Company Secretaries play a growing role in coordinating DPDP Act compliance, Board oversight, and cybersecurity incident disclosures under SEBI LODR.
CS Role Expanded in Data & Cyber Governance
The role of Company Secretaries (CS) has expanded into data privacy and cybersecurity governance, particularly for listed entities. SEBI has emphasized the CS’s responsibility in ensuring compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and timely disclosure of cyber incidents under Regulation 32 of the LODR.
The CS is now expected to coordinate with Data Protection Officers (DPOs), facilitate Board-level reviews of data policies, and ensure breach reporting within prescribed timelines. They must also verify that disclosures related to material cyber incidents are accurate and submitted without delay.
This evolving mandate positions the CS as a central node in corporate governance architecture. Legal teams should integrate CS professionals into incident response plans and privacy impact assessments to strengthen compliance posture and mitigate regulatory risk.
Citations
- SEBI (LODR) Regulations, 2015, Regulation 32
