DPDP Act checklist for AI products and automations
How India's Digital Personal Data Protection Act, 2023 applies to AI systems, chatbots and automations, with a practical checklist: data mapping, notice and consent, prompts and logs, vendors, security, breaches and data subject rights.
By CA Nitesh Khandelwal, Chartered Accountant · Updated 5 October 2026
Does the DPDP Act apply to your AI system?
India's Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India, and to processing outside India connected with offering goods or services to people in India. An AI assistant that reads customer emails, a chatbot that collects phone numbers or an agent that processes invoices with names on them all process personal data.
The organisation that decides why and how data is processed is the data fiduciary and carries the obligations. The AI and cloud vendors it uses are data processors acting on its behalf.
Key dates
The DPDP Rules were notified in November 2025. Some provisions apply immediately, the consent manager framework follows after about a year, and most obligations on data fiduciaries apply after about 18 months, by 2027. Penalties for failing to take reasonable security safeguards can reach ₹250 crore.
The checklist
- 01Map your data flows. List every place personal data enters, moves through and leaves the AI system: forms, uploads, prompts, model APIs, vector databases, logs, analytics and backups.
- 02Confirm a lawful basis and give notice. For most processing you need consent, preceded by a clear notice of what data you collect and why. Check whether any 'legitimate use' in the Act applies instead.
- 03Limit what reaches the model. Mask or remove names, phone numbers, Aadhaar and PAN numbers and other identifiers before data reaches a model, unless the task truly needs them.
- 04Control prompts, logs and retention. Decide how long prompts, outputs and logs are kept, who can see them, and delete them when the purpose is served.
- 05Review your AI vendors. Check where each vendor stores and processes data, whether it trains on your data, and what the contract says about security, sub-processors and deletion.
- 06Apply reasonable security safeguards. Encrypt data in transit and at rest, use least-privilege access for people and agents, and test for prompt injection and data leaks.
- 07Prepare for breaches. Have a plan to detect a personal data breach and notify the Data Protection Board and affected people as the Rules require.
- 08Support data principal rights. Make it possible to access, correct and erase a person's data, withdraw consent and raise a grievance, including data held in AI pipelines.
- 09Take extra care with children's data. Processing data of children under 18 requires verifiable parental consent and rules out tracking and targeted advertising aimed at them.
- 10Document it. Keep a record of data flows, decisions and controls so your compliance team, auditors and customers can review them.
If you also serve Europe
Many controls overlap with the EU's GDPR: data mapping, minimisation, vendor contracts, security and breach response. Designing for both at once is usually cheaper than adding one later.
How Loopd.SI helps
Loopd.SI's AI security practice designs DPDP-aligned AI systems: data classification, PII masking, access controls, prompt-injection testing, vendor risk reviews and documentation your compliance team can follow. This guide is general information, not legal advice.
Questions, answered.
01Is a chatbot covered by the DPDP Act?
Yes, if it collects or processes personal data of people in India, such as names, phone numbers or account details.
02When do DPDP Act obligations apply?
The DPDP Rules were notified in November 2025, with most obligations on data fiduciaries applying after about 18 months, by 2027.
03Can we send customer data to an AI model hosted outside India?
The DPDP Act allows transfers outside India except to countries the government restricts, but sector rules (for example for payments data) and customer contracts may be stricter. Minimise and mask the data you send either way.