New Delhi, September 9, 2026: Canara Bank has reportedly committed more than ₹50 crore towards compliance with India’s Digital Personal Data Protection Act (DPDPA), in what could become one of the banking sector’s significant investments in data privacy and protection infrastructure.
According to information highlighted in a recent post by privacy expert Vijayashankar Na on Naavi.org, Canara Bank has entered into a ₹52.19-crore contract with an IT solutions provider as part of its DPDPA compliance efforts. The bank has also reportedly engaged an AI platform developer under a six-month contract and an audit firm for approximately ₹82 lakh to provide resources related to DPDPA compliance.
Taken together, these engagements could represent an overall investment of around ₹60 crore, although the exact scope and final expenditure associated with the initiatives would depend on the respective contracts and deliverables.
The reported investment has also sparked discussion about the potential financial impact of DPDPA compliance across India’s banking industry. Based on Canara Bank’s estimated 7% share of the Indian banking sector, the article suggests that a similar level of spending across the industry could translate into an indicative investment of approximately ₹860 crore in DPDPA compliance.
Canara Bank, in which the Government of India holds a majority stake, is a public sector bank with significant technology infrastructure and systems that are subject to heightened regulatory and security requirements. The bank’s reported request for proposal (RFP) could provide greater clarity on the specific technology, privacy management and compliance deliverables covered under the contract.
The development comes as banks and financial institutions prepare for the implementation and enforcement of India’s data protection framework. The article also points to similar DPDPA-related procurement activity involving NABARD, while noting that some banks have reportedly engaged Big Four consulting and audit firms for their privacy compliance programmes.
The reported involvement of technology companies also highlights a growing trend in which organisations are approaching DPDPA compliance not only as a legal or governance exercise but also as a technology and digital transformation initiative. Privacy management platforms, data discovery, consent management, governance systems, artificial intelligence and data protection technologies are increasingly becoming part of enterprise compliance strategies.
The article specifically references Kyndryl and PrivaSapien, which are reportedly involved in different aspects of Canara Bank’s compliance initiative. While Kyndryl focuses on designing, building, managing and modernising critical technology systems, PrivaSapien develops privacy management and privacy-enhancing technology solutions across the data and AI lifecycle.
Also Read: PB Fintech’s PB Pay Goes Live to Offer Unified Payment Solutions for Indian Merchants
The scale of the reported investment also raises questions about how banks will integrate privacy compliance with their expanding use of artificial intelligence. As financial institutions increasingly deploy AI across customer service, risk management, analytics and other functions, ensuring that personal data is appropriately governed throughout the AI lifecycle will remain a key compliance challenge.
The effectiveness of such investments is expected to become clearer as organisations move towards formal audits and operational compliance requirements under the DPDPA framework.
For the banking industry, Canara Bank’s reported initiative could therefore serve as an important reference point for understanding the technology, financial and operational investments required to build DPDPA-ready banking ecosystems.










