Policy Advocacy

The Policy and Advocacy function at the Data Security Council of India (DSCI) serves as a strategic interface between industry, government, academia, start-ups, and other key stakeholders to shape progressive and forward-looking policies on cybersecurity, data protection, the digital economy, artificial intelligence, and other emerging technologies. This function also supports DSCI’s broader mission by contributing to knowledge-building efforts in technology policy, with a strong emphasis on privacy and security.

The key roles served by the policy advocacy function include:

  • Live Policy Consultations: We lead active consultations on critical policy areas such as data protection, cybersecurity, artificial intelligence, and emerging technologies. Inputs are gathered from DSCI’s diverse membership base and stakeholder network to inform our formal submissions to the government. These efforts have a visible impact on the evolving regulatory landscape in the country.
  • Policy Research & Advocacy: We undertake in-depth policy research and publish thought leadership on emerging legal, regulatory, and policy frameworks. Our advocacy efforts are aimed at fostering balanced, practical, and innovation-friendly regulations that support national priorities and industry growth.
  • Stakeholder Engagement: The team convenes multi-stakeholder dialogues through consultations, roundtables, and public policy forums to ensure a broad spectrum of perspectives are reflected in policy development processes.
  • Regulatory Interface: We engage constructively with government ministries, regulatory bodies, and standards organizations to offer industry insights and contribute to the formulation of robust cybersecurity and privacy regulations that build trust and resilience.
  • Capacity Building & Awareness: To promote policy literacy and preparedness, we conduct briefings, workshops, and awareness sessions for enterprises, startups, and government stakeholders on key regulatory developments and compliance imperatives.

Through these initiatives, DSCI’s Policy team plays a pivotal role in advancing a secure and trusted cyberspace while positioning India as a global leader in digital innovation, cybersecurity, and responsible technology governance.

Call for Inputs

The Reserve Bank of India released its Draft Guidance on Regulatory Expectations for Data Governance in July 2026. The Draft Guidance sets out expectations for how Regulated Entities should govern data as an organisational asset through a proportionate Data Governance Framework (DGF) aligned with their risk management framework. The DGF must be overseen by a Board-level Data Governance Committee and implemented by a Data Governance Executive Committee, with data risk managed as part of the overall risk framework and the Framework subject to periodic internal and external audit. 

The Draft Guidance proposes a governance structure comprising a Data Function, Data Owners, Data Stewards, and Data Custodians, and sets out expectations across the data lifecycle. It also outlines requirements relating to data architecture, metadata, data quality, and third-party data sharing, while emphasizing continued accountability for data shared with third parties. The last date for stakeholder input submissions is August 17, 2026.

The Policy Team at DSCI is collating stakeholder inputs for submission. If you wish to submit your inputs, please share them by August 10, 2026. You may write to us at policy@dsci.in for the same.

The Personal Data Protection Commission (PDPC), Singapore, supported by IMAI released its Proposed Advisory Guidelines on Use of Personal Data in Generative AI on 2nd June 2026. The guidelines explain how the existing Personal Data Protection Act 2012 (PDPA) applies across the Generative AI lifecycle, covering the development, deployment, and post-deployment stages. They set out when organizations may rely on the Publicly Available Exception to collect personal data through web-scraping, require AI-specific notifications before personal data is used to train or fine-tune models, and allocate data protection responsibilities across Model Providers, System Providers, and System Deployers. The guidelines also address individuals' rights to access and correct their personal data. The last date for Submission is 1 July 2026.

Please share your inputs by 29th June 2026.

You may write to us at policy@dsci.in or your detailed input, clarifications or further discussions.

Focus Areas

Artificial intelligence

Cyber Security

Data Protection

Digital Economy

Emerging Technologies

DCPLA new batch announced
Certification 

Registration Open

DCPLA new batch announced

To protect privacy of personal information from unauthorized use, disclosure, modification, or misuse, DSCI conceptualized its approach towards privacy in the DSCI Privacy Framework (DPF©) which ...

Vector8
Security Chips
Podcast 

Releasing Soon

Security Chips

Listen to the best of tech wizards as they dish out their amazing experiences and insights on all things cyber security and privacy....

Vector8
FINSEC Conclave 2025
Event 

Registration Open

FINSEC Conclave 2025

The seventh edition of the DSCI FINSEC Conclave is all set to be the perfect congregation of policy, finance, and security spheres. This year's conclave will bring together the expertise, experie...

Vector8
LinkedIn Live
LinkedIn Live 

Releasing Soon

LinkedIn Live

Join us LIVE on LinkedIn as we bring together industry leaders every month to engage in a dynamic dialogue about the latest trends in cybersecurity and privacy....

Vector8
DSCI Digest: Edition V

date1 Mar 27, 2025 

DSCI Digest: Edition V 

We bring you the DSCI Digest for you to have a condensed understanding of the industry-relevant studies conducted by DSCI. It aims to help you learn and grasp the subjects in discussion in a succ...

Vector8
Privacy Pulse 2024-25

date1 Mar 27, 2025 

Privacy Pulse 2024-25 

An overview of DSCI’s privacy initiatives, in the last year, showcasing key achievements, new launches, industry collaborations and notable publications....

Vector8
DSCI Digest: Edition IV

date1 Jan 20, 2025 

DSCI Digest: Edition IV 

We bring you the DSCI Digest for you to have a condensed understanding of the industry-relevant studies conducted by DSCI. It aims to help you learn and grasp the subjects in discussion in a succ...

Vector8
Cyber for HER - Hackathon Empowering Women in Cyber Security

date1 Jan 17, 2025 

Cyber for HER - Hackathon Empowering Women in Cyber Security 

Like many nations, India faces a critical shortage of cyber security professionals. Significant progress has been made in acknowledging the value of cyber skill...

Vector8

Policy Submissions

2026
2025
2024
2023
2022

DSCI has provided feedback on the draft amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Draft Amendment). While DSCI broadly supports the underlying intent, it has offered observations on how the proposed changes may create unintended challenges that warrant consideration before the rules are finalized.

The Data Security Council of India (DSCI) has submitted feedback on the draft amendment to the AI Committee of the Supreme Court, on its preliminary draft of the Regulations for Use of Artificial Intelligence (AI) in Courts, 2026.

The Data Security Council of India (DSCI) has submitted feedback on the draft amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which aims to curb the malicious use of synthetically generated information. While supporting the intent, DSCI has proposed targeted recommendations to avoid unintended consequences and ensure effective implementation.

The Data Security Council of India (DSCI) responded to SEBI's AI/ML consultation paper on July 11, 2025, welcoming the initiative while advocating for regulatory clarity and global alignment. DSCI's recommendations centered around establishing clear definitional frameworks, implementing risk-proportionate regulatory approaches, and reducing compliance burdens through targeted oversight mechanisms. The submission emphasized practical terminology choices, flexible data management policies, and realistic bias mitigation expectations aligned with international standards. Additionally, DSCI proposed threshold-based reporting mechanisms to ensure regulatory focus remains on substantive risks rather than minor operational issues.

The Data Security Council of India (DSCI) submitted its response to the Draft Telecom Cybersecurity Rules, 2025 released by the Department of Telecommunications (Ministry of Communications) on July 23, 2025, supporting the intent while emphasizing the need for proportionate, practical, and innovation-friendly frameworks. DSCI highlighted concerns on potential regulatory overreach through expanded scope beyond telecom entities, jurisdictional overlaps with existing legislation, and compliance burdens that could impact startups and smaller businesses. The submission highlighted specific issues around mobile number validation requirements, data access provisions, and the need for stronger safeguards to balance cybersecurity objectives with privacy and operational feasibility. DSCI recommended adopting risk-based approaches that limit obligations to telecom providers, harmonize with existing laws, embed privacy principles, and ensure compliance mechanisms support rather than hinder India's digital innovation ecosystem.

The Data Security Council of India (DSCI) has provided feedback on India's draft Digital Personal Data Protection Rules, 2025, on 5th March 2025 appreciating the principle-based approach while offering targeted recommendations to improve clarity and implementation feasibility.

DSCI submitted its feedback on the AI Governance Guidelines Report on 27th February 2025. While DSCI generally acknowledged the principle-based governance of AI in the country. Suggested a few recommendations for further strengthening the implementation of those principles.

DSCI submitted its feedback on the draft Telecommunication Rules, 2024, viz. the draft Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, draft Temporary Suspension of Telecommunication Services Rules, 2024, draft Telecommunications (Telecom Cyber Security) Rules, 2024 and draft Telecommunications (Critical Telecommunication Infrastructure) Rules on 27th September 2024.

DSCI Submitted its feedback to the RBI’s Alternative Authentication Mechanism for Digital Payment Transactions which was released on 31st July 2024.

DSCI submitted its feedback to the Draft Digital Competition Bill, 2024 on 15th May, 2024 .

DSCI submitted its inputs on the National Strategy for Robotics while generally appreciating the efforts made by MeITY, the submissions largely focused on prescribing recommendations that could further strengthen the implementation of the policy.

DSCI Submitted its feedback on the National Deep Tech Start Up Policy, 2023.

DSCI submitted its feedback on the draft SEBI’s Cyber Security and Cyber Resilience Framework in the month of August 2023.

DSCI submitted its response to the draft RBI Consultation on Cyber Resilience and Digital Payments Security Controls on 30th June, 2023.

DSCI submitted its inputs on the draft amendments to the Aadhar Good Governance Rules 2020 on 4th May 2023.

  • DSCI Submissions on the amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

DSCI submitted its response to the Online Gaming Rules draft in January 2023. In its submission, DSCI welcomed the MeITY’s move to bring regulatory certainty and legitimacy to India’s growing online gaming sector.

The Data Security Council of India (DSCI) submitted its considered feedback on NITI Aayog’s third publication in the Responsible AI series, titled “Responsible AI for All: A Use Case Approach on Facial Recognition Technology (FRT)” released in 2022.

DSCI provided comprehensive feedback on the National Health Authority's consultation paper titled "Operationalising Unified Health Interface in India" in 2022.

The DSCI submitted a detailed response to the Open Network Digital Commerce consultation paper on "Building trust in the ONDC Network" in September 2022.

DSCI along with NASSCOM submitted a comprehensive response to the Telecom Regulatory Authority of India's consultation paper on "Leveraging Artificial Intelligence and Big Data in the Telecommunication Sector" released in August 2022.

Publications

 Brief On RBI's Draft Guidance on Regulatory Principles for Model Risk Management, 2026

June, 2026 

Brief On RBI's Draft Guidance on Regulatory Principles for Model Risk Management, 2026 

On June 24, 2026, the Reserve Bank of India released its draft Guidance on Regulatory Principles for Model Risk Management,...

Brief on Proposed Advisory Guidelines on Use of Personal Data in Generative AI, 2026 (Singapore)

June, 2026 

Brief on Proposed Advisory Guidelines on Use of Personal Data in Generative AI, 2026 (Singapore) 

The Personal Data Protection Commission (PDPC), Singapore, supported by IMAI released its Proposed Advisory Guide...

Brief on Draft Regulations for Use of Artificial Intelligence in Courts, 2026

June, 2026 

Brief on Draft Regulations for Use of Artificial Intelligence in Courts, 2026 

The Supreme Court released a preliminary draft titled “Regulations for Use of Artificial Intelligence (AI) in Courts, 2026”, which ai...

Brief on Draft Guidelines for Responsible Labelling of SGI in Advertising

June, 2026 

Brief on Draft Guidelines for Responsible Labelling of SGI in Advertising 

On May 8, 2025, the Advertising Standards Council of India (ASCI) released Draft Guidelines for Responsible Labelling of Synthetically Ge...

Operationalising DPDP and Privacy by Design through PETs

May, 2026 

Operationalising DPDP and Privacy by Design through PETs 

With the enforcement of India’s DPDP framework in November 2025, data protection must evolve from a compliance exercise into a design principle embedded a...

Brief on Draft Goa Artificial Intelligence Policy, 2026

May, 2026 

Brief on Draft Goa Artificial Intelligence Policy, 2026 

On May 04, 2026, the Government of Goa released the Draft Goa Artificial Intelligence Policy, 2026. Prepared by the Department of Information Technology, E...

Brief on RBI's Draft Master Direction on Prepaid Payment Instruments (PPIs), 2026

May, 2026 

Brief on RBI's Draft Master Direction on Prepaid Payment Instruments (PPIs), 2026 

The Reserve Bank of India (RBI) issued the Draft Master Direction on Prepaid Payment Instruments (PPIs), 2026 on 22nd April 2026 ...

Brief on IRDAI's Information and Cyber Security Guidelines, 2026

April, 2026 

Brief on IRDAI's Information and Cyber Security Guidelines, 2026 

The Insurance Regulatory and Development Authority of India (IRDAI) updated its Information and Cyber Security Guidelines in April 2026. The guide...

Apr 17, 2026

Summary of RBI’s Discussion Paper on Digital Payments Safeguards

The Reserve Bank of India’s discussion paper delineates a strategic shift in digital payment oversight, moving from a primary focus on transaction velocity toward a framework of "responsible conduct" to address the escalating threat of Authorized Push-Payment (APP) frauds. The discussion paper observes that while digital payment volumes have increased 38 fold over the last decade

Brief of TRAI Direction on UCC Detect for Spam Control, 2026

April, 2026 

Brief of TRAI Direction on UCC Detect for Spam Control, 2026 

On February 27, 2026, the Telecom Regulatory Authority of India (TRAI) issued a direction under the Telecom Commercial Communications Customer Prefere...

Draft Amendment to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

April, 2026 

Draft Amendment to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 

The Ministry of Electronics and Information Technology (MeitY) released a draft amendment to the Information Technolo...

Del(h)ivering AI: India AI Impact Summit and its Key Takeaways

March, 2026 

Del(h)ivering AI: India AI Impact Summit and its Key Takeaways 

New Delhi hosted the fourth global India AI Impact Summit 2026, organised by the IndiaAI Mission under MeitY, marking the first time a Global South ...

Analysis of the IT (Intermediary Liability and Digital Media Ethics Code) Amendment Rules, 2026

March, 2026 

Analysis of the IT (Intermediary Liability and Digital Media Ethics Code) Amendment Rules, 2026 

On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) introduced the Information Tec...

Brief on the National Counter-Terrorism Policy and Strategy

March, 2026 

Brief on the National Counter-Terrorism Policy and Strategy 

On February 23, 2026, the Ministry of Home Affairs (MHA) unveiled the National Counter-Terrorism Policy and Strategy. The strategy, referred to as ‘PRA...

Summary of  Office of PSA's Whitepaper on Strengthening AI Governance through Techno-Legal Framework

February, 2026 

Summary of Office of PSA's Whitepaper on Strengthening AI Governance through Techno-Legal Framework 

The white paper proposes a proactive “techno-legal” approach that embeds legal obligations directly into AI ar...

DSCI Analysis of Union Budget

February, 2026 

DSCI Analysis of Union Budget 

Union Budget 2026–27, presented in Parliament on 1 February 2026, comes at a time of heightened global uncertainty and ongoing supply-chain realignments. While reaffirming India’s c...

Summary of White Paper on Democratising Access to AI Infrastructure

January, 2026 

Summary of White Paper on Democratising Access to AI Infrastructure 

In December 2025, the Office of the Principal Scientific Adviser to the Government of India released a white paper titled “Democratising Acces...

January 12, 2026

IT (Amendment) Rules, 2026

On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (Final Rules), aimed at addressing the malicious use of synthetically generated information (SGI). The Final Rules mandate intermediaries offering SGI creation or dissemination tools to prominently label such content and remove it in cases of misuse, following a draft amendment released for public consultation in October 2025.

December 17, 2025

Summary of DoT Directives on SIM Binding

On November 28, 2025, the Department of Telecommunications (DoT) issued a directive requiring application-based communication services, including WhatsApp, Telegram, Signal, Arattai, Snapchat, ShareChat, JioChat, and Josh

December 16, 2025

Summary of India AI Governance Guidelines

The Ministry of Electronics and Information Technology (MeitY) released the India AI Governance Guidelines on 5th November 2025. These guidelines outline a governance framework designed to foster technological...

November 17, 2025

Insight Brief on Digital Personal Data Protection Rules 2025

This document provides a concise overview of the notified Digital Personal Data Protection Rules, 2025, issued by the Ministry of Electronics...

July 20, 2025

Explanatory Note on released FAQs for CSCRF and Cloud Adoption Framework for Regulated Entities by SEBI

SEBI released the 'Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) on August 20, 2024, and the framework for adoption of cloud services on March 06, 2023.

Dec 05, 2024

Assessing India’s Cybersecurity Regulations in a Dynamic Environment

The report, supported by SAP, offers a comprehensive exploration of India’s cybersecurity landscape and its applicability on Enterprises and Enterprise Service Providers (ESPs) like the Cloud Service Providers.

Sept 05, 2024

Explanatory note on SEBI notified Cyber Security and Cyber Resilience Framework

On August 20, 2024, the Securities Exchange Board of India (SEBI) introduced the Cyber Security and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) under section 11(1) of the SEBI Act.

July 02, 2024

Exploratory Note on Digital Market Regulations: Impact on Cybersecurity and Data Economy

This exploratory note is intended to analyze common trends that have emerged in proposed and enacted digital competition regulations globally and their impact on the global data economy and cybersecurity ecosystem. In its analysis the note draws

Apr 06, 2024

Privacy-Enhancing Technologies: Global and Cross-Sectoral Regulatory Insights

This report presents an expansive study on regulatory endorsements of Privacy-Enhancing Technologies (PETs) within India and across ten diverse global jurisdictions. The research focuses on five categories of PETs, namely, Cryptography-Based PETs,

June 04, 2024

Curbing Scams in Unified Payments Interface: A White Paper on Facilitating Real-Time Reporting and Management

The white paper discusses a set of solutions for the ecosystem of actors to consider in tackling and curbing the illegitimate activity of scamsters and other fraudulent actors over the very popular Unified Payments Interface (UPI) of India. Scams over UPI involve

March 21, 2024

Mitigating Security & Privacy Risks: A Guide to Enterprise Use of Generative AI

With rapidly increasing adoption of and investment into generative AI technologies, it is imperative for enterprise and business users to identify, examine, and prepare mitigation plans for risks arising out of this emerging technology to safeguard against

March 19, 2024

DSCI Privacy Leadership Forum | Release of guidance on ‘Privacy at the Workplace’

The document on ‘privacy at the Workplace’ is intended to shed light on the emerging trends and concerns with regard to ‘Right to Privacy’ in the context of employment or within a workplace. References to ‘employees’ in the scope of this document and

Feb 29, 2024

Accelerating Public Service Delivery through Cloud Adoption

As governments adapt to citizens' growing digital needs, cloud computing emerges as a potent tool for revolutionizing public service delivery and expediting digitization. While its advantages—scalability, security, and cost-effectiveness—are undeniable,

Feb 29, 2024

DSCI Privacy Leadership Forum | Release of guidance for industry on ‘Privacy by Design’

Privacy-by-design provides a framework for a holistic approach that can be adopted by an organization in protecting the privacy of their stakeholders across the spectrum, including their customers and employees among other parties. While use of personal data

Dec 21, 2023

The Future of Data Protection in India: Parts 1 and 2

Data protection regulation in India has been undertaken through a patchwork of national and sectoral regulations over the past two decades. However, in 2023, with the enactment of the Digital Personal Data Protection Act (DPDPA), India now has a

Dec 29, 2023

Exploratory note on Deepfakes and Policy Considerations

This exploratory note is intended to provide a high-level understanding of the legal and policy developments, industry interventions, and regulatory considerations associated with the proliferating use of deepfakes.

June 09, 2023

Exploratory note on Privacy, Data Protection and Large Language Models

This exploratory note is intended to map out the functioning of Large Language Models (LLMs), which form the basis of some of the popular generative AI services, against key data protection requirements globally.

May 2023 

Sectoral Privacy Guide: Banking Sector

The guide takes a customer-centric approach to recommending best practices in privacy for Banking Sector Participants (BSPs). This guide is useful for commercial banks, non-banking financial institutions

May 2023 

Sectoral Privacy Guide: Healthcare Sector

The guide would be of assistance especially to privacy and security professionals aligned with such health service providers that constantly handle health information

May 2023 

Sectoral Privacy Guide: Insurance Sector

The guide would be of assistance for Insurance Service Providers (ISPs) who process the personal data of policyholders. The guide is especially targeted towards privacy

Podcast