Cookies & Site Data

We use only essential storage to remember your disclaimer acknowledgment and cookie choice. We do not load third-party analytics or advertising trackers today. You can review the details in our Cookie Policy.

Credentials & Affiliations

Every credential, mapped to the section of the DPDPA it actually answers.

India's DPDPA, 2023 is not a single discipline — it is a stack. Compliance, audit, engineering, AI governance and litigation each demand a distinct qualification. Below is the full catalog of credentials held across the two founding partners of DRMLAW, with the precise statutory clause each one answers.

The combined signal

DRMLAW is the only Indian techno-legal practice where both founding partners hold concurrent C.DPO.DA certification from FDPPI. This means a single firm can provide the statutory DPO appointment, the independent data audit, the engineering programme to implement controls, and the litigation representation before the Data Protection Board — without handoff risk between a law firm and a separate IT consultant. For a Significant Data Fiduciary managing a complex DPDPA programme, this eliminates the most common point of failure in compliance delivery: the gap between legal advice and technical execution.

9 credentials · DPDPA-mapped
C.DPO.DA
FDPPI

Certified Data Protection Officer & Data Auditor

Issued by · Foundation of Data Protection Professionals in India (FDPPI)
Indian professional standards body
Held by
  • Dipak Ranjan Mukherjee
  • Rupak Ranjan Mukherjee
DPDPA mapping

Section 10 (Significant Data Fiduciary obligations) · Section 20 (Independent Data Audit)

India's principal practitioner credential for Data Protection Officers and independent Data Auditors under the DPDPA, 2023.

The C.DPO.DA qualifies the holder to serve as a statutory Data Protection Officer for entities designated as Significant Data Fiduciaries under Section 10 of the DPDPA, 2023, and to conduct independent Data Audits under Section 20. Both founders hold the credential concurrently — meaning a single firm can supply both the DPO seat and the independent audit, executed by separately qualified individuals.

Advocate (HC Calcutta)
BCWB

Advocate, Hon'ble High Court at Calcutta

Issued by · Bar Council of West Bengal
Statutory bar regulator under the Advocates Act, 1961
Held by
  • Dipak Ranjan Mukherjee
DPDPA mapping

Section 27 (Data Protection Board) · Section 29 (Appeals to TDSAT)

30+ years of active courtroom practice — required to represent clients before the Data Protection Board and in appeals before TDSAT.

Enrolled with the Bar Council of West Bengal and practising at the Hon'ble High Court at Calcutta. Appearances before the Supreme Court of India, NCLT and arbitral tribunals. Without a sitting Advocate of record, a compliance practice cannot represent a Data Fiduciary before the DPB under Section 27, or in appellate proceedings before TDSAT under Section 29 — distinguishing DRMLAW from pure-play consulting firms.

AI Governance Aware
FDPPI

AI Governance Aware

Issued by · Foundation of Data Protection Professionals in India (FDPPI)
Indian professional standards body
Held by
  • Dipak Ranjan Mukherjee
DPDPA mapping

Section 11 (rights of Data Principals) · MeitY AI Advisory · DPDPA-AI interface

Formal training in AI governance frameworks and algorithmic accountability — required for boards adopting AI systems that process personal data.

Trained in AI governance frameworks and algorithmic accountability practices including impact assessment, bias testing, model documentation and human-oversight design. Directly relevant where AI / ML systems intersect with DPDPA rights (Section 11) — automated decisions affecting Data Principals — and the MeitY AI Advisory on responsible deployment of foundation models.

CCLP
CCLP

CyberLaw Certified Professional

Issued by · Cyber Law College / Naavi.org (CCLP)
Indian cyber-law specialist programme
Held by
  • Dipak Ranjan Mukherjee
  • Rupak Ranjan Mukherjee
DPDPA mapping

Information Technology Act, 2000 · IT Rules, 2021 · DPDPA interface with cyber-law

Formal certification in Indian cyber-law, the IT Act, 2000 and the IT Rules, 2021 — the regulatory ecosystem in which the DPDPA operates.

The DPDPA does not sit alone. Sections 8(5) (security safeguards) and 8(6) (breach intimation) operate alongside the IT Act, 2000 and the CERT-In Directions of 2022. The CCLP credential certifies command of this surrounding ecosystem — required to give DPDPA advice that is internally consistent with cyber-incident reporting, intermediary liability and electronic-evidence frameworks.

DPB · Advisory & Appellate
Practice

Data Protection Board of India — Advisory & Appellate Practice

Issued by · Practice qualification (function of Advocate enrolment + C.DPO.DA)
Composite practice qualification
Held by
  • Dipak Ranjan Mukherjee
DPDPA mapping

Section 27 (DPB inquiry) · Section 28 (DPB orders) · Section 29 (appeals to TDSAT)

Positioned to advise on DPB-facing matters and to appear in DPB inquiries and TDSAT appeals — not just to build compliance.

When enforcement action lands, an Indian Data Fiduciary needs an Advocate who can both interpret the underlying compliance posture (C.DPO.DA) and step into a DPB inquiry or a TDSAT appeal (Bar enrolment). Most consulting firms handle the first half; most law firms handle only the second. DRMLAW carries both in the same lead lawyer.

OCI · Planet-Scale Engineering
Oracle

Oracle Cloud Infrastructure — Planet-Scale Privacy & Cloud Engineering

Issued by · Oracle Corporation (employment record)
Global hyperscaler — verifiable employment record
Held by
  • Rupak Ranjan Mukherjee
DPDPA mapping

Section 8(4)–(5) (security safeguards) · Section 8(7) (data minimisation) · Section 16 (cross-border transfer)

Senior engineering tenure within the Oracle Cloud Infrastructure (OCI) ecosystem — managing multi-region platforms handling millions of users.

Section 8(4)–(5) requires Data Fiduciaries to deploy reasonable security safeguards and to give effect to the obligations under the Act through technical measures. That cannot be evaluated by a lawyer alone. Rupak's tenure inside the OCI ecosystem — managing multi-geography platform deployments handling millions of users across North America, Europe and Asia — gives DRMLAW direct knowledge of how cloud-native data estates actually behave at scale.

GDPR · UK · 2018
Programme record

GDPR Live Implementation — Internal Oracle division in Europe, United Kingdom (2018)

Issued by · Live programme delivery record
Verifiable enterprise programme delivery
Held by
  • Rupak Ranjan Mukherjee
DPDPA mapping

Section 5 (notice) · Section 6 (consent) · Section 8 (Data Fiduciary obligations) · Section 16 (transfer)

Led Privacy Engineering for an internal Oracle division in Europe through live GDPR implementation in the UK — not a compliance review, an engineered operating model at scale.

In 2018, led Privacy Engineering for an internal Oracle division in Europe through live GDPR implementation in the United Kingdom — consent re-architecture, data mapping across 40+ vendor systems, breach response integration and board-level reporting. GDPR Articles 5–8, 25, 32 and 33 map almost line-for-line to DPDPA Sections 5–8 and 8(6). That implementation experience translates directly into Indian programme delivery.

NIST AI RMF
NIST

NIST AI Risk Management Framework — Applied Practitioner

Issued by · U.S. National Institute of Standards and Technology
International technical standard
Held by
  • Rupak Ranjan Mukherjee
DPDPA mapping

Section 8 (security) · Section 11 (rights) — AI-augmented Data Fiduciary processing

Designs AI/ML pipeline guardrails — risk-tiering, model documentation, monitoring, incident protocols — aligned to the NIST AI Risk Management Framework.

Cutting-edge security guidance for enterprises beginning the DPDPA journey with AI in the loop. NIST AI RMF gives a defensible engineering discipline for AI risk: govern, map, measure, manage. DRMLAW applies this to the AI / ML systems that process personal data inside the Data Fiduciary's estate, so that AI augmentation does not create a new class of DPDPA exposure.

ISO/IEC 42001
ISO

ISO/IEC 42001 — AI Management System

Issued by · International Organization for Standardization
International management-system standard
Held by
  • Rupak Ranjan Mukherjee
DPDPA mapping

Section 8(4)–(5) (security) · Section 17(2) (SDF — independent Data Audits)

Builds AI governance controls aligned to ISO/IEC 42001 — the international management-system standard for artificial intelligence.

For SDFs and enterprises operating AI at scale, ISO/IEC 42001 provides the management-system spine — policy, objectives, roles, controls, monitoring, continual improvement — into which DPDPA-specific obligations bolt cleanly. DRMLAW designs the controls and the documentation so the Section 17(2) independent audit can be conducted against a recognised standard.

Where these credentials operate

See the institutional DPDPA engagement.

The catalog above is the credential stack. The link on the right is how it is operationalised inside an SDF — under a single mandate, with one accountable signature.

DRMLAW
DRMLAW
Techno-Legal

DRMLAW is a techno-legal practice combining traditional advocacy with data protection counsel and digital forensics, in compliance with the Bar Council of India's rules on advertisement.

Offices
Kolkata — Office I
7A, K.S. Roy Road
2nd Floor, Suite #10/10
Kolkata 700001
Fax +91 33 22310767
Kolkata — Office II
BJ 19, Sector II, Salt Lake
Kolkata 700091
Bengaluru
153/A, 18th Main, 24th Cross
Sector 3, HSR Layout
Bengaluru 560102, India
© 2026 DRMLAW • drmlaw.in/technolegal
Cookie Policy
Bar Council of India Rules disclaimer: The information on this website is provided for general informational purposes only. Nothing herein constitutes solicitation, advertisement or legal advice. Communication does not establish an attorney-client relationship.

Made with Emergent