Indian Privacy Law & InfoSec for
Startups
Amol Naik
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Digital Personal Data Protection (DPDP) Act 2023
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Privacy Implementation
Internal
●Data Discovery
●Data Classification
●Data Security
●Infosec Policies
●Processes to fulfil Data Rights requestsExternal/Public
●Privacy Policy
●Concent
●Contact details for Data Rights
request
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Discovery
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
When penalties are applicable?
●In case of
○Data Breach
○failure to complete Data Rights requests
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Breach via Insecure Cloud Storage
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Breach via Insecure Database
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Breach via Credential Compromise
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Breach via Application/API Vulnerability
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Data Breach via Secrets in Code
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Take Away
●Reduce Internet facing servers
●Protect employee accounts with 2FA & SSO
●Remove secrets from code
●Focus on Cloud Security
●Test applications & APIs for security issues
●Restrict access to PII data internally
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
https://www.linkedin.com/in/amolnaik4/ @amolnaik4
Thank You !!
Amol Naik
https://www.linkedin.com/in/amolnaik4/
@amolnaik4