Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

AIM Print November 2025

The November 2025 edition of AIM Print delivers a sharp overview of how leading organisations are reshaping their data and AI strategies. The issue opens with MapmyIndia, which outlines its shift from navigation tools to a full-stack digital mapping and automotive tech platform built on precision maps, digital twins and connected mobility systems.

Tiger Analytics shares how it is preparing for the next decade of enterprise AI demand with stronger delivery engines, industry-aligned solutions and operational frameworks that help clients scale responsibly. Virtusa highlights its AI-first services push, integrating cloud, engineering and consulting capabilities into unified transformation programs.

AllState India focuses on modernising core insurance workflows, strengthening risk models and upgrading analytics infrastructure through large-scale upskilling. Hexanika discusses the new phase of regulatory technology and how automation and AI-driven controls are reshaping compliance for banks. Defy outlines its strategy around enterprise AI products, IP acceleration and international market expansion.

Accenture offers a view into how companies are moving from AI experimentation to measurable outcomes with strong governance and engineering depth. Evalueserve presents its evolution toward AI-enabled research and insights delivery, expanding knowledge services across verticals. Aster highlights digital upgrades in healthcare through predictive analytics, smarter clinical workflows and operational optimisation.

Fractal Analytics details its balance of platforms and consulting-led execution across global clients. NextWealth showcases its distributed delivery model in Tier 2 and Tier 3 India for AI operations and data workflows. Areteans focuses on intelligent decisioning and customer engagement automation. Celebal Technologies concludes the issue with its work in cloud-native engineering, data modernisation and enterprise AI adoption.

Together, this edition offers a clear snapshot of how Indian and global enterprises are strengthening AI foundations and competing in a fast-shifting technology landscape.

The post AIM Print November 2025 appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why the Shift to Software-Driven Mobility Remains a Challenge

According to Capgemini’s report, ‘The Software-Driven Mobility Era,’ the promise of faster innovation and smarter vehicles is yet to fully materialise for traditional automakers. Despite widespread ambitions, the shift to software-driven mobility (SDM) remains a challenging journey.

The report highlights that only 14% of organisations have successfully scaled an SDM use case, while fewer than half have moved beyond pilot initiatives. Many legacy OEMs remain tied to vehicle architectures where software is tightly coupled with hardware, slowing innovation and limiting connectivity.

Yet, the automotive sector is now moving beyond software-defined vehicles (SDVs) toward a broader vision of SDM. This transition goes beyond embedding software in vehicles—it aims to redefine the entire mobility ecosystem through software.

Automakers worldwide are responding by building in-house software capabilities, restructuring operations to prioritise software, and forming strategic partnerships with tech companies, hyperscalers, and startups.

For example, Ford created Model e, a dedicated business unit offering services such as interior digital experiences and OTA updates for internal combustion engine (ICE) vehicles. In 2021, Renault Group launched Mobilise, a next-generation brand focused on shared, electric, and connected mobility solutions. Meanwhile, Mercedes-Benz partnered with Microsoft to enhance its in-car experience, integrating AI-powered features like the ChatGPT-based “Hey Mercedes,” Microsoft Teams, and Intune into its MB.OS, with plans to bring Microsoft 365 Copilot to vehicles soon.

Speaking to AIM, Anuraag Bharadwaj, VP & head automotive industry platform at Capgemini, emphasised that the gap isn’t due to lack of ambition, but the structural transformation that SDM demands.

“The automotive industry has traditionally been mechanical at its core. Today, it’s transforming into a connected, intelligent ecosystem. But that shift isn’t just about technology—it’s about changing how companies think, build, and deliver,” he explained.

Why Most Automakers Are Struggling to Scale

Despite the clear vision, most automotive players are stuck in the pilot stage of their software journeys. Bharadwaj mentioned that the barriers fall into three core areas — architecture, talent, and mindset.

In terms of architecture, many companies still have legacy platforms where hardware and software are tightly coupled. Decoupling them is complex, it’s like rebuilding the aircraft while flying it.

Furthermore, there’s a massive need for software engineers, data scientists, and DevSecOps talent who understand real-time, safety-critical systems. In fact, the future workforce needs a hybrid DNA of part engineer, part coder, part systems thinker.

New roles are emerging such as AI safety engineers, embedded DevSecOps leads, OTA product managers, and edge AI architects.

In the end, “OEMs are used to multi-year production cycles. Software, on the other hand, thrives on agility, sprints, and iteration. That cultural shift is tough,” Bharadwaj added.

Adding further context, Ganesh Sahai, CTO of Nagarro, told AIM that scaling software-driven mobility is more complex than technology alone.

“The real world we experience daily is filled with complexities that the human brain captures and processes in ways AI models are only beginning to replicate,” Sahai said.

While current AI has made impressive strides, the gap between what works conceptually and what scales in real life remains significant, underestimating regulatory constraints, infrastructure dependencies, edge cases, and operational economics that emerge only at scale.

In software-driven mobility specifically, autonomy levels have steadily increased, and some use cases have succeeded by solving narrow, well-defined problems, while the grand visions of fully autonomous fleets and seamless integrated platforms are progressively moving from aspiration to reality.

“We’ve proven the technology works in controlled scenarios; the exciting challenge ahead is achieving sustainable scale across the messy, unpredictable conditions of diverse real-world environments,” Sahai added.

India’s GCC Advantage

Global capability centres (GCCs) in India are believed to be the critical lever to close the execution gap in software-driven mobility.

With a huge corpus of talent, scale, and cost efficiency, India itself is a global hub for software-led automotive innovation. Bharadwaj noted that, “India has the engineering depth, AI/ML capabilities, and now a growing base of software architecture experts. It’s where global OEMs can build, test, and deploy at scale.”

Moreover, organisations are also restructuring their supply chains for geopolitical resilience, with 84% exploring new sourcing markets including India, Vietnam, and Eastern Europe, as per the above report.

Beyond traditional R&D, GCCs are taking end-to-end ownership of connected mobility platforms, embedded systems, and over-the-air update architectures. According to him, “India is no longer just a participant. It’s becoming a cornerstone in global Software-Defined Mobility development.”

As automakers diversify post-COVID, India offers resilience through its strengths in EV components, semiconductor design, and advanced mobility software platforms.

“What’s exciting is that we’re not limited to execution; we’re driving end-to-end product lifecycle innovation from concept to deployment,” Bharadwaj said.

Government initiatives like PLI for auto & semiconductors and Startup India are accelerating this shift, while the thriving tech ecosystem and deep talent pool position India as a strategic innovation hub shaping the future of connected and software-driven mobility.

He further emphasised that Indian engineering hubs have moved far beyond being mere coding centres. They have evolved into full-fledged innovation centres. Today, they own the architecture, design, and R&D for mobility software platforms.

Bharadwaj mentioned that “We are leading advancements in zonal architectures, over-the-air updates, and complete SDM stacks. Global OEMs trust Indian teams for concept-to-deployment ownership, which speaks volumes about the depth of capability here. India is not just coding; it’s architecting the future of software-defined vehicles.”

Moreover, the transformation extends beyond the metros, as tier-2 cities become powerhouses for SDV and SDM development.

Locations such as Pune, Coimbatore, Kochi, Ahmedabad, and Indore are building strong capabilities in advanced mobility software, semiconductor design, and EV technologies. These hubs offer cost efficiency, strong talent retention and robust government support. This distributed model is creating a resilient innovation network across India, making us an even stronger partner for global OEMs.

The post Why the Shift to Software-Driven Mobility Remains a Challenge appeared first on Analytics India Magazine.

9 Controversies That Shook Indian IT in 2025

India’s IT services industry entered 2025 expecting a slow demand recovery, but it instead found itself pulled into a series of controversies, some structural, some cultural, some self-inflicted.

From layoffs and bench-policy conflicts to tax rulings and workplace safety lapses, the sector saw unprecedented public and regulatory attention.

For an industry long known for tight control over narrative, 2025 underscored a shift: employee groups became more vocal, unions gained visibility, and courts increasingly shaped operational norms.

Below is a roundup of the 10 defining controversies that dominated the year.

TCS’s 12,000-Job Reduction and the “Forced Exit” Debate

TCS’s announcement of a roughly 2% workforce reduction, amounting to around 12,000 roles, triggered the year’s most discussed controversy. The move contradicted earlier optimistic hiring projections and immediately fueled allegations by employee unions that the cuts were being executed through “forced resignations.”

Though TCS maintained the exits were part of a strategic workforce recalibration, the opacity around criteria, timelines, and conversations with affected employees drew sustained criticism. The episode marked the most severe public backlash TCS had faced since the 2023 recruitment-bribery controversy.

The TCS “35-Day Bench” Rule Sparks Coercion Complaints

In a second major flashpoint, TCS introduced a rule limiting the bench period to 35 days. Employees alleged that this effectively pressured them to resign if they couldn’t secure a project quickly. Online forums exploded with testimonies describing abrupt calls, rushed appraisals, and unclear redeployment pathways.

NITES, the employee union, escalated the matter to state labour authorities. TCS defended the rule as a utilisation initiative, but the controversy cemented a narrative of tightening internal controls amid weakened demand.

“Silent Layoffs” and the 50,000-Jobs-On-the-Line Narrative

Across the top IT firms, hiring stagnated and net headcount declined, feeding a broader storyline of “silent layoffs.” Analysts estimated that as many as 50,000 roles across the sector were at risk due to a combination of low deal conversion, bench reduction, automation, and project rationalisation.

Even companies that avoided formal layoffs faced accusations of performance-linked exits, project cancellations without redeployment, and shrinking fresher intake. This sector-wide sentiment set the backdrop against which all other controversies unfolded.

The R&D Deficit: Reliance on Headcount-Led Revenue Under Spotlight

A long-standing structural criticism intensified in 2025: Indian IT’s extremely low R&D spending, typically 0.5% or less of revenue, far below global tech benchmarks, combined with a business model still heavily dependent on linear headcount growth. The GenAI wave magnified scrutiny. Despite large AI announcements, most spending went into partnerships, implementation training, and Proof of Concepts rather than proprietary research or platform development.

Investors criticised the absence of nonlinear growth engines, engineers raised concerns about shallow innovation roles, and policymakers flagged the sector’s limited contribution to India’s long-term tech IP base. As automation and AI began decoupling revenue from headcount, the weaknesses of the legacy model became more visible than ever.

Wipro’s Legal Setback Over a “Defamatory” Relieving Letter

A Delhi High Court order became a governance flashpoint: Wipro was directed to issue a clean correcting letter and pay damages to a former employee because the original relieving document allegedly implied misconduct.

The ruling moved beyond individual relief; it created a precedent around how exit documentation must be worded. For an industry heavily dependent on BGV processes and strict reference checks, the case prompted internal audits across companies and revived older concerns about opaque exit practices.

Infosys Closes a Long-Running GST/RCM Investigation

Infosys finally saw formal closure of the multi-year DGGI investigation regarding IGST liabilities on services rendered by its overseas branches. Though the closure itself was positive, the episode reignited debate over the compliance complexity facing Indian IT firms with global delivery centres.

For much of the year, the industry tracked the case closely because an adverse ruling could have triggered large backdated tax liabilities for multiple firms. The resolution stabilised sentiment, but highlighted lingering tax ambiguities in export-linked service structures.

Tech Mahindra–Satyam Legacy Tax Case Returns to Spotlight

A Telangana High Court ruling directing a fresh assessment in the long-running Satyam Computer-related tax matter brought an old controversy back into the spotlight. Though this was a legacy issue inherited through Tech Mahindra’s acquisition of Satyam over a decade ago, the renewed scrutiny sparked discussions about integration-risk management and the long tail of corporate fraud cases. It reminded the sector that past scandals can re-emerge unexpectedly, especially when tax or compliance reassessments are involved.

Infosys Campus Voyeurism Case Raises Workplace Safety Concerns

In a serious workplace-safety controversy, an Infosys employee in Bengaluru was arrested for allegedly filming a colleague inside a women’s washroom. Charged under the IT Act and provisions for voyeurism, the case prompted strong internal and public reactions. For a company celebrated for its campus culture, the incident initiated questions around surveillance blind spots, incident escalation processes, and the adequacy of preventive infrastructure.

It also pushed other IT firms to review physical-security protocols on large campuses.

Kochi Infopark Firm Faces Sexual-Harassment and Extortion Allegations

In Kerala’s Infopark, a sexual-harassment FIR against a CEO, accompanied by a counter-claim of extortion, triggered a tense and widely reported dispute. The case placed a sharp spotlight on how POSH (Prevention of Sexual Harassment) processes were being executed, audited, and communicated in mid-sized IT companies. Unlike larger IT majors, midsize and emerging players often lack well-formalised committees or documentation practices, and this incident fuelled concerns about uneven compliance maturity across the sector.

L&T Chairman’s “90-Hour Work Week” Comment Backfires on LTIMindtree

A resurfaced video of L&T’s chairman S N Subrahmanyan advocating that India’s youth should work 70–90 hours a week ignited a nationwide backlash. Though the remark was not specifically about LTIMindtree, the IT subsidiary was pulled into the debate by association. Employees and unions questioned whether such cultural expectations were influencing project pressures and delivery timelines.

HR clarifications followed, but the controversy quickly evolved into a broader discussion about burnout, unrealistic client commitments, and the sustainability of India’s IT talent model.

The post 9 Controversies That Shook Indian IT in 2025 appeared first on Analytics India Magazine.