Algorithm transparency under the DPDP Act in India is not a standalone chapter, but the Act's notice and consent duties apply fully whenever an algorithm processes personal data. Under Section 5, a data fiduciary must give a clear notice describing what personal data is collected and the purposes it is processed for — and an algorithm that scores, ranks, profiles or targets a person is a processing purpose that must be disclosed in plain language. There is no blanket right to see source code, but data principals must be told, in understandable terms, that automated processing of their personal data is taking place and why. This guide assesses how transparent your algorithmic processing is under DPDP.
Recommendation engines, credit scores, ad targeting and ranking models all process personal data. Here is exactly what the DPDP Act requires you to disclose about them.
The DPDP Act 2023 does not use the phrase 'algorithm transparency', and unlike some frameworks it does not grant a specific right to an explanation of every automated decision. But its core duties apply fully to algorithmic processing. Under Section 5, a data fiduciary must give the data principal a clear notice of what personal data is collected and the purposes of processing — and running that data through a scoring, ranking, profiling or targeting model is a purpose that has to be disclosed. Under Section 6, consent must be free, specific, informed and unambiguous, which means a person cannot meaningfully consent to profiling they were never told about.
In practice, this makes transparency a compliance requirement even without a dedicated 'right to explanation'. If your algorithm decides who sees an offer, what price they pay, whether they qualify for credit, or how they are ranked, the data principal is entitled to know that automated processing of their personal data is happening and why. Niti Bharat helps Indian companies translate opaque model behaviour into the plain-language notices and consent flows the DPDP Act expects.
Undisclosed profiling or targeting is one of the most likely triggers for a data principal complaint, because individuals notice when they are scored, ranked or targeted in ways they never agreed to. A notice that hides automated processing behind a generic line like 'we may use your data to improve our services' is unlikely to satisfy the Section 5 notice duty, and consent gathered on that basis is vulnerable to being treated as invalid. Failures of general obligations like notice and consent carry penalties of up to ₹50 crore under the Act, with far higher ceilings where a security-safeguard failure leads to a breach.
Because the DPDP Rules 2025 were notified in November 2025 with full enforcement expected around May 2027, companies relying heavily on algorithms have a limited runway to make their processing transparent and their consent specific. Niti Bharat's fixed-price DPDP compliance engagements (₹75K–₹3.2L depending on scope) include an algorithmic-processing review — mapping every model that touches personal data and rebuilding the notice and consent layer around it.
A plain-language notice template for automated processing, a profiling consent checklist, and an explainability record template you can drop into your compliance file.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.