Own the privacy seat before it is filled from outside.
India's data protection rules are being enforced from 13 November. Full compliance is due 13 May 2027. Four out of five Indian companies have not started, and three out of four cannot find anyone who understands this well enough to help them. Somebody inside each of those companies is about to be handed this. It may as well be you.
No law degree. No coding. No career restart.
Become the person your company needs in 2027, and get the out of turn hikes and promotions that come when demand is large and supply is not.
Free to attend, all 3 days, live. Only 500 seats.
Live online · 3 to 5 October 2026
By SkillArbitrage · NSE Emerge-listed · Recognised NSDC Training Partner
Either you own this, or someone hands you theirs.
The privacy seat is being created in Indian companies right now. It gets filled either by someone who already understands how the business handles data, or by someone brought in from outside who then tells you what to do.
If you wait
- The first real incident finds you without a written sequence, and the clock is statutory.
- Somebody else defines what "deletion" means in a policy, and you inherit the impossible ticket.
- Consent gets bolted on late, by which point three other systems already hold the data.
- A vendor contract arrives with clauses nobody in the building can assess.
- The privacy role appears on the org chart above you, filled from outside.
If you own it
- You write the 72 hour runbook, and your name is on the evidence trail.
- You map the obligations onto what the company already does, and know exactly which three are missing.
- You design the request and deletion process, so the policy matches what the systems can actually do.
- You become the person the vendor contracts route through.
- The seat goes to the person already doing the work.
8 places funding privacy work right now
Not a forecast. These are the sectors where the work is being paid for, and every one of them needs someone who already understands how the business runs.
Global capability centres
2,117 centres employing 2.36 million people, including over 130 UK parents and over 80 German ones. They already run European privacy rules and now need the Indian regime on the same systems.
IT services and business process firms
A 5.8 million person industry that processes other companies' customer data. Client contracts now push encryption, retention and breach pass-through down to the delivery floor.
Audit, assurance and consulting firms
Gap assessments, readiness reviews and annual audits are being sold as a service line. The firms selling it are short of people who can deliver it.
Marketing, adtech and agencies
Cookies, tracking pixels, CRM databases and lookalike audiences. Every one of them is now a consent question, and almost no agency has anyone who can answer it.
LPO, KPO, RCM and transcription
You process other people's personal data as your core business. That makes you a Data Processor with obligations flowing down from every client contract you sign.
Recruitment and background verification
Candidate data, verification checks, criminal and financial records. The most sensitive processing most companies do, and it usually sits with a vendor.
Banking, insurance, NBFCs and fintech
Already under an IT governance mandate and a localisation directive. Data protection lands on the same stack, with a second regulator watching.
Healthtech, pharma and clinical research
The most sensitive category of data, moving between hospitals, labs, sponsors and apps, in the sector found least prepared.
The 5 things nobody trained you for
Each one is a real problem with a legal constraint attached. None of them is a lecture on the Act.
The data map
Finding personal data across systems, spreadsheets, vendor tools and somebody's personal drive, then keeping the inventory true as things change. Nothing else works until this exists, and it is the most common first paid project.
Consent that actually holds
Permission that travels through the business, so that a withdrawal in one place genuinely stops a process three systems away. Most teams treat it as a tick box and find out too late that it is not.
Deletion you can prove
Erasure that is verifiable and does not break what depends on it. This is where privacy programmes actually fail, and it is the commitment a regulator tests first.
Cross border transfer
Where the data physically sits, which jurisdictions your vendors quietly add, and how to make a call on a transfer without stopping the business.
The 72 hour breach sequence
Contain, assess, report, notify, document. What is new is a statutory clock and an evidence trail that must survive review months later.
And then proving it
Every one of the five above is something a company half does already. What almost nobody can do is operate it and then evidence it to a regulator. That gap is the job.
Why there is no incumbent class
India's privacy regulator is still being staffed. Nobody in this country has ten years of experience in this law, because the law has not existed for ten years.
The profession recruits from outside itself
- 58 per cent of Indian organisations say they are training non-privacy staff into privacy roles.
- 44 per cent report that more than half their privacy team transferred in from a completely different field.
- This is not an accident. It is how the profession is being built.
And the senior seat is often a combined one
- Indian employers are advertising roles that bolt privacy onto an existing function rather than hiring a specialist.
- Where that happens, the obvious internal candidate is whoever already understands both halves.
- Which is exactly the position you are in today.
What privacy work pays in India
Only figures an employer or a survey actually published. Nothing modelled, nothing borrowed from another country.
- State Bank of India advertised its Data Protection Officer at ₹60 lakh CTC, and an Assistant Data Protection Officer at ₹45 lakh.
- SIDBI staffed its DPO Office in May 2026: a Consent Manager at around ₹40 lakh and a Data Auditor at around ₹35 lakh.
- The DPO Club India Privacy Salary Report 2025-26, from 132 Indian privacy professionals, puts 75% of in-house DPOs above ₹35 lakh, with ₹10 to 20 lakh at one to three years of privacy experience.
- And what it costs a company to buy from outside today: Indian consultancies publish gap assessments from around ₹50,000, implementation from ₹75,000 to ₹2.5 lakh, and retainers of ₹2.5 to ₹5 lakh a quarter for a named officer.
These are market figures and the direction of travel. What you earn depends on your own effort and your market.
Live online · 3 to 5 October 2026
Three working evenings. You leave each one holding something.
Free resources go out every single day, whether or not you go any further with us.
Day 1 · Saturday 3 October
You leave with your own organisation mapped against the rules
The obligations that bind an Indian company today, and which ones bite first. The five roles being created around them, and which are document-based and remote. Then we build a data map live, on a real company, and you mark up your own.
Yours that evening: the data mapping template and the role map.
Day 2 · Sunday 4 October
You leave with the rulebooks and a six month plan
GDPR against the Indian law, side by side, including what Europe's Digital Omnibus is changing right now. Which certification, and in what order, including whether an Indian professional should take CIPP/E or CIPP/A. Then a live privacy policy review against GDPR.
Yours that evening: the privacy policy template, the consent notice sample and the request handling form.
Day 3 · Monday 5 October
You leave knowing how to find and win the work
Where the work actually is and what to charge. The 72 hour breach sequence, hour by hour. Cross border transfers. What the Consent Manager category is and why a registration window opening in November matters. And how AI drafting changes the economics of this work.
Yours that evening: the impact assessment report format, the 72 hour breach checklist and the cross border transfer checklist.
This is a live camp. There are no recordings, by design. You also get the attendee WhatsApp group and a certificate on completion.
People who came from where you are sitting
Named, with employers. Published on our own channels and learner records.
Sandip Singh · BTech to Capgemini
A 2012 BTech graduate from Cuttack. Joined in November 2022, and by December 2023 was a Senior Consultant at Capgemini working as a privacy professional. No law degree at any point.
Sonal Joshi · a science degree, not a legal one
An M.Sc in pharmaceutical chemistry, now a Data Privacy Consultant at Capgemini. The backgrounds moving into this field are not only technical ones.
Stephen George Zachariah · into cybersecurity
Now on the Legal and Cybersecurity team at Volvo Group. The combined security and privacy brief is not a theory about where this goes. It is where people are already landing.
Shreya Pandey · and Govind Tiwari
Shreya is now a Senior Analyst, Privacy and Data Protection at Infosys. Govind took first clients from the UK and the US and became a Privacy and Compliance Analyst at Pluralsight, working remotely.
Ingrid Cyril Gomes · litigation to privacy in under six months
Five years in tenancy litigation and zero privacy background. First privacy job within a month of starting her search, and by March 2024 on the data privacy operations team at Marsh McLennan.
Your instructor holds the credentials
Course anchor Aishvarya Joshi holds CIPP/E, CIPM, CIPT and AIGP from the IAPP, and is an ISO 27001 Lead Auditor and ISO 27701 Lead Implementer.
You are in the right room if
- You run IT, security, infrastructure or cloud at any level, or sit in a GRC or ISO 27001 role.
- You are an auditor, CA, CS or compliance professional, and you can already read a rulebook and apply it to a business.
- You work in marketing, CRM or an agency, and you own the customer database, the tracking or the consent journeys.
- You work in LPO, KPO, RCM, transcription or payroll outsourcing, where handling other people's data is the business.
- You work in recruitment or background verification, which is some of the most sensitive processing done anywhere.
- You are in BFSI, fintech, pharma, clinical research or a GCC, where a second regulator is already watching.
- You are restarting after a career break and want structured, document-based work you can do remotely.
No law degree needed. Across the Indian privacy postings we read, roughly one in ten asked for one.
Questions people actually ask
These are the questions people asked most often in our last session, in the order they asked them.
Is this only freelancing, or are there proper jobs too?
Both. Some people take a full-time job inside a company or a consulting firm. Some do projects for different clients and keep their existing job. Some build their own small practice. You do not have to decide now. Most people start with one small project on the side and choose later.
Where do I actually find this work? I have never done this before.
Three places. Companies in India that must follow the new law and have nobody to help them. Consulting and audit firms that are selling this service and cannot find enough people. And foreign clients on freelance websites, where small privacy jobs are posted every day. We show you all three and what to say to each.
I am from a completely different field. Can I still do this?
Yes. This law is only ten months old, so almost nobody in India has long experience in it. More than half of Indian companies say they are training people from other fields into privacy roles, because there is nobody else to hire. What you need is the ability to read a rule, understand how a company works, and write clearly.
I am a lawyer. Will this be useful for me?
Very useful. You already know how to read a law and apply it to a business. That is most of the work. What you will learn is how data actually moves inside a company, what a consent system looks like, and how to price the work.
I work in IT or cybersecurity. Is there anything new here for me?
Yes, and you have the shortest route. The law reads like a security standard. Encryption, access control, logs, backups, a 72 hour clock when something goes wrong. You already run most of it. What almost nobody can do is prove it to a regulator, and that is the job.
I work in pharma, healthcare or clinical research. Does this apply to me?
Very much. Patient data and health data carry the strictest rules and the biggest penalties. Your sector is also one of the least prepared, which means the demand for people who understand both the science and the rules is high.
Does every company have to appoint a Data Protection Officer?
A DPO is only required for companies the government marks as Significant Data Fiduciaries. Every other company still has work to do: privacy notices, consent, deleting old data, handling complaints and reporting breaches. That is where most of the work is.
Do I need a certification before I can start working?
No. Many people lose six months to a year waiting to finish a certificate before they do anything. A small company that needs its privacy notice fixed will not ask to see your certificate. Start the work, and do the certificate at the same time.
Which certification should an Indian professional take, CIPP/E or CIPP/A?
This is the most common certification question we get, and the answer depends on whether you want Indian clients, foreign clients, or a job in a large company. We go through it properly on Day 2 and tell you which one fits your situation and in what order to take them.
How long will it take before I earn anything from this?
Around three to six months if you give it one to two hours a day and start reaching out early. The learning itself takes about two months. Most of the remaining time goes into building something you can show and talking to enough people. Anyone who promises you money in three weeks is not being honest with you.
I have no experience in privacy. How do I build something to show people?
You practise on a real company. Take your own employer, or a company a friend runs, and do a data map and a privacy review for it. That becomes your first work sample. Then you offer to do one small piece of work free for somebody, in return for a written reference. After two or three of those, you start charging.
Will you cover GDPR and other laws, or only the Indian law?
Both the Indian law and GDPR, side by side, so you can see where they are the same and where they differ. This matters because GDPR is what foreign clients ask about, and many Indian companies have to follow both.
Can I do this along with my full-time job?
Yes, and most people do. One to two hours a day in the evening is the normal pattern. Please read your own employment contract first, because some companies restrict outside work. Many people also start by becoming the person inside their own company who handles this, which is a promotion rather than a side job.
Will AI take over this work?
AI will write your privacy notice and produce a first draft of a report. It cannot sign that report, it cannot be the person the regulator contacts, and it cannot be held responsible if something goes wrong. Also, every AI tool a company starts using creates more privacy work, not less, because somebody has to check what data goes into it.
Is the market already full? Am I too late?
No. Four out of five Indian companies have not started this work at all, and three out of four say they cannot find anyone who understands it well enough to help. The law came into force ten months ago, so nobody has years of experience in it.
I live in a small town, not a big city. Can I still do this?
Yes. All of this work happens on a computer. You read documents, write reports and join calls. There is no office to travel to and no factory to visit. The companies that hire are in big cities, but the work itself can be done from anywhere in India.
My English is not very strong. Will that stop me?
Most of this work is written, not spoken, and you have time to think before you reply. If you can read a document and write a clear paragraph, you can do the work. It helps to be comfortable reading English, because most privacy documents are written in it.
Is the camp recorded? Can I watch it later?
No. It is live only, all three days. You keep the notes you make, the templates we share during the sessions, the WhatsApp group and a certificate.
Registration is free, and there are only 500 seats. Once they are gone, they are gone.
Enforcement lands on 13 November. The trained people still do not exist.
Free to attend. 500 seats. No recordings, so it only exists if you are there.
Claim my free seatLive online · 3 to 5 October 2026 · free · 500 seats only
By SkillArbitrage · NSE Emerge-listed · Recognised NSDC Training Partner