The DPDP Act for AI Builders: What You Cannot Ignore
India's Digital Personal Data Protection Act is now in force. Here is the AI-specific reading.
DPDP for AI: The Parts You Cannot Skip
The Digital Personal Data Protection Act is now real and enforced. If you ship AI features in India, these are the points that bite.
1. Notice and consent at the point of collection
You must tell users exactly what personal data you collect and what you do with it - including AI processing. Generic "we may use AI" is not enough.
2. Purpose limitation
Data collected to deliver service A cannot be silently used to train model B. Re-consent or anonymise.
3. Significant Data Fiduciary obligations
If you process large volumes of personal data, expect extra duties: DPIAs, audits, a Data Protection Officer.
4. Automated decision-making
Users have a right to know when a decision affecting them was made by an automated system, and a path to human review. Bake this into UX, not just policy.
5. Children's data
Processing data of users under 18 needs verifiable parental consent. No exception for "AI helps them learn faster".
A practical checklist
- Update your privacy policy with AI processing language
- Maintain a record of processing activities
- Implement a user-visible "this was an automated decision" indicator where it applies
- Have a documented deletion path for personal data - including from model training sets where applicable
This is now the baseline. Treat compliance as a product feature, not a legal afterthought.
Want to apply this to your business?
Take the free AI Readiness Assessment or book a 30-min strategy call.