Course resource
India's DPDP Act, Simplified
A working summary of the Digital Personal Data Protection Act, 2023, for people using AI tools with personal data in India.
This is a plain-English orientation, not legal advice. Rules under the Act have been issued in stages and obligations depend on your role and scale. Get proper advice before relying on any of this commercially.
What it covers
Digital personal data — any data about an identifiable individual, processed digitally. This includes data collected on paper and later digitised.
It applies to processing inside India, and to processing outside India where goods or services are offered to people in India.
The vocabulary
| Term | Plain English |
|---|---|
| Data Principal | The person the data is about |
| Data Fiduciary | You, if you decide why and how the data is processed |
| Data Processor | Someone processing it on your behalf — including, usually, your AI vendor |
| Significant Data Fiduciary | Larger or higher-risk entities, with extra obligations |
If you are pasting customer data into an AI tool, you are the Fiduciary and the AI vendor is your Processor. The obligations sit with you, not the vendor.
The obligations that matter day to day
Consent must be specific and informed. A notice in plain language saying what data, for what purpose. Bundled, blanket consent does not work. Consent is withdrawable, and withdrawal must be as easy as giving it.
Purpose limitation. Data collected for one purpose cannot be repurposed. Collecting support tickets to resolve support issues does not authorise feeding them into an AI tool to train a sales model.
Minimisation. Only the data necessary for the stated purpose.
Accuracy. Reasonable steps to keep it correct, particularly where it affects a decision about the person.
Erasure. Delete when the purpose is served or consent is withdrawn — and ensure your processors do too.
Security. Reasonable safeguards. A breach is notifiable to the Board and to affected individuals.
Children. Under 18 requires verifiable parental consent, and behavioural advertising and tracking directed at children is prohibited. This is stricter than many other regimes and catches education and consumer products in particular.
What this means for AI use specifically
1. Your AI vendor is a processor. You need a contract that binds them. Check whether your tier actually provides one — consumer tiers generally do not.
2. Pasting personal data into a free tier is hard to defend. No processor agreement, unclear retention, and possible training on the data.
3. Purpose limitation bites. Data your customers gave you for delivery, support or billing is not automatically available for AI experiments.
4. Erasure must reach your tools. If someone withdraws consent, their data must go from the AI tool's history too — not just your database. Practically this means not pasting identifiable data in the first place.
5. Cross-border transfer. Most AI vendors process outside India. The Act permits transfer except to restricted countries, but you should know where your data actually goes.
6. Breach notification is mandatory. Data exposed through an AI tool is a breach. There is no materiality threshold to hide behind.
A practical compliance posture
- Do not paste identifiable personal data into AI tools. Anonymise first.
- Where you must, use a tier with a processor agreement in place.
- Update your privacy notice to say AI tools are used, and for what.
- Keep a record of which tools process personal data, and why.
- Know your vendors' retention and deletion behaviour.
- Have a breach procedure that includes AI tools explicitly.
- Extra care with anything involving people under 18.
- Do not use AI as the sole basis for a decision affecting a person.
How it compares to GDPR
Broadly similar in shape — notice, consent, minimisation, erasure, breach notification. The practical differences worth knowing:
- DPDP is consent-centric; it has fewer alternative lawful bases than GDPR's six
- "Legitimate uses" replace some of GDPR's legitimate-interest reasoning, and are narrower
- The children's provisions are stricter
- Penalties are set as monetary ceilings per breach type rather than a turnover percentage
If you already comply with GDPR, you are most of the way there. The gaps are usually consent granularity and the children's rules.
Where to check the current position
The Act and its rules have been rolled out in phases, with transition periods. Check the Ministry of Electronics and Information Technology (MeitY) for the current commencement status and the text of the rules before making a compliance decision.
Your register
| Tool | Personal data processed | Purpose | Lawful basis | DPA in place | Retention | Reviewed |
|---|---|---|---|---|---|---|