DATA PRIVACY: A Shared Responsibility
FOR EVERY RUPEE SPENT RESPONDING TO A DATA BREACH, THE REAL COST IS MEASURED
IN SOMETHING FAR HARDER TO REBUILD — TRUST.
India's digital economy is generating data at a pace that its regulatory architecture is still scrambling to match. With over 900 million internet users and enterprise cloud adoption accelerating across every industry vertical, the country sits atop one of the world's largest, and most exposed, pools of personal data. The numbers tell an uncomfortable story. Cybersecurity incidents in India rose from 10.29 lakh in 2022 to 22.68 lakh in 2024, according to government data. Cybercrime losses are projected to reach ₹20,000 crore across sectors in 2025, with banking and financial services alone accounting for ₹8,200 crore. And the average cost of a single data breach in India has reached an all-time high of ₹19.5 crore in 2024, up 39% since 2020, according to IBM's annual Cost of a Data Breach Report.
The question is no longer whether data privacy matters. It is who, exactly, is responsible for it, and whether that responsibility is being shared equitably across the ecosystem. The honest answer, for most organisations, is no.
INDIA'S REGULATORY MOMENT — NOW WITH A DEADLINE
For years, enterprises deferred DPDP compliance decisions, citing the absence of notified rules. That window has closed. MeitY formally notified the Digital Personal Data Protection Rules, 2025 on November 13, 2025, operationalising the DPDP Act, 2023 after more than two years of legislative and consultative process. The Data Protection Board of India (DPBI) has been established and the compliance clock is now running.
The rollout is phased: procedural provisions and the DPBI framework became effective immediately from November 14, 2025; consent manager registration obligations kick in by November 2026; and all substantive compliance obligations including privacy notices, consent systems, security safeguards, breach protocols, and data principal rights infrastructure, must be fully operational by May 13, 2027. Violations can attract penalties of up to
₹250 crore per breach of obligation. That is not an 18-month grace period, it is an 18-month implementation runway, and organisations that treat it as the former will find themselves structurally exposed on Day 1 of full enforcement.
The DPDP Rules introduce specific, operational obligations. Data Fiduciaries must issue clear, standalone privacy notices before collecting data; implement technical controls including encryption, masking, access controls, and visibility logs; maintain audit logs for at least one year; and report data breaches to the DPBI within 72 hours. Significant Data Fiduciaries face additional constraints, including restrictions on cross-border transfer of traffic data. The framework draws from established global privacy principles, GDPR in the EU, PDPA in Singapore, CCPA in California, while reflecting India's own digital scale and policy priorities.
For the VAR and system integrator community, this transition window is not a compliance challenge to be observed from the sidelines. It is a commercial and advisory opportunity of the first order.
THE MYTH OF THE SINGLE ACCOUNTABLE PARTY
Ask most organisations who owns data privacy, and the answer will lead you to the CISO's office, or perhaps legal and compliance. That framing is dangerously outdated.
Under the DPDP Act, the primary accountable entity is the Data Fiduciary — the organisation that determines the purpose and means of data processing. But accountability within that organisation cannot, and should not, sit with a single function. The CISO manages security controls. The Chief Data Officer, where one exists, governs data architecture and quality. Legal interprets regulatory obligations. HR manages employee data and consent. Marketing runs customer consent workflows. Every business unit that touches personal data is, in effect, a node in the privacy accountability chain.
The breakdown typically occurs at the seams between these functions. A marketing team launches a new data collection workflow without looping in legal. A business unit onboards a SaaS application without informing IT, creating an unsanctioned data flow. A vendor receives a data extract for analytics without a proper data processing agreement in place.
None of these failures are malicious. Most are structural, the result of organisations that have built data practices around operational convenience rather than privacy architecture.
Cloud complexity compounds the challenge considerably. According to IBM's 2024 Cost of a Data Breach Report, 34% of data breaches in India involved data stored on public clouds, with breaches in public cloud environments costing the most — an average of ₹22.7 crore per incident. Incidents spanning multiple cloud environments took the longest to identify and contain, 327 days on average. The same report found that 35% of breaches globally involved shadow data, with those breaches costing 16% more on average and taking significantly longer to detect. Data sprawl is not a metaphor — it is a measurable operational liability.
India's breach record in recent years illustrates the stakes concretely. In 2024 alone, Hathway's data breach exposed the personal information of over 41.5 million customers; BSNL suffered an intrusion that put sensitive subscriber data — including IMSI numbers and SIM card details — up for sale on dark web marketplaces; and boAt saw the personal records of 7.5 million customers compromised. Each breach followed a familiar pattern: governance gaps, inadequate access controls, and delayed detection.
THE CHANNEL OPPORTUNITY: FROM RESELLER TO TRUSTED ADVISOR
For VARs, MSPs, and system integrators, the DPDP Rules create a regulatory inflection point that demands a strategic response. Any entity that processes personal data on behalf of a Data Fiduciary — which describes the function of virtually every MSP and SI with a managed services contract — qualifies as a Data Processor under the framework. This carries real legal obligations: adherence to contractual data processing terms, implementation of security standards prescribed under the Rules, and breach notification requirements.
Channel partners that have not reviewed their customer contracts and data handling practices through a DPDP lens are carrying unquantified legal exposure. The first step is internal housekeeping: understanding what personal data flows through service delivery infrastructure, and on whose behalf it is being processed.
The broader opportunity lies in what the channel can offer customers who are themselves underprepared. India's cybersecurity domestic market was valued at approximately USD 4 billion in 2024 and is on a growth trajectory, according to DSCI. The cybersecurity products segment alone generated revenue of USD
4.46 billion in 2025 and is projected to reach USD 5.98 billion in 2026, growing 25% year-on-year, according to DSCI CEO Vinayak Godse at the Annual Information Security Summit 2025. Privacy-driven spending on data classification, consent management, DLP, and DSPM is a rising share of that market.
Data Security Posture Management platforms, which provide continuous visibility into where sensitive data lives, who has access to it, and whether it is appropriately protected, are moving from early adopter to mainstream procurement conversations in Indian enterprise accounts. The channel partner that can walk into a boardroom and connect these technology investments to regulatory risk mitigation, reputational protection, and customer trust, rather than simply presenting a product stack, earns a strategic advisory relationship, not a transactional one.
THE HUMAN FACTOR: CULTURE EATS POLICY
Technology and regulation can establish the conditions for good data privacy practice. They cannot, by themselves, produce it. According to IBM's India data, phishing and stolen or compromised credentials were the most common initial attack vectors, each accounting for 18% of incidents, with business email compromise the costliest root cause at ₹21.5 crore per breach on average. These are not purely technical failures. They are human ones.
Privacy fatigue is a real phenomenon. Employees who are subjected to annual compliance training, typically a checkbox exercise — retain little actionable knowledge and develop no meaningful instinct for privacy risk. The emergence of generative AI tools has introduced an entirely new category of shadow data risk. Employees across functions are routinely feeding customer records, internal analyses, and personally identifiable information into AI assistants and productivity tools that sit entirely outside the organisation's data governance perimeter.
IBM's 2025 Cost of a Data Breach Report found that 61% of organisations lack AI governance technologies, even among those that have governance policies in place. Only a minority perform regular audits for unsanctioned AI. The gap between what employees are doing with AI tools and what IT and security teams know about is, in most Indian enterprises, substantial, and growing.
Building a genuine privacy culture requires visible leadership commitment, the appointment of Data Protection Officers or privacy leads with real authority, and the kind of ongoing contextual communication that connects privacy principles to specific workflows. The IBM data shows that organisations in India which deployed security AI and automation extensively shortened their breach lifecycle by 112 days and spent ₹13 crore less per breach on average — yet 72% of studied Indian organisations have limited or no use of these technologies. The preparedness gap is real, and it is measurable.
TECHNOLOGY AS ENABLER AND MULTIPLIER OF RISK
The same technologies transforming Indian enterprises are also expanding the surface area of data privacy risk. India's cyberspace is the second most targeted in the world, facing increasing ransomware, phishing, and supply chain attacks, according to the Carnegie Endowment for International Peace. Between 2019 and 2023, cyber attacks on the Indian government increased by 138%.
Zero-trust architecture, which assumes no implicit trust for any user, device, or workload, has become foundational to modern security design, and it serves privacy objectives as well. By enforcing granular access controls and eliminating broad ambient access to data, zero-trust reduces the blast radius of both external breaches and insider incidents. Privacy- enhancing technologies such as differential privacy, federated learning, and data tokenisation are moving from research into enterprise product roadmaps, driven by both regulatory pressure and the commercial imperative to extract value from data without compromising individual privacy.
DSPM and consent management platforms are gaining traction particularly in BFSI and healthcare, India's two most regulated sectors and, not coincidentally, its two most breach-exposed. The DPDP Rules' specific requirements around encryption, masking, and access visibility are accelerating procurement conversations that had previously stalled at the evaluation stage.
TOWARD A SHARED ACCOUNTABILITY MODEL
Data privacy cannot be owned by a single team, solved by a single technology, or legislated into existence by a single law. It is, by its nature, a distributed responsibility, one that requires aligned action from regulators, enterprises, channel partners, technology vendors, and individuals simultaneously.
The DPDP framework has permanently changed the calculus. With the Data Protection Board now established, a three-phase enforcement timeline running to May 2027, and penalties of up to ₹250 crore per violation waiting at the end of that runway, compliance is no longer a future-state aspiration. It is a time-bound operational imperative.
Organisations that treat the current phased rollout as an extension of the old ambiguity will find themselves structurally exposed when full enforcement begins. Those that use this window to build genuine privacy accountability — across people, processes, and technology, will find that it pays dividends well beyond regulatory compliance. And the channel partners that help them get there will have earned something more durable than a product sale. In a digital economy built on data, trust is infrastructure. And infrastructure, once neglected, is expensive to rebuild.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
