2 Sources
[1]
MSMEs are embracing AI without understanding the privacy risks: PrivaSapien CEO
With key provisions of India's Digital Personal Data Protection Rules set to take effect in May 2027, PrivaSapien CEO Abilash Soundararajan says MSMEs need to move beyond compliance checklists and build basic privacy and AI safeguards now. India's data privacy regime is moving from policy to implementation, with the Digital Personal Data Protection Rules 2025, notified in November, and key compliance provisions coming into effect in phases. For businesses, especially smaller firms that rely heavily on cloud platforms, SaaS tools, and AI applications, the challenge is not just understanding the law but building practical safeguards without creating a disproportionate compliance burden. PrivaSapien, a privacy engineering deep-tech start-up, is working to address this emerging need. The company helps businesses identify privacy risks, mitigate them, and use data for business and AI applications while protecting user privacy. In an interaction with The Economic Times Digital, Abilash Soundararajan, Founder & CEO, PrivaSapien, discusses what businesses need to do to prepare for the DPDP regime, why technical safeguards will be critical, how AI is changing the privacy risk landscape, and more. Edited excerpts: ET: As organisations prepare for data protection rules, what are the most critical steps they should take to ensure compliance? Abilash Soundararajan (AS): The first thing I tell every CXO is to stop treating this as a policy-writing exercise. A consent banner on your website is not compliance. The highest penalty of Rs 250 crore is for a data breach resulting from not having technical safeguards. Real readiness starts with understanding your obligations across the entire data lifecycle -- notice and consent, discovery of personal data, Data Protection Impact Assessments (DPIAs), security safeguards, and exemptions for research, archiving, and statistical use. Each is a distinct obligation, and each has to work consistently across every application, vendor, and team that touches personal data. That's harder than it sounds. A mid-sized firm can easily have a hundred applications, and each one carries roughly a dozen obligations. If you do the math, you will find that there are hundreds, if not thousands, of individual compliance workflows, not just one checklist. The second step is mapping that complexity to actual penalty exposure. Security safeguards carry the steepest penalty -- up to Rs 250 crore. Risk assessment and DPIAs follow at up to Rs 150 crore. Consent and data-principal rights sit at Rs 50 crore. That hierarchy should directly decide where your budget and engineering effort go first. Most organisations get this backwards and spend all their energy on consent banners while leaving technical safeguards untouched. ET: For MSMEs, the cost of DPDP compliance could be a much bigger burden than it is for large enterprises. What are the key challenges smaller businesses are likely to face, and how can they become DPDP-ready without building expensive legal, cybersecurity, or privacy teams? AS: For MSMEs, DPDP compliance feels like a heavy cost, but the smarter view is that privacy is a profit centre -- a discipline that lets you use data well while winning customer trust. The biggest challenge is mindset, not money. Becoming DPDP-ready doesn't require expensive legal, cybersecurity, or privacy teams; it starts with knowing what personal data you hold, why, and where it sits, backed by basic consent, retention discipline, and a grievance channel. Framed this way, compliance becomes about trust and brand building -- the very foundation for going global, earning richer data, deploying AI responsibly, and moving up the value chain. ET: As MSMEs increasingly adopt AI tools for marketing, customer service, hiring, payments, and operations, are many of them taking on data privacy and AI risks without fully understanding their exposure? What minimum safeguards should a small business put in place before deploying AI? AS: Many MSMEs are indeed taking on AI and privacy risks without grasping their exposure, precisely because the tools are so easy to adopt. This matters because MSMEs increasingly serve larger businesses, global customers, and rights-aware consumers. When data under an NDA is leaked in an AI chat, personal or sensitive information is shared with external models, or financial data is sent across borders, the question is no longer cost but non-compliance and loss of trust. Minimum safeguards are inexpensive but decisive: clear rules on what may enter AI tools, vetted deployments for sensitive data, basic access controls, awareness of data residency, and simple staff training. ET: Could stricter data protection and AI governance requirements inadvertently widen the digital divide between large companies and MSMEs? What should the government and technology ecosystem do to make responsible AI and privacy compliance affordable and accessible for smaller businesses? AS: Stricter requirements could burden smaller players (MSMEs), but the deeper truth cuts the other way. Privacy actually gives protection, shielding the digitally illiterate from being abused in a data- and AI-hungry world. To keep it affordable, the government can offer tiered obligations, free toolkits, and model templates, while the technology ecosystem builds privacy and safety by default, so responsible AI isn't a premium only large firms can buy. For the business owner, the principle stays simple: taking care of your customers and winning their confidence is the right way to build a business. ET: What are the biggest strengths and gaps in India's AI and data privacy ecosystem, and how do you see India's responsible AI and compliance ecosystem evolving over the next five years? AS: Recent times have shown a live preview of this. Publicly shared conversations from a major AI chatbot recently turned up indexed in search results, some containing medical records, employee data and company documents that were never meant to be public. Nobody hacked anything, a feature simply worked exactly as designed, and that was enough to expose sensitive data. That's precisely the kind of episode that will define the next five years. The arc, if I had to sketch it, is fairly predictable. DPDP enforcement will begin in earnest. RBI's Guidance on Regulatory Principles for Model Risk Management, 2026, will start shaping how BFSI deploys AI models. Large enterprises will move first because they have the most to lose, and some breaches and enforcement actions will inevitably happen. Those penalties, far more than any awareness campaign, will become the real catalyst for accelerated privacy and responsible AI adoption. The gap I would flag today is depth of implementation. Plenty of organisations have policies on paper. Far fewer have engineering-level controls that actually enforce those policies. Discovery without mitigation still leaves you exposed; it just tells you exactly where the exposure is. Closing that gap is where the next five years of real work will happen. ET: How would policy reforms improve the ease of doing business while ensuring responsible AI adoption and strengthening AI research and innovation? AS: The reforms around technical safeguards for safe data and AI usage are key for a safe future for humanity. That means enabling environments for privacy-enhancing technologies (PETs), privacy-preserving machine learning (ML), and supporting pseudonymous inference approaches so that organisations aren't forced to choose between data utility and compliance. An AI model, once trained, can't unlearn something the way a data principal can withdraw consent, so this must be solved at the infrastructure layer, not after the fact. The other area I will flag is agentic trust and identity. As AI agents start acting on behalf of individuals and organisations, we need clarity on how those agents are authenticated, authorised, and held accountable. Very few countries have solved this yet, and India has a real opportunity to lead here rather than follow. ET: What led to the establishment of PrivaSapien, and how is the company helping organisations navigate AI compliance? AS: Around 2018, Deepika, my better half and our COO, and I were having a conversation about the bleeding gums of a family member -- nothing typed, nothing searched, just spoken out loud near our phones. Within a short while, we started seeing ads for dental products and gum-care remedies across unrelated platforms. That was the moment it stopped being an abstract privacy concern and became personal. If something as fleeting and private as a conversation about your health can be picked up and monetised without you agreeing to it, something is fundamentally broken in how data flows through the systems we use every day. That's not innovation; that's a breach of trust. It made it clear to me that privacy couldn't be bolted on as an afterthought. It had to be engineered into how organisations handle data and AI from the ground up. We started as Truthshare initially in stealth mode, and from 2022, PrivaSapien was officially born. That's the problem PrivaSapien was built to solve, and it's why our core value to customers is an end-to-end, full-stack approach rather than a point solution. ChatGPT was launched towards the end of 2022, changing the tech world. The DPDP Act was passed in Parliament in August 2023, and the rules came in November 2025, with penalties starting in May 2027. RBI has also come up with draft Data and AI Governance guidelines. Now organisations are beginning to explore solutions. Today, it's significantly an awareness problem. Organisations need protection across the data and AI ecosystem. Our PERAI (Privacy enhancing and responsible AI) is the world's first full-stack data and AI protection platform. We have been awarded privacy contracts across sectors, including the central government, large public sector banks, e-commerce, automobile manufacturing, healthcare, media and the global AI services industry. We are positioned to contribute to setting global standards for data privacy and responsible AI from India for the world.
[2]
BharatLaw AI (Lexguide Technologies) Launches DPDPGuard.ai as India Moves Towards Full DPDP Compliance
India-built platform brings consent management online and offline data-principal rights, breach response and retention governance into a single compliance workflow As Indian businesses prepare for the phased implementation of the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025, BharatLaw AI (Lexguide Technologies) has launched DPDPGuard.ai, a compliance platform designed to help organisations operationalise data-protection requirements through automated, India-specific workflows. The stakes are significant. Under the DPDP Act, penalties for specified breaches can extend up to ₹250 crore, including for failure to take reasonable security safeguards to prevent personal data breaches. Other specified breaches can attract penalties of up to ₹200 crore, ₹150 crore and ₹50 crore, depending on the nature of the non-compliance. The urgency has increased with the notification of the DPDP Rules, 2025 in November 2025. The first substantive deadline falls in November 2026, when the framework governing the registration of Consent Managers comes into force. The broader set of operational requirements -- covering notice, security safeguards, breach reporting and data-principal rights -- follows eighteen months after notification. For most organisations, the preparation window is now measured in months rather than years. The challenge extends beyond understanding the legislation. Organisations must translate regulatory requirements into repeatable processes, and do so against specific operational clocks. In the event of a personal data breach, affected Data Principals and the Data Protection Board are to be informed without delay, with detailed information furnished to the Board within 72 hours. Data Principals must also be informed at least 48 hours before personal data is erased under the applicable retention framework. DPDPGuard.ai brings consent management across digital and non-digital channels, privacy-policy generation, data-principal rights handling, cookie discovery and classification, breach lifecycle management and retention governance into one connected workflow. It includes a consent banner supported by a tamper-evident audit trail, in which each consent record is cryptographically hashed and chained so that alteration can be detected on verification; an AI-assisted privacy-policy generator built around the DPDP framework; and a self-service portal through which Data Principals can view and withdraw consents, raise grievances and file rights requests. Statutory deadlines for breach reporting and erasure are tracked and notified against the clock that governs each. A significant part of the platform addresses consent collected away from a website or an app. Consent captured at paper forms, QR codes, field agents, point-of-sale counters and IVR flows is recorded in the same audited register as web and mobile consent, with itemised opt-in against each stated purpose. Each capture produces a verifiable receipt, and the Data Principal can withdraw consent later without holding an account. Where consent is given on behalf of a child, only a cryptographic hash of the guardian's verification evidence is stored, never the identity document itself. For development teams, DPDPGuard.ai publishes software development kits for Android, iOS, Flutter, React Native, JavaScript, Node.js, JVM and Python, alongside a component for Convex applications, so that consent collection and rights handling can be embedded directly into an organisation's own products. Chintan Shah, Founder, BharatLaw AI (Lexguide Technologies), said, "Data privacy is increasingly an operational and governance responsibility for businesses, rather than a standalone legal requirement. The challenge is to translate regulatory obligations into processes that can be consistently implemented and monitored. A large share of consent in India is still collected at a counter, on a form or over a phone call, and a compliance record that covers only the website is an incomplete one." DPDPGuard.ai is designed for organisations that process significant volumes of personal data, with potential use cases spanning BFSI and fintech, e-commerce and retail, telemarketing, healthcare, EdTech and SaaS. Unlike generic global cookie-consent tools that may require adaptation for Indian requirements, it has been built around the Indian framework -- tracking the CERT-In six-hour and DPDP 72-hour reporting clocks separately, supporting Consent Manager registration, publishing notices across the languages named in the Eighth Schedule, and checking DPDP erasure obligations against sectoral minimum-retention requirements.
Share
Copy Link
India's Digital Personal Data Protection Rules take effect in phases from November 2026, with penalties up to ₹250 crore for data breaches. Experts warn that MSMEs are rapidly adopting AI tools for operations without understanding privacy risks or building basic safeguards, leaving them exposed to massive compliance failures.
India's data privacy regime is shifting from policy to enforcement as the Digital Personal Data Protection Rules 2025, notified in November, prepare to take effect in phases starting November 2026
1
. For MSMEs that rely heavily on cloud platforms, SaaS tools, and AI applications, the window to prepare is now measured in months rather than years, yet many are embracing AI tools without grasping the privacy risks they are taking on.Abilash Soundararajan, Founder and CEO of PrivaSapien, a privacy engineering deep-tech start-up, emphasizes that businesses must stop treating DPDP as a policy-writing exercise
1
. The highest penalty of ₹250 crore is reserved for data breaches resulting from failure to implement technical safeguards, not missing consent banners. Real readiness requires understanding obligations across the entire data lifecycle, including notice and consent, data discovery, Data Protection Impact Assessments, security safeguards, and exemptions for research and statistical use. A mid-sized firm can easily have a hundred applications, each carrying roughly a dozen obligations, creating hundreds or thousands of individual compliance workflows.Under the DPDP Act 2023, penalties for specified breaches extend up to ₹250 crore for failing to take reasonable security safeguards to prevent personal data breaches
2
. Other specified breaches can attract penalties of up to ₹200 crore, ₹150 crore, and ₹50 crore depending on the nature of non-compliance. Risk assessment and Data Protection Impact Assessments carry penalties up to ₹150 crore, while consent and data-principal rights violations sit at ₹50 crore. This penalty hierarchy should directly determine where budget and engineering effort go first, yet most organizations get this backwards, spending energy on consent banners while leaving technical safeguards untouched1
.Many MSMEs are taking on AI governance and privacy risks without fully grasping their exposure, precisely because AI tools for marketing, customer service, hiring, payments, and operations are so easy to adopt
1
. When data under an NDA is leaked in an AI chat, personal or sensitive information is shared with external models, or financial data is sent across borders, the question is no longer cost but non-compliance and loss of trust. MSMEs increasingly serve larger businesses, global customers, and rights-aware consumers, making these data leaks particularly damaging. Minimum safeguards are inexpensive but decisive: clear rules on what may enter AI tools, vetted deployments for sensitive data, basic access controls, awareness of data residency, and simple staff training.The urgency has increased with the notification of the DPDP Rules 2025 in November 2025
2
. The first substantive deadline falls in November 2026, when the framework governing registration of Consent Managers comes into force. The broader set of operational requirements covering notice, security safeguards, breach reporting, and data-principal rights follows eighteen months after notification. In the event of a personal data breach, affected data principals and the Data Protection Board must be informed without delay, with detailed information furnished to the Board within 72 hours. Data principals must also be informed at least 48 hours before personal data is erased under the applicable retention framework.BharatLaw AI, operated by Lexguide Technologies, has launched DPDPGuard.ai, a compliance platform designed to help organizations operationalize data protection requirements through automated, India-specific workflows
2
. The platform brings consent management across digital and non-digital channels, privacy policy generation, data-principal rights handling, cookie discovery and classification, breach lifecycle management, and retention governance into one connected workflow. It includes a consent banner supported by a tamper-evident audit trail where each consent record is cryptographically hashed and chained so that alteration can be detected on verification.Related Stories
A significant part of DPDPGuard.ai addresses consent collected away from websites or apps
2
. Consent captured at paper forms, QR codes, field agents, point-of-sale counters, and IVR flows is recorded in the same audited register as web and mobile consent, with itemized opt-in against each stated purpose. Chintan Shah, Founder of BharatLaw AI, noted that a large share of consent in India is still collected at a counter, on a form, or over a phone call, and a compliance record that covers only the website is incomplete. Unlike generic global cookie-consent tools that require adaptation for Indian requirements, DPDPGuard.ai has been built around the Indian framework, tracking the CERT-In six-hour and DPDP 72-hour reporting clocks separately.
Source: CXOToday
For MSMEs, DPDP compliance feels like a heavy cost, but the smarter view is that data privacy is a profit centre, a discipline that lets businesses use data well while winning customer trust
1
. The biggest challenge is mindset, not money. Becoming DPDP-ready starts with knowing what personal data you hold, why, and where it sits, backed by basic consent tracking, retention discipline, and a grievance channel. Framed this way, compliance becomes about trust and brand building, the very foundation for going global, earning richer data, deploying AI responsibly, and moving up the value chain. Stricter data protection requirements need not widen the digital divide between large companies and MSMEs if the government and technology ecosystem make responsible AI and privacy compliance affordable and accessible for smaller businesses.Summarized by
Navi
20 Nov 2025•Policy and Regulation

01 Dec 2025•Policy and Regulation

21 Oct 2024•Policy and Regulation

1
Technology

2
Policy and Regulation

3
Technology
