Governance

Building AI Systems Around India’s Digital Personal Data Protection Framework

India’s data protection framework does not ban AI. It asks plain questions about the personal data your system touches: why you hold it, who can see it, how long you keep it and what happens when something goes wrong.

BYBO Editorial12 min read

FigurePersonal data in an AI workflow
  1. CollectionNotice and consent, or a legitimate use
  2. What the model seesOnly the fields the task needs
  3. Storage and logsAccess controlled, monitored, time-limited
  4. VendorsA contract and safeguards you can check
  5. ErasureRemoved from records, logs and indexes
Contents
  1. In brief
  2. Who does the law make responsible, and for what?
  3. When may an AI system use someone’s personal data?
  4. How much personal data should the model actually see?
  5. What do the security and breach rules mean for logs?
  6. How long can a system keep the data, and how do you delete it?
  7. What changes for children’s data and larger organisations?
  8. Where do vendors, processors and transfers outside India fit?
  9. Where should you start, and who enforces this?
  10. Where this has limits
  11. Questions
  12. Sources

In brief

  • The Act names the roles. A data fiduciary decides why and how personal data is processed, and answers for its processors.
  • Most obligations become design questions: what the model sees, who reads the logs, how long anything is kept.
  • The Rules were notified on 14 November 2025 with a phased timeline. Check the current position before relying on any date.
  • This is general information, not legal advice. Ask a qualified adviser about your own processing.

Who does the law make responsible, and for what?

The Digital Personal Data Protection Act, 2023 uses three plain names. A Data Fiduciary determines the purpose and means of processing personal data (section 2(i)). A Data Principal is the individual the data is about (section 2(j)). A Data Processor processes it on a fiduciary’s behalf (section 2(k)). If your business decides why customer information is used and how, you are the fiduciary, even when a vendor’s software does the work.

Personal data means any data about an individual who is identifiable by or in relation to it (section 2(t)). Processing is defined widely, and includes collection, storage, retrieval, use, indexing, sharing and erasure (section 2(x)). Section 3 applies the Act to digital personal data processed within India, and to processing outside India connected with offering goods or services to people in India. Enquiry messages, KYC files, support transcripts and CRM notes are all in scope.

How much personal data should the model actually see?

Purpose limitation and minimisation turn into three concrete decisions: what goes into the prompt, what goes into the retrieval index and what is written to the log. Each creates a copy of personal data that must then be protected, found and erased.

  • Inventory the personal data each workflow touches: which fields, which documents, which channels.
  • Send the fields the task needs rather than the whole customer record.
  • Mask or tokenise identifiers the task does not need. Rule 6 names masking and virtual tokens as security measures.
  • Decide in writing whether a vendor may use your data to improve its models.
  • Record the specified purpose for each workflow, so nobody justifies a use by saying the data was already in the file.

What do the security and breach rules mean for logs?

Section 8(5) requires reasonable security safeguards for personal data in your possession or control, including processing done on your behalf. Rule 6 sets the minimum: encryption, obfuscation, masking or virtual tokens; control of access to the computer resources used; visibility on access through logs, monitoring and review, so unauthorised access can be detected and investigated; backups; retention of those logs and data for one year unless another law requires otherwise; a contract term obliging your processor to take safeguards; and technical and organisational measures to make them effective.

Set that beside the way AI systems are usually built. Prompts, outputs and traces often contain personal data, and once they do they are personal data in your possession. The access rules you apply to the customer database apply to the prompt log too. Decide what is written there before launch, in the same spirit as permissions, logs and approval gates.

A personal data breach is defined broadly in section 2(u): any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability. Section 8(6) requires intimation to the Board and to each affected person, and rule 7 sets out the shape of it.

Breach intimation as rule 7 sets it out
WhoWhenWhat it must contain
Each affected personWithout delayThe breach, likely consequences, mitigation, safety steps, a contact
The Board, first messageWithout delayNature, extent, timing, location and likely impact
The Board, follow-upWithin 72 hoursDetailed facts, causes, mitigation, findings, remedies, intimations sent

How long can a system keep the data, and how do you delete it?

Section 8(7) requires erasure when consent is withdrawn, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is necessary to comply with a law in force. You must also cause your processor to erase what you gave it. Section 12 separately gives the person a right to correction, completion, updating and erasure on request.

Section 8(8) deems the purpose no longer served when the person neither approaches you for it nor exercises her rights for a prescribed period. Rule 8 and the Third Schedule prescribe those periods for specified classes, such as an e-commerce entity with not less than two crore registered users in India: three years from her last approach or from the commencement of the Rules, whichever is latest, with carve-outs for account access and stored tokens. Rule 8(2) requires at least forty-eight hours’ notice before that erasure.

There is a floor as well as a ceiling. Rule 8(3) requires personal data, associated traffic data and other logs of the processing to be kept for a minimum of one year, for the purposes in the Seventh Schedule, unless another law requires longer. The Rules illustrate it with an e-book platform that keeps order details and processing logs for a year even after the customer deletes her account.

Deletion in an AI system is rarely one button. A person’s data may sit in the application record, the prompt log, the retrieval index, the analytics copy, the vendor’s stored conversations and last night’s backup. Map those places while the system is being built. Our own privacy information page is a short example of the plain tone that suits this.

What changes for children’s data and larger organisations?

A child is anyone who has not completed eighteen years (section 2(f)). Section 9 requires verifiable consent from a parent or lawful guardian before processing a child’s personal data, prohibits processing likely to cause a detrimental effect on a child’s well-being, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 asks for due diligence that the person identifying herself as the parent is an identifiable adult. Rule 12 and the Fourth Schedule exempt certain classes and purposes, subject to conditions.

Under section 10 the Central Government may notify a fiduciary, or a class of them, as a Significant Data Fiduciary, weighing factors that include the volume and sensitivity of personal data processed and the risk to the rights of Data Principals. Such a fiduciary must appoint a Data Protection Officer based in India and an independent data auditor, and carry out periodic impact assessments and audits. Rule 13 makes those annual, requires significant observations to reach the Board, and adds due diligence that algorithmic software used to process personal data is not likely to pose a risk to those rights.

Where do vendors, processors and transfers outside India fit?

Section 8(1) is the sentence to remember when a vendor offers comfortable terms. The fiduciary is responsible for complying with the Act for any processing undertaken by it or on its behalf by a processor, irrespective of any agreement to the contrary. Section 8(2) permits engaging a processor only under a valid contract, and rule 6(1)(f) requires that contract to provide for security safeguards. Outsourcing the work does not outsource the responsibility. Six things belong in the contract:

  • The purposes the vendor may process for, and an explicit position on training models with your data.
  • Sub-processors, and notice before they change.
  • Security measures, and the evidence you can ask for.
  • Breach notification to you fast enough to meet the rule 7 timelines.
  • Deletion on request and on exit, including logs and derived copies.
  • Where processing and storage take place.

On transfers, the Act takes a specific approach. Section 16(1) allows the Central Government, by notification, to restrict transfers of personal data for processing to a country or territory it notifies. Section 16(2) makes clear this does not displace any Indian law giving higher protection or a stricter restriction, so sector rules still bind you. Rule 15 adds that a transfer is subject to requirements the Government may specify about making personal data available to a foreign State, and rule 13(4) allows specified data of Significant Data Fiduciaries to be kept within India. In practice, know which region each provider processes in and keep the ability to change it, which is the vendor lock-in question in another form.

Where should you start, and who enforces this?

Enforcement sits with the Data Protection Board of India, established under section 18. Section 27 lets it direct urgent remedial measures on a breach intimation, inquire into breaches and impose penalties. Section 33 allows the monetary penalties in the Schedule after an inquiry and a hearing, having regard to the nature, gravity and duration of the breach and what was done to mitigate it. The Schedule sets ceilings of up to two hundred and fifty crore rupees for failing to take reasonable security safeguards, up to two hundred crore rupees each for breach intimation and children’s obligations, and up to fifty crore rupees for any other breach.

  1. Inventory the personal data each AI workflow touches, including prompts, logs and indexes.
  2. Write the specified purpose for each workflow and check your notice covers it.
  3. Reduce what the model sees: fields instead of full records.
  4. Decide what is written to logs, who may read them and how long they stay.
  5. Put the processor contract in place before data moves.
  6. Rehearse a deletion request and a breach intimation on paper, with a name against each step.

One design point is easy to miss. Section 8(3) requires completeness, accuracy and consistency of personal data likely to be used in a decision affecting the person or disclosed to another fiduciary. If your system prepares decisions about people, that is another reason to keep a person in the loop with the evidence beside the output. The rest is ordinary discipline, described in what enterprise AI governance means in practice. Our Infrastructure & Governance work covers the access controls, logs and evidence such a review asks for.

Where this has limits

  • This article is general information, not legal advice. How the Act and Rules apply depends on your facts, and a qualified adviser should confirm your position.
  • Commencement is phased and the text can change. Confirm the current provisions and dates from the Gazette or the Ministry before relying on them.
  • Other laws may go further. Section 16(2) preserves any law giving higher protection or stricter transfer restrictions, so sector requirements can still apply.
  • Minimisation reduces exposure; it does not remove it. A system that never sees a phone number can still cause harm through a wrong answer.

Frequently asked questions

Does the DPDP Act apply to our AI system?

If it processes digital personal data in India, or processes it outside India in connection with offering goods or services to people in India, then yes. Section 3 sets that reach, and section 2(x) defines processing widely enough to cover collection, storage, retrieval, use and erasure. There is no separate carve-out for artificial intelligence.

Do we need consent before using customer data with an AI tool?

You need a lawful purpose and a ground: either consent or one of the certain legitimate uses in section 7 (section 4). Where consent is the ground, section 6(1) limits it to the personal data necessary for the specified purpose described in your notice. Using the same records for a different purpose, such as improving a model, is a fresh question rather than an extension of the original consent.

When must a personal data breach be reported under the DPDP Rules?

On becoming aware of a breach, rule 7 requires you to inform each affected person without delay, in plain language: the nature of the breach, the likely consequences for her, what you are doing, what she can do and a contact. The Board must be told without delay with a description, then given detailed information within seventy-two hours, or longer if it allows that on a written request.

When do the DPDP Rules, 2025 actually take effect?

They were notified on 14 November 2025. As notified, rules 1, 2 and 17 to 21 commenced on publication in the Official Gazette, rule 4 one year after publication, and rules 3, 5 to 16, 22 and 23 eighteen months after publication. The Press Information Bureau describes this as an eighteen-month phased compliance period. Timelines can be amended, so confirm the current position before planning around a date.

Where BYBO fits

Sources

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023)Ministry of Electronics and Information Technology, Government of India
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))Ministry of Electronics and Information Technology, Government of India
  3. DPDP Rules, 2025 Notified: A Citizen-Centric Framework for Privacy Protection and Responsible Data UsePress Information Bureau, Government of India

General information for business readers, not legal, financial or regulatory advice. Examples are illustrative, not client work. Published 11 September 2026.

Build a system you can explain.

See Infrastructure & Governance