
In an exclusive piece for MediaBrief, Praveen Singh, Co-Founder and CEO, Tubelight Communications, writes about how the DPDP Act is reshaping brand communication, why privacy must become a core business value, and where most organisations fall short. Singh also shares what responsible data practices look like in an omnichannel world, how brands can build trust through transparency, and the roadmap ahead for compliant customer engagement.
Customer conversations today occur everywhere, including on WhatsApp, email, SMS, social media, and calls. Every one of those channels carries a piece of customer information. And with that comes a huge responsibility.
Technology can connect everything, but it also increases the chances of something going wrong. Privacy isn’t a checkbox anymore. It has become the foundation of trust between a business and its customers.
India has taken a strong step in this direction with the Digital Personal Data Protection (DPDP) Act. It clearly defines how personal data should be collected, used, and stored. More importantly, it puts the accountability directly on the organizations that handle the data.
According to the PwC India Survey, only 16% of Indian consumers understand their rights under the DPDP Act and around 56% are unaware of basic protections for their personal data. The survey underpins the need for awareness about the rights and duties regarding their personal information.
Also read: Exclusive | DPDP Rules 2025 – Four leaders on turning data protection into trust, engagement, and strategy
What the DPDP Act Means for Businesses
Under the Act, every organization is considered a data fiduciary. That means you’re not just holding data; you’re responsible for it. Consent has to be clear, specific, and time-bound. No hidden permissions. No assumptions.
People should know what’s being collected, why it’s being collected, and how long you’ll keep it. If a data breach happens, the company must respond fast, fix the issue, and inform those affected.
The law also brings stricter rules for handling children’s data and much heavier penalties for violations. But honestly, it shouldn’t take a penalty to make us do the right thing. Compliance should be a shared value across teams, not something owned by just the legal department.

Omnichannel Communication and Privacy
When enterprises talk about “omnichannel”, they often think about a seamless experience. The truth is, behind that smooth experience is a complex web of systems talking to each other. A minor mistake can expose sensitive data. Every chat, every message and every automated response is powered by customer data from multiple sources.
Technology helps, but never rely on it
Automated systems can make data requests and withdrawals easier for customers. All this helps. But it’s still only part of the answer.
Technology isn’t a replacement for human judgement. Compliance depends on ethics and awareness and not just code. The right training, culture, and mindset make the real difference.
Keeping Communication Clear
Most people don’t read long privacy policies. They just want things explained simply: what data are you collecting, what are you doing with it, and how can they opt out? That’s it.
Transparency builds confidence. Complicated language does the opposite. The simpler and more direct we are, the stronger the relationship gets.
Extending Responsibility to Partners
Many privacy lapses happen outside the company, through vendors, agencies, or contractors. That’s where a lot of businesses slip up. A contract isn’t enough. You have to ensure your partners also follow the same standards. It’s not about blame. It’s about building a common understanding that customer data deserves equal respect at every touchpoint.

Internal Awareness Matters
In most organizations, breaches happen because someone didn’t know better, not because they intended harm. Regular awareness sessions go a long way.
A few minutes of awareness can prevent an incident that could cost a brand the reputation built over years.
Closing the Gaps
Many Indian companies are still adjusting to this new way of working. Some don’t have a strong consent process yet. Others see compliance as a one-time project. But this is not going away. It’s an ongoing responsibility.
This is a good time for businesses to pause, look at how data moves within their systems, and fix weak spots. When privacy becomes part of daily decision-making, it starts showing in the way customers trust the brand.
Learning from Global Practices
Countries like those in the EU or Singapore have been ahead in data protection. Their models show that strong privacy laws don’t stop innovation; they actually support it. Indian organizations that align with such standards early will find it easier to build international credibility.
Laws will keep evolving. Technology will change, too. But if we see privacy not as a compliance burden but as a commitment to do right by our customers, it will always be a strength and a true mark of trust.






































