Langprotect

DPDP Act & AI Compliance

Understand how India's Digital Personal Data Protection Act applies to AI systems processing digital personal data, and the safeguards organizations should implement to protect personal information.

Enacted: August 2023Regulator: Ministry of Electronics and Information Technology (MeitY)Scope: Digital Personal Data
DPDP Act

What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes India's framework for processing digital personal data while recognizing individuals' right to protect their personal data and organizations' need to process data for lawful purposes.

The Act applies to digital personal data processed in India and, in certain circumstances, to processing outside India when it is connected with offering goods or services to individuals in India.

For organizations adopting AI, the Act becomes relevant whenever personal data flows through AI applications, assistants, agents, APIs, analytics systems, or other AI-powered workflows.

The DPDP framework establishes obligations around lawful processing, notice and consent, security safeguards, breach notification, data retention, children's data, individual rights, and additional requirements for Significant Data Fiduciaries.

The Digital Personal Data Protection Rules, 2025 provide further operational requirements for implementing the Act.

What Does the DPDP Act Require?

The DPDP Act establishes obligations for Data Fiduciaries and protections for Data Principals. Organizations using AI should consider how these requirements apply when personal data enters, moves through, or is generated by AI systems.

Sections 4–5

Lawful Processing

Process digital personal data only for a lawful purpose and on the basis of consent or a specified legitimate use.

Sections 5–6

Notice & Consent

Provide clear notice about personal-data processing and obtain consent that is free, specific, informed, unconditional, and unambiguous where consent is the basis for processing.

Section 8

Data Fiduciary Obligations

Implement appropriate technical and organizational measures, maintain reasonable security safeguards, address breaches, and comply with applicable retention and grievance requirements.

Section 8(5) + Rule 6

Personal Data Security

Implement reasonable security safeguards to prevent personal-data breaches, including prescribed technical and organizational measures.

Section 8(6) + Rule 7

Breach Notification

Notify the Data Protection Board and affected Data Principals when a personal-data breach occurs, in accordance with prescribed requirements.

Section 8(7)–(8)

Data Erasure

Erase personal data when the specified purpose is no longer being served or consent is withdrawn, subject to applicable legal retention requirements.

Section 9 + Rules 10–12

Children's Data

Obtain verifiable parental consent and comply with additional restrictions when processing children's personal data.

Section 10 + Rule 13

Significant Data Fiduciaries

Meet additional requirements including a Data Protection Officer, independent data auditor, impact assessments, and periodic audits.

Sections 11–14

Data Principal Rights

Support rights relating to access, correction, erasure, grievance redressal, and nomination.

Section 16 + Rule 15

Cross-Border Transfers

Comply with restrictions and requirements prescribed by the Central Government for transferring personal data outside India.

DPDP Act at a Glance

Get a quick overview of India's DPDP Act, including its scope, key roles, implementation timeline, and core data-protection requirements. Understand how the framework applies to organizations processing digital personal data through AI and other digital workflows.

REGULATIONDigital Personal Data Protection Act, 2023
ENACTEDAugust 11, 2023
MINISTRYMinistry of Electronics and Information Technology (MeitY)
JURISDICTIONIndia
PROTECTED DATADigital Personal Data
KEY ROLESData Principal, Data Fiduciary, Data Processor, Significant Data Fiduciary
RULESDigital Personal Data Protection Rules, 2025
MAXIMUM PENALTYUp to ₹250 crore for certain breaches

The Act received Presidential assent on August 11, 2023. The final DPDP Rules were notified on November 13, 2025, with different provisions taking effect on different dates.

Implementation Status

The DPDP framework is being implemented in phases.

13 November 2025

Initial provisions, including the provisions establishing the Data Protection Board, came into force.

13 November 2026

The next phase includes provisions relating to Consent Managers.

13 May 2027

The major substantive provisions covering Data Fiduciary obligations, Data Principal rights, penalties, and other core requirements are scheduled to come into force.

Who Should Consider DPDP Compliance?

The DPDP Act is relevant to organizations that process digital personal data in India, as well as certain organizations outside India processing data in connection with offering goods or services to individuals in India.

Indian Enterprises

Indian Enterprises

Organizations collecting, storing, analyzing, or otherwise processing digital personal data as part of their operations.

SaaS & Technology Companies

SaaS & Technology Companies

Software companies processing customer or user information through digital platforms and applications.

AI Companies

AI Companies

Organizations developing or deploying AI applications, copilots, agents, or AI-powered services that process personal data.

Data Processors & Service Providers

Data Processors & Service Providers

Technology and service providers processing personal data on behalf of Data Fiduciaries.

Significant Data Fiduciaries

Significant Data Fiduciaries

Organizations designated by the Central Government as SDFs and subject to additional governance, audit, and impact-assessment requirements.

DPDP Readiness Checklist

Identify where digital personal data is collected and processed
Map AI applications and workflows that process personal data
Establish a lawful basis for processing
Provide appropriate notices to Data Principals
Implement valid consent mechanisms where required
Define roles for Data Fiduciaries and Data Processors
Implement reasonable security safeguards
Monitor and respond to personal-data breaches
Establish appropriate data retention and erasure processes
Support Data Principal access, correction, erasure, and grievance rights
Implement additional safeguards for children's data where applicable
Assess whether the organization qualifies as a Significant Data Fiduciary
Maintain appropriate audit, impact-assessment, and governance processes where required
Review third-party AI providers and data-processing arrangements
Monitor applicable requirements for cross-border data transfers

How DPDP Fits Into the AI Compliance Landscape

The DPDP Act focuses on the protection of digital personal data. Organizations using AI often need to implement it alongside broader privacy, security, and AI governance frameworks.

GDPR

GDPR

GDPR establishes a comprehensive framework for protecting personal data in the European Union. DPDP similarly regulates personal-data processing in India, but the two frameworks have different definitions, obligations, rights, and enforcement mechanisms.

ISO/IEC 42001

ISO/IEC 42001

ISO/IEC 42001 establishes an Artificial Intelligence Management System for governing AI-related risks and opportunities. DPDP focuses specifically on the processing and protection of digital personal data.

SOC 2

SOC 2

SOC 2 evaluates organizational controls against the AICPA Trust Services Criteria. DPDP establishes legal obligations for processing and protecting digital personal data in India.

NIST AI Risk Management Framework

NIST AI Risk Management Framework

NIST AI RMF provides a voluntary framework for identifying and managing AI risks. Organizations can use it alongside DPDP to address broader AI governance and risk-management considerations.

Frequently Asked Questions

Solution Brief

DPDP Act & AI

DPDP Act & AI Solution Brief
LangProtect Logo
DPDP Act & AI

Strengthen AI Data Protection for DPDP

Learn how LangProtect helps organizations protect personal data across AI interactions and strengthen their DPDP compliance efforts.