Course resource

India's DPDP Act, Simplified

A working summary of the Digital Personal Data Protection Act, 2023, for people using AI tools with personal data in India.

This is a plain-English orientation, not legal advice. Rules under the Act have been issued in stages and obligations depend on your role and scale. Get proper advice before relying on any of this commercially.

What it covers

Digital personal data — any data about an identifiable individual, processed digitally. This includes data collected on paper and later digitised.

It applies to processing inside India, and to processing outside India where goods or services are offered to people in India.

The vocabulary

Term Plain English
Data Principal The person the data is about
Data Fiduciary You, if you decide why and how the data is processed
Data Processor Someone processing it on your behalf — including, usually, your AI vendor
Significant Data Fiduciary Larger or higher-risk entities, with extra obligations

If you are pasting customer data into an AI tool, you are the Fiduciary and the AI vendor is your Processor. The obligations sit with you, not the vendor.

The obligations that matter day to day

Consent must be specific and informed. A notice in plain language saying what data, for what purpose. Bundled, blanket consent does not work. Consent is withdrawable, and withdrawal must be as easy as giving it.

Purpose limitation. Data collected for one purpose cannot be repurposed. Collecting support tickets to resolve support issues does not authorise feeding them into an AI tool to train a sales model.

Minimisation. Only the data necessary for the stated purpose.

Accuracy. Reasonable steps to keep it correct, particularly where it affects a decision about the person.

Erasure. Delete when the purpose is served or consent is withdrawn — and ensure your processors do too.

Security. Reasonable safeguards. A breach is notifiable to the Board and to affected individuals.

Children. Under 18 requires verifiable parental consent, and behavioural advertising and tracking directed at children is prohibited. This is stricter than many other regimes and catches education and consumer products in particular.

What this means for AI use specifically

1. Your AI vendor is a processor. You need a contract that binds them. Check whether your tier actually provides one — consumer tiers generally do not.

2. Pasting personal data into a free tier is hard to defend. No processor agreement, unclear retention, and possible training on the data.

3. Purpose limitation bites. Data your customers gave you for delivery, support or billing is not automatically available for AI experiments.

4. Erasure must reach your tools. If someone withdraws consent, their data must go from the AI tool's history too — not just your database. Practically this means not pasting identifiable data in the first place.

5. Cross-border transfer. Most AI vendors process outside India. The Act permits transfer except to restricted countries, but you should know where your data actually goes.

6. Breach notification is mandatory. Data exposed through an AI tool is a breach. There is no materiality threshold to hide behind.

A practical compliance posture

How it compares to GDPR

Broadly similar in shape — notice, consent, minimisation, erasure, breach notification. The practical differences worth knowing:

If you already comply with GDPR, you are most of the way there. The gaps are usually consent granularity and the children's rules.

Where to check the current position

The Act and its rules have been rolled out in phases, with transition periods. Check the Ministry of Electronics and Information Technology (MeitY) for the current commencement status and the text of the rules before making a compliance decision.

Your register

Tool Personal data processed Purpose Lawful basis DPA in place Retention Reviewed
Back to dashboard