IAPP Asia Forum 2026

Privacy | AI governance | Cybersecurity law

SINGAPORE

21-23 July

Back to conference agenda

Navigating India’s Personal Data Breach Regime in the AI Age

Wednesday, 22 July

14:45 - 15:45 SGT

Intermediate level

BREAKOUT SESSIONAI GOVERNANCEPRIVACYAI LITERACYDATA SECURITYINCIDENT MANAGEMENTLAW AND REGULATIONREGULATORY GUIDANCETECHNOLOGY

India’s Digital Personal Data Protection Act, 2023 is set to revamp privacy practices in the region by May 2027. It reserves its highest penalties for personal data breaches: USD22 million for not reporting a breach to an affected person or the Data Protection Board of India; and USD28 million for not implementing “reasonable security safeguards” to prevent breaches. By enabling the board to adopt “techno-legal measures,” the DPDPA anticipates the use of automated tools to implement such requirements.

This session unpacks the DPDPA’s breach-related requirements and examines if their design will remain suited to a rapidly AI-driven environment. It will explore how AI is changing the scale, speed and entryways for personal data breaches; how global regulators and entities are, accordingly, adapting their existing reporting regimes; and what lessons this may hold for India’s Board and regulated entities building compliance systems in the region.

What you will learn:

• How new AI applications, such as generative AI tools and agentic AI systems, are re-shaping the nature and scale of personal data breaches.

• The DPDPA’s breach-related requirements and identifying practical compliance lessons based on insights from parallel regimes in Asia and Europe.

• How AI tools can improve breach detection and reporting, and if they can enable “techno-legal” measures to comply with the DPDPA’s breach regime.

Moderator and speakers

headshot of Varun Sen Bahl

Varun Sen Bahl

Lawyer and Tech Policy Researcher

headshot of Bilal Mohamed

Bilal Mohamed

Policy Manager for India

Future of Privacy Forum

headshot of Karishma Sundara

Karishma Sundara

Founder

Kintsugi Law

headshot of Monika Tomczak-Górlikowska

Monika Tomczak-Górlikowska

AIGP, CIPP/E, CIPT

Group Head of Privacy, Digital and Regulatory

Prosus and Naspers