India's Digital Personal Data Protection Act 2023 is now enforceable. For AI products the practical checklist is short but unforgiving: lawful basis, consent UX, purpose limitation, fiduciary duties, breach reporting, cross-border, and a designated Data Protection Officer once you hit Significant Data Fiduciary thresholds.
- DPDP Act 2023
- India's personal-data protection law. Applies to any entity processing the personal data of Indian residents, whether based in India or not. Headline penalty: up to ₹250 crore per breach class. Enforcement: Data Protection Board of India.
- DPDP applies to any AI product touching Indian personal data — including foreign SaaS.
- Seven control families cover the practical ground.
- Significant Data Fiduciary status triggers DPO, audit and impact-assessment duties.
- The ₹1,799 DPDP frame validates your stack before a regulator does.
The seven control families
- Lawful basis. Consent or one of the legitimate-use exceptions, evidenced per data class.
- Consent UX. Granular, withdrawable, in plain language, no dark patterns.
- Purpose limitation. Data used only for the purpose consented; no silent re-use for model training.
- Fiduciary duties. Accuracy, retention limits, security safeguards, breach notification.
- Cross-border. Default permitted; watch the negative list as it evolves.
- Children & disabled. Verifiable consent, no behavioural tracking, no targeted ads.
- SDF duties. DPO, periodic audit, DPIA, algorithmic risk review.
DPDP vs GDPR — the deltas that bite
| Topic | DPDP 2023 | GDPR |
|---|---|---|
| Lawful bases | Consent + listed legitimate uses | Six bases including legitimate interests |
| Penalty headline | ₹250 cr per breach class | 4% global turnover |
| Cross-border | Default allowed; negative list | Adequacy / SCC / BCR |
| DPO trigger | On SDF designation | Threshold-based |
Frequently asked
- Does DPDP apply to my AI product if I'm based outside India?
- Yes. DPDP applies to any entity processing the personal data of Indian residents, regardless of where the entity is based.
- What is the maximum DPDP penalty?
- Up to ₹250 crore per breach class. Failure to take reasonable security safeguards leading to a personal-data breach carries the headline penalty.
- Can I still train on personal data?
- Only with a valid lawful basis — typically explicit consent for the training purpose, or one of the listed legitimate-use exceptions. Silent re-use for training is non-compliant.
- Who is a Significant Data Fiduciary?
- An entity designated by the central government based on data volume, sensitivity, risk to rights, electoral risk, and security implications. SDFs have additional duties including DPO appointment, periodic audit and DPIA.
- How does the ₹1,799 DPDP audit help?
- It runs you through the seven control families, produces a per-control finding sheet, and hands back a remediation plan you can share with your DPO or board.
Validate your DPDP posture for ₹1,799.
Per-control findings, severity, remediation. Ready to share with your DPO or board.
