FDPPI at Eight: A Journey of Evolution and Vision

FDPPI completes eight years of its existence this month. It is therefore a good time to look back at how the organization has evolved during this period and the journey that brought us here.

As most of you are aware, I have been working in the domain of Cyber Laws since 1998, when an Expert Committee of MeitY recommended that India should enact a law based on the UNCITRAL Model Law on E-Commerce. The concern at that time was that there was no legal recognition for electronic documents, which could adversely affect the interests of E-Commerce and Electronic Data Interchange (EDI) activities.

The recommendations of the committee eventually became the  the Draft E-Commerce Act, 1998, which was subsequently renamed the Information Technology Bill, 1999. At that time, I was particularly attracted to the concept of Digital Signatures and developed some business propositions around it for companies. I was also one of the few Thawte representatives in India involved in the validation of Digital Certificates through what was then called the “Thawte Notary” programme.

I also brought out my book, “Cyber Laws for Every Netizen in India,” in December 1999, when the Bill was presented in Parliament. The Bill eventually became law in July 2000 and was notified in October 2000.

Once the law was enacted, I started Cyber Law College and introduced courses covering various aspects of Cyber Law. At that time, the focus areas included Domain Name Law, Privacy Law, Digital Signature Law and Digital Contract Law.

When we discussed “Privacy” in those early years, the emphasis was largely on HIPAA in the United States and other emerging privacy laws such as COPPA. In Europe, the OECD privacy guidelines were an important reference, followed subsequently by the UK Data Protection Act, 1998.

However, it was the coming into force of the GDPR in 2018 that generated widespread interest in Data Protection in India. The concern was largely triggered by the potential penalty of 4% of global turnover. There was considerable anxiety that Indian data-processing companies, having accepted indemnity obligations from EU Data Controllers, could potentially find themselves exposed to significant liabilities. There was also concern about whether DPOs in India could face adverse consequences for GDPR non-compliance.

This prompted me to look at creating FDPPI, initially with the objective of protecting and empowering the DPO community in India.

At that time, Naavi.org, Cyber Law College and Ujvala Consultants were already engaged in awareness building, education and consultancy. However, it was felt that if a larger professional community was to participate meaningfully in Data Protection, there was a need for a separate professional organization.

After discussions with close friends and professionals in the industry, it was decided to establish FDPPI as a Section 8 Company.

The three original objectives of FDPPI were:

  1. Empowerment of Data Protection professionals
  2. Increasing the value and recognition of the Data Protection professional community
  3. Ensuring harmony between Cyber Security professionals and Privacy activists

Once the prospects of an Indian Data Protection law became clearer with the constitution of the Justice Srikrishna Committee, Cyber Law College increasingly became an in-house training and education arm of FDPPI, while FDPPI took up the broader responsibility of professional certification.

Naturally, questions arose: How could there be “Certified Data Protection Professionals” when the only applicable Data Protection legislation in India was the Information Technology Act, 2000?

The answer lay in the evolution of the IT Act itself. Following the 2008 amendments, particularly the introduction of Section 43A, the IT Act had become a reasonably effective framework for protection of personal data. Compliance with Section 43A was therefore an important Data Protection compliance requirement at that time.

I had, however, already started developing a broader compliance approach. In March 2009, I introduced the first compliance framework, the Indian Information Security Framework (IISF 309), as a framework for compliance with the IT Act, including Section 43A.

Some organizations restricted their recommendations to a “reasonable security practices” framework under Section 43A and were satisfied with addressing only those limited requirements. I continued to advocate a more holistic approach to IT Act compliance.

That philosophy later became extremely useful when FDPPI began developing a more focussed approach to Data Protection compliance.

At the earliest opportunity, FDPPI evolved from being primarily an Education and Certification organization into a Standards Development Organization, with the emergence of the DGPSI — Data Governance and Protection Standard of India.

While the Government went through the long journey from PDPB 2018, PDPB 2019, DPB 2021 and finally DPDPB 2022, FDPPI continued to update its certification programmes and develop its compliance frameworks in anticipation of the changing legal environment.

In my view, the most significant contribution of FDPPI to the Indian Data Protection community has been the evolution of DGPSI.

DGPSI subsequently blossomed into different variants — for SMEs, for AI deployment and for specific sectors and regulatory environments. The later development of DGPSI-GDPR, DGPSI-HR, DGPSI-DP, DGPSI-Hospital, DGPSI-Banks and other variants has transformed DGPSI into a family of standards that is, in many ways, internationally unique.

The Certification programmes also continued to evolve — from general Data Protection certification to more specialized programmes for DPOs in 2026.

Another important milestone was the launch of AIDAI — Association of Independent Data Auditors of India.

AIDAI represents a forward-looking vision for the post-May 2027 environment, when the DPDPA is expected to generate a significant requirement for trained and competent Data Auditors.

Thus, the journey from Naavi.org to FDPPI; from FDPPI as a certification organization to a Standards Development Organization; and now towards an Association of Independent Data Auditors represents a remarkable evolution over the last eight years.

Over the years, the Indian Data Protection Summit (IDPS) has provided a platform for presenting these developments and achievements to the professional community.

One important characteristic of FDPPI has remained constant throughout this journey: its independence.

FDPPI is not aligned with the Government, any Big Tech company, or NASSCOM. It has therefore been able to maintain an independent position in the Data Protection ecosystem. This independence becomes particularly relevant as India moves towards the creation of a large and competent community of independent Data Auditors.

The current initiatives such as AIGSI — Artificial Intelligence Governance Standard of India and AIDAI-SOP600 — a framework for aggregation of Data Audits represent the next generation of projects that FDPPI is pursuing.

They are part of our attempt to anticipate the needs of the future rather than merely respond to the requirements of the present.

Despite the limitations of resources, the support and contribution of more than 500 members, through their time, knowledge and professional efforts, have kept FDPPI growing and reaching new milestones year after year.

FDPPI is also increasingly passing into the hands of a new generation of managers. Mr. Ashok Kini and Mr. Vijayendra Shenoy are leading the business and operational activities forward, while the Board of Directors, with Nagendra as the Founding Director and Ramesh Venkataraman providing policy support, continues to guide the organization. Persons like Manju have provided valuable and often silent support to the operations.

2027 will be a defining year.

With the DPDPA moving towards full implementation, we are already experiencing a situation where the demand for professional services — particularly training — is beginning to overwhelm our available capacity.

We therefore look forward to explosive growth in the coming years.

But when we speak of “growth”, we do not necessarily mean that FDPPI will become a large employer of professionals.

We intend to remain a lean organization.

Our Associate Members are the backbone of FDPPI. We have consciously adopted what I call the “Banyan Tree Model” — where new branches take root, grow independently and support the larger structure, thereby making the organization stronger and more sustainable.

This model is not about creating a large centralized organization. It is about creating a large and capable professional ecosystem.

On the eve of our 8th AGM tomorrow, I invite all professionals who believe in the importance of Data Protection, professional independence and responsible governance to join FDPPI and become part of this continuing journey.

The first eight years were about building the foundation.

The next phase is about building the ecosystem.

Naavi

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.