Vikash Chourasia, Scientist at the Ministry of Electronics and Information Technology (MeitY), Government of India, offered an inside view of the journey behind India’s Digital Personal Data Protection (DPDP) framework at the Ampus Cyber GRC India AI Conclave 2026, explaining how the law evolved, the intent behind some of its key provisions and his own role in the drafting process. Addressing the gathering, Chourasia said the DPDP framework represents a significant shift in the way India approaches personal data, both from the perspective of citizens and businesses. He noted that organisations are increasingly looking at compliance not merely as a legal obligation, but as an opportunity to establish themselves as responsible businesses.
Also read: Top 7 Indian Tools for Seamless DPDP Compliance in 2026
“DPDP adds two values. One is for the citizen. I can claim that my country offers a very global data protection regime. For businesses, this brings a great opportunity of first-mover advantage in the data protection regime,” Chourasia said. He pointed out that the conversation around data protection is also changing within businesses. Compliance, he said, is gradually moving beyond being viewed simply as a legal requirement, with organisations beginning to recognise the importance of demonstrating responsible data practices. At the same time, the legislation introduces substantial penalties to ensure that data protection receives the seriousness it requires. Chourasia said the penalty provisions were designed as a deterrent, particularly in an environment where data has become a core business asset.
“As we are speaking of AI coming in, cloud coming in, and a lot of agents taking data, it becomes really very important to have this kind of law in practice. It is important for everyone to understand the journey of data in the ecosystem, where your data is transiting, and that is where the security and data protection roles start coming together,” he said. According to Chourasia, the DPDP law was deliberately written in a relatively accessible language, unlike traditional legislation that often relies heavily on formal legal terminology. While this makes the law easier to read, he said it also creates considerable room for interpretation.
“You will find that the language is entirely English. You can read it like a novel, like a book. It is not the legal language which we have traditionally used. That creates a lot of scope for interpretation. But if you understand the intent behind the provisions, you will find that the law does justice to the subject,” he said. He added that the underlying principles remain consistent with data protection regimes globally, including concepts such as lawful processing, transparency, consent, notices and user rights. “If you read three laws, you will find the same intellect everywhere, the requirement of lawfulness of processing, transparency in processing, user rights, consent and notices. What is very important here is the intent behind writing something like that. If you capture the intent and honestly think about what needs to be done, you will find that the law does a lot of justice to the subject,” Chourasia said.
Why ‘data fiduciary’ and ‘data principal’ matter
Chourasia also explained some of the terminology used in India’s framework, particularly the choice of terms such as ‘data fiduciary’ instead of ‘data controller’. He said the terminology was intended to reflect the relationship of trust between an organisation handling personal data and the individual whose data is being processed. “I am a strong believer that a name should have a meaning because it reflects the intent. Take ‘data fiduciary’ versus ‘data controller’. A controller, if somebody says that to me, it kind of alarms me that somebody is controlling. Whereas, when you say fiduciary, the relationship of trust is upfront,” he said.
Similarly, he said the term ‘data principal’ was intended to reinforce the individual’s control over personal data. “Data subject, to me, sounds more like clinical trials. Data principal says, ‘I have control over it. I have command over it.’ These are the kinds of intent that we have tried to bring into the framework,” Chourasia said. He also highlighted the introduction of the right to nominate as one of the distinctive elements of the Indian framework, particularly in circumstances involving death or incapacitation.
From policy to implementation of DPDPA
Chourasia stressed that the next phase of data protection will depend heavily on implementation, particularly at the technology and developer level. He said the government is looking at ways to take privacy-by-design principles beyond policy discussions and into actual development environments. He referred to initiatives involving technologies such as differential privacy, federated learning and synthetic data, aimed at helping the developer community understand how privacy-preserving technologies can be adopted in real-world systems.
“We wanted to take DPDP to the developer community because that is where it really happens. A lot of discussion has happened around the concept of privacy by design, but we wanted to enable it in some manner. We are working towards making these technologies available to the developer community and creating awareness about how they can be adopted,” he said. Chourasia said the business community would also need to experiment with how privacy requirements are incorporated into products, user interfaces and notices. According to him, compliance should not be treated as a one-time exercise, but as a continuing process involving technology, risk management and product design.
What does the Rs 250-crore penalty mean for the banking sector?
A key question from the audience centred on the much-discussed penalty provisions under the DPDP framework and whether there were specific implications for the banking industry. Chourasia clarified that the law is not sector-specific and applies horizontally across industries. “First of all, this is industry- and technology-agnostic. It is not a vertical law; it is a horizontal law. So, there is nothing specific to banking. And the Rs 250 crore is an upper limit. It does not mean that Rs 250 crore is automatically the penalty,” he said.
He explained that the government deliberately chose a significant upper limit because smaller penalties could potentially be treated as just another cost of doing business by large organisations whose business models depend heavily on data. “When you say Rs 10,000 or Rs 1 lakh as a penalty, there are companies of that stature which may want to exploit data because data is their core engine. They may simply be willing to pay ten times that penalty and say, ‘Okay, let me do the business.’ We wanted to create a level of seriousness around data protection,” Chourasia said.
He added that the final penalty would be determined by the Data Protection Board and would not be imposed arbitrarily. “There are proper legal safeguards. One can appeal against it, there is an appeal mechanism and one can also go to the courts. So, the principles of natural justice will be met. There is nothing to be scared of in terms of penalties, but yes, penalties do exist because they create attention and seriousness,” he said.
How will ‘significant data fiduciaries’ be identified?
Another question focused on the absence of clearly defined criteria for identifying significant data fiduciaries and whether organisations should expect additional compliance requirements. Chourasia said the framework would follow a risk-based approach, with the government determining the criteria for identifying significant data fiduciaries. “The significant data fiduciary will be notified by the government. There may be several criteria. It could be the number of users, the nature or volume of data being handled, or other factors. The end idea is to understand the risk perception about a company or a class of fiduciaries,” he said.
He stressed that compliance would evolve gradually rather than requiring every organisation to immediately meet the highest level of obligations. “Compliance is a journey which takes time. We wanted the data fiduciary role to be played well first. Then, gradually, we can identify those who need additional requirements, such as a Data Protection Impact Assessment or a Data Protection Officer in India,” Chourasia said.
Drawing a parallel with the evolution of the GDPR framework, he said India was similarly at the beginning of a longer journey. “You cannot be at the height of a flyover without going on that ramp. We are on that ramp. We will gradually come there. It will take many, many steps, but we should not avoid that journey,” he said. Chourasia also indicated that the government was conscious of the need to avoid making compliance so restrictive that it disrupts legitimate business and digital activity. “We do not want this to become an interrupted law in the country. If we suddenly make data protection extremely stringent at the highest level, it will become difficult even to conduct something as simple as this conference because a lot of personal data gets processed when people come here. We want to slowly and gradually upscale the whole operation around data,” he said.
Will India adopt an adequacy-based approach for cross-border data transfers?
Cross-border data flows were another area of discussion, with an audience member asking whether India would follow an adequacy-list model similar to the European Union. Chourasia said the DPDP framework does not, by default, stop the cross-border movement of personal data. Instead, India has adopted a different approach. “Adequacy is needed if you block personal data from being transferred. Our law does not stop personal data from being transferred. We use a negative-list approach,” he said.
He explained that the thinking around cross-border data transfers had evolved considerably during the development of the legislation. “Initially, we thought there would be categories such as personal data, sensitive personal data and critical personal data, with different treatment for cross-border transfers. But by the time we reached 2023, the thought process had evolved. We said that personal data can flow anywhere, but the protection of that data should remain the core intent,” Chourasia said.
Under the framework, the government can notify countries or territories to which personal data should not be transferred. “What we have done is provide for a legal provision under which the government, if required, can notify a country or territory where personal data cannot be transferred. That becomes the negative list. By default, we have stood for the free flow of data,” he said. At the same time, Chourasia said India was exploring adequacy arrangements with European counterparts because of the potential commercial benefits for the country’s IT and digital services sector. “We are exploring adequacy with our counterparts in Europe because their legal mandate requires it. If we get adequacy, there can be a lot of business advantage for India as a country which serves the world in terms of IT. But there is no requirement for adequacy under DPDP itself,” he said.















