Privy by IDfy, the enterprise privacy and data-governance platform from IDfy, today announced it has crossed 50+ enterprise DPDP implementations Across BFSI, insurance, telecom, healthcare, retail and other sectors, covering 500M+ data principals, 2B+ consent records and over 10 PB of data.
MUMBAI, India, Oct. 6, 2026 /PRNewswire/ — India’s privacy challenge did not begin with the Digital Personal Data Protection Act (DPDP Act). It began much earlier, with the sheer scale and complexity of personal data powering the country’s digital economy.

IDfy has long worked at the intersection of identity, verification, fraud, and risk, dealing with the documents, identifiers, and customer journeys unique to Indian businesses. That experience with Indian personal data became an important foundation for Privy by IDfy, its enterprise privacy and data-governance platform.
“We have spent 15 years working with some of the most sensitive personal data in India. Five years ago, we made a deliberate long-term bet that privacy would become fundamental to the digital economy and backed that conviction with capital, people and product investment. We’re proud to see that journey now entering its next phase, where privacy and trust are becoming core infrastructure for how enterprises build and grow.” – Ashok Hariharan, Founder & CEO, IDfy.
Privy by IDfy is now working Across 50+ enterprise implementations spanning across banking and financial services, fintech, insurance, retail and e-commerce, telecom, healthcare, real estate, manufacturing and other digital businesses.
Across ongoing deployments, that footprint extends to 500M+ data principals, more than 2B consent records, and over 10 PB of personal data being discovered and governed.
But the more interesting Story is what those implementations are revealing.
India’s data problem is unlike most markets
India did not build its digital economy around one clean, standardised data environment.
A single individual can appear differently Across institutions, products and systems, with personal information spread across identity documents, applications, databases, spreadsheets, PDFs, images, archives and third-party platforms. Identifiers are often masked, and formats vary, with data spread across structured and unstructured sources.
The pattern holds across industries. Customer data moves between financial products, insurers and healthcare providers share information across networks, and digital businesses hold data on customers, employees, partners and vendors.
The result is data fragmented not just across systems, but across processes, teams and third parties. Same regulation. Very different data estates.
That is the starting point for understanding why DPDP implementation looks so different from one enterprise to another.
Where DPDP Meets Enterprise Reality
One of the clearest lessons from 50+ implementations is that there is no standard DPDP programme.
Each organisation brings its own mix of legacy technology, cloud applications, third parties, internal processes and ownership structures.
The regulation may be common. The implementation rarely is.
Legal may interpret the requirement. Technology has to implement it. Information security assesses risk. Procurement manages processors. Product teams determine what gets collected. Business teams have to make the new processes work.
The difficulty is therefore not always technology. Often, it is getting the organisation aligned around how personal data should actually be governed.
A Data Principal request may appear to be a rights-management problem until the organisation has to find the same person across multiple systems.
A deletion request may turn into a retention question.
A third-party assessment may reveal that knowing who a vendor is is very different from knowing exactly what data has been shared with them.
And consent itself becomes meaningful only when it can be connected to the processing happening behind it.
“Connecting to a database is the easy part,” said Paritosh Desai, Chief Product Officer, IDfy. “The real challenge is recognising personal data in all the ways it actually appears across documents, scans, images, masked identifiers and industry-specific formats. Rudimentary pattern matching will find the obvious four or five fields. Context-aware discovery understands what it is looking at, where it is looking, and what is likely to exist there. Scanning tells you what matches. Context tells you what matters. Governance tells you what to do about it.”
The foundational questions increasingly become:
What personal data do we have? Where is it? Why do we have it? Who can access it? Where does it go?
That is why personal-data discovery, classification and lineage are moving closer to the centre of enterprise privacy programmes.
50+ Implementations. Real Data. Real Lessons. Real DPDP Experience.
This is also where Privy’s scale begins to matter.
The value of 50+ deployments is not simply having 50+ customers. It is seeing the same broad regulatory requirements collide with dozens of different enterprise realities.
Teams learn where programmes typically stall. Which stakeholders should have been involved earlier. Which integrations become difficult because of legacy infrastructure. Which apparent privacy problems are actually data, identity, or process problems.
It also explains why Privacy cannot be approached as a set of disconnected workflows. Rights, consent, assessments, third-party risk, incidents, and compliance evidence all depend on the enterprise having a reliable understanding of the data underneath them.
“Privacy implementation at enterprise scale cuts across technology, processes, people, legacy systems and multiple business teams, and no two organisations start from the same place,” said Malcolm Gomes, COO, IDfy and Head of Privy by IDfy. “What 50+ implementations have reinforced for us is that success depends on how well you navigate that complexity and move from policy to execution. Enterprises should expect more than a product from their privacy partner. They should expect a partner who has seen the difficult scenarios before, knows where implementations tend to get stuck, and can help them get to operating reality faster.”
What Comes After May 2027
May 2027 may be the immediate regulatory milestone, but it is unlikely to mark the end of enterprise privacy programmes.
The systems being put in place today will have to operate as businesses add new products, systems, data sources and technologies. AI is already adding another layer to that complexity, bringing privacy questions into how organisations use, move and govern data.
For enterprises, that makes implementation experience increasingly important, particularly experience built around Indian data, complex enterprise environments and the intersection of privacy and AI.
The distinction may ultimately be less about meeting a compliance deadline and more about having the capability to keep adapting as the data environment changes.
With 50+ enterprise implementations and IDfy’s 15 years of working with Indian personal data, Privy by IDfy has seen that complexity first-hand.
DPDP compliance may be the immediate task. Building the capability to govern data as the enterprise evolves is the longer journey.
What Comes After May 2027
May 2027 may be the immediate regulatory milestone, but it is unlikely to mark the end of enterprise privacy programmes.
The systems being put in place today will have to operate as businesses add new products, systems, data sources and technologies. AI is already adding another layer to that complexity, bringing privacy questions into how organisations use, move and govern data.
For enterprises, that makes implementation experience increasingly important, particularly experience built around Indian data, complex enterprise environments and the intersection of privacy and AI.
The distinction may ultimately be less about meeting a compliance deadline and more about having the capability to keep adapting as the data environment changes. DPDP compliance may be the immediate task. Building the capability to govern data as the enterprise evolves is the longer journey.
About Privy by IDfy
Privy by IDfy is India’s full-stack DPDP compliance and data privacy governance platform. It helps enterprises manage personal data discovery and governance, privacy impact assessments, third-party risk, consent, data principal rights and privacy incidents on one platform, supported by an AI compliance copilot. Built on IDfy’s 15 years of experience with Indian identity and personal data, Privy is one of the first DPDP platforms in India to operate at this scale across banks, insurers, edtech, healthcare, manufacturing, fintechs, telecom operators, retailers and digital businesses. Privy by IDfy won The DPDPInnovation Challenge, run by MeitY and NeGD under the Ministry of Electronics and Information Technology. Learn more at https://www.privybyidfy.com/.
View original content to download multimedia:https://www.prnewswire.com/in/news-releases/what-privy-by-idfys-50-enterprise-implementations-reveal-about-indias-privacy-reality-302899342.html











