SANDEEP SENGUPTA
MD, ISOAH DATA SECURITIES PVT. LTD.
“If some PII is dumped into WhatsApp, do we have a tool to detect it? And if any employee has done it, and the moment that data is out in the market, the company will be penalized, as it is the data fiduciary.
The biggest challenge that one will face on 13th May 2027—it is not the Data Board that will come after you. The people who will come after you are your competitors and disgruntled employees. They want to create a nuisance because they don’t want to disrupt your business. They want to keep you engaged with something else rather than focusing on your job.
So, when you make the plan for your DPDP, on one side is the policy and consent. But make a real-life case study. I would say, conduct a red-teaming exercise to understand how many ways people can come and disturb you.
So finally, for DPDP, go for the box, but get it audited by ethical hackers. Whenever there is manual involvement, the right mix is important. DPDP can be put in a box, but auditors will think out of the box, and so will criminals. You have to continuously monitor and that cannot be done manually; that has to be done by a box. So, the maintenance will be by the box, but the audit and gap assessment have to be manually done by a seasoned professional.”





