May 2027 matters. But the bigger shift is already underway. Privacy is converging with data governance, AI, risk and security, and the enterprises that build the foundation now will be better prepared for what comes next.
India’s privacy conversation has changed. A year ago, much of the discussion inside enterprises was about understanding the Digital Personal Data Protection framework. What does it require? Who should own it? What will compliance involve? Today, those questions are giving way to harder ones.
Where exactly does personal data sit? Can enterprises trace why it was collected? Can consent be connected to how that data is subsequently used? If an individual asks for their data to be corrected or erased, can that request be executed across multiple systems? Do organisations know which processors have access to the data? What happens when the same data is used by an AI system? And can the enterprise demonstrate that all of these controls are actually working?
Privy by IDfy is seeing this transition first-hand through more than 50 enterprise privacy implementations across banking and insurance, NBFCs, investment and wealth, fintech and payments, retail and e-commerce, telecom, healthcare, real estate and other sectors.
What those implementations reveal is that India does not have a privacy awareness problem anymore. It has an operationalisation challenge. There is also a second, bigger shift underway.
Privacy can no longer be treated as an isolated compliance programme. It is increasingly becoming part of how enterprises govern data, deploy AI, manage risk, build security and earn customer trust.
That convergence is likely to define the next phase of India’s privacy maturity.
The real gap is between knowing and doing
Most large enterprises today understand the importance of DPDP. Leadership teams are aware of it. Legal and compliance functions are engaged. Privacy programmes have been initiated. But awareness is not the same as operational readiness. The real complexity begins when an organisation tries to translate a regulatory requirement into something that works across hundreds of applications, thousands of employees, multiple customer journeys and an ecosystem of third parties.
Take something as seemingly straightforward as an erasure request. For an organisation to honour it meaningfully, it first needs to know where that person’s information exists. That could mean a CRM, a mobile application, a data warehouse, an archived database, a marketing platform, spreadsheets maintained by individual teams and systems operated by external processors.
The question quickly shifts from, and act on the data everywhere it exists?” “Do we have an erasure process?” to, “Can we actually find That shift from policy to execution is where privacy maturity becomes visible. Across Privy’s implementations, one lesson has become particularly clear:
Enterprises cannot govern personal data they cannot see.
Many privacy programmes naturally begin with what is most visible to the customer, such as privacy notices, consent mechanisms and rights request forms. But the deeper work is less visible and often more consequential. Enterprises need to discover personal data across their technology estate, classify it, understand why it is being processed, trace where it moves, identify who has access to it and establish which processors interact with it.
This is why data discovery, mapping and governance are becoming foundational to DPDP implementation rather than being treated as secondary data-management exercises. Only when enterprises understand their data can they begin connecting privacy obligations to the data itself.
May 2027 is a working deadline, not the finish line
May 2027 is understandably receiving enormous attention.The DPDP Rules were notified on November 13, 2025, with key substantive provisions coming into force 18 months after notification. That makes May 2027 an important operating deadline for Indian enterprises.
But enterprises should be careful not to build only for a date. Businesses that spend the coming months simply trying to become compliant by May may find themselves revisiting the same systems and controls soon after. Because businesses do not stand still. New products are launched. New vendors are onboarded. Customer journeys change.
Applications are added or replaced. Acquisitions create new technology estates. Data moves into new environments. Business models evolve. And now, AI is accelerating all of it. AI models, copilots, agents and automated decision systems are introducing new ways of accessing, combining and deriving value from information. Data that may have originally been collected for one business process can suddenly become an input into another use case entirely.
Privacy therefore cannot be a one-time mapping exercise followed by a static policy. It has to move at the speed of the enterprise. That is why enterprises starting now have an opportunity that goes beyond regulatory readiness. They can build the data-governance foundation for the next phase of their business.
The immediate return may be DPDP readiness. The longer-term return is the ability to understand what data the organisation holds, where it moves, why it is used, who can access it and whether it can confidently be used for the next product, partnership or AI application.
The companies that get this foundation right now will not simply be more prepared for May 2027. They will be better prepared for what comes after it.
AI makes privacy and data governance more important, not less
AI changes the privacy conversation in a fundamental way. Consider a dataset collected several years ago for a particular business purpose.Today, an organisation may want to use that information for personalisation, analytics, fraud detection, a customer-service copilot, an internal large language model or another AI application.
That creates a new set of questions. Where did the data originate? What was the original purpose? Does the new use align with it? Does the dataset contain personal information? Is all of that information required? Can its lineage be established? Which models interact with it? Which vendors have access to it? What happens to the information after it reaches an AI system?
These are privacy questions. They are also security questions, data-governance questions, risk questions and AI-governance questions. The separation between those disciplines is becoming harder to maintain. A new AI deployment can introduce a privacy risk. A third-party AI provider can introduce both security and processor risk. Poor data lineage can become a compliance problem. An opaque customer journey can simultaneously create consent, consumer-protection and reputational risks.
This is why AI governance and DPDP compliance are increasingly converging. It also creates an important business advantage for organisations that have already done the difficult privacy work. An enterprise that knows what data it holds, understands its lineage, has mapped purposes and permissions, governs third parties and has established accountability is starting its AI journey from a very different position than one trying to reconstruct all of that after the AI use case has gone live.
Good privacy governance creates the conditions for better AI governance.
In that sense, privacy should not be seen as something that slows AI adoption. Done well, it can help an enterprise adopt AI with greater confidence.
The regulatory environment is already pointing in the same direction
DPDP is also not the only reason enterprises should be acting now\.Across sectors, other regulatory developments are reinforcing the same underlying principle: organisations need stronger control and accountability over how data is collected, governed and used.
In July 2026, the Reserve Bank of India issued draft Guidance on Regulatory Expectations for Data Governance. The draft signals a broader regulatory focus on governance structures, data architecture, quality, metadata, lineage and accountability across regulated entities.
Also read: Modernising Actuarial Data for Faster, More Reliable Insights
For banks and NBFCs already preparing for DPDP, the overlap is significant. Privy has examined this convergence in its analysis of RBI’s data governance framework and DPDP. The e-commerce sector is seeing the same direction of travel. The Consumer Protection (E-Commerce) (Amendment) Rules, 2026 come into force on January 1, 2027. Among other requirements, they strengthen expectations around dark patterns, transparency and the use of consumer information, including express and affirmative consent for specified purposes.
Financial services, NBFCs, e-commerce and the broader digital economy are not governed by one identical framework. But the direction is increasingly consistent. Know the data. Know why it is being used. Give individuals meaningful choice where required. Understand who else has access to it.
Establish accountability. Maintain evidence. Be able to demonstrate that the controls actually work. This is why the conversation cannot be limited to,
2027?”
The more useful question is:
“What governance capability will the enterprise need for the next five or ten years?” “What needs to be done before May
Consent is important. It is not the whole privacy problem.One of the risks visible in the market is the tendency to reduce DPDP readiness to consent management. Consent is important. It is also highly visible, which makes it a natural starting point. But enterprise privacy becomes far more complicated once the journey after consent is examined.
Consent is connected to a purpose. That purpose is connected to personal data. That personal data resides across systems. Those systems interact with employees, applications, vendors and increasingly AI models. A Data Principal request depends on finding that information.
A privacy impact assessment depends on understanding how that information is being processed. An incident requires the enterprise to know what personal data may have been affected. Third-party risk depends on knowing which processors have access to what information and why.
AI governance depends on understanding what information is entering a model, the purpose for which it is being used and the risks that use creates. These are not independent problems. They are different views of the same data lifecycle. This is precisely why Privy has been built as a full-stack DPDP compliance and privacy governance platform, rather than as a point solution for consent.
Privy connects three layers that increasingly need to work together: Consent Lifecycle Management, Continuous Compliance and Risk Management, and Personal Data Discovery and Governance.
Across these sit capabilities spanning consent governance, Data Principal rights, cookie management, privacy impact assessments, incident management, third-party risk, data discovery, classification and lineage. The objective is not simply to digitise existing compliance activity.It is to connect privacy controls to one another and, more importantly, to the underlying data they are intended to govern.
That is what makes privacy operational at enterprise scale.
Privacy cannot remain the responsibility of the privacy team
Technology can provide visibility, automate workflows and establish controls. But some of the biggest maturity gaps are organisational. Privacy often begins with legal, compliance, cybersecurity or risk teams. It cannot remain there. Consider how many privacy decisions are made outside a privacy function every day.
A product manager decides what information a new feature should collect. An engineer decides how long information remains in a database. Marketing determines how customer information will be used across a campaign. Procurement selects a processor that may handle personal information.
HR manages employee data throughout the employment lifecycle. A data science team decides what data will train a model. A business team signs up for a new AI tool and uploads enterprise information into it. None of those actions may be described internally as a privacy decision.
But increasingly, they are. The enterprises making the strongest progress are therefore moving privacy from specialist ownership towards institutional accountability. The privacy function establishes the framework and guardrails. Technology enables execution. But accountability has to extend into product, engineering, marketing, procurement, operations, HR, security and AI teams.
This is also where capabilities such as privacy impact assessments and privacy-by-design workflows become important.They allow privacy to move closer to where business decisions are actually being made, instead of being added as an approval step after the decision has already been taken.
That is when privacy starts becoming part of how the enterprise operates.
Experience matters when the problem becomes this interconnected
There is another lesson from more than 50 implementations. At enterprise scale, context matters. A privacy programme does not operate in isolation from identity, risk, fraud, cybersecurity, customer experience, data architecture or enterprise technology. That is particularly relevant to how Privy has evolved.
Privy is built on more than 14 years of IDfy’s experience in RegTech and trust
infrastructure, working on problems across identity, risk and fraud for large enterprises. The Privy platform brings that enterprise context into privacy governance. That experience becomes increasingly important because many of the problems now being classified as privacy problems begin somewhere else.
They can begin with a customer journey. A vendor. A data warehouse. A product feature. An identity flow. An AI deployment. Or a security incident. The enterprise therefore needs an operating layer capable of connecting those contexts rather than creating another silo.
This is also why recognition of privacy technology should ultimately be measured by whether it can work in real enterprise environments.Privy was ranked #1 in MeitY’s Code for Consent: DPDP Innovation Challenge, an initiative focused on building systems aligned to India’s DPDP requirements. More on Privy’s MeitY DPDP Innovation Challenge recognition.
But the bigger validation comes from implementation. Every enterprise environment is different. Every implementation offers new insight into where privacy can break down when policy meets infrastructure, processes, people and scale. That accumulated experience becomes increasingly important as enterprises move from asking what DPDP says to asking how to make it work.
The opportunity is bigger than compliance
There is a temptation to frame all of this as the cost of a new regulation. That would miss the larger opportunity. Data is already one of the most important assets an enterprise holds, and AI is making that asset more valuable. It is also making it more consequential.
The ability to understand, govern and confidently use data will increasingly influence how quickly organisations can innovate. An enterprise that has visibility into its data can make better decisions about what can be used. An enterprise with strong purpose and consent governance can build clearer customer journeys.
An enterprise with mature third-party governance can scale partnerships with greater confidence. An enterprise that can trace the data entering its AI systems can govern those systems more effectively. Privacy therefore has the potential to move from being viewed purely as a compliance cost to becoming part of the infrastructure that enables responsible growth.
Privy’s work with enterprises is already showing signs of that transition. The early conversations were largely about interpretation: “What does DPDP require?”Today, they are increasingly about execution: “How do we discover personal data across a complex technology estate?”
“How do we connect a customer’s consent to what happens downstream?” “How do we manage a rights request across multiple applications?” “How do we govern hundreds or thousands of processors?” “How do we understand which data is entering our AI systems?” “How do we prove that the controls we designed are actually working?”
These are harder questions. They are also much better questions.
India can help define what privacy at population scale looks like
There is a larger story here too. India is operationalising a modern data-protection framework across one of the world’s largest populations and one of its fastest-evolving digital ecosystems. Few markets combine this kind of population scale, digital adoption, enterprise transformation and AI ambition.
That makes what India builds significant beyond India itself. Emerging economies around the world will face many of the same tensions. How do they protect individuals while continuing to innovate? How do they create accountability without paralysing digital businesses?
How do they introduce AI into environments where enormous amounts of personal information already exist? How do they make privacy work at population scale rather than only on paper? India has an opportunity to help build an answer. The organisations working on privacy infrastructure in this market are therefore participating in a transition that extends beyond regulatory compliance.And the 50-plus enterprises already working with Privy are only an early indication of how much transformation still lies ahead.
The world after May 2027
May 2027 will matter. But the more interesting question is what happens after it. The regulatory baseline will have changed. AI adoption will continue to accelerate. Enterprise data estates will become more complex. Third-party ecosystems will expand. Customer expectations around how information is handled will evolve.
Sectoral regulators will continue developing their own expectations around data, digital choice, risk and accountability. In that environment, privacy cannot survive as a periodic compliance exercise. It needs to become infrastructure. Infrastructure that continuously discovers data.
Infrastructure that connects consent to purpose. Infrastructure that makes rights executable. Infrastructure that monitors risk. Infrastructure that understands third parties. Infrastructure that allows AI adoption to happen with visibility rather than uncertainty.
Infrastructure that creates evidence as the enterprise operates.
This is the enterprise reality Privy has been built to address.
The organisations choosing to begin that work today are not simply solving for a deadline. They are creating a stronger foundation for how they will use data tomorrow. The early privacy question was:What does DPDP require enterprises to do? The better question now is:
How can an organisation use data confidently, responsibly and at scale for whatever comes next?
More than 50 enterprise implementations offer an early indication of where India’s privacy journey is headed. And they suggest that May 2027 should be seen not as the end of the privacy journey, but as the beginning of a very different enterprise reality.

The article has been written by Malcolm Gomes, Chief Operating Officer at IDfy & Head of Privy by IDfy














