- ₹250 crore ($30 million) fines: Maximum penalty for DPDP Act violations.
- 80% of Indian organizations unprepared as late as 2025 for compliance.
- 500 million users covered by IDfy's Privy platform, processing 70-80 million consent notices.
Experts would likely conclude that India's government endorsement of Baldor Technologies' IDfy signals a critical shift toward robust, scalable data privacy infrastructure as the DPDP Act enforcement approaches.
A Govt Nod Signals a Tectonic Shift in India's Data Privacy Race
MUMBAI, India – July 08, 2026 – A government-backed innovation challenge quietly concluded this week, but its outcome sends a loud and clear message to boardrooms across India. Baldor Technologies, which operates as the 15-year-old trust infrastructure company IDfy, was named the winner of the ‘Code for Consent’ challenge, an initiative by the Ministry of Electronics and Information Technology (MeitY) to find the most robust solutions for India’s new data privacy regime. While Jio Platforms secured the runner-up spot, IDfy’s victory is more than a simple corporate win; it’s a government endorsement of a new philosophy for handling personal data as the country braces for the full enforcement of the Digital Personal Data Protection (DPDP) Act.
For years, I’ve watched companies treat data privacy as a line item for the legal department—a series of checkboxes to tick before moving on to the real business of growth. This result suggests that era is definitively over. The government isn't just looking for compliant consent notices; it's looking for industrial-grade infrastructure capable of governing data across sprawling, complex digital ecosystems. And in a market where most businesses are still struggling to understand the new rules, this challenge has effectively drawn a blueprint for what 'good' looks like.
The High-Stakes Race for DPDP Compliance
To grasp the significance of this moment, one must understand the seismic shift represented by the DPDP Act, 2023. Unlike previous guidelines, the Act is a comprehensive legal framework with serious teeth. It grants individuals (Data Principals) powerful rights over their data—including the right to access, correct, and erase it—and places stringent obligations on the companies that collect and process it (Data Fiduciaries).
The cornerstone of the law is explicit, unambiguous consent. Gone are the days of pre-ticked boxes and buried clauses in lengthy terms of service. Under the DPDP Act, consent must be freely given, specific, informed, and as easy to withdraw as it is to grant. More critically, failure to comply carries staggering penalties, with fines reaching up to ₹250 crore (approximately $30 million) for a single violation, such as failing to implement adequate security safeguards.
This creates a daunting operational challenge for Indian enterprises. Recent industry surveys paint a sobering picture of unpreparedness. As late as 2025, some reports suggested that over 80% of Indian organizations had not even begun their compliance journey. The core problem is that for most companies, personal data isn't neatly filed away; it’s a fluid asset flowing across dozens of apps, vendor systems, marketing platforms, and legacy databases. Simply finding where all the personal data resides is a monumental task, let alone building systems to manage consent and individual rights at scale.
More Than a Pitch: A Government-Backed Blueprint Emerges
The ‘Code for Consent: The DPDP Innovation Challenge’ was designed to cut through this complexity. Run by MeitY Startup Hub and the National e-Governance Division (NeGD), it wasn’t a typical startup pitch competition. According to the organizers, entries were subjected to a rigorous evaluation of their technical, functional, and legal readiness, culminating in live demonstrations. The goal was to surface solutions that could work in the real world, not just on a PowerPoint slide.
IDfy's win for its platform, Privy, was based on its strong alignment with the DPDP Act, technical robustness, and practical applicability. This government validation is a powerful market signal. It tells enterprises that compliance isn't about a single piece of software, but about an interconnected system that can manage consent, track data, handle user rights requests, and—crucially—produce verifiable evidence for regulators.
"What made this challenge different was the depth of the evaluation," said Malcolm Gomes, COO of IDfy and head of its Privy platform. "It wasn't a pitch. We were tested on legal readiness, technical robustness, and interoperability, then had to demonstrate it live. That validated something we've argued for a while: consent capture is the easy part. The hard part is governing data across discovery, access, rights, and evidence at enterprise scale, and being able to prove it."
This perspective cuts to the heart of the issue. A simple pop-up banner might capture consent, but it can’t answer the harder questions that will inevitably follow: Where did that user's data go? Which third-party vendors have access to it? And can you delete it from every system within a reasonable timeframe if the user requests it? The government's nod to IDfy suggests these are precisely the questions companies will be expected to answer.
From Verification to Governance: A 15-Year Bet Pays Off
For IDfy, this moment is less a pivot and more a logical culmination of its 15-year journey. The company didn't just appear with the arrival of the DPDP Act. It has been operating deep within India's trust economy for over a decade, building what it calls its 'TrustStack' for identity verification, fraud prevention, and risk intelligence. This history gives it a unique, ground-level understanding of India’s data landscape that is difficult for global competitors or new startups to replicate.
This deep-seated experience means understanding the nuances of a 'phygital' economy where data collection happens both online and on paper, the necessity of providing consent notices in multiple Indian languages, and the specific data-handling quirks of regulated sectors like banking and insurance. By extending its TrustStack into privacy governance with Privy, the company is leveraging its long-honed expertise in managing sensitive data at scale and producing audit-ready records.
This integrated approach is becoming increasingly vital. The lines between cybersecurity, privacy, and AI governance are blurring. A single data breach can instantly become a compliance failure under the DPDP Act, a vendor risk management crisis, and a public relations nightmare. Platforms like Privy are designed to operate at this intersection, providing a unified control layer to manage these interconnected risks. The win suggests that the market, and the government, value this holistic approach over siloed, single-purpose tools.
A Market Moving from Theory to Infrastructure
The recognition arrives as privacy readiness finally climbs the boardroom agenda. The demand is palpable, and IDfy's footprint shows it. Privy is already live in over 50 enterprise environments, including major players like Axis Bank, HSBC, Airtel, and Shriram Finance. The platform reportedly covers nearly 500 million users and has already processed between 70 and 80 million consent notices, making it one of the largest real-world DPDP implementation efforts in the country.
These numbers reveal a market in transition. The most forward-thinking enterprises are no longer treating DPDP compliance as a one-time project to be completed before the deadline. Instead, they are treating privacy governance as essential operational infrastructure—as fundamental as their cloud hosting or their CRM system. It's a continuous process, not a finite task.
As the final deadlines for DPDP implementation draw closer, the theoretical questions about compliance will become urgent practical realities for thousands of businesses. The public recognition from MeitY for a solution that emphasizes scale, interoperability, and end-to-end governance offers a clear direction for a market in need of answers. The systems that will power India’s new era of digital trust are being chosen now.
Topics & Related
Cybersecurity
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →