Data Privacy

Our techno-legal professionals help organizations build robust data privacy programmes that satisfy both regulatory obligations and stakeholder expectations. We advise on DPDPA (India), GDPR, CCPA, and NIST AI Framework compliance, covering data discovery, consent management, privacy-by-design implementation, and governance frameworks. Our IT audit consulting services in this area connect legal, technical, and operational perspectives into a single, coherent privacy programme

Capabilities
Data Privacy Offerings
01
Readiness Assessment
Evaluate your current privacy practices, identify any gaps and enhance your data privacy posture.
02
Comprehensive Data Flows
Map how personal data is collected, processed, stored, and shared across systems and processes in your environment through detailed Data Flow Diagrams.
03
Data Privacy Trainings
Our engaging and customized training sessions help team members address privacy concerns in a practical while contributing to the building of a privacy aware culture.
04
Privacy Impact Assessment
Conduct a systematic evaluation to identify privacy risks associated with new projects, systems, or processes that collect, use, or share personal data.
05
Data Processing Agreements and Other Measures
Guidance and review of Data Processing Agreements and contracts to define required security and governance controls.
06
Data Subject Rights (DSR) requests
Define processes to respond effectively to access, rectification, deletion, and portability requests from Data Subjects.
Our Insights
Real Problems, Real Thinking
The notification of the DPDP Rules, 2025 represents a decisive shift in India’s data privacy and governance landscape, operationalizing the Digital Personal Data Protection Act, 2023 and establishing a comprehensive framework for how organizations must collect, process, store, retain, and share digital personal data. The rules introduce stringent expectations around consent and notice management, user rights enablement, breach notification, cross-border data transfers, vendor and third-party oversight, and enhanced security safeguards, significantly expanding the scope of compliance obligations for enterprises across sectors. For organizations, this is not merely a regulatory change but a strategic and operational transformation that requires immediate and structured action. Businesses will need to undertake enterprise-wide data discovery and mapping, redesign consent and user rights workflows, automate retention and erasure mechanisms, strengthen audit trails and breach response protocols, and embed privacy governance into board-level oversight. The phased implementation timelines further emphasize the need for early readiness planning to mitigate compliance gaps, reputational risks, and potential regulatory penalties. As data continues to become central to digital transformation and customer engagement, aligning with the DPDP Rules, 2025 will be critical to building trust, ensuring regulatory resilience, and enabling responsible data-driven growth. To understand the detailed applicability of the rules, their business impact, and our perspective on how organizations should prepare and respond, read our comprehensive POV.
  • 3-4Min Read
India’s IT landscape has experienced a dramatic shift over recent decades, moving away from traditional, paper-dependent bookkeeping methods to a vibrant, tech-powered ecosystem. Today, organizations depend on — ranging from enterprise resource planning (ERP) tools to cloud platforms — not only to boost efficiency but also to safeguard compliance, security, and data accuracy of financial reporting. This change entails additional responsibility since keeping thorough records helps to prove financial integrity and responsibility. An audit trail acts as the "black box" of an organization—a kind of financial journal that captures every activity. It records who did what, when, and how within the financial system. This creates a straightforward way to verify the accuracy and accountability of financial records. Think of it as holding a backstage pass that lets you peek behind the curtain—offering complete visibility into every transaction for transparency, tracking access to sensitive data to bolster security, and capturing system changes to ensure compliance. With their growing importance, audit trails are now a legal must-have in India, following regulatory mandates that came into effect on April 1, 2023. The push for audit trail comes straight from the Companies (Accounts) Rules, 2014, where Rule 3(1) says any organization using accounting software—whether it's ERP systems or even web portals—must have a permanent audit trail that can't be turned off. It’s got to automatically track every change, stamp it with a timestamp, and keep those records on hand for audits. Meanwhile, auditors, under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, must double-check that this feature was running all year, and wasn't tampered with. This rule isn't just for large organizations—it applies to every Indian organization. Whether it's nonprofits under Section 8 or foreign entities, it covers everything from standalone to consolidated financial statements.
  • 2-3 Min Read
Point of View | 6-8 Min Read Organizations today are navigating a risk landscape that no longer sits still. Technological change, environmental pressure, and shifting societal expectations are blurring the traditional boundaries between risk categories, creating a complex, interconnected environment where a single disruption rarely stays contained to one part of the business. Developing the ability to identify, understand, and mitigate these risks has become essential for organizations aiming for resilient, sustainable growth, not just for risk teams but for leadership as a whole. This shift also creates an opening for internal audit functions specifically. Emerging risks give internal audit teams a genuine opportunity to demonstrate agility, sound judgment, and strategic insight, reinforcing their role as a driver of organizational resilience and long-term value creation, not just a compliance checkpoint. Two risk categories in particular deserve close attention heading into 2026: business continuity and human capital. Business Continuity Risk: From Contained Incidents to Domino Effects Business continuity risks are the probable disruptions that hinder an organization's ability to operate effectively and deliver essential services. These disruptions can originate from multiple sources at once, including natural disasters, technological failures, cybersecurity incidents, geopolitical conflicts, and supply chain breakdowns. The COVID-19 pandemic and the Suez Canal blockage remain two of the clearest recent examples of how severely these risks can disrupt global operations, and both illustrate a pattern that continues to define continuity risk today: these disruptions are highly interconnected and interdependent. A relatively minor disruption in one part of a supply chain or operating model can trigger a cascading effect that produces operational and financial consequences across an entire global organization. Strengthening operational resilience is no longer a defensive, back-office exercise. It is essential for maintaining stakeholder trust and sustaining long-term value delivery, particularly as investors, regulators, and customers increasingly expect organizations to demonstrate they can absorb shocks without losing continuity of service. Human Capital Risk: The Execution Gap Behind Every Strategy Human capital risk is the vulnerability organizations face in attracting, retaining, and developing their talent. Employees remain an organization's most valuable asset and one of its most vital pillars, which means failures in talent management do not stay contained to HR. They ripple directly into business continuity, innovation capacity, and competitive position. An organization can have a well-designed strategy for navigating cyber risk, geopolitical disruption, or digital transformation, but a strategy is only as strong as the people available to execute it. Talent gaps slow an organization's ability to respond to any other risk on this list, which is why human capital risk increasingly gets discussed alongside operational and continuity risk rather than treated as a separate HR concern. Why These Two Risks Are Increasingly Discussed Together Business continuity and human capital risk are not independent categories that happen to appear on the same risk register. They compound each other. A continuity event, whether a cyberattack, a supply chain disruption, or a geopolitical shock, tests an organization's talent bench directly: whether the right people with the right authority and training are in place to respond in real time. Conversely, an organization with unresolved talent gaps going into a disruption will find that disruption harder to contain and slower to recover from. This is exactly the kind of interconnection that internal audit functions are well positioned to surface. Rather than reviewing continuity plans and workforce risk as separate audit engagements, leading internal audit teams are increasingly examining how these risks interact and where a gap in one amplifies exposure in the other. What This Means for Internal Audit and Risk Leaders in 2026 Organizations preparing their 2026 risk agendas should treat business continuity and human capital risk as connected priorities, not parallel checklist items. Practically, this means: Testing continuity plans against realistic scenarios that also account for staffing and skills availability, not just system and process recovery Reviewing whether critical roles have documented succession and cross-training coverage, particularly in functions central to incident response Assessing where talent gaps could slow the organization's response to a continuity event, and prioritizing those gaps ahead of a crisis rather than after one Giving internal audit a mandate to examine risk interconnection directly, rather than auditing each risk category in isolation Frequently Asked Questions What is business continuity risk? Business continuity risk refers to probable disruptions that hinder an organization's ability to operate effectively and deliver essential services, arising from sources such as natural disasters, technology failures, cybersecurity incidents, geopolitical conflict, or supply chain disruption. What is human capital risk? Human capital risk is the vulnerability an organization faces in attracting, retaining, and developing the talent it needs, with direct consequences for business continuity, innovation capacity, and competitive position when not managed effectively. Why are business continuity and human capital risk often discussed together? These risks compound each other. A continuity disruption tests whether an organization has the right talent in place to respond, while unresolved talent gaps make any continuity event harder to contain and slower to recover from. What role does internal audit play in managing emerging risks like these? Internal audit is increasingly positioned to examine how risks like continuity and talent interconnect, rather than auditing each in isolation, giving organizations a clearer view of where one risk gap amplifies exposure elsewhere. What real-world events illustrate business continuity risk? The COVID-19 pandemic and the 2021 Suez Canal blockage are widely cited examples of how a single disruption can cascade into significant global operational and financial consequences. Who should be paying attention to these emerging risks? Chief risk officers, heads of internal audit, COOs, and board risk committees responsible for setting the organization's 2026 risk agenda and resilience priorities. Talk to Our Team Building a risk agenda that connects continuity planning with workforce readiness, rather than treating them separately? Pierag's Business Risk Advisory practice helps organizations design internal audit and risk management approaches built for how today's risks actually interact. Talk to our team about your 2026 risk agenda. Related reading: Emerging Risks and Trends: Navigating What's Next 2026 | Beyond Net Zero: Why Climate Adaptation Is the Next ESG Frontier | Audit Trail: Ensuring Financial Integrity and Accountability
  • 2-5 Min Read
Driving Impact
Our Technology Risk Advisory
Leadership Team
cross-icon
Gaurav Khandelwal
Gaurav Khandelwal
Partner - Risk Advisory Leader
Gaurav is a Risk Advisory Practice Leader at Pierag Consulting, one of the fastest-growing firms in the advisory space. A Chartered Accountant by profession, he is a seasoned Governance, Risk, and Compliance professional with over 20 years of experience in consulting and industry. An ex-Big 4 leader, he is renowned for advising clients on managing risks and assisting large-scale organizations in implementing robust governance frameworks across sectors such as real estate, infrastructure, consumer products, beverages, hospitality, and healthcare. In his industry role, Gaurav was instrumental in driving the culture and implementing frameworks across governance, risk, and compliance. Under his leadership, Tata Realty won prestigious accolades, including the Risk and Compliance Awards at ICICI Lombard and the CNBC TV18 India Risk Management Awards. Earlier, in his leadership roles at Big 4, he led multiple risk-based internal audit engagements for diverse clients, including companies engaged in the operations and maintenance of roads, steel manufacturing across multiple locations, leading players in the Indian credit card market, and liquor manufacturers with several bottling units. He has also worked on enterprise risk management engagements, developing frameworks to effectively identify and address strategic and operational risks through structured monitoring and reporting mechanisms. For instance, he assisted a leading footwear company in re-assessing its ERM framework, prioritizing key risks, and co-developing a comprehensive mitigation plan. Gaurav has extensive experience in compliance program implementation, where he has been responsible for setting up compliance functions and reporting structures, ensuring comprehensive mapping of legal and regulatory requirements across functions, and strengthening ongoing compliance monitoring. Additionally, he successfully managed end-to-end IFC implementation for one of India’s leading healthcare brands, covering 24 hospitals across the country.

Key Expertise and Achievements

  • Risk-Based Internal Audits and Internal Controls Assurance
  • IFC/SOX Readiness, Implementation, and Compliance
  • Enterprise Risk Management Frameworks and Mitigation Planning
  • Business Process Reengineering and Regulatory Compliance
  • Large-scale IFC implementation in the healthcare industry (24 hospitals)
  • Award-winning governance and compliance leadership at Tata Realty.
cross-icon
Dipesh Khushalani
Dipesh Khushalani
Technology Risk Advisory Leader
Dipesh's journey is a testament to the amalgamation of passion and diverse experiences. His enthusiasm for computer games and experimentation with technology laid the groundwork for a career in this field. He has built a comprehensive skillset from his tenures at leading firms like KPMG India and SBI Cards, specializing in a wide range of areas including Privacy (GDPR, DPDPA), Cybersecurity, IT Audits, IT SOX, SOC 1 & SOC 2 reporting, and Business Continuity Planning. Dipesh is a Certified Information Systems Auditor (CISA) and holds an MBA in Information Systems and Security, along with a PG Diploma in Cyber Laws. His broad expertise extends across multiple sectors such as BFSI, NBFCs, Manufacturing, Aviation, and Telecom. Dipesh brings a holistic perspective to his work, with his interests in dramatics, filmmaking, and martial arts honing the creativity and adaptability needed to thrive in the dynamic technology risk domain.
cross-icon
Ankush Sharma
Ankush Sharma
Associate Director – Technology Risk Advisory
“Clarity amidst complexity, resilience amidst uncertainty.” Guided by this belief, Ankush has built his career on transforming risks into opportunities for resilience and growth. A Chartered Accountant who cleared the exam at the young age of 21, Ankush’s entry into the profession was inspired by his mother’s dream. While becoming a CA fulfilled her vision, his own passion leaned towards technology — a pursuit that naturally drew him into the world of Technology Risk Advisory, where he could combine his financial foundation with his curiosity for IT. Ankush’s professional journey began with his articleship at Dewan P.N. Chopra & Co., followed by industrial training at Gaursons India, which gave him early exposure to audits, controls, and governance. Over the next 12+ years, his career spanned Wipro Infotech, AXA XL, British Council, Teleperformance, and now Pierag Consulting. As the first employee in Pierag’s Technology Risk practice, Ankush played a pivotal role in building and scaling the service line. His career spans both the Indian market and extensive international experience, collaborating with teams across the US, UK, and more than 100 countries. This global exposure has given him a deep understanding of diverse regulatory environments and best practices. He has advised enterprises on SOC 1/SOC 2, HITRUST, PCI DSS, TPRM, and large-scale SOX/ICOFR programs, with most engagements spanning banking, insurance, telecommunications, and e-commerce industries. From guiding Fortune 100 firms on global SOX programs to enabling India’s largest airline to achieve data privacy compliance, Ankush has consistently delivered outcomes that combine regulatory rigor with business agility, while also leading ERP transformations, cybersecurity frameworks, and global risk advisory programs where he is recognized for bringing clarity and structure to complexity. What sets Ankush apart is his visionary approach: he views every engagement not just as a compliance exercise, but as a chance to build trust, transparency, and accountability in the digital age. Colleagues recognize him as a strategist who simplifies complexity, while clients value his ability to embed governance without slowing business momentum. Outside work, Ankush embraces the open road, often embarking on road trips across India — from the mountains to the coasts — journeys that reflect his resilience, curiosity, and determination to reach new horizons. A passionate coffee lover, his weekends are devoted to family and friends over thoughtful conversations, while weekdays often find him sharing the same enthusiasm for coffee and dialogue with colleagues — moments that keep him both grounded and inspired. What began as fulfilling his mother’s dream has evolved into his own passion for technology. Today, Ankush embodies resilience, foresight, and integrity — living proof that inherited dreams and personal vision together can create a powerful path forward. Professional Qualifications and Certifications:
  • Chartered Accountant
  • Bachelor of Commerce
  • ISO 27001:2022 Lead Auditor
  • ISO 27001:2022 Lead Implementer
  • Six Sigma Green Belt
 Expertise:
  • SOX & ICOFR Compliance
  • SOC 1 / SOC 2 & HITRUST Readiness
  • ERP Risk & Controls (SAP, Oracle Fusion, NetSuite)
  • Data Privacy & Cybersecurity (GDPR, DPDP, HIPAA, PCI DSS)
  • Third-Party Risk Management
Client sectors include, but are not limited to: BFSI, ITES, Manufacturing, Pharmaceuticals, Telecommunications, E-Commerce, and Healthcare.  
cross-icon
Karan Trehan
Karan Trehan
Associate Director - Technology Risk Advisory
cross-icon
Piyush Paliwal
Piyush Paliwal
Associate Director – Technology Risk Advisory

Piyush Paliwal’s professional journey reflects his commitment to bridging technology, risk, and business needs to create value-driven solutions for clients across industries. With over 9 years of experience spanning Deloitte USI, Deloitte Canada, HCL Technologies, and now Pierag Consulting, Piyush has developed deep expertise in Technology Risk Advisory, specializing in internal controls, IT audits, compliance, and risk assessments, delivering solutions across geographies including the US, Canada, UK, South Asia, and India.

At Pierag, he leads complex engagements in areas such as Risk-based Internal Audits, SOX compliance, SOC reporting readiness, ITGC reviews, IFC/ICOFR, SSAE18 assessments, and IT Application Controls. His expertise also extends to specialized areas such as Third-Party Risk Management (TPRM), Enterprise Risk Management (ERM), Data Privacy, Cybersecurity, GRC tools, IAM solutions, and regulatory frameworks like SOX, ICFR, COSO, and COBIT—helping organizations build robust compliance and control environments.

Piyush’s work spans a broad spectrum of industries, including Telecom, Technology, Manufacturing, eCommerce, FMCG, BFSI, and Life Sciences & Healthcare. Beyond technical delivery, he has played a pivotal role in client relationship management, practice building, training, and quality reviews, as well as leading teams to navigate diverse regulatory requirements. His international experience—particularly his secondment with Deloitte Canada—has further sharpened his perspective on global compliance and risk.

He holds a Master of Business Administration (Finance) and a Bachelor of Engineering (IT). He is also a certified ISO 27001:2022 Lead Implementor and ISO 42001:2023 Lead Implementor (Intertek), demonstrating his commitment to staying ahead in information security and emerging AI governance. Piyush’s expertise in working with enterprise systems such as SAP, PeopleSoft, Windows, UNIX, SQL Server, and Oracle etc. adds further depth in aligning technology environments with internal control frameworks and regulatory guidance for complex and high-growth organizations.

Recognized as a trusted advisor, Piyush brings not just strong domain knowledge but also the ability to connect business priorities with technology controls, making him a leading voice in the Technology Risk Advisory space.

Secure Your Technology Landscape
Ensure your IT environment is resilient and compliant with evolving regulations. Our Technology Risk Advisory services help you identify gaps, enhance control effectiveness, and build confidence in your technology landscape.