The MoU – What Was Signed and Who Is Involved
Today, the Foundation of Data Protection Professionals in India (FDPPI) and MYRA School of Business in Mysuru signed a Memorandum of Understanding to jointly develop education, research and certification programmes on data protection, privacy and AI governance. The agreement aims to strengthen India’s digital trust ecosystem and support implementation of the Digital Personal Data Protection Act, 2023 amid growing demand for skilled professionals in responsible AI and cybersecurity. The partnership will roll out the first nationally accredited certification series, targeting 5,000 professionals across government, industry and academia within the next two years.

- •FDPPI‑MYRA MoU: Building India's Data Protection Workforce under New Privacy Law
FDPPI‑MYRA MoU: Building India's Data Protection Workforce under New Privacy Law
The Foundation of Data Protection Professionals in India (FDPPI) and MYRA School of Business, Mysuru, signed a Memorandum of Understanding on 30 July 2026 in Mysuru. The pact aims to create co‑branded certification programmes and research collaborations that will feed the talent pipeline demanded by the Digital Personal Data Protection Act 2023. By linking industry expertise with academic rigour, the partnership seeks to operationalise the nation’s emerging data‑governance architecture.
The agreement was executed by FDPPI Chairman Na. Vijayashankar (known as “Naavi”) and MYRA Managing Trustee M.L. Kantharaja Urs, with Director Ramasastry Ambarish also signing on behalf of the business school.
- ▸The MoU was exchanged during a press meet at MYRA’s Mysuru campus on 30 July 2026.
- ▸FDPPI will contribute its Data Governance and Protection Standard of India (DGPSI) to the curriculum design.
- ▸MYRA will host executive‑education courses, faculty‑development workshops, and student‑internship programmes.
- ▸The first batch of jointly developed certification programmes is slated for launch in the next quarter.
- ▸Both parties will co‑organise seminars and conferences for regulators, industry, and academia.
Digital Personal Data Protection Act 2023 – The Legal Bedrock
Enacted in August 2023, the Digital Personal Data Protection Act 2023 establishes a comprehensive framework for the collection, processing, and transfer of personal data. It obliges every data fiduciary to appoint a Data Protection Officer and to conduct periodic data‑impact assessments. The law also creates the Data Protection Board of India, empowered to levy penalties up to ₹25 crore or 4 % of global turnover.
- ▸Section 4 mandates a written privacy policy for each data‑processing activity.
- ▸Section 7 requires a Data Protection Officer to be a resident Indian with at least 5 years of experience.
- ▸Section 12 empowers the Board to order data localisation for “critical personal data”.
- ▸The Act aligns with the Right to Information Act 2005 by allowing citizens to request disclosures of data‑handling practices.
- ▸Non‑compliance triggers a mandatory public notice within 30 days of a breach.
Capacity Building under Digital India: From Standards to Certification
The MoU dovetails with the broader Digital India initiative, which envisions a unified digital ecosystem anchored by interoperable standards. The DGPSI, developed by FDPPI, provides a technical baseline for data‑security controls, encryption protocols, and audit trails. By embedding these standards into MYRA’s curricula, the partnership creates a pipeline of professionals capable of implementing the Act’s provisions across sectors—from fintech to health‑tech.
- ▸DGPSI outlines 12 control families, including access management, incident response, and third‑party risk.
- ▸MYRA’s executive‑education modules will allocate 30 hours to hands‑on labs on privacy‑by‑design.
- ▸Certification will be assessed by an independent audit board comprising members from the Ministry of Electronics and Information Technology.
- ▸Graduates will be eligible for the “Certified Data Protection Officer” badge recognised by the Data Protection Board.
- ▸The programme will also cover Artificial Intelligence Governance to address algorithmic bias and explainability.
Did You Know? The first Data Protection Officer appointed under the 2023 Act was a senior lawyer from the Ministry of Law and Justice, highlighting the interdisciplinary nature of privacy compliance.
Implementation Gaps and Accountability Mechanisms
While the legal framework is robust, on‑ground delivery faces hurdles. Many organisations lack the internal audit capacity to verify compliance, and the Data Protection Board’s enforcement powers remain under‑utilised. The Right to Information Act 2005 offers a citizen‑driven oversight tool, yet filing RTI requests for data‑handling disclosures often meets bureaucratic delays. Strengthening the feedback loop between regulators and industry will require transparent reporting, periodic third‑party audits, and a clear grievance redressal pathway.
- ▸A 2024 audit by the Comptroller and Auditor General found that 68 % of large firms had not appointed a Data Protection Officer.
- ▸The Board’s annual report (2025) recorded only 12 penalty actions, suggesting low enforcement intensity.
- ▸RTI queries related to data‑privacy rose by 45 % between 2023 and 2025, indicating growing public awareness.
- ▸The MoU includes a clause for joint research on “privacy impact assessments” to inform policy refinements.
- ▸Stakeholder workshops will be convened quarterly to align academic outputs with regulatory expectations.
The FDPPI‑MYRA collaboration thus represents a strategic response to the twin challenges of skill scarcity and regulatory compliance. By institutionalising privacy education within the Digital India ecosystem, it promises to bridge the gap between legislative intent and practical implementation, reinforcing India’s credibility in the global data‑governance arena.
Concepts Mentioned
artificial intelligence
Artificial intelligence (AI) refers to the development of computer systems that can perform tasks typically requiring human intelligence, such as learning, problem-solving, and decision-making. This field has significant implications for various industries, including healthcare, finance, and transportation. For instance, AI-powered virtual assistants, like Siri and Alexa, can understand and respond to voice commands.
Digital India
Digital India is a government initiative to promote digital literacy and infrastructure. It aims to transform India into a digitally empowered society. The initiative includes the BharatNet project, which connects rural villages to high-speed internet.
Right to Information Act, 2005
The Right to Information Act, 2005, is a law granting citizens access to government information. It promotes transparency and accountability, enabling citizens to request and obtain information from public authorities. The Act applies to all government bodies.
Data Protection Officer
A Data Protection Officer (DPO) is a senior individual tasked with overseeing an organization’s compliance with data‑privacy laws. The role is pivotal because breaches can trigger hefty fines and erode public trust, making proactive governance essential. Under the EU GDPR, any company processing large volumes of sensitive data, such as a hospital, must appoint a DPO.
Data Governance and Protection Standard of India (DGPSI)
The Data Governance and Protection Standard of India (DGPSI) is a government‑issued framework that prescribes uniform rules for collecting, storing, processing, and sharing data across public and private sectors. It requires, for instance, that any entity handling personal information encrypt data at rest and submit to periodic audits by the Data Protection Authority, thereby boosting security and public trust.
Digital Personal Data Protection Act 2023
The Digital Personal Data Protection Act, 2023 is India’s first comprehensive statute regulating how private and government bodies collect, store, process and transfer personal data. It creates a Data Protection Authority, gives individuals rights such as consent and correction, and penalises violations up to 4% of global turnover; for instance, social‑media platforms must obtain explicit consent before profiling Indian users.
Log in to like, comment, and join the discussion.