At the FutureCrime Summit 2026, a panel titled “Data Fiduciary Accountability: Governance, Audits and the Role of Data Protection Officers in India” examined how organizations must rethink responsibility for personal data as India’s privacy and digital governance landscape matures.
The session brought together Suditi Tandon, Senior Officer, Global Data Privacy Office Specialist, Corporate Legal & Compliance, Hella India Automotive Private Limited; Krishan Kumar, Vice President, SPECTRA; Dipanshu Parashar; and Nirmal Raj M, Principal Officer & Risk Compliance Lead, Onmeta. The FutureCrime Summit’s published speaker information identifies Tandon in her global data privacy role, while professional information identifies Kumar as Vice President at SPECTRA and Nirmal Raj M as Principal Officer & Risk Compliance Lead at Onmeta.
Their discussion addressed an increasingly significant question for Indian organizations: who is ultimately accountable when businesses collect, process, share and retain large volumes of personal information?
Data Accountability Moves Beyond Compliance
The panel theme reflected the shift from treating privacy as a largely legal or documentation-driven obligation toward making data governance an organization-wide responsibility.
For data fiduciaries, accountability requires knowing what personal information is being collected, why it is required, where it is stored, who can access it and how long it should remain within organizational systems. As businesses become increasingly dependent on cloud platforms, digital services and third-party technology providers, maintaining visibility over the movement of data can become considerably more difficult.
The role of governance therefore extends beyond privacy notices and consent mechanisms. Organizations need internal processes capable of identifying risks, assigning responsibility and ensuring that privacy requirements are reflected in day-to-day operations.
Audits Test Whether Governance Works
Another central element of the discussion was the importance of data audits. Policies may establish what an organization intends to do, but audits help determine whether those policies are actually being followed.
Effective privacy audits can examine data inventories, access controls, retention practices, vendor relationships and internal procedures. They can also expose gaps between written policies and operational reality before those weaknesses develop into significant compliance or security problems.
This approach is particularly important as organizations increasingly work with external vendors and technology platforms. Accountability does not necessarily end when information is transferred to another service provider. Data fiduciaries must understand how information is being handled throughout its lifecycle.
DPOs Take On A Strategic Role
The session also placed particular emphasis on Data Protection Officers, whose responsibilities increasingly sit at the intersection of law, technology, governance and organizational risk. Tandon’s work within a global data privacy office represented the corporate privacy and compliance perspective, while Kumar’s professional focus includes legal technology, artificial intelligence and data privacy. Nirmal Raj M brought experience spanning risk, compliance, financial integrity and cybercrime response. Rather than functioning only as compliance administrators, DPOs can become important institutional safeguards by advising leadership, reviewing privacy risks and helping ensure that data-handling practices remain accountable.
The broader message emerging from the FutureCrime Summit panel was that effective data protection cannot depend on a single department. Governance, audits, technical safeguards, senior management oversight and clearly assigned responsibility must operate together.
As organizations increasingly build their services around data, accountability is becoming not merely a compliance requirement but a central component of digital trust.
