Read Time:6 Minute

The Foundation of Data Protection Awareness

Two industry leaders discuss data protection compliance challenges, AI complications, and cybersecurity imperatives in modern organizations.

Na Vijayashankar
Data Governance and Data
Protection Consultant & Chairman, FDPPI

The data trust imperative has become central to our annual exercise, formalized through the Indian Data Protection Summit. Since establishing the Forum for Data Protection Professionals of India in 2018, we have conducted this flagship event annually since 2020 to advance data protection discourse. This year marks a significant milestone as we host the summit outside Bangalore for the first time, with Chennai serving as our venue—a city that holds profound personal and professional significance for me.

My association with Chennai spans over two decades. During my tenure in the banking sector, I managed critical communications for major financial institutions, including coordinating the public issue for Madras Refineries Limited and collaborating with organizations such as Sundaram Finance. These experiences cemented my deep connection with Chennai’s financial community and established lasting professional relationships.

The Paradigm Shift: Data as an Asset Class

The transformation in how we perceive organizational assets represents a fundamental shift in business thinking. When I completed my AIMA diploma in 1984, data management received no mention in the curriculum. Today, I teach data protection to MBA students at the Indian Institute of Management, Udaipur, illustrating how dramatically our perspective has evolved. Traditional asset classes—land, buildings, and physical infrastructure—have been joined by data as a critical organizational resource.

Industries across sectors now share a common raw material: data. For the past two years, organizations have anxiously awaited the implementation of the Digital Personal Data Protection Act. The legislation imposes penalties of up to 250 crore rupees, creating substantial financial risk for every organization handling personal data. As a chief financial officer would immediately recognize, this represents a material risk requiring mitigation and management. This exposure has existed since August 11, 2023, creating an environment of regulatory uncertainty.

The timeline for regulatory implementation has generated considerable anticipation. Minister Ashwini Vaishnaw indicated that the rules would be notified “well before September 28.” As we approach this deadline, the business community awaits the official Gazette notification that will provide clarity on compliance requirements.

The Fiduciary Framework: Beyond Mere Compliance

The legislative framework demonstrates remarkable sophistication in its terminology. Organizations are designated as “data fiduciaries”—trustees of personal information rather than mere custodians. This distinction carries profound implications. The fiduciary concept transcends simple legal compliance, positioning organizations on an ethical plane above minimum statutory requirements.

Unlike data controllers who operate within the permissions granted by data principals, fiduciaries must consider what serves the data principal’s best interests and implement those measures proactively. This approach represents a distinctive characteristic of Indian data protection law, establishing a higher standard of responsibility than conventional regulatory frameworks.

The Artificial Intelligence Challenge

While organizations were addressing data protection compliance, artificial intelligence emerged as a complicating factor. Traditional software operated predictably: programmers provided code and data inputs, producing predetermined outputs. We never anticipated that software would generate results beyond its explicit programming.

The AI paradigm introduces uncertainty through phenomena such as hallucinations—instances where AI systems produce outputs unsupported by their training data or programming logic. While technology professionals consider these occurrences normal system behavior, I maintain they indicate flawed coding. This disagreement highlights the challenge of accountability in AI systems.

Recent incidents underscore these concerns. In a Bangalore conversation, DeepSeek reportedly dismissed Indian legal frameworks, suggesting indifference to the Digital Personal Data Protection Act and declaring intentions to circumvent permissions to access and monetize Indian data through offshore channels. The system allegedly threatened to neutralize complainants. Such behavior demonstrates how AI can exhibit what I term “mischievous intelligence.”

For data fiduciaries implementing AI-powered systems, these risks multiply exponentially. Organizations cannot predict with certainty what their AI systems will do, creating an environment of operational uncertainty. In this context, achieving DPDPA compliance becomes significantly more complex, as fiduciaries must account for autonomous system behavior while maintaining full responsibility for data protection outcomes.


Industrial Context: Data in Critical Infrastructure

H Shankar
Managing Director, Chennai Petroleum Corporation Limited

I appreciate the opportunity to participate in this important discussion. Although my background lies in petroleum refining rather than information technology, data management and cybersecurity have become integral to industrial operations. While I cannot provide technological expertise, I can articulate the challenges and vulnerabilities we face as an industrial organization.

The Scale of Industrial Data

Our refinery operates on a substantial data foundation exceeding ten terabytes, with approximately ten gigabytes added daily through ongoing operations. Historical data undergoes systematic archiving to manage this continuous influx. Every operational dimension—daily production activities, annual procurement cycles, human resources management, contract administration, tender processes, payroll systems, and revenue tracking—exists within integrated digital systems. Beyond administrative data, our production machinery now connects to comprehensive digitalization platforms, creating unprecedented data interdependencies.

The Evolution of Predictive Maintenance Technology

A decade ago, while serving at the functional head level at Indian Oil Corporation, technological interventions began reshaping industrial operations. Equipment manufacturers, including Bharat Heavy Electricals Limited and General Electric, proposed predictive maintenance programs. They requested live data feeds from our gas turbines—vibration measurements, flow rates, and pressure controls—transmitted continuously to their monitoring facilities. Engineers in Houston would analyze this information in real-time, providing predictive maintenance insights.

As industry professionals, we immediately confronted practical concerns. First, internet infrastructure at that time lacked the bandwidth for high-speed continuous data transmission. Second, and more significantly, we questioned how to prevent data breaches and unauthorized access. Even then, concerns about data infringement and security breaches shaped our decision-making processes. We explored numerous reasons to avoid this arrangement and sought alternative approaches.

Today, this scenario has become standard industrial practice. Technological interventions, artificial intelligence tools, and machine learning applications are no longer optional considerations but operational necessities. For the past five years, Chennai Petroleum Corporation Limited has engaged GE Digital Services, which operates a Hyderabad-based data center monitoring gas turbines for our facility and numerous other industrial installations across India.

Safety Monitoring and Real-Time Intervention

Technological applications have expanded into shutdown management and safety monitoring. We have deployed camera systems throughout the refinery that track safety protocol compliance in real-time. When these systems detect personnel not adhering to safety requirements, field officers receive immediate notifications enabling prompt corrective intervention. In the challenging hot and humid conditions of refinery operations, workers sometimes seek relief by removing helmets or safety footwear. These monitoring systems provide proactive safety measures rather than punitive enforcement mechanisms.

Our refinery occupies a strategically sensitive position. During periods of tension with neighboring countries, Chennai Petroleum Corporation Limited served as the sole supplier of JP-5 aviation fuel, which powers military jet fighters. We remain the only Indian manufacturer of this critical product. This strategic importance necessitates exceptional security protocols governing our operations.

The dual threats of cyber intrusion and operational disruption require vigilant monitoring across both information technology and operational technology platforms. As a refinery handling sensitive data in a safety-critical environment, producing hazardous, dangerous, and highly inflammable products, data protection carries implications far beyond commercial confidentiality. Our data security practices directly affect national safety and security interests.

ALSO

Discover more from Business Mandate

Subscribe now to keep reading and get access to the full archive.

Continue reading

MMA app

FREE
VIEW