Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Oracle Trains 32,000 Experts as AI Agents Redefine HR for Enterprises

When we last spoke to Yvette Cameron, senior vice president of global HCM product strategy, she described a future where AI doesn’t just answer HR queries but quietly runs the workflows that keep organisations moving. A couple of months later, meeting her in person at Oracle AI World 2025, that prediction has materialised, and the shift has been sharper in India than anywhere else.

“The challenges that HR has faced over the years haven’t changed,” she told AIM. “We still need to build good leaders. We need to develop skills in our organisation. We need to find and hire the right talent.”

Click Here to Register for Best Firm Summit

And she said that AI has exacerbated those challenges. It’s made them more difficult because the complexity, the speed and scale and the expectations now around how HR is helping address these challenges have shifted significantly.

Cameron said employees today expect systems that anticipate their needs, not just respond to them. “We expect that experiences won’t just meet our expectations, but they’ll anticipate what it is that we need with AI,” she added.
Leaders, meanwhile, expect decisions to move faster and with better context. “We expect that there will be faster decision making, better decision making, supported by AI,” she added. And skill development, the heart of India’s IT and GCC workforce, is becoming an AI-driven exercise. “We expect that as part of developing skills, those skills will be recommended to us… based on what AI can start to infer from various signals from across the organisation.”

Oracle’s AI Agents are Already at Work

In a major rollout on September 16, Cameron’s team introduced 13 new AI agents natively embedded inside the cloud HCM suite. “These agents are focused on improving the productivity and experience of employees, managers and specialists across the organisation,” she said.

One of the most notable is the new Career Coach, an AI agent that does more than show employees job openings. Using real-time skills intelligence, it can negotiate an entirely new career path with an employee.

“If I want to move from finance to engineering, the agent can identify the gaps, create a learning plan, and dynamically generate a journey that guides me step by step,” Cameron said.

This makes internal mobility far more proactive than traditional HR systems that rely on static career ladders.

Cameron said that the backbone of all these capabilities, AI Agent Studio, has quietly grown into one of the strongest enterprise agent frameworks in the industry. “We introduced the AI Agent Studio back in May, and it’s now delivering agentic capabilities across not just HCM but the entire enterprise,” she said.
In a little less than a year, more than 32,000 experts have been trained to build and test agents.

Partners, including Accenture, Deloitte, PwC, Cognizant, TCS, Wipro and others, have invested in Oracle to develop 100 industry-specific AI use cases across sectors, including manufacturing, utilities, financial services, and healthcare.

“This is truly differentiated,” Cameron said. “Most vendors make you go to a third party to get agent solutions. We make innovation seamless.” Further, to ensure safety, Oracle applies a 21-point quality check, covering security, guardrails and output integrity, before any partner agent reaches a customer.

“We subject our partners to the same quality standard we apply to ourselves,” she added.

AI Agents are Helping Companies Retain Best Talent

One of the most eyebrow-raising examples Cameron shared was the new resignation agent.

“When an employee starts their resignation process, an agent automatically kicks off creating a new requisition,” she revealed. Because the system understands skills, managers and role context, it can: create a draft requisition and simultaneously scan the organisation for internal successors.

This turns attrition into a trigger for career advancement, not churn. “When people leave, it’s an opportunity to progress someone else’s career and surface untapped talent,” Cameron said.

Cameron also shared how AI agents are transforming one of HR’s most complex areas, performance and goals. The agents now ingest updates from Slack, WhatsApp, and email, and later summarise them, analyse sentiment and recommend managerial action

“We guide managers with conversations they should have with their employees,” Cameron said. “In essence, we’re tracking performance in context, not just at review time.”

Adoption Has Hit a Hockey Stick Moment

BCG’s latest report on “AI at Work” gives a reality check and states that only 13% of employees see them deeply integrated into their daily workflows, and only one-third of employees understand how these tools function. That number seems to be changing rapidly.

Despite early caution from enterprises, adoption has surged. Oracle revealed that 60% of customers now use some form of AI in Fusion HCM, a 45% YoY increase.

India: The Next Frontier for Skills Intelligence


When Cameron last spoke to AIM, she underscored the importance of skills visibility in India, one of the world’s largest talent economies. That priority, she said, has only become more urgent.
Today, Oracle’s agents guide employees through internal job opportunities, upskilling plans, dynamic learning journeys and even full skills transitions. In a market where replacing talent is both costly and slow, Cameron believes AI-driven internal mobility will become a defining differentiator for Indian enterprises.Cameron said HR has now reached a fundamentally new era, where “AI is changing the way we work… we have really reached a turning point.”

HR teams, she argued, are no longer just digitising workflows but are becoming the strategic layer that anticipates needs, guides teams and elevates organisational decision-making. “AI isn’t about replacing humans or potential. It’s about augmenting and accelerating them,” she concluded.

The post Oracle Trains 32,000 Experts as AI Agents Redefine HR for Enterprises appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.