Go back

India’s data law is giving rise to a new consent economy for banks

12m 16s

India’s data law is giving rise to a new consent economy for banks

India's implementation of the Digital Personal Data Protection Act has fundamentally changed how companies can collect and use personal data, including for routine communications like promotional WhatsApp messages. The law mandates clear, specific user consent and grants individuals rights to access, correct, or delete their data. This has transformed compliance from a simple checklist into a complex operational challenge, spawning a new industry estimated to be worth thousands of crores. Startups and established firms are helping businesses build systems to manage consent across platforms, but debates persist, particularly around whether KYC (Know Your Customer) firms can act as consent managers without conflict of interest. Enforcement focuses heavily on data security and breach reporting, with severe penalties incentivizing compliance. However, observers question whether the systems being built will genuinely enhance user control over personal data or primarily serve to limit corporate legal liability. The full compliance deadline is mid-2027, but companies are already investing heavily to adapt.

Transcription

1498 Words, 9561 Characters

English
If you use WhatsApp, you have probably received messages from companies, delivery updates, payment reminders, promotional offers, sometimes it's a brand that you remember interacting with, sometimes it isn't. The messages though still arrive and most of the time you ignore them or you delete them without much thought. But behind those messages, it's a growing legal question in India. When is a company allowed to contact you and what permission did you actually give them to do so? That question has become harder to answer since India's digital personal data protection act became operational in November last year. The low reshapes how companies can collect, store and use personal data including something as basic as your phone number. Consent now has specific requirements, it has to be free, informed, specific and unambiguous. Users can ask companies what data they hold, correct it, delete it or withdraw consent entirely. And companies are required to build systems that make these rights usable not theoretical. For businesses, this has changed how everyday communication works. Even something as familiar as a WhatsApp promotion can trigger internal debates about compliance. Founders and compliance teams are spending hours discussing who initiated a conversation, what permissions exist and how those permissions are recorded. One of the people fielding these questions is Gaurav Meta, the founder of Concur, a startup working in compliance management. Since the law took effect, his role has involved translating legal language into operational decisions companies can follow across teams and platforms. And the deadline for full compliance is mid-2027, but preparations are already underway. Companies are investing significant sums to avoid penalties that can run into hundreds of cross-off rupees. At the same time, an entire industry seems to be forming to help businesses manage consent at scale. Now, as that industry grows, a larger issue is slowly coming into focus. The systems being built today will decide how much control users really have over their data, including who gets to speak to them and under what terms. Welcome to Debrae, a business podcast from the Kent. I'm your host, Nikita Sharma and I don't chase the new cycle. Instead, every day of the week, my colleague, Rachel Varghese and I will come to you with one business story that is worth understanding and worth your time. Today is Tuesday, the 27th of January. Once the data protection law became operational, companies quickly realized that compliance was not going to be a simple checklist. It required new systems, new rules and new budgets. Enterprises began asking what compliance actually looks like on the ground, and many of those questions started landing with a new class of startups. One of them is Concur, which I mentioned earlier, founded by Gaurav Meta. His work involves translating the law into something that companies can execute across teams and technologies. That translation has value. For large enterprises, compliance services can cost up to 18 crore rupees in the first two years, and about 10 crores every year after that. Penalties for non-compliance meanwhile can go up to 250 crore rupees with high exposure when children's data is involved. Raghuveer Kancherla, the co-founder of Governance and Compliance at Forms Printo, spoke to my colleague, the Ken Reporter, in their pulsing, and he compared compliance to finance. In the same way that finance teams maintain accounts, compliance teams now have to manage consent frameworks and privacy obligations. And this shift has helped create a market that Shashankaranchati, the co-founder of consent management startup Redacto, estimates to be worth at least 2000 crore rupees in India. Still, building the space is not straightforward. Consent, at some point, stops becoming a legal question and becomes a systems problem. It has to work across channels, windows, and internal teams, and it also has to be enforced through technology. Large enterprises often gravitate towards established players. Some work with Indian KYC companies like IDFee, while others rely on multinational governance companies that bring experience from Europe's GDPR regime. Platforms such as privy by IDFee integrate consent and data governance directly into enterprise systems. But what happens as a result is attention around definitions. The low specifies that a consent manager must be incorporated in India and avoid conflicts of interest with data fiduciaries. Startups like concur and Redacto argue that this excludes KYC firms and foreign headquartered companies and KYC firms do not agree. If the market cannot resolve this disagreement, it will fall to the data protection board of India, which is expected to begin registering consent managers in November. Until then, companies are still moving ahead even as the rules continue to take shape. For more on this, stay tuned. Some of the risks that the law is trying to address are already visible. For example, in early 2025, a large trading platform hired the Data Security Form Matters.AI to audit its systems. The audit uncovered something quite troubling. A former employee who had left three years earlier had set up a script that siphons sensitive information to a telegram channel. Under the current law, such a breach would need to be reported to the data protection board within 72 hours. Effected users would have to be informed and penalties like I said could reach into hundreds of crores. Matters.AI has since started offering tools that help companies accurately delete data when users revoke consent alongside its other cybersecurity services. Other startups are choosing different areas of focus. Redacto, for example, concentrates on tracking where personal data flows and where it is stored. The company positions itself as a privacy-only layer that does not collect data itself, which it says helps avoid conflicts of interest. Redacto sees early demand from healthcare and financial services. Industries that handle large volumes of sensitive data and are likely to face closer regulatory scrutiny. Spring to meanwhile, which initially worked with startups now focuses on large enterprises and estimates recurring compliance costs of 4-5 crore rupees a year for mid-sized companies. Established players, on the other hand, argue that consent is only one part of compliance. Ashok Hariharan, the founder of IDP, points that areas like third-party risk management, cookie controls, and data discovery often receive less attention but carries significant exposure. IDP sells consent governance as a part of a broader compliance offering. The sharpest debate, though, centers on conflicts of interest. GRC companies argue that KYC firms should not act as consent managers because their business depends on continuous access to data. Yashu Bansal, who is assistant professor at Manipur Law School, illustrates the concern. He says, if a KYC firm verifies users and also manages consent, every revoked permission affects its own onboarding and verification workflows. Hariharan, though, disagrees with that framing. He distinguishes between a consent manager, acting on behalf of users and enterprise facing systems that help fiduciaries implement consent at scale. From his perspective, governance platforms operate on behalf of companies and the law does not prohibit KYC firms from offering such systems. The Information Technology Ministry has shortlisted IDP, Redacto and Geo platforms to help develop a modular consent framework. While this is not authorization to act as consent managers, it does signal confidence in their technical capabilities. Still, some observers, including Internet Freedom Foundation director Apar Gupta, want that government-backed innovation efforts can influence who eventually receives registrations. But beyond the market structure, there is a deeper question about what compliance ends up prioritizing. Gupta argues that the real test is whether companies trend in user agency or focus primarily on limiting liability. A case described by matters.ai founder Keisha Murthy actually is a good example of this. At one of India's largest banks, a senior executive downloaded sensitive customer data before leaving the company. He disguised the file as a medical report and shared it on WhatsApp. No customer harm was reported, but the bank's immediate concern was identifying and containing the breach. That response reflects how the law is weighted. According to Murthy, the Data Protection Act places more emphasis on security than on privacy. Preventing data leaks and misuse sits at the center of enforcement. Kanchela believes that the headline penalty figure of 250 crore rupees exists to force attention. Whether it remains notional or becomes routine will actually depend on the enforcement. For now though, it is enough to get companies to engage. And that engagement is already reshaping how businesses think of something as ordinary as a WhatsApp message. And how much control users truly have over the data behind it. Debrake is produced from the newsroom of the Ken India's first subscriber focus business news platform. What you're listening to is just a small sample of a subscriber only offerings and a full subscription offers daily, long form feature stories, newsletters and a whole bunch of premium podcasts. To subscribe, head to the Ken.com and click on the red subscribe button on the top of the website. Today's episode was hosted and produced by my colleague, Snigthash. [Music]

Podcast Summary

Key Points:

  1. India's Digital Personal Data Protection Act, operational since November 2023, has strict consent requirements (free, informed, specific, unambiguous) for companies to contact users, reshaping business communication.
  2. Compliance has created a new industry and significant costs for businesses, with startups and established firms offering services to manage consent and data governance, while debates over market rules and conflicts of interest continue.
  3. The law emphasizes data security and breach reporting, with high penalties (up to ₹250 crore) driving corporate engagement, but a key question remains whether compliance will prioritize user control over data or merely corporate liability limitation.

Summary:

India's implementation of the Digital Personal Data Protection Act has fundamentally changed how companies can collect and use personal data, including for routine communications like promotional WhatsApp messages. The law mandates clear, specific user consent and grants individuals rights to access, correct, or delete their data. This has transformed compliance from a simple checklist into a complex operational challenge, spawning a new industry estimated to be worth thousands of crores.

Startups and established firms are helping businesses build systems to manage consent across platforms, but debates persist, particularly around whether KYC (Know Your Customer) firms can act as consent managers without conflict of interest. Enforcement focuses heavily on data security and breach reporting, with severe penalties incentivizing compliance. However, observers question whether the systems being built will genuinely enhance user control over personal data or primarily serve to limit corporate legal liability.

The full compliance deadline is mid-2027, but companies are already investing heavily to adapt.

FAQs

It is a law that regulates how companies collect, store, and use personal data, requiring specific consent and granting users rights over their data. It became operational in November 2023.

Consent must be free, informed, specific, and unambiguous. Users can withdraw consent or request data access, correction, or deletion.

Penalties can reach up to 250 crore rupees, with higher risks when children's data is involved. Companies must report breaches within 72 hours.

A consent manager is an entity that must be incorporated in India and helps users manage their data consent, avoiding conflicts of interest with data fiduciaries.

Companies are investing in new systems and compliance services, with costs ranging up to 18 crore rupees initially. Many work with startups or established firms to manage consent and data governance.

Healthcare and financial services are early adopters due to handling sensitive data and facing regulatory scrutiny. They use tools to track data flow and storage.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.