Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Back To Home

DPDP Compliance

Privacy Engineering in Practice: Implementing PETs (Privacy Enhancing Technologies) for DPDP Compliance

Privacy Engineering in Practice: Implementing PETs (Privacy Enhancing Technologies) for DPDP Compliance

Privacy Engineering in Practice: Implementing PETs (Privacy Enhancing Technologies) for DPDP Compliance

Research Team (Tsaaro)

Published

WhatsAppFacebookXLinkedIn
The Indian Privacy Adjudication Report

Introduction 

Privacy engineering is simply a practice where crucial privacy safeguards are built into the technology, the product design, and the software systems from the very start, rather than looking into these requirements at a later stage. The idea behind privacy engineering is that, while building IT systems and other related technologies, privacy, as a crucial element, is considered at every stage. With the increasing need to constantly protect personal information and to abide by privacy-related laws, it has become pertinent to plan and inculcate privacy requirements at an earlier stage in the creation of new technologies and software.  

Even in India, the need for privacy engineering has significantly expanded in order to duly comply with the Data Protection and Privacy (DPDP) Act. The DPDP Act under Section 33 and the Schedule, imposes high monetary penalties for different types of data breaches. For instance, the penalty ranges from Rupees 200-500 Crores for core rights violations and security failures. Therefore, considering the gravity of the penalties imposed by the Act, all the technologies and software systems used by different companies should ensure that these systems have Privacy as a default setting.  

Now, in order to inculcate and implement this practice of privacy engineering, one of the tools that organisations may incorporate is the Privacy Enhancing Technologies (PETs). The OECD defines PETs as those technologies that enable the “collection, analysis and sharing of information while protecting data confidentiality and privacy.” PETs are technological tools that are used by organizations to analyze data and gain useful insights without exposing personal data. This reduces the risk of data breaches while still providing the required results. PETs would definitely form a crucial element through which DPDP could be implemented. Adoption of PETs for privacy engineering could be the future approach for organizations in India to not only use them as a compliance checklist but also to have a competitive advantage over other businesses.  

Advantages of adopting PETs in privacy engineering: 

The primary benefit of using PETs while developing technologies is apparent; it ensures that the provisions of the DPDP Act are complied with. Principles like data anonymization and data minimization would be easy to tackle with PETs playing their part. With the advent of multiple AI tools, a lot of sensitive information would be collected. Incorporating PETs would help organizations to manage and process such data in a legally compliant manner. Additionally, companies that use PETs would automatically gain a competitive edge because it shows their customers that they’re responsible with how they use the data and thereby gain both the customers' and employees’ trust. Sometimes, when a company wants to outsource its work, and it also includes the sharing of sensitive data, those companies using PETs are more likely to get the deal. With so many advantages, PETs would most likely be the step in implementing privacy engineering in practice.  

Risks of adopting PETs in Privacy Engineering: 

There are multiple advantages of using PETs in privacy engineering, and they are going to be the core engine for implementing the DPDP Act. However, they cannot be the sole drivers in adopting privacy engineering. They might definitely be one of the core components of privacy engineering; however, an assessment of the processing activities should be taken by the organizations to ascertain the clear purpose of using PETs and to also look into the potential issues they might pose. The probable risks of adopting PETs are: 

Some privacy tools are still developing and may struggle to handle large amounts of data or be vulnerable to attacks. Before choosing one, it's worth checking how well-tested and reliable it actually is. These tools often require a certain level of technical know-how to set up and use correctly. Without that knowledge, it's easy to install them incorrectly, which can throw off the balance between keeping data private and keeping it useful. Even with some knowledge, there's still a risk of making mistakes during setup. For example, mishandling encryption keys. When this happens, the tool may not actually be protecting people, the way it was intended, leaving real risks unaddressed. One of the papers highlighted a medical study where stronger privacy protections led to a simulated increase in patient risk, illustrating that getting this balance wrong can have serious consequences.

Types of PETs: 

There are types of PETs that an organization can use based on its requirements. They are broadly divided into three categories, and different technologies mostly fall within these categories:  

  • PETs that reduce identifiability: These technologies mainly reduce the connection between personal information and the individual to whom it relates. By reducing identifiability, they support the principle of data minimization and lower the risk of re-identification. Differential Privacy is one example that helps give useful insights without decrypting the information.  


  • PETs that shield the data: These technologies focus on protecting personal information during storage, transmission, or processing without affecting the accuracy or usefulness of the data. Homomorphic Encryption is one example that enables any activities to be performed directly on encrypted information without the need to decrypt the data.  


  • PETs that distribute data processing: These technologies reduce privacy risks by distributing data processing activities across multiple systems instead of centralizing all information in a single location. For example, Secure Multi-Party Computation allows multiple parties to jointly perform computations on their respective datasets without revealing their underlying information to one another. 

Some other examples of different types of PETs are: 

  • Zero-Knowledge Proofs (ZKPs): Zero-Knowledge Proofs enable one party to demonstrate that a particular statement is true without revealing any additional information beyond the validity of that statement. 


  • Federated Learning (FL): Federated Learning is a machine learning approach in which models are trained across multiple systems without requiring the underlying data to be transferred to a centralized location. 


  • Synthetic Data: Synthetic Data consists of artificially generated information that replicates the real datasets without directly reproducing actual personal information. 


  • Trusted Execution Environments (TEEs): Trusted Execution Environments are secure hardware-based environments that isolate sensitive computations from the operating system and other applications running on a device. 

Current status of PETs in India: 

As per the Data Security Council of India (DSCI) and Aldefi’s report on PETs, India currently lacks a legal framework specifically governing the use of PETs. Instead, Indian law focuses on broader obligations relating to data security, confidentiality, and protection of personal information. Some of the existing frameworks are: 

The Information Technology Act and the SPDI Rules require organizations to implement security practices and procedures to protect personal information from unauthorized access, disclosure, or misuse. The SPDI Rules further encourage compliance with standards such as ISO/IEC 27001, which incorporates controls relating to encryption, access management, auditing, and information security governance.  

As mentioned above, the enactment of the Digital Personal Data Protection Act, 2023, would ultimately require organizations to adopt privacy engineering. Although the Act does not explicitly require organizations to implement PETs, many of its obligations likely require the adoption of PETs. Requirements relating to consent management, notice mechanisms, data principal rights, and reasonable security safeguards may be more effectively implemented through privacy engineering measures.  

Further, Significant Data Fiduciaries are required to undertake additional compliance measures such as Data Protection Impact Assessments, audits, and governance mechanisms, all of which may require the incorporation of PETs within organizational systems. Organizations are expected to invest in privacy-enhancing technologies to showcase accountability, strengthen data governance practices, and ensure that they meet their compliance obligations.  

Conclusion  

There are different sectors that are adopting PETs at different speeds. The knowledge and awareness about the PETs vary across different sectors, and there’s a lot of disparity in adopting these PETs across different sectors. Some industries have started taking privacy engineering seriously, while others are still far behind. This uneven adoption is a problem, especially with the DPDP Act now in the picture. PETs are not complicated to understand in terms of what they do. They simply make sure that personal data is handled with more care, whether that means encrypting it, anonymizing it, or making sure it never even leaves the device in the first place. The technology exists, and it works. 

What is missing right now is education. Awareness programs and education about PETs in privacy engineering are crucial for India to reach that level of adoption that ultimately keeps in mind the different privacy requirements.  A lot of organizations in India still do not fully understand what PETs are or how they can be used in their specific line of work. Until those changes are made, adoption will remain slow and inconsistent. For India to genuinely reach a good standard of data privacy, it is not enough to just pass laws. Companies need to understand why privacy engineering matters and how PETs can help them get there. Awareness programs and proper training across industries would go a long way in making that happen. 

Want to stay ahead? 

Reach out to the experts at  tsaaro.com today. 

We Help You to Grow Your Business Faster & Easier

Our Mission is to assist businesses in achieving compliance with data privacy, cybersecurity regulations & Responsible AI. We have worked with over 150+ Clients. Some of our key clients are Adani, Booking.com, NPCI, Godrej, DS Group, CRED, BharatPe, Aster DM, Vistara Airlines, Kotak Mahindra, Vodafone, Flipkart & more.


  • Comprehensive Compliance Support – From data privacy to Responsible AI, we cover it all.

  • Cybersecurity Expertise – Protect your business from evolving digital threats.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Customized Solutions – Compliance strategies tailored to your business needs.

  • Global Standards – Align with GDPR, DPDP, and ISO frameworks seamlessly.

  • Efficient Implementation – Achieve compliance faster with expert guidance.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our Mission is to assist businesses in achieving compliance with data privacy, cybersecurity regulations & Responsible AI. We have worked with over 150+ Clients. Some of our key clients are Adani, Booking.com, NPCI, Godrej, DS Group, CRED, BharatPe, Aster DM, Vistara Airlines, Kotak Mahindra, Vodafone, Flipkart & more.


  • Comprehensive Compliance Support – From data privacy to Responsible AI, we cover it all.

  • Cybersecurity Expertise – Protect your business from evolving digital threats.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Customized Solutions – Compliance strategies tailored to your business needs.

  • Global Standards – Align with GDPR, DPDP, and ISO frameworks seamlessly.

  • Efficient Implementation – Achieve compliance faster with expert guidance.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our Mission is to assist businesses in achieving compliance with data privacy, cybersecurity regulations & Responsible AI. We have worked with over 150+ Clients. Some of our key clients are Adani, Booking.com, NPCI, Godrej, DS Group, CRED, BharatPe, Aster DM, Vistara Airlines, Kotak Mahindra, Vodafone, Flipkart & more.


  • Comprehensive Compliance Support – From data privacy to Responsible AI, we cover it all.

  • Cybersecurity Expertise – Protect your business from evolving digital threats.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Customized Solutions – Compliance strategies tailored to your business needs.

  • Global Standards – Align with GDPR, DPDP, and ISO frameworks seamlessly.

  • Efficient Implementation – Achieve compliance faster with expert guidance.

  • Trusted Advisory – Led by certified privacy and security professionals.