HomeAnalysisDPDP Act Exposes India’s Shortage of Privacy Engineers

DPDP Act Exposes India’s Shortage of Privacy Engineers

India’s Digital Personal Data Protection Act is creating demand for professionals who can turn privacy rules into functioning technology controls, but companies are finding that the country’s existing compliance machinery is not prepared for that transition. The emerging gap is not simply a shortage of lawyers or policy advisers. It is a shortage of people who can trace data through complex enterprise systems, build consent and deletion mechanisms, and produce evidence that those controls actually work.

That shift matters because privacy has traditionally been divided among legal, compliance and cybersecurity teams. Their work has often focused on interpreting obligations, assessing risks and preparing policies. The implementation challenge is different. Organisations must connect those policies to production systems, databases, customer interfaces and internal data flows. As companies adopt artificial intelligence, the question is also moving beyond who can access data to what an organisation is permitted to infer from it.

Sachin Salian, senior vice-president and global business and delivery head at Writer Information, described the change as a move from regulatory compliance to technical compliance. In practical terms, that means moving from advisory work and policy documents to structured controls embedded in enterprise technology. The distinction is important: a company may have a privacy policy, but that does not establish that a customer’s consent can be withdrawn across all relevant systems or that personal data can be deleted completely when required.

Srinivas L, joint chief executive officer and joint managing director of 63SATS Cybertech, said there was a supply gap in the market. He noted that many professionals currently offer gap assessments, policy creation and readiness advice, while engineering capability remains scarce. The distinction points to an institutional problem in how privacy responsibilities are being organised. Organisations may be able to identify what they should do, yet still lack the technical staff needed to make those requirements operational.

The difficulty is rooted in the way enterprise data systems have developed. Companies have built data networks over 15 or 20 years, often adding applications, databases and processes over time. Those systems were not necessarily designed around a single, integrated consent mechanism. A customer’s information may therefore move through several connected or partially connected environments, making it difficult to identify every location where the data is stored, processed or copied.

Consent withdrawal illustrates the problem. A customer-facing process may allow a person to change or withdraw consent, but that action has to travel through the organisation’s wider data architecture. If the relevant systems do not communicate with one another, the change may not be reflected consistently. The challenge is not just designing a digital button or a new policy. It is ensuring that the resulting instruction is recognised across the data flows that support business operations.

Data erasure creates a related test. Companies need to know whether information has been removed from the systems covered by the request and whether they can demonstrate that the process was completed. Salian said that if an organisation is asked whether it has deleted data, it must be able to show evidence. This makes auditability a central part of privacy engineering. A control that operates invisibly, or cannot produce a reliable record, may be difficult to verify even if the organisation believes it has complied.

The market response is beginning to include tools for consent management, cookie management and data mapping. These tools can help organisations identify where information is held and how permissions are handled. But the comments reported by The Times of India indicate that technology products alone will not resolve the problem. Organisations still need people who understand the relationship between business processes, legal requirements and the architecture of older systems. The implementation challenge is therefore both technical and organisational.

Legacy technology intensifies that challenge. Mainframes and COBOL-based databases were built for earlier operational requirements and were not designed around modern consent or data-lifecycle expectations. Retrofitting new controls into such environments can be more complicated than adding privacy features to a newly designed system. It may require organisations to understand dependencies that have accumulated over decades, including systems that remain operationally important but are difficult to modify.

This creates a different kind of privacy workload. Instead of treating compliance as a document that can be reviewed periodically, companies have to treat it as a continuing systems function. Data maps may need to remain current. Consent decisions may need to be connected to downstream processing. Deletion requests may require traceable workflows. Evidence of action may need to be retained in a form that allows an organisation to demonstrate what happened. The supplied reporting does not establish how widely these capabilities currently exist across Indian companies, but it clearly identifies engineering as the scarce component.

Artificial intelligence is widening the scope of the question. Kapil Mahajan, global chief information and technology officer at Allcargo Group, said AI had changed the privacy issue from who could access data to what organisations were permitted to infer from it. AI systems can combine multiple legitimate data points and generate information that a customer may never have explicitly provided. That creates a distinction between collected information and derived information.

The distinction has implications for enterprise architecture. Traditional access controls are designed to regulate who can view or use a particular dataset. AI-enabled systems can create new conclusions by combining datasets, meaning that governance also has to consider the outputs produced by processing. Mahajan described the change as one from protecting data to governing intelligence, while cautioning that technological capability does not by itself establish that an enterprise should possess or use a particular insight.

This is where privacy work intersects with technology governance. A system can be technically capable of connecting data, generating a profile or making an inference. Whether it should do so is a separate question. The people responsible for implementing privacy controls therefore need to understand not only databases and applications, but also how models, data combinations and automated outputs affect individuals.

The emerging roles created by the DPDP Act are consequently broader than conventional compliance positions. They sit between legal interpretation and software implementation. Such professionals may need to translate a policy requirement into a system rule, identify where that rule must be applied, test whether it functions across legacy infrastructure and record evidence of its operation. Their work also has to keep pace with changing data practices, particularly as companies adopt AI across business processes.

The policy-to-technology gap also changes the responsibilities of senior management. If privacy is treated only as a legal function, technology teams may receive requirements too late or without enough operational detail. If it is treated only as a cybersecurity issue, organisations may focus on unauthorised access while overlooking consent, inference and lifecycle controls. The reporting suggests that implementation requires a combined approach in which legal, compliance, cybersecurity, data and engineering functions work on the same architecture.

What remains uncertain is the scale of the shortage and the extent to which Indian companies have begun rebuilding their systems. The available report provides no industry-wide measure of the supply gap, no estimate of the number of privacy engineers required and no comparative assessment of company readiness. It does, however, identify a consistent implementation pattern: policy documents and readiness assessments are more readily available than the engineering needed to make privacy controls work across complex systems.

That pattern is the larger urban and economic question behind the DPDP transition. India’s digital economy is being supported by data systems that were built at different times, for different purposes and with different technical assumptions. Bringing those systems under a common privacy framework will depend not only on the wording of regulation, but also on the people, tools and institutional processes capable of connecting rules to everyday digital operations. The next phase of India’s privacy push will therefore be measured less by the presence of policies than by whether organisations can demonstrate how those policies operate in code.



























RELATED ARTICLES

Most Popular

Latest News