New Delhi: Shifting toward regulatory compliance, data privacy, and ethical technology adoption on the second afternoon of the FutureCrime Summit 2026 at Bharat Mandapam, industry leaders, legal scholars, and former government officials convened for Panel 12. Titled “From Privacy to Responsible AI: DPDP Act Compliance, Data Protection and AI Governance,” the session examined the operational, technical, and legal challenges of enforcing India’s Digital Personal Data Protection (DPDP) Act while governing rapid artificial intelligence deployment.
The panel explored how organizations can bridge the gap between statutory mandates, machine learning data flows, and effective corporate governance.
Policy Context, Human-Centric Design, and Technical Hurdles
Rakesh Maheshwari, Advisor on Cyber Laws and Tech Policy, and Former Senior Director & GC of Cyber Law & Data Governance at MeitY, outlined the government’s role as custodian of the DPDP Act. He explained that while CERT-In guidelines govern technical system security, the DPDP Act focuses on the granular operationalization of informed consent, breach reporting, and data processing. Maheshwari stressed that under statutory grievance mechanisms, the burden of proof rests on organizations to transparently disclose what personal data is collected and how it is processed.

Mimansa Ambastha, Founder of Starlex Consultancy, emphasized that DPDP compliance requires human-centric consent design and proactive “dry runs” for AI programs to avoid continuous retrofitting. She noted that prioritizing privacy offers a competitive edge by building consumer trust. However, Ambastha cautioned that machine learning models currently struggle with true “unlearning” or complete data erasure. She highlighted that the law mandates “reasonable” security safeguards rather than absolute invulnerability, urging organizations to move past decorative compliance.
Ashok Tarachand Ukrani, Former District Judge in the Gujarat Judiciary, identified forensic infrastructure limitations as the primary hurdle in legal enforcement. He observed a gap between legislative intent and technical capabilities, noting that courts struggle to verify whether a specific AI algorithm failed or if data fiduciaries actually fulfilled statutory compliance obligations.

Deep Pal Singh, Chief Risk Officer at Aditya Birla Capital, stated that large enterprises view DPDP compliance as an operational imperative rather than a mere regulatory mandate. He detailed ongoing industry efforts to perform gap assessments, merge Governance, Risk, and Compliance (GRC) data, and align DPDP requirements with broader AI governance frameworks. Singh also highlighted that corporate defenses must immediately patch loopholes identified by CERT-In, emphasizing that mandatory breach reporting protocols make high-level cyber defense essential for client data protection.
Akhil Kumar Jha, Director Delivery at GoTrust, pointed out a widespread lack of education regarding automated software tools that facilitate seamless DPDP implementation.

Vibhav Mithal, Associate Partner (Litigation) at Anand and Anand, cited key judicial precedents—including the Colgate v. NIXI case before the Delhi High Court—to illustrate how courts are tackling emerging cyber fraud, domain spoofing, and digital brand protection.
