Accountability for India’s DPDP Act: Chirag Goswami Questions Corporate Responsibility

C

Chirag Goswami

LinkedIn Author

💡 LinkedIn Top Voice💡 || Cyber Security || Cybernara – We’ve Only One Mission: Provide the Best Cyber Security Solution

In a recent LinkedIn post, Chirag Goswami highlights a critical question facing businesses in India following the implementation of the Digital Personal Data Protection (DPDP) Act: who bears the responsibility for compliance within an organization?

Goswami’s commentary stems from a personal experience where he was asked for sensitive personal data, including his phone number and email, before even being able to view a service’s product. This immediate demand for information, without clear explanation or consent options, led him to observe the casual manner in which personal data is still being collected in India.

“This is how casually personal data is still collected in India.”

The introduction of the DPDP Act, as Goswami points out, signifies a shift towards greater data protection. However, the practical implications for corporate structures and accountability remain a significant area of concern.

The Unanswered Question of DPDP Accountability

Goswami frames the central issue with a direct, albeit rhetorical, question posed to companies:

“Who is responsible for DPDP inside your organisation?”

This question, according to Goswami, cuts to the core of how businesses are preparing for and integrating the new data protection regulations. It suggests that while the law is now in effect, the internal mechanisms for ensuring compliance might be lagging.

Identifying the Data Principal within Organizations

As Chirag Goswami implies, the lack of clarity on internal responsibility can lead to a diffusion of accountability. Without a designated individual or department clearly tasked with overseeing DPDP compliance, there’s a risk that critical aspects of the law might be overlooked. This could range from obtaining proper consent for data collection to managing data subject rights and ensuring data security measures are robust.

Goswami’s observation about the premature collection of personal data underscores the gap between regulatory intent and corporate practice. He argues that the ease with which companies may still request such information highlights a potential lack of internal awareness or commitment to the principles enshrined in the DPDP Act.

The Broader Implications for Consumer Trust

In Chirag Goswami’s view, addressing the question of internal responsibility is not just a matter of legal compliance but also crucial for building and maintaining consumer trust. When individuals are asked for personal data without transparency or context, it erodes confidence in how their information will be handled.

The DPDP Act aims to empower individuals and provide them with greater control over their personal data. However, as Goswami’s post suggests, the effectiveness of this legislation hinges on businesses establishing clear lines of accountability internally. Without this, the casual collection of data, as experienced by Goswami, is likely to persist, undermining the very goals of the new data protection law.

Ultimately, Chirag Goswami’s post serves as a timely reminder for Indian businesses to proactively define and assign responsibility for DPDP compliance, ensuring they not only meet legal obligations but also foster a culture of data privacy and respect for consumer rights.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on January 22, 2026 | View original post on LinkedIn →