Author Archives: naavi

Course on PDPA in association with Cyber Law College

Cyber Law College, which has been conducting Cyber Law related courses since 2000 as well as courses on HIPAA and GDPR, has now started a Web Class based course on Personal Data Protection Act.

This course for “Certificate in PDPA” will consist of 12 live sessions to be conducted by Na.Vijayashankar (Director Cyber Law College) and Chairman FDPPI and cover the following topics.

  1. Evolution of Privacy Law in India. (ITA 2000-ITA 2008-Puttaswamy Judgement.Etc.) and
  2. Understanding the Concept of Privacy and its relation with Data Protection
  3. Applicability, Exemptions, Transitional Provisions
  4. Data Principal’s Rights and Data Protection Obligations
  5. Grounds of Processing
  6. Transfer of Personal data outside India
  7. DPA and DPO
  8. Compliance Obligations
  9. Penalties and Offences and Grievance Redressal mechanism
  10. Data Protection Challenges under New Technologies
  11. Data Governance Framework
  12. Interactive discussion and Review

Each session would be approximately for 90 minutes. It is envisaged that the course will commence in the second half of November 2019 and there would be two classes each week for 6 weeks. Exact schedule of the classes will be announced later.

As an introductory offer, the fees for the course is set at Rs 6000/- only.

A Copy of the prospectus is available here

Existing members of FDPPI can sponsor/refer any participant and such participants would be provided a cashback of Rs 1000/-.

At the end of the course there would be an online test following which the certificates would be issued by FDPPI.

Interested persons may enroll at the earliest by visiting  here


Watch the video on the introduction to the program here:

Discussion on Data Governance

Data Governance is getting increased attention now since after the PDPA becoming a law there would be need for further legislation on processing of “Community Data” and “Aggregated Anonymized Data”. This may perhaps be addressed through a new legislation on “Data Governance”. The Government has set up an Expert Committee for this purpose.

More information on these developments are found here:

    1. Formation of the Expert Committee
    2. Views of Kris Gopalakrishna…1.. What do they indicate for the Privacy Regulation in India
    3. Views of Kris Gopalakrishna…2.. Leveraging Data for the benefit of individuals
    4. Views of Gopalakrishna …3…on Privacy
    5. Data Productivity vs Data Security
    6. What is Community Privacy? and who has the right of disposal?

There is every indication that “Data Governance Act of India” will sooner or later come into operation. It is good for the Data Protection Professionals to be watchful of these developments.

Data Protection will continue to be an important segment of Data Governance. But it is possible that a new outlook will come to bear on “Data Security” with a lot more liberal outlook than what the data protection professionals would be accustomed to today. The interpretations may move from the GDPR side to the CCPA side, unless the law is clear.

FDPPI will closely watch the developments on Data Governance and as a part of its activities will keep “Data Governance”  on our radar along with “Data Protection”.

In order to initiate the discussions, FDPPI is conducting a webinar on Data Governance on 12th October 2019 at 5.30 pm. Interested persons may contact for an invitation.


Cyber Forensics in Privacy Era

Bangalore Chapter of FDPPI organized a Knowledge Sharing session on the theme “Cyber Forensics in the Privacy Era” at Deloitte office on 17th September 2019 between 5.00 pm and 7.30 pm.

Mr Sebastin Edussery, Head Security, IFS, Deloitte, India addressed the gathering  and discussed interesting case studies on Cyber Forensics and the Privacy issues that a Forensic investigator needs to contend with.

This  was then followed by a session on “Evidentiary Challenges in Cyber Forensics” by Naavi, the Chairman of FDPPI.

The sessions were well appreciated by the participants.


ISO standard for Privacy Management to be discussed

On 11th September 2019, FDPPI has organized a webinar on ISO 27701 which is an extension to ISO 27001 and covers the requirements of PIMS. (Privacy Information Management System).

Speaker is Ms Sandhya Khamsera, Founding Partner and CEO of Pricoris LLP.

After the advent of GDPR, BS 10012 was released to directly address the PIMS.  Recently, ISO released the document titled ISO27701 as an extension of ISO 27001 for enabling a framework for managing the security of Personal Information.

Ms Sandhya will discuss some of the salient features of the framework.

The webinar will be at 11.00 am and a  link can be obtained from the FDPPI WhatsApp group or sending an email to FDPPI


Delhi Chapter of FDPPI launched

In a well attended meeting held at the office of Deloitte, Gurugaon, the Delhi Chapter of FDPPI was formally launched.

Mr Gautam Kapoor, partner, Deloitte speaking on the occassion highlighted the special role of the Delhi Chapter in being able to closely track the policy developments since Delhi happens to the political capital of the country.

Mr Nakul Chopra who will be the provisional honorary president, made a presentation providing a brief overview of the proposed Personal Data Protection Act.

Mr Naavi made a presentation on the Data Audits as envisaged in PDPA and highlighted the need for developing a system for computing Data Trust Score.

The membership of the chapter would be expanded and the Governing council would be formally set up.

Data Audit under PDPA

PDPA (Personal Data Protection Act) is an important legislation which the Government of India is set to pass in the Parliament at the earliest. With the passage of the Aadhaar Amendment Act, it has become even more critical that the Government passes the Personal Data Protection Act without much delay since this contains the commitment for protection of Privacy without which some of the provisions of the Aadhaar continue to attract criticism.

While like any other Privacy protection legislation, PDPA also speaks of permitted grounds of processing of personal information, the obligations of the processor, the rights of the data owner, the penalties etc, it must be recognized that PDPA has imposed a huge responsibility on the “Audit Community” for protecting Privacy of the Indian Citizens.

PDPA envisages an annual “PDPA Compliance Audit” as a mandatory provision besides internal audits from time to time by the Data protection officer. There will also be audits whenever a Data Breach is suspected and whenever there is a perceived conflict with the RTI.

Some of these issues will be discussed by Naavi during an event in Delhi on 16th July 2019 at the Deloitte, Gurugaon office. The occassion will also mark the launch of the Delhi Chapter of FDPPI and open to non members also on invitation. Interested persons may contact Mr Nakul Chopra of Deloitte Delhi for more information.


One year of GDPR and the emerging year of PDPA

We are completing one year of GDPR. GDPR brought in a new awareness across the world about Data Protection for which all professionals having a stake in the industry has to thank.

As we celebrate the anniversary of GDPR, in India it is time to look forward to the year of PDPA.

With the return of the Modi Government, we can expect that the passage of PDPA will be smooth and before the end of this year, we will have the DPA in place.

FDPPI has dedicated itself to the cause of PDPA and will involve itself with outreach programs to spread the knowledge.

Additionally FDPPI will be co-coordinating its activities with other similar  organizations to undertake many other projects which will be discussed from time to time.

We look forward to suggestions from the professionals in this regard.



Emerging opportunities for Data Privacy Professionals in India

Justice B N Srikrishna Committee drafted “Personal Data Protection Bill -2018” is under the review of Ministry of Information Technology, Government of India. Once the Bill become an Act of Parliament, it is going to affect every entity, which is collecting personal data of India citizens.

In its current form, the Act is going to touch each and every commercial and non-commercial entities possession Indian Citizens’ personal data irrespective of format or purpose. The upcoming Act already gaining attention of organizations’ senior managements and Boards to prepare their respective organizations to meet the provisions of Act.

In a bid to increase the awareness about the forthcoming legislation and to understand its impact on the industry and the professionals in the industry, FDPPI Mumbai Chapter is organizing a webinar on “Emerging opportunities for Data Privacy Professionals in India” on 11th May, 2019 at 8.00 PM (IST)

Topic:   Emerging opportunities for Data Privacy Professionals in India

Speaker: Na.Vijayashankar (Naavi), Data Protection Consultant


  1. Welcome and Brief about the FDPPI (Foundation for the Data Protection Professionals in India) by Mr Adepu Bondiah
  2. Presentation by Naavi covering
    1. Emerging opportunities for Data Protection Professionals in India
    2. How Does PDPA 2018 differ from GDPR
    3. Challenges in Compliance for Data Fiduciaries and Data Processors
    4. Challenges in conducting Data Audit and Computing Data Trust Score
    5. Q &A
  3. Vote of Thanks: Mr Rakesh Goyal

Participation is by invitation.

For invitation, Contact Mr Adepu Bondiah, or Rakesh Goyal or Mr Anil Chiplunkar or Mr Ritesh Bhatia, the Governing Council members of FDPPI, Mumbai.

Request for Invitation may be sent to 

FDPPI, Mumbai

Inauguration of Chennai Chapter

The Chennai Chapter of FDPPI was formally inaugurated on 16th March 2019 in a grand function in Hotel Rain Tree, Anna salai along with a workshop on Section 65B of Indian Evidence Act. The program was jointly conducted by FDPPI and CySi (Cyber Society of India).

A Full report of the event is available at

Ms Anitha Rajesh the President of the Chennai Governing Council , Mr Sridhar and Mr Balaji members and naavi are seen in the picture. Durai Kannaiyan and Nagendra who are the other members of the Governing Council were not present.

During the event Naavi explained the relevance of Section 65B for Data Protection industry besides a detailed discussion on its impact on the law enforcement and judiciary.


Program on Section 65B jointly with CySi in Chennai

 Launch of Chennai Chapter ad Workshop in Chennai

Section 65B of Indian Evidence Act is an important legislative provision which came to effect on 17th October 2000 and determines how Electronic Evidence has to be presented in a Court of Law for admissibility.

Several aspects of Data Protection require, archiving of data and presentation of data in quasi judicial and judicial fora and hence understanding this section is important for the DPOs in India.

On 16th March 2019, Cyber Society of India (CySi) of which Mr Naavi was the founder Secretary, and FDPPI are organizing a one day workshop on Section 65B of Indian Evidence Act. This is the first time in the last 20 years that a dedicated one day workshop is being organized on this subject. (Details are available here)

Naavi was the person who submitted the first Section 65B Certificate in any Court in India which was during the case of State of Tamil Nadu Vs Suhas Katti in AMM Egmore Court in 2004. Mr S.Balu the current President of CySi was the IO in that case which was historically the first case in which conviction took place under ITA 2000 in India.

During this occassion, FDPPI is set to launch its Chennai Chapter on 16th March 2019 along with an event being conducted by Cyber Society of India (CySi)  on on Section 65B of Indian Evidence Act.

During the program, Naavi is also  launching the print version of his e-book on Section 65B of Indian Evidence Act.

Members of FDPPI in Chennai are requested to make the event a success.