Privacy After Hours - Edition 1
Beyond Consent
A closed-door checkpoint on DPDP execution with leaders building privacy into real systems.
Mumbai | 29th January 2026 | 60+ senior leaders

DPDP Has Moved From Interpretation To
Execution.
Privacy After Hours was created for one reason:
to bring together leaders who are not just discussing privacy, but operationalising it.
Edition 1 unpacked what happens after consent:
when personal data spreads across systems, vendors, workflows, and teams.
What We Covered
Three conversations that defined the room
The 90-Day Reality Check
Inside a DPDP Incident (The Privacy War Room)
The Value of Privacy

Who Was In The Room
Senior leaders across:
Privacy
Legal
Security
Risk
Product
Compliance
Business Operations
Industries represented:
Banking & Lending
Fintech
Insurance
Retail & Digital
Enterprise Tech


What Became Clear
Consent is necessary, but not sufficient.
Accountability breaks between teams, not inside systems.
Third parties don’t reduce responsibility; they multiply complexity.
Incident readiness is the new baseline.
Privacy ROI is measurable when governance becomes operational.
What’s Next
We meet again in 90 days.
Privacy After Hours is designed as a recurring checkpoint because DPDP readiness isn’t built in one quarter.


A Few Moments From
The Room








Hear from the Attendees
‘Privacy After Hours’ was a well-thought-out and curated event bringing the relevant privacy stakeholders from across the industry to exchange notes on the learnings, implementation challenges, and next steps. The opportunity to get the DPDP perspective directly from Justice BN Srikrishna was very enriching.
The curated dialogues by Justice B.N. Srikrishna and Mr Supratim Chakraborty from Khaitan & Co. were really insightful. The biggest takeway from the event for me was implementing privacy-by-design from inception and leveraging privacy for trust, resilience and ROI.
I appreciated the interactive format with lawyers and practitioners openly discussing the real DPDP implementation roadmap. Justice Srikrishna’s session was particularly valuable in grounding the key provisions in their original policy context. The event made DPDP feel less like abstract law and more like a practical governance journey.
The focus on moving from policy to practice made the session extremely relevant. The discussion on the first 90 days after the DPDP Rules reinforced how governance, accountability, and operational readiness must move in parallel. A timely and highly practical exchange for privacy leaders.
Congratulations to IDfy and KCO for hosting a brilliant event. The DPDP Act is one of the most consequential pieces of legislation for India's digital and AI journey. It was a privilege to hear about the making of the law from its original architect, Hon. Justice BN Srikrishna. Great interactions, amazing evening.
It was a fantastic evening, really loved the insightful session by Justice Srikrishna and the incident management simulation led by Mr. Supratim.


Get the event summary
Receive a crisp write-up of key takeaways and the evening’s structure.












