The DPDP Act 2023 is technology-neutral, so there is no separate carve-out or special exemption for AI systems. If your AI system collects, stores, uses, or generates personal data of individuals in India at any stage — training, fine-tuning, inference, or output — then DPDP applies to that processing exactly as it would to any other software. What matters is not that the system is called AI, but whether personal data is being processed and on what lawful basis. This checker walks you through where your AI touches personal data and flags where DPDP obligations attach.
DPDP is technology-neutral: personal data processed by an AI system is still personal data. Answer a few questions to see exactly where the Act applies to your system.
No — and this is the single most misunderstood point about DPDP and AI. The DPDP Act 2023 is deliberately technology-neutral. It does not name AI, machine learning, or large language models anywhere, and it grants no exemption for them. The Act regulates the processing of digital personal data, and an AI system that ingests, stores, uses, or produces personal data is doing exactly that. Whether the processing happens through a rules engine, a spreadsheet, or a neural network is irrelevant to the law. This means every DPDP obligation — lawful basis under S.6, notice under S.5, security safeguards under S.8, children's protections under S.9, and data principal rights under S.11 to S.14 — applies to AI processing without modification.
The practical consequence is that AI teams cannot treat compliance as a future problem to be solved when AI-specific regulation arrives. The obligations already exist under DPDP, which was enacted in 2023 with detailed Rules notified in November 2025 and full enforcement expected around May 2027. Niti Bharat helps AI and data-driven product teams map their systems against these existing obligations, so compliance is built into how the model is trained and deployed rather than bolted on after an inquiry.
Start by tracing personal data through every stage of your pipeline rather than reasoning about the model in the abstract. Ask three questions: does personal data enter during training or fine-tuning; do user inputs at inference contain personal data; and does the model output or infer personal data about identifiable individuals? If the answer to any is yes, DPDP applies to that processing and you are the data fiduciary responsible for it. A common blind spot is inference — teams focus on training data while overlooking that every prompt, uploaded document, and query a user submits may carry personal data you are now storing and processing.
Once you know where personal data lives in your system, you can attach the right obligation to each stage: a lawful basis and notice for collection, purpose and retention limits for storage, security safeguards for the whole pipeline, and a working process to honour data principal rights. Niti Bharat's fixed-price DPDP engagements (₹75,000 to ₹3.2 lakh depending on scope) include exactly this kind of AI-aware data-flow mapping and gap analysis, turning an abstract worry about AI compliance into a concrete, defensible plan.
A practical PDF that maps each stage of an AI or ML pipeline — training, inference, output and third-party model calls — to the specific DPDP obligation that applies, with a data-flow worksheet.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.