MSMEs are embracing AI without understanding the privacy risks: PrivaSapien CEO
With key provisions of India’s Digital Personal Data Protection Rules set to take effect in May 2027, PrivaSapien CEO Abilash Soundararajan says MSMEs need to move beyond compliance checklists and build basic privacy and AI safeguards now.

Abilash Soundararajan, Founder & CEO, PrivaSapien
ET: As organisations prepare for data protection rules, what are the most critical steps they should take to ensure compliance?
Abilash Soundararajan (AS): The first thing I tell every CXO is to stop treating this as a policy-writing exercise. A consent banner on your website is not compliance. The highest penalty of Rs 250 crore is for a data breach resulting from not having technical safeguards.
Real readiness starts with understanding your obligations across the entire data lifecycle—notice and consent, discovery of personal data, Data Protection Impact Assessments (DPIAs), security safeguards, and exemptions for research, archiving, and statistical use. Each is a distinct obligation, and each has to work consistently across every application, vendor, and team that touches personal data.
That’s harder than it sounds. A mid-sized firm can easily have a hundred applications, and each one carries roughly a dozen obligations. If you do the math, you will find that there are hundreds, if not thousands, of individual compliance workflows, not just one checklist.
The second step is mapping that complexity to actual penalty exposure. Security safeguards carry the steepest penalty—up to Rs 250 crore. Risk assessment and DPIAs follow at up to Rs 150 crore. Consent and data-principal rights sit at Rs 50 crore. That hierarchy should directly decide where your budget and engineering effort go first. Most organisations get this backwards and spend all their energy on consent banners while leaving technical safeguards untouched.
ET: For MSMEs, the cost of DPDP compliance could be a much bigger burden than it is for large enterprises. What are the key challenges smaller businesses are likely to face, and how can they become DPDP-ready without building expensive legal, cybersecurity, or privacy teams?
AS: For MSMEs, DPDP compliance feels like a heavy cost, but the smarter view is that privacy is a profit centre—a discipline that lets you use data well while winning customer trust. The biggest challenge is mindset, not money.
Becoming DPDP-ready doesn’t require expensive legal, cybersecurity, or privacy teams; it starts with knowing what personal data you hold, why, and where it sits, backed by basic consent, retention discipline, and a grievance channel. Framed this way, compliance becomes about trust and brand building—the very foundation for going global, earning richer data, deploying AI responsibly, and moving up the value chain.
ET: As MSMEs increasingly adopt AI tools for marketing, customer service, hiring, payments, and operations, are many of them taking on data privacy and AI risks without fully understanding their exposure? What minimum safeguards should a small business put in place before deploying AI?
AS: Many MSMEs are indeed taking on AI and privacy risks without grasping their exposure, precisely because the tools are so easy to adopt. This matters because MSMEs increasingly serve larger businesses, global customers, and rights-aware consumers. When data under an NDA is leaked in an AI chat, personal or sensitive information is shared with external models, or financial data is sent across borders, the question is no longer cost but non-compliance and loss of trust. Minimum safeguards are inexpensive but decisive: clear rules on what may enter AI tools, vetted deployments for sensitive data, basic access controls, awareness of data residency, and simple staff training.
ET: Could stricter data protection and AI governance requirements inadvertently widen the digital divide between large companies and MSMEs? What should the government and technology ecosystem do to make responsible AI and privacy compliance affordable and accessible for smaller businesses?
AS: Stricter requirements could burden smaller players (MSMEs), but the deeper truth cuts the other way. Privacy actually gives protection, shielding the digitally illiterate from being abused in a data- and AI-hungry world.
To keep it affordable, the government can offer tiered obligations, free toolkits, and model templates, while the technology ecosystem builds privacy and safety by default, so responsible AI isn’t a premium only large firms can buy. For the business owner, the principle stays simple: taking care of your customers and winning their confidence is the right way to build a business.
ET: What are the biggest strengths and gaps in India’s AI and data privacy ecosystem, and how do you see India’s responsible AI and compliance ecosystem evolving over the next five years?
AS: Recent times have shown a live preview of this. Publicly shared conversations from a major AI chatbot recently turned up indexed in search results, some containing medical records, employee data and company documents that were never meant to be public. Nobody hacked anything, a feature simply worked exactly as designed, and that was enough to expose sensitive data. That’s precisely the kind of episode that will define the next five years.
The arc, if I had to sketch it, is fairly predictable. DPDP enforcement will begin in earnest. RBI’s Guidance on Regulatory Principles for Model Risk Management, 2026, will start shaping how BFSI deploys AI models. Large enterprises will move first because they have the most to lose, and some breaches and enforcement actions will inevitably happen. Those penalties, far more than any awareness campaign, will become the real catalyst for accelerated privacy and responsible AI adoption.
The gap I would flag today is depth of implementation. Plenty of organisations have policies on paper. Far fewer have engineering-level controls that actually enforce those policies. Discovery without mitigation still leaves you exposed; it just tells you exactly where the exposure is. Closing that gap is where the next five years of real work will happen.
ET: How would policy reforms improve the ease of doing business while ensuring responsible AI adoption and strengthening AI research and innovation?
AS: The reforms around technical safeguards for safe data and AI usage are key for a safe future for humanity. That means enabling environments for privacy-enhancing technologies (PETs), privacy-preserving machine learning (ML), and supporting pseudonymous inference approaches so that organisations aren’t forced to choose between data utility and compliance.
An AI model, once trained, can’t unlearn something the way a data principal can withdraw consent, so this must be solved at the infrastructure layer, not after the fact. The other area I will flag is agentic trust and identity. As AI agents start acting on behalf of individuals and organisations, we need clarity on how those agents are authenticated, authorised, and held accountable. Very few countries have solved this yet, and India has a real opportunity to lead here rather than follow.
ET: What led to the establishment of PrivaSapien, and how is the company helping organisations navigate AI compliance?
AS: Around 2018, Deepika, my better half and our COO, and I were having a conversation about the bleeding gums of a family member—nothing typed, nothing searched, just spoken out loud near our phones. Within a short while, we started seeing ads for dental products and gum-care remedies across unrelated platforms.
That was the moment it stopped being an abstract privacy concern and became personal. If something as fleeting and private as a conversation about your health can be picked up and monetised without you agreeing to it, something is fundamentally broken in how data flows through the systems we use every day. That’s not innovation; that’s a breach of trust. It made it clear to me that privacy couldn’t be bolted on as an afterthought. It had to be engineered into how organisations handle data and AI from the ground up. We started as Truthshare initially in stealth mode, and from 2022, PrivaSapien was officially born. That’s the problem PrivaSapien was built to solve, and it’s why our core value to customers is an end-to-end, full-stack approach rather than a point solution.
ChatGPT was launched towards the end of 2022, changing the tech world. The DPDP Act was passed in Parliament in August 2023, and the rules came in November 2025, with penalties starting in May 2027. RBI has also come up with draft Data and AI Governance guidelines. Now organisations are beginning to explore solutions. Today, it’s significantly an awareness problem. Organisations need protection across the data and AI ecosystem. Our PERAI (Privacy enhancing and responsible AI) is the world’s first full-stack data and AI protection platform. We have been awarded privacy contracts across sectors, including the central government, large public sector banks, e-commerce, automobile manufacturing, healthcare, media and the global AI services industry. We are positioned to contribute to setting global standards for data privacy and responsible AI from India for the world.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.