Read Time:7 Minute

A Discussion on Regulation vs. Self-Governance as India Prepares for DPDPA

India’s data protection landscape stands at a crossroads. As the Digital Personal Data Protection Act (DPDPA) awaits full implementation, a crucial question emerges: Should the government provide detailed compliance checklists, or should industries embrace self-regulation? At ‘The Data Trust Imperative: Technology, Governance and the Future of Data Protection’ conclave, four experts explore this complex terrain.


Discussion Participants


The Great Regulatory Debate

Mr Na Vijayashankar: There are always two schools of thought in the industry. Some people say that regulators have to come up with a complete checklist of what needs to be done and give detailed instructions. If you look at any of the guidelines coming from GDPR, they will be 20 pages, 30 pages each for one small implementation.

However, here’s the fundamental challenge. DPDPA is applicable across multiple industries. There is a hospital on one side, a bank on the other side, an educational institution on another side. The law can be only one, but implementations have to be different. In such a scenario, should we expect the government to come up with detailed compliance guidelines, or should we as industry people try to opt more for self-regulation?


Finding the Middle Path

Gp Capt R Vijayakumar: The checklist is something many ask for because it’s easy for us to just take it up. But what I really feel is that the government is wanting to do—there should be a middle path because every organization, every company, they have their own codes and their own system.

As far as data protection is concerned, hospital data will be totally different than manufacturing and other companies. There can’t be one thing which will meet the requirements of everybody. That is why sectoral approach has been beautifully designed.

At the moment, to the best of my ability, we all work in silos. The DPO should coordinate with other organizations so that they come and share their insights. It’ll become helpful to other organizations because everybody has got the best practices.


A Practitioner’s Perspective

Ms Deepalakshmi Vadivelan: Data protection and privacy itself is a journey. It’s not a one-time activity or an annual activity where you look at company secretarial position or labor law compliances. It’s every minute we need to undergo that assessment and determine what we are doing.

It’s very challenging to create a single framework which is going to define universal law for addressing healthcare, banking, or education industry. It’s too restrictive if you try to follow the particular checklist required for healthcare and apply the same to education. I feel it’s an unfair practice.

The law has to come and set the floor or the fundamental requirements for every entity to follow with respect to industries or sectors. More than the organizations, I definitely encourage sector-specific frameworks. We should move within either an MSME industry or sectors—hospitals, banking, education—we have to look at it.

Let me outline two critical parameters for sector-specific frameworks. One is principles-based—the fundamental principles required under this law have been taken care of in the privacy framework. Second is the requirements part—the standard framework requirements. How can this be constantly improved? Because there is always a gap between the law and the technology which is getting developed.


The Call for Sectoral Leadership

Mr Na Vijayashankar: If we do not want an imposed regulation from the government, somebody has to take leadership in the industry. This leadership has to come from each sector. Different sectors will have to identify who will be the sectoral leader who will start putting the sectoral members together for generating some kind of common framework.

Let me give you practical examples. Take pharmacies. There are perhaps 500 or 2,000 pharmacies in the city of Madras. All of them are dealing with information related to health. If at all there is something which is sensitive, they are also handling sensitive information. How will a pharmacy on the street corner be able to be compliant with DPDPA unless somebody handholds such organizations? There has to be an association of pharmacies.

Similarly, can a university take responsibility for DPDPA compliance of all their colleges? If they don’t take the responsibility, how can individual colleges take that responsibility?


The Role of Independent Directors

Mr Premanand V N: From an independent director’s perspective, the directors look at independent directors as experts. They engage them as experts in one of the fields.

The independent director creates a document where he specifies the policies have to be like this and makes an awareness across the company about data protection. Once he makes the awareness, data protection, just like cyber security, becomes a habit with each employee. They start following certain principles and slowly it becomes a discipline.

Let me share some historical context. In 1989, I worked with Coney elevators where we had typewriters and stenographers. The managing director told me to do a complete training program for all employees on how to use computers for day-to-day activities. Similarly today, the data protection practice is not available in many companies. Independent directors come in, give their advice, and bring in the discipline of making the company compliant.


Framework Solutions

Ms Deepalakshmi Vadivelan: Any framework which gives a structured and actionable roadmap to translate or demystify legal provisions into practical aspects to implement—I think that’s what this framework does. I’m referring to the Data Governance and Protection Standard of India (DGPSI).

It’s complementary by its design to DPDPA act because it provides detailed standards aligning to the principles—purpose limitation, minimization, addressing rights to individuals, grievance redressal mechanisms. Every function can create their checklist out of the 24 controls.

Building trust is crucial. Don’t wait for the act to come or rules to come. This has become mandatory for all of us, especially when on boarding with any organization as part of supplier or vendor on boarding.


The Technology Dimension

Mr Na Vijayashankar: Recently, the government of India through NEGD came up with BRIS—a framework for consent. They asked many software companies to generate solutions through a coding competition for consent management.

Here’s my challenge to the software industry: Do you think the software industry can come up with a framework? Many times software people say, ‘I have this software, I will try to modify it to your requirement.’ What we want is: this is the law, you have to develop a software for that particular thing.

Ms Deepalakshmi Vadivelan: Organizations deploying applications need to apply principles of privacy by design. Don’t wait for an organization to seek you asking how this software ensures privacy. Encryption, consent as purpose, mandatory versus voluntary fields—all these need to be tracked in the software.


Moving Forward: A Call to Action

Mr Na Vijayashankar: We need to identify sectoral leaders, and I would like organizations like MMA to start thinking about this and try to encourage sectoral leaders. Most of the time these associations have been there to develop business for their respective groups, but now we have to get their priorities reoriented toward DPDPA compliance.

Whenever you get another congregation of industry people, the question we first ask should be: are you DPDPA compliant? In your industry association or group, how many are DPDPA compliant?

Gp Capt R Vijayakumar: Self-regulation is a must for everything. If you don’t have self-regulation in terms of data, we’ll get a heart attack.


The Path Forward

India’s data protection journey requires a collaborative approach where government sets the baseline, industries develop sector-specific frameworks, and organizations embrace self-regulation. The discussion reveals clear priorities:

Government’s Role: Establish foundational principles and minimum compliance standards applicable across all sectors.

Industry Leadership: Identify sectoral leaders who can develop tailored frameworks addressing specific industry needs—from pharmacies to universities, banks to hospitals.

Organizational Responsibility: Adopt proactive compliance measures, leverage independent directors’ expertise, and embed privacy by design into technology solutions.

Collaborative Action: Break down silos through DPO networks, share best practices across organizations, and build sector-specific associations that prioritize compliance over business development alone.

The urgency is clear. Organizations can no longer wait for detailed government checklists. Self-regulation, supported by sector-specific frameworks and collaborative leadership, offers the most practical path to meaningful DPDPA compliance—one that respects India’s diverse economic landscape while building the data trust imperative that defines our digital future.

ALSO

Discover more from Business Mandate

Subscribe now to keep reading and get access to the full archive.

Continue reading

MMA app

FREE
VIEW