The Policy and Advocacy function at the Data Security Council of India (DSCI) serves as a strategic interface between industry, government, academia, start-ups, and other key stakeholders to shape progressive and forward-looking policies on cybersecurity, data protection, the digital economy, artificial intelligence, and other emerging technologies. This function also supports DSCI’s broader mission by contributing to knowledge-building efforts in technology policy, with a strong emphasis on privacy and security.
The key roles served by the policy advocacy function include:
Through these initiatives, DSCI’s Policy team plays a pivotal role in advancing a secure and trusted cyberspace while positioning India as a global leader in digital innovation, cybersecurity, and responsible technology governance.
In September 2026, the Insurance Regulatory and Development Authority of India (“IRDAI”) released a public consultation paper titled “Public Insurance Registry - Digital Public Infrastructure for Insurance’ on creating the proposed Public Insurance Registry (“PIR”). By establishing a standardized, interoperable data layer, the PIR aims to increase financial inclusion, build consumer trust, and reduce the high costs associated with manual documentation. The PIR serves a wide array of stakeholders, including policyholders who gain a consolidated view of their coverage, and insurers who benefit from sharper risk assessment and streamlined regulatory reporting.
Key Highlights
The Policy Team at the Data Security Council of India is in the process of collating and preparing a consolidated submission and would request interested stakeholders to submit their inputs to policy[at]dsci[dot]in by Monday, September 28, 2026.
Artificial intelligence
Cyber Security
Data Protection
Digital Economy
Emerging Technologies

To protect privacy of personal information from unauthorized use, disclosure, modification, or misuse, DSCI conceptualized its approach towards privacy in the DSCI Privacy Framework (DPF©) which ...

Listen to the best of tech wizards as they dish out their amazing experiences and insights on all things cyber security and privacy....
The seventh edition of the DSCI FINSEC Conclave is all set to be the perfect congregation of policy, finance, and security spheres. This year's conclave will bring together the expertise, experie...
Join us LIVE on LinkedIn as we bring together industry leaders every month to engage in a dynamic dialogue about the latest trends in cybersecurity and privacy....

We bring you the DSCI Digest for you to have a condensed understanding of the industry-relevant studies conducted by DSCI. It aims to help you learn and grasp the subjects in discussion in a succ...

An overview of DSCI’s privacy initiatives, in the last year, showcasing key achievements, new launches, industry collaborations and notable publications....

We bring you the DSCI Digest for you to have a condensed understanding of the industry-relevant studies conducted by DSCI. It aims to help you learn and grasp the subjects in discussion in a succ...
Like many nations, India faces a critical shortage of cyber security professionals. Significant progress has been made in acknowledging the value of cyber skill...
In September 2026, IRDAI released a consultation paper proposing the Public Insurance Registry (PIR), a digital public infrastructure for insurance that seeks to create a standardized and interoperable data layer for the sector. The PIR is designed to improve financial inclusion, enhance consumer trust, and streamline insurance access through a privacy-centric, consent-based framework. Key highlights include a federated data architecture that minimizes data collection, strong DPDP-aligned privacy safeguards, benefits for a broad range of stakeholders, and a phased implementation model under IRDAI-led governance.
This submission is DSCI's industrial consolidated response to RBI's Draft Guidance on AI/ML model risk management, flagging gaps around undefined terms, overlapping governance structures, third-party vendor accountability, and weak operational safeguards like kill-switches and incident reporting.
DSCI has provided feedback on the Reserve Bank of India’s Draft Guidance on Regulatory Expectations for Data Governance (“Draft Guidance”). While DSCI broadly supports the objectives of the Draft Guidance, it has offered observations and recommendations to improve clarity, proportionality, and ease of implementation.
DSCI has provided feedback on the draft amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Draft Amendment). While DSCI broadly supports the underlying intent, it has offered observations on how the proposed changes may create unintended challenges that warrant consideration before the rules are finalized.
The Data Security Council of India (DSCI) has submitted feedback on the draft amendment to the AI Committee of the Supreme Court, on its preliminary draft of the Regulations for Use of Artificial Intelligence (AI) in Courts, 2026.
The Data Security Council of India (DSCI) has submitted feedback on the draft amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which aims to curb the malicious use of synthetically generated information. While supporting the intent, DSCI has proposed targeted recommendations to avoid unintended consequences and ensure effective implementation.
The Data Security Council of India (DSCI) responded to SEBI's AI/ML consultation paper on July 11, 2025, welcoming the initiative while advocating for regulatory clarity and global alignment. DSCI's recommendations centered around establishing clear definitional frameworks, implementing risk-proportionate regulatory approaches, and reducing compliance burdens through targeted oversight mechanisms. The submission emphasized practical terminology choices, flexible data management policies, and realistic bias mitigation expectations aligned with international standards. Additionally, DSCI proposed threshold-based reporting mechanisms to ensure regulatory focus remains on substantive risks rather than minor operational issues.
The Data Security Council of India (DSCI) submitted its response to the Draft Telecom Cybersecurity Rules, 2025 released by the Department of Telecommunications (Ministry of Communications) on July 23, 2025, supporting the intent while emphasizing the need for proportionate, practical, and innovation-friendly frameworks. DSCI highlighted concerns on potential regulatory overreach through expanded scope beyond telecom entities, jurisdictional overlaps with existing legislation, and compliance burdens that could impact startups and smaller businesses. The submission highlighted specific issues around mobile number validation requirements, data access provisions, and the need for stronger safeguards to balance cybersecurity objectives with privacy and operational feasibility. DSCI recommended adopting risk-based approaches that limit obligations to telecom providers, harmonize with existing laws, embed privacy principles, and ensure compliance mechanisms support rather than hinder India's digital innovation ecosystem.
The Data Security Council of India (DSCI) has provided feedback on India's draft Digital Personal Data Protection Rules, 2025, on 5th March 2025 appreciating the principle-based approach while offering targeted recommendations to improve clarity and implementation feasibility.
DSCI submitted its feedback on the AI Governance Guidelines Report on 27th February 2025. While DSCI generally acknowledged the principle-based governance of AI in the country. Suggested a few recommendations for further strengthening the implementation of those principles.
DSCI submitted its feedback on the draft Telecommunication Rules, 2024, viz. the draft Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, draft Temporary Suspension of Telecommunication Services Rules, 2024, draft Telecommunications (Telecom Cyber Security) Rules, 2024 and draft Telecommunications (Critical Telecommunication Infrastructure) Rules on 27th September 2024.
DSCI Submitted its feedback to the RBI’s Alternative Authentication Mechanism for Digital Payment Transactions which was released on 31st July 2024.
DSCI submitted its feedback to the Draft Digital Competition Bill, 2024 on 15th May, 2024 .
DSCI submitted its inputs on the National Strategy for Robotics while generally appreciating the efforts made by MeITY, the submissions largely focused on prescribing recommendations that could further strengthen the implementation of the policy.
DSCI Submitted its feedback on the National Deep Tech Start Up Policy, 2023.
DSCI submitted its feedback on the draft SEBI’s Cyber Security and Cyber Resilience Framework in the month of August 2023.
DSCI submitted its response to the draft RBI Consultation on Cyber Resilience and Digital Payments Security Controls on 30th June, 2023.
DSCI submitted its inputs on the draft amendments to the Aadhar Good Governance Rules 2020 on 4th May 2023.
DSCI submitted its response to the Online Gaming Rules draft in January 2023. In its submission, DSCI welcomed the MeITY’s move to bring regulatory certainty and legitimacy to India’s growing online gaming sector.
The Data Security Council of India (DSCI) submitted its considered feedback on NITI Aayog’s third publication in the Responsible AI series, titled “Responsible AI for All: A Use Case Approach on Facial Recognition Technology (FRT)” released in 2022.
DSCI provided comprehensive feedback on the National Health Authority's consultation paper titled "Operationalising Unified Health Interface in India" in 2022.
The DSCI submitted a detailed response to the Open Network Digital Commerce consultation paper on "Building trust in the ONDC Network" in September 2022.
DSCI along with NASSCOM submitted a comprehensive response to the Telecom Regulatory Authority of India's consultation paper on "Leveraging Artificial Intelligence and Big Data in the Telecommunication Sector" released in August 2022.
In September 2026, the Advertising Standards Council of India introduced the Guidelines for Responsible Labelling of Synthetically Generated Content in Advertising ("the Guidelines"), which set out when advertisers must disclose the use of AI-generated content and identify categories of synthetic content that may not be used in advertising. Developed following stakeholder consultations on a draft released in May 2026, the Guidelines respond to the growing use of AI to create, enhance, and personalize advertising content. The Guidelines will take effect three months after publication.
In September 2026, IRDAI released a consultation paper proposing the Public Insurance Registry (PIR), a digital public infrastructure for insurance that seeks to create a standardized and interoperable data layer for the sector. The PIR is designed to improve financial inclusion, enhance consumer trust, and streamline insurance access through a privacy-centric, consent-based framework. Key highlights include a federated data architecture that minimizes data collection, strong DPDP-aligned privacy safeguards, benefits for a broad range of stakeholders, and a phased implementation model under IRDAI-led governance.
OPSA releases Discussion Paper on “Enabling Cross-Border Data Interoperability for AI Systems” (September 2026) examining how India can enable trusted cross-border data use for AI while balancing data sovereignty, privacy, regulatory autonomy and innovation. It explores a risk-based framework centered on technical compatibility, accountability and institutional coordination, including differentiated approaches to data access, controlled processing, auditability and the use of model-to-data mechanisms for sensitive datasets.
The Department of Consumer Affairs, Government of India, has amended the Consumer Protection (E-Commerce) Rules, 2020 through the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 to strengthen consumer protection and promote greater transparency in the e-commerce ecosystem. The amendments seek to address evolving consumer concerns in the digital marketplace while ensuring a balanced regulatory framework that supports both consumer interests and Ease of Doing Business.
In September 2026, the Reserve Bank of India issued the Draft RBI (KYC) Amendment Directions, 2026, following the Supreme Court's order dated August 4, 2026. The draft amends the KYC Directions, 2025, and introduces a Standard Operating Procedure (SOP) for banks on placing temporary debit holds on accounts or funds linked to money mule activity and cyber-enabled financial fraud.
In July 2026, the Delhi High Court delivered an interim judgment in ANI Media Pvt. Ltd. v. OpenAI OpCo LLC (2026), marking India's first substantive judicial examination of how copyright law applies to the training and operation of large language models (LLMs).
On 20 July 2026, the Department of Telecommunications notified the Telecommunications (Authorization for Telecommunication Network) Rules, 2026, establishing a unified authorization framework for establishing, operating, maintaining and expanding telecommunication networks.
The Reserve Bank of India issued the RBI (Commercial Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 on the 31st of July 2026. The directions come into effect immediately upon issuance, underscoring the urgency the RBI attaches to cyber security preparedness in the banking sector.
The Reserve Bank of India has released the draft Guidance on Regulatory Expectations for Data Governance, setting out expectations for how Regulated Entities should govern data as an organizational asset.
On June 24, 2026, the Reserve Bank of India released its draft Guidance on Regulatory Principles for Model Risk Management,...
The Personal Data Protection Commission (PDPC), Singapore, supported by IMAI released its Proposed Advisory Guide...
The Supreme Court released a preliminary draft titled “Regulations for Use of Artificial Intelligence (AI) in Courts, 2026”, which ai...
On May 8, 2025, the Advertising Standards Council of India (ASCI) released Draft Guidelines for Responsible Labelling of Synthetically Ge...
With the enforcement of India’s DPDP framework in November 2025, data protection must evolve from a compliance exercise into a design principle embedded a...
On May 04, 2026, the Government of Goa released the Draft Goa Artificial Intelligence Policy, 2026. Prepared by the Department of Information Technology, E...
The Reserve Bank of India (RBI) issued the Draft Master Direction on Prepaid Payment Instruments (PPIs), 2026 on 22nd April 2026 ...
The Insurance Regulatory and Development Authority of India (IRDAI) updated its Information and Cyber Security Guidelines in April 2026. The guide...
The Reserve Bank of India’s discussion paper delineates a strategic shift in digital payment oversight, moving from a primary focus on transaction velocity toward a framework of "responsible conduct" to address the escalating threat of Authorized Push-Payment (APP) frauds. The discussion paper observes that while digital payment volumes have increased 38 fold over the last decade
On February 27, 2026, the Telecom Regulatory Authority of India (TRAI) issued a direction under the Telecom Commercial Communications Customer Prefere...
The Ministry of Electronics and Information Technology (MeitY) released a draft amendment to the Information Technolo...
New Delhi hosted the fourth global India AI Impact Summit 2026, organised by the IndiaAI Mission under MeitY, marking the first time a Global South ...
On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) introduced the Information Tec...
On February 23, 2026, the Ministry of Home Affairs (MHA) unveiled the National Counter-Terrorism Policy and Strategy. The strategy, referred to as ‘PRA...
The white paper proposes a proactive “techno-legal” approach that embeds legal obligations directly into AI ar...
Union Budget 2026–27, presented in Parliament on 1 February 2026, comes at a time of heightened global uncertainty and ongoing supply-chain realignments. While reaffirming India’s c...
In December 2025, the Office of the Principal Scientific Adviser to the Government of India released a white paper titled “Democratising Acces...
On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (Final Rules), aimed at addressing the malicious use of synthetically generated information (SGI). The Final Rules mandate intermediaries offering SGI creation or dissemination tools to prominently label such content and remove it in cases of misuse, following a draft amendment released for public consultation in October 2025.
SEBI released the 'Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) on August 20, 2024, and the framework for adoption of cloud services on March 06, 2023.
This exploratory note is intended to analyze common trends that have emerged in proposed and enacted digital competition regulations globally and their impact on the global data economy and cybersecurity ecosystem. In its analysis the note draws
This report presents an expansive study on regulatory endorsements of Privacy-Enhancing Technologies (PETs) within India and across ten diverse global jurisdictions. The research focuses on five categories of PETs, namely, Cryptography-Based PETs,
The white paper discusses a set of solutions for the ecosystem of actors to consider in tackling and curbing the illegitimate activity of scamsters and other fraudulent actors over the very popular Unified Payments Interface (UPI) of India. Scams over UPI involve
With rapidly increasing adoption of and investment into generative AI technologies, it is imperative for enterprise and business users to identify, examine, and prepare mitigation plans for risks arising out of this emerging technology to safeguard against
The document on ‘privacy at the Workplace’ is intended to shed light on the emerging trends and concerns with regard to ‘Right to Privacy’ in the context of employment or within a workplace. References to ‘employees’ in the scope of this document and
As governments adapt to citizens' growing digital needs, cloud computing emerges as a potent tool for revolutionizing public service delivery and expediting digitization. While its advantages—scalability, security, and cost-effectiveness—are undeniable,
Privacy-by-design provides a framework for a holistic approach that can be adopted by an organization in protecting the privacy of their stakeholders across the spectrum, including their customers and employees among other parties. While use of personal data
Data protection regulation in India has been undertaken through a patchwork of national and sectoral regulations over the past two decades. However, in 2023, with the enactment of the Digital Personal Data Protection Act (DPDPA), India now has a