Home » Resources » [VIDEO] DPDP Readiness: Secure, Comply, Stay Ahead [VIDEO] DPDP Readiness: Secure, Comply, Stay Ahead
Transcript Welcome everyone. My name is George Janssen, General Counsel of Blanket Technology Group and the DPO. So we’re going to talk today about India’s DPDP Act, Data Privacy Act in India, which is no longer something organisations can put off. The rules were notified in November twenty five and the Data Protection Board is now operational and full enforcement will happen per May twenty seven. So I’m joined today by Yash Pashpayee from our legal team, Mega Baghal, our India account manager, Deepa Kumar, our solutions engineer for Blanco India. And between the three of them, they’ll be providing a unique kind of perspective from each one of their angles in the way they interact with the businesses in India and the gaps they are seeing in this big transformation, which we are about to undertake in India. So, Yash, let us start with you. Can you in plain terms walk us through the requirements a bit on the DPD Act and what is exactly required from organisations to implement and to pay attention to? So, George, whenever I talk about the DPD Act, I like to start with the mindset shift rather than the legal debts itself. Organizations don’t actually own the customer’s data. They are the custodians of it. And what act refers to them as data fiduciaries. Now once this sends in, everything else that the law is asking for starts to make a lot more sense. And before I go to your question and just to set the scope, this act applies to any organization processing digital personal data within India, but also to the organization sitting outside India if they offer goods or services to people here. So it’s a wide net that we are talking about. Now if, coming back to your question, if I have to narrow it down to what matters the most right now, I would point to four things. The first is the consent. It has to be explicit, tied to a specific purpose, and documented properly. And here is something that people underestimate, that when someone withdraws the consent, you’re expected to actually stop processing their personal data then and there. It sounds very straightforward on paper, but think of the data that has traveled across internal teams and third party vendors. Actually pulling this data back consistently is a much more harder exercise than the most organizations expect, which naturally leads into the second point that is purpose limitation. If you have collected a data for one reason, one purpose, you can’t quietly start using it for something else without going back and getting a fresh consent in place. The third one is probably the one I’ll flag as the most overlooked, that is data erasure. Now once the purpose is served or the consent has been returned, the data needs to be permanently deleted. This isn’t only about the life systems that we are talking about. It covers the retired devices too. So the moment a laptop or a server is decommissioned, it generally tends to fall off an organization’s radar, but the legal obligation that comes along with it doesn’t disappear. The data is still there and it is the organization’s responsibility to permanently delete that data and actually prove that the data is gone. The fourth one I would say is the breach notification. If a breach happens, both the data protection board and the affected individual needs to be told without any delay. Lastly, to add to it, I’ll say the penalties are aren’t symbolic either. We are talking up to two hundred and fifty crores for inadequate security safeguards and up to two hundred crores if you fail to notify a breach on time. Very good to know. So this is quite serious business, obviously. And we also have to mention, I guess, the third party claims which could follow, right, from customers, from companies, etcetera. Repercussions could be very, very severe. Thank you for that kind of summary. So we’re talking also about the mind shift change, right? Mega, going to you a bit. What are you seeing with the customers, with the IT leaders you speak to in the field about that transformation and the gaps you are seeing, right? Because it is a transformation essentially, right? How you handle your data, the devices, etcetera. In my opinion, George, the awareness that the act exists is there. But when I sit down with this IT and security leaders, this awareness is not translated into action. The major gap that I see is data visibility because most organizations today will not be able to clearly tell you what personal data they hold, where this data is, and for how long they have kept it. Now without this foundation, it is very difficult to meet the erasure obligation obligation and the purpose limitation obligation that you just mentioned. The other gap and which is more concerning for me is end of life asset decommissioning. Because in today’s time, organizations think that whenever a laptop is decommissioned or storage is retired and sent out of the organization’s control, the assumption is that the data is also gone. But the data is not gone because a factory reset that these organizations do, that is not data erasure. Even if you are storing those devices in a locked room, that is also not data erasure. The data is very much on that device and it is fully recoverable. So under the DPDP Act, even if you have decommissioned the devices and sent out of your organization’s premises or control, since these devices still have data on it, it is still the responsibility of the organisation. Interesting. And it links back a little bit to what Yash was saying about a custodian role, right? And the two points you mentioned. The first about kind of control of the data you have from beginning to end, knowing what you have. I guess you cannot, let’s call it, address or control anything if you don’t know what you have essentially in the first place, right? So it becomes a kind of a big chaos, you could say, a big mess and it’s high security risk as a result. And the last point you mentioned, very important, of course, end of asset life cycle, we could say management. How do you properly erase the data? How do you control that in a proper way? And this is not a theoretical discussion, right? So you’re not just preaching, right? So there are major examples of where we’ve seen where this could lead. Could you tell us more about that? Yeah. I think I’ll start with the most popular case that most IT leaders also know, which is the Morgan Stanley case. So the bank faced, I think, over one hundred and sixty three million US dollars in cumulative fines, penalties and settlements because decommissioned devices left the bank’s premises with sensitive customer data on it. And then these devices were kind of handed to an inexperienced IT vendor, I would say, and they were resold online. And these devices were never fully recovered by the bank. And this is not a fringe situation, George, because we are seeing the same pattern in India, where if you look at the data incidents, they’re generally you can trace them back to recycle hard drives. You can trace them back to retired servers, which were decommissioned without proper data sanitization and sent out of the organization’s control. By the way, such kind of data incidents under the DPDP Act, again, like Yash mentioned, would carry penalties of up to INR two fifty crore Indian rupees, which is very huge actually. That’s interesting. And I think it’s also because Morgan Stanley being a bank, there is sensitive data obviously on those devices. But I can imagine there are so many companies in India, banks, hospitals, telco providers, everyone processing sensitive customer data. And if something happens to that, course, the repercussions are huge. So, it’s very good to know this. Globally, you see it play out, but we fully expect this in India to happen well. So that’s very interesting. Sorry, continue. You had a question or you want to say Yeah. The gap that I would like to also mention is proper documentation. Because even with organisations that are doing everything operationally right on the ground, they sometimes are not able to prove that. Now in the DPDP Act, the data protection board will ask for sanitization records. They will ask for chain of custody of every IT asset. If you’re not able to produce that quickly, this evidences quickly, then it is a compliance failure. Right? And it doesn’t matter regardless of whatever you’re doing on the ground. Proper documentation is very important because if you don’t document the process, it still becomes a compliance failure, like I said. Yeah, makes sense. Agreed. I think this is a really good addition as well. So, now moving over to Deepak. So, Mehta has described the problem clearly. Think devices leaving the company, the environment without proper sanitization, without documentation, without evidence. So, what does fixing that gap look like, Deepak? Thank you, George. Actually, that’s very real and very true what Megha has just described. And the root cause is almost the same, what Megha has just mentioned. Nowadays, sanitization is treated as something that happens very eventually rather than something that should be built inside the decommission process itself. Okay. So, once that is changed, the moment this change shift comes in, the moment erasure part becomes the integral part of the decommissioning itself rather than it being an afterthought, this problem automatically disappears. And now coming to the organizations which are very large at scale, where we have more than thousands of devices and which has to be processed and at the end of the life cycle they have to be decommissioned. So if in that scenario, the process is a manual process, Okay. In that scenario, there will be gaps coming in. Like there will be a documentation gap. There will be inconsistency in the data erasure process. There will be a few hiccups or challenges when erasing each and every kind of assets. So in that scenario, the main way of resolving this is putting erasure, the data erasure of the citation part, as an automation part, as an integral part of the decommissioning process where we are absolutely working on three major things. First is that every data, every machine which we are erasing or a company is erasing should produce a certified eraser certificate. That leads to an audit trail. Next is the certificate should automatically come in. And the last thing which I can tell is that this all process should be centralisedly monitored, and all the certificates or the data citation documentation should be centralised, managed so that it is easy to track, easy to monitor and can be controlled. So once these things are properly polished and set up in an organisation, I think we can avoid any kind of fines and penalties applying on the TPTP side. Thank you, Deepak. And it’s linking to the point indeed what Megha said about documentation evidence, right? You don’t want to scramble after the fact. So Mega, how does Blanco make that possible in practice? To build on what Deepak just said, with Blanco compliance becomes a default outcome of the decommissioning process. It is not an afterthought. It is not Default outcome. Interesting. Default outcome. So it is not a separate step that will depend on somebody remembering to do it. You know? So Blanco provides certified data erasure and across all device categories, whether it is a laptop, if it is a desktop, a server, mobile storage media. And all of this data erasure activity is in line with the NISD eight hundred eighty eight and IEEE standards. And the standards are important because they are the most recognized standards when you talk about auditors and regulators. So whenever a device is decommissioned, Blanco will erase all the data from that device and it will automatically generate a tamper proof erasure certificate. Now this certificate will have the details of the device, its serial number, the date, what method was applied. Also this certificate, because we’re talking about documentation and evidences. So this certificate then becomes the evidence that you can use to demonstrate the compliance under section eight erasure obligation under the act. So you can demonstrate compliance using this certificate. And all of these certificates Deepak was talking about having a centralized control kind of an environment. So all of these certificates are also centralized. They are very easily retrievable from anywhere whenever an auditor and an audit demands. So it becomes easy to also have this kind of audits. And with Blanco, if it is a organization that is, let’s say, using a third party IT vendor, the chain of custody is visible. As in it is very easy to maintain the chain of custody visibility. And with that, what happens is even if the device has left the organization’s control, you will still see have a complete visibility of the chain of custody. So there are no blind spots and there are no gaps in the audit process. And I think I would also like to say that in the DPDP Act, the leisure obligation, it does not end. It applies every time a device is retired. It applies every time a retention period lapses. It applies every time a data principal request deletion. So with Blanco, organizations can make this sustainable at scale. So that is there are certain ways in which Blanco can help. Interesting. I think it makes life easier, as you just mentioned, with such a system in place and a process that you can produce things readily, right, for an auditor, for a government authority, for a customer, etcetera, rather than having to scramble indeed and to dig the organisation to find what you need as the evidence. So that’s very helpful. Thank you for that. So thank you, Yash, Mega, Deepak. It’s very helpful, I would say, input on this topic. So I think what this conversation does tell us is that DPDP compliance is not a theoretical thing. It connects directly to how organisations manage their data and their devices on the ground every day. And with the data increasing every day with the AI transformation, with the digital boomers now in India, with the number of devices increasing exponentially, it is definitely something that needs to be front of mind, I would say. So a couple of things to take away. So I think number one, we could say you are a custodian of your data, of your customer’s data. You’re not the owner, you’re the custodian. So you’re responsible for properly managing this data until the end. So the second, I would say, takeaway here is the end of life asset management is one of the most overlooked compliance risks under the DPD Act. So it’s something we just see by a couple of examples. So a retired device with data still on it, like a hard drive or a phone, still is your liability, right? I think it’s a fair conclusion. I think number three, I would say enforcement of this Deep BPD Act will be May twenty seven. So that’s less than a year away. And this transformation takes time. As you just mentioned, there’s a couple of gaps. We’re seeing a lot with the organisations. So I would recommend, I would say, to our customers and to the business in India to move now and to start this transformation, I would say. And we’re here to help. Well, thank you all for your attention. And yes, it was a pleasure to speak today with all of us. Thank you
Let Blancco help you ensure data deletion compliance under the India DPDP Act. Sign up for your free enterprise trial today. Experience Blancco Data Erasure