All insights
GovernanceIndiaStrategy

The DPDP Act for AI Builders: What You Cannot Ignore

India's Digital Personal Data Protection Act is now in force. Here is the AI-specific reading.

Teknesya Networks 23 May 20261 min read
The DPDP Act for AI Builders: What You Cannot Ignore

DPDP for AI: The Parts You Cannot Skip

The Digital Personal Data Protection Act is now real and enforced. If you ship AI features in India, these are the points that bite.

1. Notice and consent at the point of collection

You must tell users exactly what personal data you collect and what you do with it - including AI processing. Generic "we may use AI" is not enough.

2. Purpose limitation

Data collected to deliver service A cannot be silently used to train model B. Re-consent or anonymise.

3. Significant Data Fiduciary obligations

If you process large volumes of personal data, expect extra duties: DPIAs, audits, a Data Protection Officer.

4. Automated decision-making

Users have a right to know when a decision affecting them was made by an automated system, and a path to human review. Bake this into UX, not just policy.

5. Children's data

Processing data of users under 18 needs verifiable parental consent. No exception for "AI helps them learn faster".

A practical checklist

  • Update your privacy policy with AI processing language
  • Maintain a record of processing activities
  • Implement a user-visible "this was an automated decision" indicator where it applies
  • Have a documented deletion path for personal data - including from model training sets where applicable

This is now the baseline. Treat compliance as a product feature, not a legal afterthought.

Want to apply this to your business?

Take the free AI Readiness Assessment or book a 30-min strategy call.