The Policy and Advocacy function at the Data Security Council of India (DSCI) serves as a strategic interface between industry, government, academia, start-ups, and other key stakeholders to shape progressive and forward-looking policies on cybersecurity, data protection, the digital economy, artificial intelligence, and other emerging technologies. This function also supports DSCI’s broader mission by contributing to knowledge-building efforts in technology policy, with a strong emphasis on privacy and security.
The key roles served by the policy advocacy function include:
Through these initiatives, DSCI’s Policy team plays a pivotal role in advancing a secure and trusted cyberspace while positioning India as a global leader in digital innovation, cybersecurity, and responsible technology governance.
The Reserve Bank of India released its Draft Guidance on Regulatory Expectations for Data Governance in July 2026. The Draft Guidance sets out expectations for how Regulated Entities should govern data as an organisational asset through a proportionate Data Governance Framework (DGF) aligned with their risk management framework. The DGF must be overseen by a Board-level Data Governance Committee and implemented by a Data Governance Executive Committee, with data risk managed as part of the overall risk framework and the Framework subject to periodic internal and external audit.
The Draft Guidance proposes a governance structure comprising a Data Function, Data Owners, Data Stewards, and Data Custodians, and sets out expectations across the data lifecycle. It also outlines requirements relating to data architecture, metadata, data quality, and third-party data sharing, while emphasizing continued accountability for data shared with third parties. The last date for stakeholder input submissions is August 17, 2026.
The Policy Team at DSCI is collating stakeholder inputs for submission. If you wish to submit your inputs, please share them by August 10, 2026. You may write to us at policy@dsci.in for the same.
The Personal Data Protection Commission (PDPC), Singapore, supported by IMAI released its Proposed Advisory Guidelines on Use of Personal Data in Generative AI on 2nd June 2026. The guidelines explain how the existing Personal Data Protection Act 2012 (PDPA) applies across the Generative AI lifecycle, covering the development, deployment, and post-deployment stages. They set out when organizations may rely on the Publicly Available Exception to collect personal data through web-scraping, require AI-specific notifications before personal data is used to train or fine-tune models, and allocate data protection responsibilities across Model Providers, System Providers, and System Deployers. The guidelines also address individuals' rights to access and correct their personal data. The last date for Submission is 1 July 2026.
Please share your inputs by 29th June 2026.
You may write to us at policy@dsci.in or your detailed input, clarifications or further discussions.
Artificial intelligence
Cyber Security
Data Protection
Digital Economy
Emerging Technologies

To protect privacy of personal information from unauthorized use, disclosure, modification, or misuse, DSCI conceptualized its approach towards privacy in the DSCI Privacy Framework (DPF©) which ...

Listen to the best of tech wizards as they dish out their amazing experiences and insights on all things cyber security and privacy....
The seventh edition of the DSCI FINSEC Conclave is all set to be the perfect congregation of policy, finance, and security spheres. This year's conclave will bring together the expertise, experie...
Join us LIVE on LinkedIn as we bring together industry leaders every month to engage in a dynamic dialogue about the latest trends in cybersecurity and privacy....

We bring you the DSCI Digest for you to have a condensed understanding of the industry-relevant studies conducted by DSCI. It aims to help you learn and grasp the subjects in discussion in a succ...

An overview of DSCI’s privacy initiatives, in the last year, showcasing key achievements, new launches, industry collaborations and notable publications....

We bring you the DSCI Digest for you to have a condensed understanding of the industry-relevant studies conducted by DSCI. It aims to help you learn and grasp the subjects in discussion in a succ...
Like many nations, India faces a critical shortage of cyber security professionals. Significant progress has been made in acknowledging the value of cyber skill...
DSCI has provided feedback on the draft amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Draft Amendment). While DSCI broadly supports the underlying intent, it has offered observations on how the proposed changes may create unintended challenges that warrant consideration before the rules are finalized.
The Data Security Council of India (DSCI) has submitted feedback on the draft amendment to the AI Committee of the Supreme Court, on its preliminary draft of the Regulations for Use of Artificial Intelligence (AI) in Courts, 2026.
The Data Security Council of India (DSCI) has submitted feedback on the draft amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which aims to curb the malicious use of synthetically generated information. While supporting the intent, DSCI has proposed targeted recommendations to avoid unintended consequences and ensure effective implementation.
The Data Security Council of India (DSCI) responded to SEBI's AI/ML consultation paper on July 11, 2025, welcoming the initiative while advocating for regulatory clarity and global alignment. DSCI's recommendations centered around establishing clear definitional frameworks, implementing risk-proportionate regulatory approaches, and reducing compliance burdens through targeted oversight mechanisms. The submission emphasized practical terminology choices, flexible data management policies, and realistic bias mitigation expectations aligned with international standards. Additionally, DSCI proposed threshold-based reporting mechanisms to ensure regulatory focus remains on substantive risks rather than minor operational issues.
The Data Security Council of India (DSCI) submitted its response to the Draft Telecom Cybersecurity Rules, 2025 released by the Department of Telecommunications (Ministry of Communications) on July 23, 2025, supporting the intent while emphasizing the need for proportionate, practical, and innovation-friendly frameworks. DSCI highlighted concerns on potential regulatory overreach through expanded scope beyond telecom entities, jurisdictional overlaps with existing legislation, and compliance burdens that could impact startups and smaller businesses. The submission highlighted specific issues around mobile number validation requirements, data access provisions, and the need for stronger safeguards to balance cybersecurity objectives with privacy and operational feasibility. DSCI recommended adopting risk-based approaches that limit obligations to telecom providers, harmonize with existing laws, embed privacy principles, and ensure compliance mechanisms support rather than hinder India's digital innovation ecosystem.
The Data Security Council of India (DSCI) has provided feedback on India's draft Digital Personal Data Protection Rules, 2025, on 5th March 2025 appreciating the principle-based approach while offering targeted recommendations to improve clarity and implementation feasibility.
DSCI submitted its feedback on the AI Governance Guidelines Report on 27th February 2025. While DSCI generally acknowledged the principle-based governance of AI in the country. Suggested a few recommendations for further strengthening the implementation of those principles.
DSCI submitted its feedback on the draft Telecommunication Rules, 2024, viz. the draft Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, draft Temporary Suspension of Telecommunication Services Rules, 2024, draft Telecommunications (Telecom Cyber Security) Rules, 2024 and draft Telecommunications (Critical Telecommunication Infrastructure) Rules on 27th September 2024.
DSCI Submitted its feedback to the RBI’s Alternative Authentication Mechanism for Digital Payment Transactions which was released on 31st July 2024.
DSCI submitted its feedback to the Draft Digital Competition Bill, 2024 on 15th May, 2024 .
DSCI submitted its inputs on the National Strategy for Robotics while generally appreciating the efforts made by MeITY, the submissions largely focused on prescribing recommendations that could further strengthen the implementation of the policy.
DSCI Submitted its feedback on the National Deep Tech Start Up Policy, 2023.
DSCI submitted its feedback on the draft SEBI’s Cyber Security and Cyber Resilience Framework in the month of August 2023.
DSCI submitted its response to the draft RBI Consultation on Cyber Resilience and Digital Payments Security Controls on 30th June, 2023.
DSCI submitted its inputs on the draft amendments to the Aadhar Good Governance Rules 2020 on 4th May 2023.
DSCI submitted its response to the Online Gaming Rules draft in January 2023. In its submission, DSCI welcomed the MeITY’s move to bring regulatory certainty and legitimacy to India’s growing online gaming sector.
The Data Security Council of India (DSCI) submitted its considered feedback on NITI Aayog’s third publication in the Responsible AI series, titled “Responsible AI for All: A Use Case Approach on Facial Recognition Technology (FRT)” released in 2022.
DSCI provided comprehensive feedback on the National Health Authority's consultation paper titled "Operationalising Unified Health Interface in India" in 2022.
The DSCI submitted a detailed response to the Open Network Digital Commerce consultation paper on "Building trust in the ONDC Network" in September 2022.
DSCI along with NASSCOM submitted a comprehensive response to the Telecom Regulatory Authority of India's consultation paper on "Leveraging Artificial Intelligence and Big Data in the Telecommunication Sector" released in August 2022.
On June 24, 2026, the Reserve Bank of India released its draft Guidance on Regulatory Principles for Model Risk Management,...
The Personal Data Protection Commission (PDPC), Singapore, supported by IMAI released its Proposed Advisory Guide...
The Supreme Court released a preliminary draft titled “Regulations for Use of Artificial Intelligence (AI) in Courts, 2026”, which ai...
On May 8, 2025, the Advertising Standards Council of India (ASCI) released Draft Guidelines for Responsible Labelling of Synthetically Ge...
With the enforcement of India’s DPDP framework in November 2025, data protection must evolve from a compliance exercise into a design principle embedded a...
On May 04, 2026, the Government of Goa released the Draft Goa Artificial Intelligence Policy, 2026. Prepared by the Department of Information Technology, E...
The Reserve Bank of India (RBI) issued the Draft Master Direction on Prepaid Payment Instruments (PPIs), 2026 on 22nd April 2026 ...
The Insurance Regulatory and Development Authority of India (IRDAI) updated its Information and Cyber Security Guidelines in April 2026. The guide...
The Reserve Bank of India’s discussion paper delineates a strategic shift in digital payment oversight, moving from a primary focus on transaction velocity toward a framework of "responsible conduct" to address the escalating threat of Authorized Push-Payment (APP) frauds. The discussion paper observes that while digital payment volumes have increased 38 fold over the last decade
On February 27, 2026, the Telecom Regulatory Authority of India (TRAI) issued a direction under the Telecom Commercial Communications Customer Prefere...
The Ministry of Electronics and Information Technology (MeitY) released a draft amendment to the Information Technolo...
New Delhi hosted the fourth global India AI Impact Summit 2026, organised by the IndiaAI Mission under MeitY, marking the first time a Global South ...
On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) introduced the Information Tec...
On February 23, 2026, the Ministry of Home Affairs (MHA) unveiled the National Counter-Terrorism Policy and Strategy. The strategy, referred to as ‘PRA...
The white paper proposes a proactive “techno-legal” approach that embeds legal obligations directly into AI ar...
Union Budget 2026–27, presented in Parliament on 1 February 2026, comes at a time of heightened global uncertainty and ongoing supply-chain realignments. While reaffirming India’s c...
In December 2025, the Office of the Principal Scientific Adviser to the Government of India released a white paper titled “Democratising Acces...
On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (Final Rules), aimed at addressing the malicious use of synthetically generated information (SGI). The Final Rules mandate intermediaries offering SGI creation or dissemination tools to prominently label such content and remove it in cases of misuse, following a draft amendment released for public consultation in October 2025.
SEBI released the 'Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) on August 20, 2024, and the framework for adoption of cloud services on March 06, 2023.
This exploratory note is intended to analyze common trends that have emerged in proposed and enacted digital competition regulations globally and their impact on the global data economy and cybersecurity ecosystem. In its analysis the note draws
This report presents an expansive study on regulatory endorsements of Privacy-Enhancing Technologies (PETs) within India and across ten diverse global jurisdictions. The research focuses on five categories of PETs, namely, Cryptography-Based PETs,
The white paper discusses a set of solutions for the ecosystem of actors to consider in tackling and curbing the illegitimate activity of scamsters and other fraudulent actors over the very popular Unified Payments Interface (UPI) of India. Scams over UPI involve
With rapidly increasing adoption of and investment into generative AI technologies, it is imperative for enterprise and business users to identify, examine, and prepare mitigation plans for risks arising out of this emerging technology to safeguard against
The document on ‘privacy at the Workplace’ is intended to shed light on the emerging trends and concerns with regard to ‘Right to Privacy’ in the context of employment or within a workplace. References to ‘employees’ in the scope of this document and
As governments adapt to citizens' growing digital needs, cloud computing emerges as a potent tool for revolutionizing public service delivery and expediting digitization. While its advantages—scalability, security, and cost-effectiveness—are undeniable,
Privacy-by-design provides a framework for a holistic approach that can be adopted by an organization in protecting the privacy of their stakeholders across the spectrum, including their customers and employees among other parties. While use of personal data
Data protection regulation in India has been undertaken through a patchwork of national and sectoral regulations over the past two decades. However, in 2023, with the enactment of the Digital Personal Data Protection Act (DPDPA), India now has a