Headlines

From policy to code: DPDP creates new privacy roles

dpdp


From policy to code: DPDP creates new privacy roles

BENGALURU: India’s data privacy push is creating demand for a new breed of technology professionals who can translate regulations into working systems, as companies grapple with increasingly complex data environments and rapid adoption of artificial intelligence (AI).Privacy has traditionally been handled by legal, compliance and cybersecurity teams. But as the Digital Personal Data Protection (DPDP) Act moves towards implementation, companies are finding that having policies on paper is very different from making technology comply with them.

The new privacy-tech jobs

The new privacy-tech jobs

“The challenge is that organisations are moving from legal and advisory work to putting structured policies and controls in place. It is moving from regulatory compliance to more of a technical compliance,” said Sachin Salian, senior VP and global business and delivery head at Writer Information. That is creating a shortage of professionals who can engineer privacy controls into enterprise systems.“There is definitely a supply gap,” said Srinivas L, joint CEO and joint MD of 63SATS Cybertech. “Most people are offering advisory services – gap assessments, creating policy documents and telling you how ready you are for DPDP. But what is very scarce is engineering.” The challenge becomes clear when companies try to implement requirements such as allowing customers to withdraw consent.“You have built these networks for the last 15 or 20 years and there is a system of data flow happening. There is no consent mechanism built into that data,” Srinivas said. Making consent withdrawal and data erasure work across production systems can require companies to rebuild complex data flows.Companies are also struggling to demonstrate that privacy controls work across their systems. “If tomorrow I ask whether you have deleted the data, you need to show the evidence,” Salian said. While tools for consent, cookie management and data mapping are emerging, “it is a journey,” he said. Legacy technology adds to the challenge. Mainframes and COBOL-based databases were not designed for modern consent and data-lifecycle requirements.For Allcargo Group global CITO Kapil Mahajan, AI has changed the privacy question itself. AI can combine multiple legitimate data points to infer information a customer never explicitly provided.“The whole privacy question was, who can access this data? That, to me, shifted,” Mahajan said. “The new question is: what are we permitted to infer from it?” “The architecture now has to evolve from protecting data to governing intelligence,” he said. “Just because technology can know something doesn’t mean an enterprise should know it.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *