Skip to content
JOURNAL · BUILDING

DPDP Act 2026 — the practical compliance checklist for Indian AI products

A practical, control-by-control DPDP Act 2023 checklist for Indian AI products in 2026: lawful basis, consent UX, purpose limitation, fiduciary duties, cross-border, children, and Significant Data Fiduciary obligations. Validate the lot with a ₹1,799 guided DPDP audit.

By Dr. Nitnem Singh Sodhi9 min read← all essays
▸ ANSWER

India's Digital Personal Data Protection Act 2023 is now enforceable. For AI products the practical checklist is short but unforgiving: lawful basis, consent UX, purpose limitation, fiduciary duties, breach reporting, cross-border, and a designated Data Protection Officer once you hit Significant Data Fiduciary thresholds.

DPDP Act 2023
India's personal-data protection law. Applies to any entity processing the personal data of Indian residents, whether based in India or not. Headline penalty: up to ₹250 crore per breach class. Enforcement: Data Protection Board of India.
▸ TL;DR
  • DPDP applies to any AI product touching Indian personal data — including foreign SaaS.
  • Seven control families cover the practical ground.
  • Significant Data Fiduciary status triggers DPO, audit and impact-assessment duties.
  • The ₹1,799 DPDP frame validates your stack before a regulator does.

The seven control families

  1. Lawful basis. Consent or one of the legitimate-use exceptions, evidenced per data class.
  2. Consent UX. Granular, withdrawable, in plain language, no dark patterns.
  3. Purpose limitation. Data used only for the purpose consented; no silent re-use for model training.
  4. Fiduciary duties. Accuracy, retention limits, security safeguards, breach notification.
  5. Cross-border. Default permitted; watch the negative list as it evolves.
  6. Children & disabled. Verifiable consent, no behavioural tracking, no targeted ads.
  7. SDF duties. DPO, periodic audit, DPIA, algorithmic risk review.

DPDP vs GDPR — the deltas that bite

TopicDPDP 2023GDPR
Lawful basesConsent + listed legitimate usesSix bases including legitimate interests
Penalty headline₹250 cr per breach class4% global turnover
Cross-borderDefault allowed; negative listAdequacy / SCC / BCR
DPO triggerOn SDF designationThreshold-based
▸ FAQ

Frequently asked

Does DPDP apply to my AI product if I'm based outside India?
Yes. DPDP applies to any entity processing the personal data of Indian residents, regardless of where the entity is based.
What is the maximum DPDP penalty?
Up to ₹250 crore per breach class. Failure to take reasonable security safeguards leading to a personal-data breach carries the headline penalty.
Can I still train on personal data?
Only with a valid lawful basis — typically explicit consent for the training purpose, or one of the listed legitimate-use exceptions. Silent re-use for training is non-compliant.
Who is a Significant Data Fiduciary?
An entity designated by the central government based on data volume, sensitivity, risk to rights, electoral risk, and security implications. SDFs have additional duties including DPO appointment, periodic audit and DPIA.
How does the ₹1,799 DPDP audit help?
It runs you through the seven control families, produces a per-control finding sheet, and hands back a remediation plan you can share with your DPO or board.
▸ NEXT STEP

Validate your DPDP posture for ₹1,799.

Per-control findings, severity, remediation. Ready to share with your DPO or board.