By: Karnvir Mundrey
I went to Privacy by Design 2026 expecting a discussion about compliance. I left with an uncomfortable answer to a much larger question: what will it take for the world to trust Indian business?
Halfway through a morning panel at Privacy by Design 2026 in Bengaluru, I raised my hand.
I did not ask about a clause in the Digital Personal Data Protection Act or what compliance would cost. I asked a question that felt more uncomfortable the moment it left my mouth.
Why do so many international businesses still hesitate to trust Indian companies?
Some of my work involves helping Indian businesses enter overseas markets and helping foreign companies find partners here, including in aerospace. Everywhere, I hear the same hesitation. Indian firms are admired for intelligence and ingenuity, yet doubts remain about precision, transparency and whether a promise will survive pressure. In aerospace, a component specified at 5 millimetres cannot arrive at 5.001. Could we build a rating mechanism, I asked, to make trust visible?
No single panellist answered me completely. The answer arrived in fragments over the day. It came in a grocery history a company refused to delete, and a ₹5 lakh loan taken out in a stranger’s name. It came in a Danish furniture company that forgot to switch off an old computer system, and a warning that sat unread on the Titanic for two hours. And it came in the story of an Indian company that won overseas business by saying one word.
No.
By evening, the fragments had formed a conclusion. India’s next startup crisis may not begin with a shortage of capital. It may begin in the gap between what our companies promise and what their systems can prove.
That gap is called trust.
A privacy conference that was really about growth
DPDP Zone’s Privacy by Design 2026 took place at the Radisson Blu Atria on 18 September. This Week India reported 350 attendees, including about 250 founders and representatives of 35 venture capital firms, alongside lawyers, security chiefs, bankers and product leaders.
The programme was built around a commercial argument rather than a legal one. DPDP, the organisers said, is not a box to tick but a way to win customers and investors.
The clock made that argument urgent. The DPDP Rules were notified in November 2025. The Consent Manager framework and the penalty machinery switch on in November 2026. On 13 May 2027, everything else applies: consent, security, breach reporting, retention and deletion. Penalties reach ₹250 crore for failing to protect data and ₹200 crore for failing to report a breach, and they can stack.
₹250 crore is not a number that scales down politely for a startup.
Sharath Shyamasunder, founder of DPDP Zone, opened by discarding the most tired metaphor in technology. “Data isn’t oil. Data is us,” he said.
Oil is an inert commodity. Data can reveal an illness, a salary, a debt, a fear. A company holds fragments of human lives, often from people who clicked “accept” without knowing where those fragments would travel.
Sharath called DPDP India’s “GST moment” for privacy. Companies that adapted early to GST came out with cleaner processes and faster operations. Early privacy adopters, he argued, may likewise become quicker to evaluate, safer to partner with and easier to fund.
The first step is almost embarrassingly basic: find out what data you hold. What do you collect, and why? Where is it stored, who sees it, which vendors receive it, and how long do you keep it? In a growing company, customer data ends up scattered across CRMs, WhatsApp chats, cloud folders, laptops and vendors. The privacy notice says one thing; the organisation does another. That is where mistrust begins. Not with malice, but with disorder.
I have a confession here. That day, I collected dozens of visiting cards and phone numbers. At one point I asked a remote staffing firm whether I could courier a stack of cards to a freelancer to type into a spreadsheet. Under DPDP, that freelancer becomes my data processor. The organisers had thought about this more carefully than I had: their event partner had committed to handling attendee data responsibly from registration to follow-up.
If you like our writings, support us! Scan the image to show your appreciation!
The data a company would not delete
For me, privacy stopped being theoretical because of an old office phone number.
The number was being reassigned to a colleague, and years of my online orders were still attached to it. I asked the delivery company to remove the history. I called customer care. They asked me to email. I emailed. The reply was polite, and it was a no.
When the microphone came my way during the privacy panel, I told that story.
Aditya, a cybersecurity leader, explained that deletion is rarely a single command. The same record sits in live systems, invoices, security logs, fraud monitoring and backups. Tax rules may require parts of it to be kept. If the data has trained an AI model, deleting the original may not remove what the model learned.
Abhishek Tiwari of PwC added the legal detail. Large e-commerce, social media and gaming platforms will have to erase a user’s data after three years of inactivity. Once enforcement begins, a refusal without a valid reason becomes a grievance I can file.
Then Ravi Raman of Beyond Risk made the distinction that stayed with me. A company may have a lawful reason to keep your data. It has no right to keep using it once you withdraw consent. Your rights come in an order: first stop the use, then correct the data, then delete it.
I had been asking for the wrong thing first.
A few minutes later, another member of the audience raised the stakes. He had received a morning phone call asking him to pay the instalment on a ₹5 lakh loan. He had never taken a loan. Someone had used his identity. He had gone to the bank, the police and the cybercrime cell, and nothing had moved.
“Personal data” was suddenly no longer an abstract legal category. It was a debt someone else had created and a credit record to be repaired. Sushant Shetty of DBS pointed him to the banking ombudsman. Where fraud happens without the customer’s consent, he said, the institution is expected to compensate first and argue later. Aditya’s warning was bleaker. Much of our identity data has already leaked, and identity theft is coming here in earnest.
Consent management, retention controls and traceable deletion are not administrative chores. They are products waiting to be built. India will need a whole layer of privacy infrastructure before the rights in its law become real.
When deletion is the dangerous choice
Sandesh Cadabam runs Cadabams, one of India’s largest private mental healthcare groups. Patients now write in asking him to delete their records. But what if that patient returns months later in crisis, at risk of harming themselves, and the history that could guide their care has been erased? Medical and legal duties may also require parts of the record to survive.
Indiscriminate retention is dangerous. Careless deletion can be dangerous too. His answer is clarity at the start: tell patients what is collected, why, who will see it, what can be erased and what must be kept.
Trust, I began to understand, does not always mean giving people the answer they want. It means giving them an honest answer, a defensible reason, and a process they can challenge.
Three companies that thought nothing would happen
Antra Ahuja of Saga Legal then walked us through companies that learned the hard way. I looked up two of them afterwards. The full stories are better than the headlines.
The system nobody switched off. Danish furniture retailer IDdesign moved to a new customer system, but an old one kept running in some stores. It held names, addresses, phone numbers and purchase histories for about 385,000 customers, none ever deleted. In 2019, the Danish regulator proposed a fine of DKK 1.5 million.
Then came the twist. A local court cut the fine by more than 90 per cent, ruling that only the subsidiary’s revenue counted. Prosecutors appealed to the Court of Justice of the European Union, which ruled in 2025 that the whole group’s worldwide turnover counts. The final fine was €200,900, and because management knew about the problem, the violation was held to be intentional.
Nobody stole anything. Someone simply forgot to turn off an old system.
The one-person IT department. Lithuanian payments firm MisterTango collected more data than it needed. More than 9,000 screenshots of customers’ banking sessions became publicly accessible, and the breach went unreported. The regulator also found that a single employee ran the entire IT infrastructure, including functions meant to check each other. The fine was €61,500.
Anyone running a lean startup should read that last detail twice.
The company where nothing happened. An Austrian firm suffered no breach and lost no data. It simply had no one customers could contact with a privacy complaint. The fine was roughly ₹60 lakh.
Then Antra delivered her real warning. GDPR ties fines to turnover. DPDP sets fixed penalty ceilings per type of breach, so a seed-stage startup faces the same schedule as a listed company. The real cost of getting privacy wrong, she said, is becoming the next case study in someone’s slides.
The AI problem begins when the demo ends
Vijai Velu put the AI debate plainly. Computing power can be rented, and models improve every day. The unresolved gap is governance.
Imagine an AI agent that processes invoices. In a pilot at one office, it performs brilliantly. Then it is rolled out across 15 entities in eight countries, meets different tax rules and hundreds of exceptions, and has to decide them. Who is responsible when it gets one wrong? Who can override it? An impressive demo hides those questions. Scale exposes them, and retrofitting governance afterwards costs far more.
Recruitment showed the same problem in personal form. AI hiring vendors promise to make hiring 70 or 80 per cent faster, but almost none measures the quality of hire. The real test is whether the candidates an AI shortlists go on to become good employees. Nirupama Vellore Ganapathy, founder of Ad Astra Consultants, urged buyers to ask harder questions. How is candidate consent managed? How long is the data kept? Where does AI create value, and where does it create exposure?
One recruitment leader told a story that captured the whole discussion. Competing for a Fortune 10 contract, his firm submitted a 10-page proposal while eighteen rivals submitted 50 to 200 pages. The client was indignant, so he asked her to check his firm’s delivery record for her over five years. She did. His point: AI can write anyone a 500-page proposal. It cannot fake a record of delivery.
The question is no longer whether a company uses AI. It is whether anyone remains accountable after it does.
The most valuable word in Indian business may be “no”
When the panel returned to my question, someone recalled that Indian IT was once dismissed abroad as “body shopping.” Infosys and TCS changed that perception through years of dependable delivery, not slogans.
Then Bharath Jatangi of Pace Wisdom told the story that became, for me, the moral centre of the conference.
He once flew to meet an overseas prospect who knew he was coming from India and had clearly prepared for him. The prospect handed him a list of ten services and asked what his company could do on each. They talked for forty-five minutes. By the end, Bharath had reached an uncomfortable conclusion: his company did none of them.
So he said so. This is not something we can deliver. He got up to leave.
The client was delighted, which puzzled Bharath. At the door, the man called him back. He wanted to know why an Indian company wasn’t claiming it could do all ten.
Six months later, Bharath’s phone rang. It was the same client. He did not ask whether Bharath could help. He said he wanted to work with him.
Bharath’s diagnosis was cultural. We give a wobbly, head-tilting haan when the honest answer is no, and foreign clients cannot tell the difference. Our celebrated jugaad needs a boundary. Resourcefulness is a virtue when it solves a hard problem with limited means. It becomes a liability when it excuses imprecision, or the belief that “almost correct” is good enough.
In aerospace or pharmaceuticals, 5.001 millimetres is not a version of 5. It is a rejection.
I would add one thing. On a recent trade delegation to Vietnam, I heard over dinner how a single busload of badly behaved Indian tourists had shaped an entire city’s view of us. We are proud of Atithi Devo Bhava, the guest is god. We must first learn to be good guests.
Trust accumulates when companies make narrower promises, meet exact specifications, report problems early, and refuse work they cannot do.
Sometimes growth begins with the deal we are willing to lose.
Investors were listening for the same evidence
Fifteen startups pitched to investors in an invite-only demo session. On the investor panel, a strong idea was treated as merely the opening of a conversation. Investors look for founder–market fit, honesty about weaknesses, and a founder who knows the customer better than they do.
The advice was direct. Start fundraising six months before you need the money and allow at least three months for diligence. Approach funds that invest at your stage, and check whether they already back a competitor. Raise after hitting a milestone, not to reach one.
Rajesh R., an angel investor, once met a founder in the morning and wrote a cheque by four that afternoon. But he also watches for something less glamorous: a founder willing to run a compliant business and take advice. Clean accounts and a credible data policy shorten diligence. Inconsistencies create suspicion.
Trust runs the other way too. One panellist warned founders about “data hoggers”: investors who consume months of time and sensitive information without ever giving a clear decision.
Drawing on my years in investment banking in London, I asked whether a founder might do better from Singapore or the Bay Area, free of Bengaluru’s traffic and bureaucracy. The panel conceded that the Bay Area is older, deeper and faster, but pushed back on the rest. On reflection, they were right. India’s venture ecosystem has transformed in fifteen years, and investors are backing it with conviction.
Capital follows confidence. Even the boldest vision eventually has to pass diligence.
Trust travels through an ecosystem
A startup controls its product, but its data passes through cloud providers, partners, banks and distributors. Every hand-off either reinforces privacy or quietly weakens it.
Sushant Shetty urged founders to see banks as networks, not just lenders. DBS has close to a million SMB customers and can connect startups to investors, cybersecurity training and new markets. Tellingly, he said, DBS has spent years promoting itself as the world’s safest bank rather than its best. But before any bank introduces a startup to its customers, it has to believe the startup will not become a source of regulatory or reputational damage. Privacy is part of the permission to enter.
Sushant also described one founder who understood this early. The company sat on data valuable enough to make it among India’s most valuable. The promoter refused to monetise it until a proper consent framework existed, because the data belonged to his clients. He waited seven or eight years.
Trust also runs inward
After lunch, Tarun of Wonderfly told a story about the Titanic.
At 9:40 on the night of the disaster, another ship radioed an ice warning. The Titanic hit the iceberg at 11:40. For two hours, the wireless operator, Jack Phillips, had the warning in his hands, and it never reached the people who needed it.
Then he asked how many of us had lost a valued employee in the past year without seeing it coming. About fifteen hands went up. The signs are usually there, he said: slower replies to email, quietly slipping work. We simply don’t read them.
He handed out envelopes dated sixty days ahead. Have one real conversation, he told us, with the person you can least afford to lose, about something other than work. Then open the envelope and answer honestly whether you did.
The same discipline applies to founders themselves. Ravi Raman named a red flag I had never considered: the promoter who takes no salary. It looks like sacrifice, but it suggests the line between promoter and company was never drawn. At the same time, he warned against burying a young startup under fifteen compliance frameworks because one customer sent a questionnaire. Build risk management into the product, so it grows with the business.
The help almost nobody asks for
The final speaker, Bharat of the Karnataka Digital Economy Mission, asked how many founders had registered with Startup Karnataka.
Four hands went up.
Most had no idea what they were missing. Elevate gives up to ₹50 lakh without taking equity and has funded more than 1,300 startups. Elevate Next offers up to ₹1 crore to deep-tech startups that relocate to Karnataka. Reimbursements for patents, certifications, exhibitions, cloud services and hiring can save a startup up to ₹2 crore over five years. A scheme you discover after its window closes might as well not exist.
The question I should have asked
As the day ended, I thought back to the moment I raised my hand.
Why does the world hesitate to trust Indian business?
I now suspect I asked it the wrong way. My question placed trust outside us, as a verdict handed down by foreign customers and investors. The more useful question is closer to home:
What evidence do we give people, every day, that we deserve to be trusted?
Not a rating system or another logo on a website. A deletion request that enters a documented workflow instead of vanishing into customer care. An AI decision a human can explain and reverse. A founder who refuses to sell data without consent. A supplier who says, “We cannot do that well, so we will not pretend we can.”
Tarun’s envelopes are dated 17 November, four days after India’s Consent Manager rules take effect. It is a coincidence, but a telling one. Every story I heard that day had the same shape: a warning, a choice, and a consequence. Jack Phillips held the ice warning for two hours. IDdesign’s old system kept running for years. And Bharath, facing a skeptical client, chose no when haan would have been easier.
Indian companies now hold their own warning, with a date on it: 13 May 2027. We can treat DPDP as paperwork to rush through at the last minute. Or we can treat it as the world will: as evidence of whether Indian businesses can be trusted with other people’s information, and by extension with their orders, components and contracts.
We have built digital payment rails, global technology companies and spacecraft. The next infrastructure India must build is less visible. It gets built every time a company collects less data, keeps a precise promise, admits a limitation, and accepts responsibility when something goes wrong.
Trust is often described as a soft value. After a day among founders, investors, lawyers and bankers, I left convinced of the opposite.
Trust may be the hardest infrastructure India has ever had to build, and the most valuable.
Support The Future Of PR
TheFutureOfPR.com explores the stories behind business, reputation, leadership, investment and global trade-especially the ideas that conventional media often overlooks.
Investing
If you enjoy independent reporting, thoughtful analysis and stories from the ground, you can support my work. Your contribution helps fund the continued development of TheFutureOfPR.com.
Click here: buymeacoffee.com/tfofpr to appreciate this writing.
Thank you for helping independent ideas travel further.
Karnvir Mundrey is a narrative strategist and media entrepreneur who helps founders, institutions and international businesses turn complex ideas into influential public stories.
He is the Founder of Atharva Lifesciences Consulting Pvt. Ltd. , Atharva Marcom and Founder Editor of TheFutureOfPR.com. He has also authored a book on Nutraceuticals (available on Amazon). He is also recognized as India’s longest running podcast host, continuously running since 2006!
Reach out at tfofpr@gmail.com or at +918296303806.
Subscribe to TheFutureOfPR.com to get great ideas on life, education, health & fitness, real estate, glamour, jewelry, movies, and podcasts! Follow TheFutureOfPR.com on Facebook , Twitter and Linkedin!
Karnvir Mundrey is also the producer and host of 4 YouTube channels. Finest Fintalk brings you the latest in Finance, LitInMin for Books, The Health Tips Podcast for health and Atharva Marcom for leadership talks
Share this article with people who you think might benefit. They will thank you for it!
















Comments