The developments in the IT industry after the DPDPA, represent the second instance where the attitude of people towards intangible assets is undergoing a major change.
The first such instance was when the “IP Mindset” entered the system. Now it is the time of the “Privacy Mindset.” There is an interesting similarity between the two.
The concept of Intellectual Property evolved, among other reasons, from the need to protect the interests of the creator. The objective was that the creativity of an individual should not simply be appropriated and exploited by a larger and more powerful organisation.
Thereafter, it appears that the IP law became institutionalised. Organisations became better equipped than individual creators to understand, interpret and enforce IP contracts. In many situations, what was intended to protect the creator eventually became a contractual mechanism through which the organisation acquired extensive rights over the creator’s output.
The law had not necessarily failed. But the power equation had changed. And with it, something more important was lost.
Trust.
A creative person enters an organisation because he wants to convert an idea into something useful. But if every thought he expresses is immediately viewed through the prism of ownership, assignment, confidentiality and commercial exploitation, the relationship begins to change.
The organisation starts asking: “How much can we legally own?” but the creator starts asking: “What can I safely say?”
That is a unproductive transformation indicating the breaking of trust. The moment a creative person starts believing that whatever he says may become an asset of the organisation, his natural instinct to experiment gets replaced by caution. He watches his steps firmly planted on the ground instead of flying with imagination. And innovation suffers.
This is where the emerging Privacy Mindset becomes interesting.
We are now entering a data-driven business environment in which personal data has acquired enormous economic value. The law has stepped in because, once again, there is a significant imbalance of power.
On one side is the Data Principal, who provides or generates data about himself. On the other side is the Data Fiduciary, which has the technology, resources, analytics capability and commercial motivation to derive value from that data.
The DPDPA attempts to bring discipline into this relationship. But there is a danger. If the experience of the IP world is any indication, the legal protection provided to the weaker party can gradually become a sophisticated compliance mechanism operated by the stronger party.
Today, we are impressed by the prospect of hefty penalties. Organisations are investing in privacy programmes. Consultants are being appointed. Policies are being drafted. Privacy notices are being rewritten. Consent mechanisms are being redesigned. There is a feeling that the law has finally arrived and that organisations will now think twice before exploiting personal data.
But what happens after the transition period? Will organisations simply absorb the cost of compliance? Or will they seek an ROI on privacy compliance? That is where the real test begins.
There is a specific danger that “consent” itself could become another instrument of commercialisation.
The question may gradually shift from: “Have we obtained meaningful consent?”
to:
“How much commercial value can we extract from the consent we have obtained?”
And once that happens, Privacy notices could become the new IP contracts. The lawyer’s innovation may then be directed towards designing a notice that is technically comprehensive, legally defensible and sufficiently complicated to ensure that almost every conceivable use of the data has been covered.
The individual may click: “I Agree.” And the organisation may later say: “But you consented.”
Legally, the organisation may have a point. But does that necessarily mean that the individual understood what he had agreed to?
This is where transparency and simplicity become critical. A privacy notice should not become a legal hiding place.
A document can be legally exhaustive and still be practically meaningless to the person whose data is being processed. The real question is not merely whether the organisation has obtained a legally valid consent. The question is whether the Data Principal has been given a meaningful opportunity to understand the bargain.
That distinction will determine whether the DPDPA becomes an instrument of empowerment or merely another sophisticated mechanism for legitimising exploitation.
The intention behind data protection legislation is to build trust in the digital economy. We should therefore be careful that the compliance machinery does not produce the opposite result. If a Data Principal begins to feel that his personal data has become an asset which everyone except him can monetise, the law would have achieved only partial success.
The objective is not be to prevent legitimate commercial use of data. There is nothing inherently wrong with commercial harnessing of data. But there is a yellow line between harnessing and exploitation.
We need to mark this yellow line and make the Data Principal see it.
This is where organisations such as FDPPI, and frameworks such as DGPSI, have an important role to play.
The objective of Compliance and the Framework should not merely be to help organisations demonstrate that they are compliant. The objective should be to encourage a form of compliance where the organisation’s use of personal data is transparent enough that even when the organisation is commercially benefiting from the data, the Data Principal is not left with a feeling that he has been tricked into giving away something valuable.
That is a much higher standard than mere legal compliance. It is a standard of trust. Perhaps this is the real challenge before the privacy community today.
We need to build a relationship with the data principal where data can be commercially harnessed without commercially exploiting the individual. A relationship where the organisation should ask itself “What should I do with this data if I want the Data Principal to continue trusting me?”
That, is the real test of the Privacy Mindset.
Let us review after a few years and see whether the DPDPA has truly become an instrument of protecting society—or whether, like some aspects of the IP journey, it has merely given exploitation a more sophisticated legal language.
We hope DGPSI will be an instrument that assists in compliance of DPDPA without compromising on the Trust factor.
That is the objective… To make DGPSI a symbol of Trusted Personal Data Processing.
“Compliance without Compromise of Trust” should be the tag line for the DGPSI frameworks….
Naavi








