Whitepaper
Governing PII in the Age of Generative AI Regulation, Risk & Resilience
A practical framework for CISOs and compliance leaders navigating PII governance, DPDPA obligations, and AI adoption in Indian financial services.

What to Expect

Why accountability is the new perimeter in an AI-first environment

The gap between AI adoption and governance, shadow AI, third-party risk, and audit blind spots

What proving DPDPA compliance looks like in practice, with a May 2027 enforcement deadline
Co-authored by:

Abhijit Chakravarthy
EVP, Networks & Cyber Security,
Kotak Mahindra Bank

Dr. Vishal Gauri
Chief Executive Officer,
Seclore
Inside the Whitepaper
A BFSI cybersecurity leader’s guide to PII governance in an AI-first, DPDPA-regulated environment.
The new data risk landscape
How AI adoption has outpaced governance in Indian BFSI
DPDPA: what it demands and where AI creates gaps
What India’s DPDPA Rules require, and the three specific compliance gaps that AI adoption exposes
Why conventional security controls fall short
Why DLP and perimeter tools were not built for AI systems
A four-pillar governance framework, mapped to DPDPA
Understand, Control, Prove, Adapt: a data-centric architecture for AI-era governance
Two real scenarios from the field
An AI loan pipeline that left 47,000 customer files in a vendor’s cloud A shadow AI incident that made a customer’s erasure request impossible to fulfil.
What leaders should do now, before May 2027
Six immediate priorities for CISOs, compliance heads, and security leaders
Who should read this?
This whitepaper is for security, compliance, risk, and legal leaders at Indian banks and financial institutions who are navigating AI adoption alongside the DPDPA enforcement timeline.

1
CISOs and Security Leaders
Responsible for data risk posture, AI governance, and breach readiness under DPDPA’s 72-hour notification requirement.
2
DPOs and Compliance Heads
Accountable for demonstrating lawful processing, managing Data Principal rights, and preparing for SDF obligations from May 2027.
3
Legal and Risk Teams
Interpreting DPDPA obligations, managing third-party AI vendor accountability, and building an audit-defensible evidence trail.
4
CXOs and Board Members
Accountable for INR 250 crore penalty exposure, reputational risk in a trust-dependent sector, and AI adoption decisions at the business level.
5
CIOs and IT Heads
Responsible for integrating AI tools into enterprise architecture while ensuring data governance controls remain intact across the stack.
Related Resources
TRUSTED BY INDUSTRY-LEADING ENTERPRISES