Bank of Baroda Breach

It is unfortunate that a massive personal data breach has been reported at Bank of Baroda resulting in the compromise of the personal data of many customers. It is said that over 1TB of data has been posted on dark web and it was compromised through an email of one employee. The leaked data includes Aadhaar information also making it a highly harmful information leak.

India Today report

Had the Data Protection Board was in place and DPDPA 2023 was effective, this should have resulted in more than Rs 250 crores of penalty. Fortunately in the current scenario only CERT In can act under ITA 2000 and impose a penalty of upto Rs 1 crore. The customers can however file an individual/collective legal action for damages under Section 46 of ITA 2000 or through a writ petition at a High Court.

This is indicative of the failure of the information security system in Banks in general and if not addressed promptly, could lead to repetition in other Banks.

It would be interesting to observe how other banks respond to this threat. As some body looking at DGPSI-Banks as a DPDPA compliance framework, we would be watching the event closely.

We can continue the debate with ..What is the value of such data if BOB has to buy it back from the hacker?

It is presumed that the number of data sets lost would be in the range of 1 million. Dark web may value it at a minimum of Rs 100 each. The value of data lost could therefore be in a conservative estimate equal to Rs 100 million or Rs 10 crores.

Naavi

Posted in Privacy | Leave a comment

RBI Guidelines on Data Governance now available for public comments

At a time Naavi/FDPPI are working on the DGPSI-Banks as a framework for DPDPA compliance for Banks, it is interesting to see that the RBI has also issued a “Draft Guidance on Regulatory Expectations for Data Governance” for public comments.

Copy of the draft Governance is available here: 

The draft Guidance is applicable to following regulated entities:

i. Commercial Banks
ii. Small Finance Banks
iii. Payments Banks
iv. Local Area Banks
v. Regional Rural Banks
vi. Urban Co-operative Banks
vii. Rural Co-operative Banks
viii. All India Financial Institutions
ix. Non-Banking Financial Companies
x. Asset Reconstruction Companies
xi. Credit Information Companies

2. Comments on the draft Guidance are invited from regulated entities, members of public and other stakeholders by August 17, 2026.

The comments / feedback may be submitted through the link under the ‘Connect 2 regulate’ Section available on RBI’s website or alternatively be forwarded to:

The Chief General Manager, Operational Risk Group Department of Regulation, Central Office Reserve Bank of India, Shahid Bhagat Singh Marg, Fort,Mumbai – 400 001
Or
By e-mail (dor.datagovfed@rbi.org.in) with the subject line ‘Feedback on Guidance on  Regulatory Expectations for Data Governance’

Since most of the suggestions are already part of the framework DGPSI Banks, we will integrate the RBI draft suggestions in the framework.

Watch this space…

Naavi

Posted in Privacy | Leave a comment

One Day Workshop on DPDPA by Corporatelore Communications

On 24th, Corproatelore communications, Mumbai has organized a one day workshop for its clients at Holiday Inn, Mumbai.

Naavi will be conducting the workshop.

Interested persons may contact Corproatelore Communications over email: business@corporatelore.in

Other details are available here.

Posted in Privacy | Leave a comment

The Era of Certified Independent Data Auditor training begins

The concept of Independent Data Auditor introduced by FDPPI will be a watershed event in the history of Data Protection in India. The Era is now set to begin.

Venue:

Fairfield Marriott, 59th C Cross, 4th M Block, Rajaji Nagar, Bengaluru, India, 560 010

Date: August 21,22 and 23, 2026

Location

Tentative Curriculum:

Day 1:

-Introduction to the Course
-Overview of DPDPA
-Challenges in implementation of DPDPA

-Challenges in Auditing of Banks

-Role of an Auditor vis-a-vis a DPO or a Consultant
-Professional independence and conflict of interest
-Legal exposure and liability of audit opinions
-Engagement acceptance and scope definition
-Ethical standards and confidentiality obligation
-Audit Principles & Methodology: (Principles of ISO 19001
-Audit lifecycle
-Evidence Collection
-Documentation standards and audit trail
-Audit Engagement Contract

Day 2:

-Understanding organisational context and business model
-Stakeholder interview
-Designing audit checklists
-Sampling strategy and time budgeting

-Frameworks (ISO + DGPSI Architecture)
-Introduction to ISO 27701 privacy information management
-DGPSI as an Indian compliance assurance framework
-DGPSI Principles
-DGPSI Full and DGPSI Lite

Day 3:

DGPSI Variants:
-DGPSI-AI — AI governance assurance
-DGPSI-HR — employee data governance audit
-DGPSI-DP — core DPDPA compliance audit
-DGPSI-Hospital-DPDPA Compliance framework for a hospital
-DGPSI-Banks

-AIGSI-AI Governance and Protection Standard of India

Audit Simulation

Certification

All participants will get participation Certificates

Online examination will be available after 15 days.  Those who pass the cut off will get the completion certification.

Certificate will be issued as FDPPI-MYRA Certified Independent Data Auditor

Fees:

Rs 30000/-+GST (Total Rs 35400/-)

Early Bird Discount Rs 5000/- upto 31st July 2026 Rs 5000/- (Net price Rs 25000+GST, Total Rs 29500/-)

REGISTRATION AND PAYMENT OF FEES

P.S: We shall provide a pre-event master class on “Requirements of being a DPO”.

Posted in Privacy | Leave a comment

One day workshop in Mumbai on DPDPA

Corporatelore Communication, Mumbai is organizing a one day workshop on DPDPA on 24th July 2026 at Holiday Inn, Mumbai.

The program will be conducted by Naavi.

The details of the program are available below.

Download the flyer

Payment can be made to:

Bank Details & Payment Information
Beneficiary Name: CORPORATELORE COMMUNICATION
Bank Name: Canara Bank
Branch: Bandra West, Mumbai – 400050
Account Number: 0103201008775
IFSC Code: CNRB0000103
Digital Payment (Optional)
UPI ID: s2a.clc@oksbi

 

Naavi

Posted in Privacy | Leave a comment

Why we call Data Auditors as “Guardians of DPDPA Compliance”

DPDPA introduced the statutory profession of “Independent Data Auditor” under Section 10.

Section 10 described the additional responsibilities of a Significant Data Fiduciary which stated that the Significant Data Fiduciary shall appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and  periodic DPIA.

Rule 13 of the DPDPA Rules mentions

 -A Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board* a report containing significant observations in the Data Protection Impact Assessment and audit. (*Board means Data Protection Board, the regulator)

-A Significant Data Fiduciary shall observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals.

In view of the requirement for direct report of significant observations, the Independent Data Auditor (IDA) has been cast a duty on behalf of the regulator.

This provides the IDA a statutory relevance in the eco  system of DPDPA Compliance. In view of this FDPPI interprets that the Data Auditor functions as the eyes and ears of the DPB. The need to be involved in periodic audit also signifies a continuous monitoring of the activity of a significant data fiduciary.

The law does not currently specify the credentials required for being a Data Auditor and what does the word “Independent” imply. It also does not specify if the annual audit, the DPIA and the periodic audits can be performed by different auditors and whether there is any check on an organization playing one auditor against the other.

We hope these issues will be clarified over a period of time by the DPB or MeitY.

However, without waiting for the Government to provide a criteria for the Data Auditors and the Code of Conduct which makes them “Independent”, FDPPI has gone ahead with its own pro active decision to create a knowledge base and certification for the Data Auditors and the Code of Conduct for “Independence”. In order to enforce this code of conduct, FDPPI has created an “Empanelment” under AIDAI (Association of Independent Data Auditors). In order to provide incentivisation for empanelment, AIDAI will be providing a Business Exchange platform which will enable its trained persons to interact with the industry for audit business.

At this point of time we do envisage that an organization may experiment with different auditors for DPIAs while settling down for the annual audit with one of them. However, the changes and the need thereof may be documented by the company and the subsequent auditors.

Since some organizations particularly in the IT services industry may have multiple applications dealing with different sectors, FDPPI envisages that “Sectoral Specialist IDAs” may conduct DPIAs for different sector facing applications. For example if there is an application which can be used both for health care and Finance, the IDA who specializes in health care may conduct a DPIA for health care facing application while finance related application may be audited by an IDA who specializes in Finance.

The DPDPA rules also envisage an audit of “Algorithms” or “AI”. RBI has also indicated that Models and AI need to be audited. In such circumstances there may be a IDA who specializes only in AI models or Autonomous algorithms. Perhaps DGPSI-AI can be used for this purpose.

FDPPI is therefore developing individuals who specialize in different DGPSI frameworks to serve different industries.

Currently the sectoral DGPSI frameworks are available for HR, Data Processor platforms, Banks, Bank Branches, Hospitals. Additional frameworks for Education are also being developed.

In each of these sectors, there is scope for specialization and FDPPI will develop “Champions” for each of the frameworks indicated below.

Watch this space and keep in touch with Naavi if you want to take part in such sectoral specialization.

Naavi

 

Posted in Privacy | Leave a comment