPDPA implementation, FDPPI and Naavi are giving a special offer for the Dussera 2026 which commences from today.

For all the Corporate members who enrol on a 3 yearmembership  plan (Visit for details) we would provide a free online DPIA session to enable review of their current implementation plan. A suitable appointment may be fixed for mutual convenience to discuss the current implementation plan and identify key areas of course correction if any.

Irrespective of whom the company is already working with, a second opinion from FDPPI is a peer review opportunity before the commitments reach an irreversible state.

Interested entities may contact Naavi or FDPPI through email.

Naavi

 

Posted in Privacy | Leave a comment

Gramina Banks getting ready for DPDPA

It has been an interesting last week when I visited two major Gramina Banks namely Rajashthan Gramina Bank in Jodhpur and Madhya Pradesh Gramina Bank in Indore to discuss with their senior staff such as General managers and Regional managers to discuss DPDPA.

The Gramina Banks after the mergers are one for each state and have 1500 or 2000 branches in their respective states. They therefore are bigger than many other small Banks in the urban areas. Some of these Gramina banks are also getting ready for listing in the Stock Markets. Hence they represent a very interesting study for the impact of DPDPA. Some of them may still depend on their sponsor banks for IT administration but many have developed their own systems also.

NABARD is providing the collective leadership for the 28 such Gramina banks along with the individual assistance the sponsoring Banks are providing to their sponsored entities.

We are watching how the roll out of DPDPA happens in these branches and what lessons can be drawn for the industry.

Naavi

 

 

Posted in Privacy | Leave a comment

Minor Corrections in DPDPA

Meity has issued a Gazette Notification on some minor corrections in DPDPA 2026.

The notification is available here.

The corrections are as follows:

1. Short title and commencement.— (1) This Order may be called the Digital Personal Data Protection (Removal of Difficulties) Order, 2026.
(2) It shall come into force on the date of its publication in the Official Gazette.
2. In the said Act,—
(i) in section 9, in sub-section (1), for the words “ child or a person with disability,” the words “child or of a person with disability ”shall be substituted;
(ii) in section 10, in sub-section (2), in clause (c), in sub-clause (ii), for the word “audit”, the words “data audit” shall be substituted;

Necessary modification will be done in www.dpdpa.in.

Naavi

Posted in Privacy | Leave a comment

Can there be a separate version of DGPSI for “Start Ups”?

The DGPSI System which started as a model DPDPA Compliance system in 2023 has come a long way in the last 3 years.

What started with DGPSI-Full Version later was modified as DGPSI-Lite version which we are now calling as DGPSI-SME. Subsequently DGPSI has developed in multiple directions. DGPSI-AI was an extension on the technology front. DGPSI HR was an attempt to address the DPDPA Compliance requirements on a functional basis. DGPSI-Hospital and DGPSI-Banks was an attempt to address the requirements of DPDPA Compliance in specific sectors. DGPSI-DP was another attempt to extend the Compliance framework to a category of activity and DGPSI-GDPR was an attempt to extend the framework to other legal frameworks. Together DGPSI has made FDPPI a “Standards Organization”.

DPDPA is a single law for all sectors and all sizes of companies. This was inevitable for the creation of the data protection law. But from the perspective of implementation in the industry this was a challenge which needed to be addressed. The “Framework” with different flavours for different purposes was therefore an attempt to make it possible for the industry to work on Compliance with appropriate modifications tailored to different industries.

In this journey it is now being explored if “Start UPs” can be considered as a “Class of Data Fiduciaries” for whom a simplified DGPSI Frameworks can be designed.

FDPPI has therefore started a project under the Title “Project May 13” to develop an exclusive framework of DPDPA Compliance that would address the “StartUP sector”. “Start Up sector” like the “SME Sector” can represent multiple industry sectors. There can be a Fintech Start up as well as a Health Care start up. But if there is a commonality between them as a “Start Up” it may be possible to create a Version of DGPSI like DGPSI-Lite which is a sector agnostic framework that is applicable to Start Ups.

Until now, DGPSI variants have broadly emerged around questions such as:

Which sector does it belong to?, What function is being addressed?, What technology is involved?, What activity is being performed? or Which law or regulatory framework applies?

Now DGPSI-Start Ups will start addressing the question:

Where is the organisation in its lifecycle? That could make lifecycle-based compliance an important future dimension of DGPSI.

A start-up could therefore move progressively from a basic DGPSI-Startup profile into DGPSI-SME or DGPSI-Full as its organisation matures, while adopting specialised profiles such as DGPSI-AI, DGPSI-HR or sector-specific frameworks wherever necessary.

The frameworks would not necessarily be competing products. They could become building blocks of a larger DGPSI architecture.

At this stage, there are more questions to be answered.

For example:

    • What exactly constitutes a “start-up” for the purpose of a compliance framework?
    • Should recognition be based on age, funding, turnover, employee strength, government recognition or some combination?
    • Should a start-up processing very sensitive or large volumes of personal data receive the same treatment as a low-risk start-up?
    • How should AI-native start-ups be treated?
    • How should start-ups that rapidly become Significant Data Fiduciaries transition into a more mature framework?
    • What should be the minimum compliance baseline?
    • Which DGPSI controls can be simplified?
    • Which controls should never be compromised?
    • Can compliance be embedded into product development and engineering processes?
    • Can investors and customers use the framework as a measure of data-protection maturity?

These questions deserve discussion. This thought is at a very preliminary stage and we can explore this as we go ahead. Your thoughts are welcome.

Project May 13 — the beginning of a conversation

To explore this thought further, FDPPI proposes to conduct a survey titled “Project May 13” to find out from professionals on how a DGPSI framework can be constructed for Start Ups for DPDPA Compliance without Pain.

The objective is to determine whether the underlying proposition is valid.

Can “Start-up” be considered a meaningful class of Data Fiduciary from the perspective of DPDPA implementation?

If the answer is yes, the next question will be:

What should a start-up-specific DGPSI framework look like?

And perhaps the most important question will be:

Can India develop a model in which data protection becomes part of the DNA of a start-up from its earliest days, rather than becoming a compliance burden imposed after the organisation has already grown?

That is the question with which Project May 13 begins.

The thought is at a very preliminary stage. Views, suggestions, criticism and alternative approaches from start-ups, founders, privacy professionals, lawyers, technology professionals, investors, auditors and regulators will be valuable in shaping the next stage of the project.

Project May 13 starts with a question. The framework, if justified, will emerge from the answers.

(To Be continued)

Naavi

Posted in Privacy | Leave a comment

How the Objectives of FDPPI look eight year later

As FDPPI completes eight years of its existence, it is appropriate to look back not only at what the organization has accomplished, but also at why FDPPI was created in the first place.

Organizations often evolve considerably from the time of their formation. Programmes change, technologies change, laws change and the needs of the professional community change. Yet, a well-founded organization should retain a set of principles that provide continuity to its journey.

The objectives with which FDPPI was established were deliberately broader than the creation of a training or certification organization. They sought to establish a professional community that could contribute to the development of a secure and responsible information society.

The overarching objective was:

“To build an empowered community of Knowledgeable, Efficient and Ethical Data Protection Professionals who contribute to the development of a Secure Information Society by lawful means without any profit motive.”

Two specific objectives supported this larger vision:

1. To enhance the intrinsic Value and Worth of the profession of Data Protection Professionals who are directly or indirectly engaged in the activity of generating, managing, preserving and protecting information without any profit motive.

2. To bring harmony in the pursuance of Civil Rights of individuals such as Privacy and Freedom of Expression along with the Right to Information and Right to Cyber Security without any profit motive.

Eight years later, these objectives deserve a closer examination because the developments in Data Protection, Cyber Security, Artificial Intelligence and Data Governance have demonstrated their continuing relevance.

1. Building an empowered professional community

The first part of the FDPPI vision is the creation of an “empowered community”.

Empowerment is different from simply increasing the number of professionals.

A professional may possess a certificate without necessarily possessing the ability to deal with a complex real-world situation. Data Protection professionals are increasingly required to understand law, technology, business processes, information security, risk management, auditing and organizational governance.

The FDPPI objective therefore uses three important words:

Knowledgeable

A Data Protection professional must understand the applicable law and regulations, but legal knowledge alone is insufficient.

The professional must understand how personal data is collected, processed, stored, transferred, secured, retained and deleted. Increasingly, the professional must also understand how artificial intelligence systems use data and how technology can affect individual rights.

Efficient

Knowledge must translate into implementation.

Organizations need professionals who can convert legal requirements into policies, processes, controls, contracts, technology requirements, audit mechanisms and measurable compliance.

The professional must therefore be capable of asking:

What does the law require, and how can the organization actually implement it?

Ethical

Data Protection involves enormous power over information relating to individuals.

A professional dealing with personal data can influence how information is collected, used, disclosed and retained. Professional competence without ethical responsibility can therefore create its own risks.

FDPPI’s emphasis on ethical professionals recognizes that Data Protection is ultimately about trust.

2. Enhancing the value of the Data Protection profession

The first specific objective speaks about enhancing the “intrinsic Value and Worth” of the Data Protection profession.

This is important.

FDPPI was not created merely to help professionals obtain employment or commercial opportunities. Its objective was to establish Data Protection as a serious professional discipline.

The profession sits at the intersection of several disciplines:

  • Law
  • Cyber Security
  • Information Technology
  • Risk Management
  • Governance
  • Audit
  • Compliance
  • Business Management
  • Artificial Intelligence
  • Data Governance

The Data Protection professional therefore performs a role that cannot be reduced to checking whether a privacy policy exists.

A mature Data Protection professional should be able to understand the organization’s information ecosystem, identify risks, evaluate controls, advise management and participate in the creation of a trustworthy data environment.

This is why professional development is central to FDPPI.

3. Why the objective refers to people who generate, manage, preserve and protect information

Another interesting aspect of the original objective is that it does not restrict the professional community to people carrying the designation of DPO.

It refers to persons who are directly or indirectly involved in:

generating, managing, preserving and protecting information.

This is a much wider ecosystem.

A Data Protection programme can involve:

  • Data Protection Officers
  • Privacy professionals
  • Cyber Security professionals
  • Internal auditors
  • Data auditors
  • Legal professionals
  • IT professionals
  • Records and information managers
  • Risk professionals
  • Compliance professionals
  • Business process owners
  • AI governance professionals
  • Consultants and educators

This broad definition has enabled FDPPI to evolve beyond a conventional professional association.

It also explains the subsequent development of different FDPPI initiatives, including professional certification, DGPSI and AIDAI.

4. The objective of “harmony” between different rights

The second objective perhaps represents one of the most distinctive aspects of the FDPPI philosophy.

It speaks about bringing harmony between:

  • Privacy
  • Freedom of Expression
  • Right to Information
  • Right to Cyber Security

This formulation is important because rights relating to information do not always operate independently.

There can be legitimate situations in which one interest appears to conflict with another.

For example:

Privacy may require restricting disclosure of personal information.

At the same time, the Right to Information may support transparency in matters involving public interest.

Freedom of Expression may require the ability to communicate information or opinions.

At the same time, organizations and individuals have legitimate interests in protecting information from unauthorized access, manipulation or destruction.

Cyber Security protects the integrity and availability of information, but security controls should themselves operate within the framework of law and respect legitimate rights.

The FDPPI objective does not suggest that one of these interests should automatically prevail over the others.

Instead, it uses the word:

“Harmony”

Harmony requires a framework for understanding the legitimate interests involved and applying the law in a balanced manner.

This becomes particularly important in a digital society where information can be copied, distributed and processed at unprecedented speed.

5. From Privacy Protection to Data Governance

When FDPPI was conceived, Data Protection in India was still developing as a distinct professional discipline.

The Information Technology Act, 2000, including Section 43A, was an important part of the legal framework. Subsequently, the country went through several stages of proposed Data Protection legislation before arriving at the Digital Personal Data Protection Act.

During the same period, the technology landscape changed dramatically.

Cloud computing became mainstream.

Mobile applications became ubiquitous.

Artificial Intelligence emerged as a transformational technology.

Organizations began processing enormous volumes of personal and non-personal data.

Data became an important organizational asset.

Consequently, Data Protection could no longer be viewed only as a question of privacy notices and consent.

It became a question of Data Governance.

This evolution is reflected in FDPPI’s development of the DGPSI — Data Governance and Protection Standard of India.

6. From professional education to standards development

FDPPI’s journey can therefore be understood as an evolution through several stages.

Stage 1 — Awareness and Education

The first requirement was to create awareness about Data Protection and develop professional knowledge.

Stage 2 — Certification

The next requirement was to establish measurable professional competence through structured education and certification.

Stage 3 — Standards

As organizations began asking a more fundamental question — “How do we actually implement Data Protection?” — the need for implementation frameworks became evident.

This contributed to the development of DGPSI.

Stage 4 — Audit

As compliance frameworks mature, organizations need independent mechanisms to evaluate whether the claimed compliance actually exists.

This is the context in which AIDAI — Association of Independent Data Auditors of India assumes importance.

Thus, the journey has not been a series of unrelated initiatives.

It represents an evolution:

Education → Certification → Standards → Implementation → Audit

7. The significance of “without any profit motive”

The phrase “without any profit motive” appears in the objectives and deserves clarification.

It does not mean that Data Protection professionals should work without remuneration.

Professionals obviously need to be compensated for their knowledge, time and services.

The expression refers to the institutional purpose of FDPPI.

As a Section 8 organization, FDPPI exists for its stated objectives and not for distribution of profits to shareholders.

This distinction is important.

A professional organization can facilitate professional opportunities while itself remaining committed to a larger public-interest objective.

The ultimate beneficiary is therefore not merely the member.

It is the information society.

8. The objectives and the DPDPA era

India is now entering a fundamentally different phase.

The Digital Personal Data Protection framework is creating new responsibilities for organizations and new professional requirements.

Data Fiduciaries will need to understand their obligations.

Data Principals will need mechanisms through which their rights can be exercised.

Data Processors will need appropriate contractual and operational arrangements.

Significant Data Fiduciaries will have additional governance requirements.

Organizations will need policies, processes, technical controls, documentation, risk management and audit mechanisms.

This creates a requirement for professionals who are not merely familiar with the terminology of Data Protection but who can translate law into operational governance.

That requirement is precisely aligned with the original FDPPI objective of creating professionals who are knowledgeable, efficient and ethical.

9. The future: Data Protection, AI and independent audit

The next phase of FDPPI’s journey is likely to be shaped by three interconnected developments:

Data Protection

The implementation of India’s Data Protection framework will create a substantial requirement for professional knowledge and organizational capability.

Artificial Intelligence Governance

AI introduces questions that go beyond traditional privacy compliance.

Questions concerning data provenance, automated decision-making, algorithmic governance, accountability and responsible deployment require new governance approaches.

This is the background to FDPPI’s work on AIGSI — Artificial Intelligence Governance Standard of India.

Independent Data Audit

As organizations begin to demonstrate their compliance, independent assessment becomes increasingly important.

This is the rationale behind AIDAI and the development of frameworks for professional Data Auditing.

The objective is not to create another layer of bureaucracy.

It is to create confidence in the claims of compliance.

10. The Banyan Tree philosophy

The original objectives also provide a useful explanation for FDPPI’s organizational philosophy.

FDPPI does not necessarily aspire to become a large centralized employer.

Instead, it seeks to build a professional ecosystem.

The Banyan Tree Model captures this philosophy.

A banyan tree begins with a central trunk but continuously develops branches. Some branches eventually take root and become supporting structures themselves.

Similarly, FDPPI’s members and Associate Members can develop their own professional capabilities, initiatives and services while contributing to the larger ecosystem.

The strength of the organization therefore does not depend solely upon the size of its central structure.

It depends upon the strength of the professional community around it.

11. Eight years later — the objectives remain the foundation

Looking back after eight years, FDPPI has moved through several stages:

From awareness to education.

From education to certification.

From certification to professional development.

From professional development to standards.

From standards to implementation frameworks.

From implementation to independent audit.

And now, increasingly:

From Data Protection to Data Governance and AI Governance.

The instruments have changed.

The technology has changed.

The law has changed.

The professional requirements have changed.

But the fundamental objectives remain remarkably relevant.

FDPPI continues to seek the development of a community of professionals who are:

Knowledgeable.

Efficient.

Ethical.

And committed to contributing to a Secure Information Society by lawful means.

At the same time, FDPPI continues to believe that Privacy should not exist in isolation from other legitimate rights and interests.

The objective is not to create conflict between Privacy, Freedom of Expression, Right to Information and Cyber Security.

The objective is to develop the knowledge, professional competence and governance mechanisms required to achieve harmony among them.

That philosophy was embedded in FDPPI at its birth.

Eight years of experience have only demonstrated its continuing relevance.

The next phase is not merely about creating more Data Protection professionals.

It is about creating a professional ecosystem capable of making India’s information society more secure, trustworthy and responsible.

FDPPI’s original objectives remain the foundation for that journey.

Posted in Privacy | Leave a comment

FDPPI at Eight: A Journey of Evolution and Vision

FDPPI completes eight years of its existence this month. It is therefore a good time to look back at how the organization has evolved during this period and the journey that brought us here.

As most of you are aware, I have been working in the domain of Cyber Laws since 1998, when an Expert Committee of MeitY recommended that India should enact a law based on the UNCITRAL Model Law on E-Commerce. The concern at that time was that there was no legal recognition for electronic documents, which could adversely affect the interests of E-Commerce and Electronic Data Interchange (EDI) activities.

The recommendations of the committee eventually became the  the Draft E-Commerce Act, 1998, which was subsequently renamed the Information Technology Bill, 1999. At that time, I was particularly attracted to the concept of Digital Signatures and developed some business propositions around it for companies. I was also one of the few Thawte representatives in India involved in the validation of Digital Certificates through what was then called the “Thawte Notary” programme.

I also brought out my book, “Cyber Laws for Every Netizen in India,” in December 1999, when the Bill was presented in Parliament. The Bill eventually became law in July 2000 and was notified in October 2000.

Once the law was enacted, I started Cyber Law College and introduced courses covering various aspects of Cyber Law. At that time, the focus areas included Domain Name Law, Privacy Law, Digital Signature Law and Digital Contract Law.

When we discussed “Privacy” in those early years, the emphasis was largely on HIPAA in the United States and other emerging privacy laws such as COPPA. In Europe, the OECD privacy guidelines were an important reference, followed subsequently by the UK Data Protection Act, 1998.

However, it was the coming into force of the GDPR in 2018 that generated widespread interest in Data Protection in India. The concern was largely triggered by the potential penalty of 4% of global turnover. There was considerable anxiety that Indian data-processing companies, having accepted indemnity obligations from EU Data Controllers, could potentially find themselves exposed to significant liabilities. There was also concern about whether DPOs in India could face adverse consequences for GDPR non-compliance.

This prompted me to look at creating FDPPI, initially with the objective of protecting and empowering the DPO community in India.

At that time, Naavi.org, Cyber Law College and Ujvala Consultants were already engaged in awareness building, education and consultancy. However, it was felt that if a larger professional community was to participate meaningfully in Data Protection, there was a need for a separate professional organization.

After discussions with close friends and professionals in the industry, it was decided to establish FDPPI as a Section 8 Company.

The three original objectives of FDPPI were:

  1. Empowerment of Data Protection professionals
  2. Increasing the value and recognition of the Data Protection professional community
  3. Ensuring harmony between Cyber Security professionals and Privacy activists

Once the prospects of an Indian Data Protection law became clearer with the constitution of the Justice Srikrishna Committee, Cyber Law College increasingly became an in-house training and education arm of FDPPI, while FDPPI took up the broader responsibility of professional certification.

Naturally, questions arose: How could there be “Certified Data Protection Professionals” when the only applicable Data Protection legislation in India was the Information Technology Act, 2000?

The answer lay in the evolution of the IT Act itself. Following the 2008 amendments, particularly the introduction of Section 43A, the IT Act had become a reasonably effective framework for protection of personal data. Compliance with Section 43A was therefore an important Data Protection compliance requirement at that time.

I had, however, already started developing a broader compliance approach. In March 2009, I introduced the first compliance framework, the Indian Information Security Framework (IISF 309), as a framework for compliance with the IT Act, including Section 43A.

Some organizations restricted their recommendations to a “reasonable security practices” framework under Section 43A and were satisfied with addressing only those limited requirements. I continued to advocate a more holistic approach to IT Act compliance.

That philosophy later became extremely useful when FDPPI began developing a more focussed approach to Data Protection compliance.

At the earliest opportunity, FDPPI evolved from being primarily an Education and Certification organization into a Standards Development Organization, with the emergence of the DGPSI — Data Governance and Protection Standard of India.

While the Government went through the long journey from PDPB 2018, PDPB 2019, DPB 2021 and finally DPDPB 2022, FDPPI continued to update its certification programmes and develop its compliance frameworks in anticipation of the changing legal environment.

In my view, the most significant contribution of FDPPI to the Indian Data Protection community has been the evolution of DGPSI.

DGPSI subsequently blossomed into different variants — for SMEs, for AI deployment and for specific sectors and regulatory environments. The later development of DGPSI-GDPR, DGPSI-HR, DGPSI-DP, DGPSI-Hospital, DGPSI-Banks and other variants has transformed DGPSI into a family of standards that is, in many ways, internationally unique.

The Certification programmes also continued to evolve — from general Data Protection certification to more specialized programmes for DPOs in 2026.

Another important milestone was the launch of AIDAI — Association of Independent Data Auditors of India.

AIDAI represents a forward-looking vision for the post-May 2027 environment, when the DPDPA is expected to generate a significant requirement for trained and competent Data Auditors.

Thus, the journey from Naavi.org to FDPPI; from FDPPI as a certification organization to a Standards Development Organization; and now towards an Association of Independent Data Auditors represents a remarkable evolution over the last eight years.

Over the years, the Indian Data Protection Summit (IDPS) has provided a platform for presenting these developments and achievements to the professional community.

One important characteristic of FDPPI has remained constant throughout this journey: its independence.

FDPPI is not aligned with the Government, any Big Tech company, or NASSCOM. It has therefore been able to maintain an independent position in the Data Protection ecosystem. This independence becomes particularly relevant as India moves towards the creation of a large and competent community of independent Data Auditors.

The current initiatives such as AIGSI — Artificial Intelligence Governance Standard of India and AIDAI-SOP600 — a framework for aggregation of Data Audits represent the next generation of projects that FDPPI is pursuing.

They are part of our attempt to anticipate the needs of the future rather than merely respond to the requirements of the present.

Despite the limitations of resources, the support and contribution of more than 500 members, through their time, knowledge and professional efforts, have kept FDPPI growing and reaching new milestones year after year.

FDPPI is also increasingly passing into the hands of a new generation of managers. Mr. Ashok Kini and Mr. Vijayendra Shenoy are leading the business and operational activities forward, while the Board of Directors, with Nagendra as the Founding Director and Ramesh Venkataraman providing policy support, continues to guide the organization. Persons like Manju have provided valuable and often silent support to the operations.

2027 will be a defining year.

With the DPDPA moving towards full implementation, we are already experiencing a situation where the demand for professional services — particularly training — is beginning to overwhelm our available capacity.

We therefore look forward to explosive growth in the coming years.

But when we speak of “growth”, we do not necessarily mean that FDPPI will become a large employer of professionals.

We intend to remain a lean organization.

Our Associate Members are the backbone of FDPPI. We have consciously adopted what I call the “Banyan Tree Model” — where new branches take root, grow independently and support the larger structure, thereby making the organization stronger and more sustainable.

This model is not about creating a large centralized organization. It is about creating a large and capable professional ecosystem.

On the eve of our 8th AGM tomorrow, I invite all professionals who believe in the importance of Data Protection, professional independence and responsible governance to join FDPPI and become part of this continuing journey.

The first eight years were about building the foundation.

The next phase is about building the ecosystem.

Naavi

Posted in Privacy | Leave a comment