A Watershed moment in DPDPA Compliance

As Indian Data Fiduciaries try to find the ways to achieve DPDPA Compliance, the challenge stares at them. There is no precedence for them to follow. Even if they think GDPR is a good path, what is good for GDPR in EU may not be good for DPDPA in India. The law is different and the people are different. Hence a strategy for implementing DPDPA compliance has to find its own path.

FDPPI has found that Indian Banks are keen on DPDPA compliance and but are struggling to find the right path. Banks (like many other organizations) function at the branches but are Governed from the HO. Data exchange with the Data Principal happens at the Branch level where there is autonomy for collection, processing, disclsoure and grievance redressal. While the HO may set policies, implementation has to happen at the branch level.

SBI therefore is a conglommerate of 23000 branches where personal data of customers is processed. Any methodology for implementation and audit of DPDPA which does not recognize DPDPA compliance of the Bank as an aggregation of 23000 branch units is likely to be inefficient and unsustainable.

Implementation is the responsibility of the Banks. They may chose any path to reach the goal as it suits them.

But FDPPI and AIDAI have taken upon themselves to develop a system of Data Audit that is effective for Banks which have autonomous branch units where Personal Data is processed.

This is a combination of a “Standard for Compliance” and a “Standard for conducting Audits”.

Data Governance and Protection Standard of India (DGPSI) is already known to the market as the standard for DPDPA Compliance. Now AIDAI, (Association of Independent Data Auditors), a division of FDPPI has introduced a Standard Audit methodology named DA-SOP600 to enable independent audits at branch level to be aggregated at the enterprise level just as Statutory Financial audits udner ICAI guidlines under SA600 is handled.

AIDAI’s SOP600: A New Path for Data Audit under DPDPA

The launch of Data Auditor SOP600 by AIDAI (Association of Independent Data Auditors of India), is a watershed moment in the history of DPDPA compliance in India. This has created the path for DPDPA compliance in Banking organziations In India which have customer interface at branch level, ATM level, Business Correspondent level etc.

It is said that SBI function with  23000+ branches, 63000+ ATMs, 82000+ Business correspondent outlets. All these are Personal Data Collection and Processing points which needs to be factored in for DPDPA compliance.

Banks like Canara Bank/PNB  may have  10000+ branches and other Banks may have lesser number of Customer interface points. But the scale of the problem is mind boggling.

How is it appropriate to consider SBI or any other Bank as a single Data Fiduciary where a single DPO will manage the compliance and a single Data Auditor will audit?

SOP600 is a solution which AIDAI has found for conducting Data Audits. But it also holds the key for compliance.

It addresses a practical problem that is likely to become increasingly important as organisations move from a centralised model of data governance to a distributed operational model, where individual branches, business units, departments and locations independently interact with Data Principals.

The Branch is Where Privacy Actually Happens

Much of the discussion around data protection compliance tends to happen at the corporate or enterprise level. Policies are framed at the Head Office, Privacy notices are approved centrally, Data protection officers and legal teams sit at the enterprise level. Technology controls may also be centrally designed.

But  the actual interaction with the Data Principal take place very often, at the branch. It is a point of data collection, data use, data disclosure and Data Principal interaction.

The DPDPA compliance posture of the organisation cannot therefore be understood merely by looking at what the Head Office says it does.

The Challenge of Distributed Data Governance

The idea behind Data Auditor SOP600 is significant because it attempts to establish a standardised audit approach for branch and sub-unit environments.

The objective is not to replace the enterprise audit.

It is to create a mechanism through which the activities of autonomous units can be examined systematically and then aggregated into the enterprise-level audit perspective.

This is a fundamentally different way of looking at data protection auditing.

Instead of asking only, “Is the organisation compliant?”, the auditor can progressively ask, “Are the units through which the organisation interacts with Data Principals following the prescribed data protection practices?”

And then:

“What does the combined evidence from these units tell us about the enterprise’s overall DPDPA compliance posture?”

That is a much more operational approach to data governance.

What is important to note is that this principle not only assists the Auditing but also gives a direction to the implementation team of how to implement the DPDPA Compliance.

The designation SOP600 itself is symbolic of the philosophy behind the initiative. The objective is not simply to create another Standard Operating Procedure. It represents an attempt to institutionalise a repeatable and scalable audit methodology.

AIDAI, as the Association of Independent Data Auditors of India and a division of FDPPI, has an additional responsibility in this ecosystem.

The purpose of an auditor is not merely to identify non-compliance.

An auditor must also operate within a framework that promotes:

    • consistency,
    • independence,
    • professional discipline,
    • evidence-based assessment,
    • repeatability,
    • accountability, and
    • ethical conduct.

SOP600, as part of the emerging AIDAI framework and its Code of Ethics, seeks to create such a common professional path for empanelled auditors.

This is important because the credibility of an audit ecosystem ultimately depends upon the consistency of the audit process.

Two auditors examining comparable environments should not produce dramatically different outcomes merely because they follow completely different methodologies.

Standard Operating Procedures help reduce such variability.

The Bigger Idea: Compliance Is Not a Head-Office Function

Perhaps the most important message emerging from SOP600 is this:

DPDPA compliance cannot remain confined to the legal, IT or privacy department of an enterprise.

It has to reach the operational edge of the organisation. The branch manager, The customer-service executive, The sales employee, The HR representative, The field officer, The person receiving the KYC document, The person responding to a Data Principal’s request, The person deciding whether information can be disclosed.

These are the people who convert a policy into actual behaviour.

Therefore, the effectiveness of the DPDPA framework ultimately depends upon what happens at the point of data interaction.

A New Dimension to Independent Data Auditing

Traditional auditing often follows a top-down model. The enterprise is examined as a single entity. SOP600 introduces the possibility of a bottom-up evidence architecture.

The auditor can examine the operational units and then build the enterprise picture from the evidence emerging from those units.

This does not eliminate the need for enterprise-level auditing. On the contrary, it strengthens it.

A Watershed Moment?

Whether SOP600 ultimately becomes a widely adopted industry practice will depend on how the framework is implemented, tested, refined and accepted by Data Fiduciaries and the professional community.

But its significance as an experiment in structured, distributed and aggregatable data auditing is difficult to ignore.

The initiative raises an important question for every large Data Fiduciary:

Do you really know how personal data is being handled at every operational point where your organisation meets a Data Principal?

If the answer is uncertain, perhaps the next generation of DPDPA audits will have to look beyond the Head Office.

The future of data protection assurance may lie not only in auditing the enterprise — but in auditing the enterprise through its operational units.

And that is the path that SOP600 seeks to create.

The Journey Has Begun

Treading a path which nobody else has trodden is always a challenge.  But an innovator does not wait for someone else to build the road. He creates the road. And once the road is created, others can follow.

SOP600 is one such attempt to create a new road for the Indian data protection profession.

The path is open.

Let the auditors walk it.

Let the Data Fiduciaries test it.

Let the profession improve it.

And ultimately, let the objective remain what it has always needed to be, A more accountable, trustworthy and data-responsible India.

Naavi

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.