DPDP 2023 Compliance Guide for AI Companies in India
India's Digital Personal Data Protection Act 2023 introduces strict obligations for any company that processes personal data using AI — including 30-day DSR deadlines, 72-hour breach notifications, and penalties up to ₹250 crore.
In this guide
- 1What is the DPDP Act 2023?
- 2Who does DPDP apply to?
- 3Key obligations for AI companies
- 4DSR management: the 30-day deadline
- 5Breach notification: the 72-hour rule
- 6Penalties: up to ₹250 crore per violation
- 7How to get DPDP compliant: practical steps
What is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 (DPDP) is India's first comprehensive data protection legislation, receiving Presidential assent in August 2023. It replaces the patchwork of IT Act provisions that previously governed data privacy and introduces clear rights for data principals (individuals) and obligations for data fiduciaries (organisations that process personal data). For AI companies, DPDP is particularly significant because virtually every AI system that touches Indian users processes personal data — whether it's a recommendation engine, a credit-scoring model, a healthcare AI, or a customer service chatbot. The Act applies to the processing of digital personal data within India and to processing outside India where the data was collected in India.
Who does DPDP apply to?
If your AI system processes digital personal data of individuals in India, DPDP applies — regardless of where your company is incorporated. This extraterritorial reach is similar to the EU's GDPR and catches many Indian subsidiaries of global companies as well as Indian SaaS companies serving domestic users. The Act distinguishes between Data Fiduciaries (organisations that determine the purpose and means of processing) and Data Processors (who process on behalf of fiduciaries). Most AI companies are Data Fiduciaries for their core product data. Significant Data Fiduciaries — a category the government can designate based on data volume, sensitivity, or risk — face additional obligations including data audits, Data Protection Impact Assessments (DPIAs), and appointment of a Data Protection Officer.
- Any company processing personal data of Indian residents — regardless of where the company is based
- AI SaaS companies, fintech platforms, healthcare AI, and e-commerce recommendation engines
- Cloud service providers processing Indian personal data on behalf of customers
- Significant Data Fiduciaries designated by the government (additional obligations apply)
Key obligations for AI companies
AI companies face a specific set of challenges under DPDP that traditional software companies don't. First, the purpose limitation principle — data collected for one purpose cannot be repurposed to train a different AI model without fresh consent. If you collected user interaction data to personalise a product, you cannot silently use it to train a new fraud detection model. Second, automated decision-making is scrutinised: where AI systems make decisions that significantly affect individuals (credit decisions, hiring, medical diagnosis), data principals have the right to a human review and an explanation of the decision. Third, consent mechanisms for AI must be granular — users must be able to consent to specific types of processing, not just a blanket acceptance.
- Purpose limitation: cannot repurpose personal data for new AI training without fresh consent
- Right to explanation for automated decisions that significantly affect individuals
- Granular consent — separate consent for analytics, personalisation, and model training
- Data minimisation: collect only what the AI model genuinely needs
- Storage limitation: delete personal data once the AI processing purpose is fulfilled
- Maintain a Record of Processing Activities (ROPA) covering all AI data flows
Ready to automate your compliance?
Anverith AI covers DPDP, RBI FREE-AI, MeitY, and 6 other frameworks — all in one platform.
DSR management: the 30-day deadline
Data Subject Requests (DSRs) are one of the most operationally challenging aspects of DPDP for AI companies. Under the Act, data principals can exercise the right of access (know what data you hold), the right to correction, and the right to erasure. The Act requires responses within a 'reasonable period' — industry guidance and the draft rules suggest 30 days as the benchmark. For AI companies, erasure requests are particularly complex: when a user asks to be forgotten, you must delete their data not just from your databases but also consider whether their data contributed to a trained model. While re-training a model to remove a specific user's contribution is not explicitly required today, this is an evolving area. Document your position carefully and implement a model retraining schedule that includes data deletion.
Breach notification: the 72-hour rule
Any personal data breach must be notified to the Data Protection Board of India within 72 hours of the organisation becoming aware of it. This is a strict deadline that requires mature incident response processes. Crucially, the notification threshold is broad — you must notify even if you are not certain a breach has occurred but have reasonable grounds to believe one may have. AI companies need automated monitoring for model inversion attacks (where an attacker can reconstruct training data from a model), data exfiltration from training pipelines, and unauthorised access to inference endpoints that process personal data. Each of these scenarios triggers the 72-hour clock.
- 72 hours from becoming aware — not from confirming the breach
- Notification goes to the Data Protection Board of India
- Document breach detection time, containment actions, and data types affected
- Maintain an incident response runbook specific to AI system breach scenarios
- Test your breach response with tabletop exercises at least twice a year
Penalties: up to ₹250 crore per violation
The DPDP Act carries significant financial penalties. Failure to notify a breach can attract a fine up to ₹200 crore. Failure to implement reasonable security safeguards can result in penalties up to ₹250 crore. Non-fulfilment of obligations related to children's data (DPDP has strict rules on processing data of under-18s) can attract up to ₹200 crore. These are per-violation penalties, not annual caps. For AI companies processing large volumes of data, non-compliance is an existential risk. The Data Protection Board has the power to investigate, conduct hearings, and impose penalties without requiring a court order.
How to get DPDP compliant: practical steps
Getting compliant requires both technical and organisational changes. Start with a data mapping exercise to identify every personal data flow in your AI systems — training data ingestion, inference inputs and outputs, logging, and analytics. Then assess your current consent mechanisms, DSR workflows, and breach detection capabilities against DPDP requirements. Most AI companies need to build or buy a DSR management system, implement a 72-hour breach notification workflow, appoint a DPO (if designated as a Significant Data Fiduciary), and update contracts with data processors. Anverith's Privacy Engine automates DSR tracking with a 30-day countdown, breach notification with a 72-hour clock, and DPA lifecycle management — reducing manual compliance overhead by 80%.
- Step 1: Data mapping — document all personal data flows in your AI systems
- Step 2: Consent audit — verify all data processing has a valid legal basis
- Step 3: Build DSR workflows with a 30-day SLA tracker
- Step 4: Implement breach detection and a 72-hour notification runbook
- Step 5: Update DPAs with all data processors and sub-processors
- Step 6: Appoint DPO if your organisation is likely to be a Significant Data Fiduciary
About this guide
Written by the Anverith AI Compliance Team. Published June 12, 2026 · 9 min read. Anverith AI is India's AI Trust Platform — automating compliance across ISO 42001, DPDP 2023, RBI FREE-AI, EU AI Act, and 5 other frameworks.
Get compliant faster with Anverith AI
Automate ISO 42001, DPDP 2023, RBI FREE-AI, and EU AI Act compliance. First score in 48 hours. Trust Passport in days.