Which action should the CEO take?
India’s data-protection framework applies to data about an identifiable individual; properly anonymised data is therefore not automatically treated as personal data. Because re-identification can create privacy, security, and commercial risk, further use of an anonymised dataset should be preceded by a business-risk assessment rather than assuming consent is always required or applying non-Indian guidance as binding law.
Community Discussion