Do you have to disclose when a decision is made by AI under DPDP? Where an AI or automated system materially decides or scores something about a person — a loan approval, a job screen, a fraud or risk flag, an insurance quote, a content or account action — transparency about that processing is a core expectation under the DPDP Act 2023's notice and fairness principles. The Act requires notice that is clear and specific about how personal data is used, and processing that is fair and accountable; a person subjected to a consequential automated decision should be told, in plain language, that automation is involved, what data drives it, and how they can seek a human review or raise a grievance. An automated decision disclosure kit gives you the notice language, the transparency statement, and the human-review and grievance path to make AI-driven decisions defensible rather than a black box. This kit produces those disclosures tailored to your decision type.
Notice language, transparency statements and a human-review path for AI and automated decisions under DPDP — tailored to the type of decision, its impact and the data that drives it.
This section provides the core notice a person should receive when a consequential decision about them is made or materially assisted by an automated system. It tells them, in plain language and without legalese, three things: that automated processing is involved in the decision, what broad categories of their personal data the system uses, and that they can request a human review or raise a grievance. This is not an abstract courtesy — the DPDP Act's notice principle requires clarity about how personal data is used, and its fairness and accountability expectations disfavour opaque, unexplained decisions that significantly affect a person. A one-line 'this decision was automated' with no route to challenge it does not meet that bar.
The template is written to be dropped into the actual moment the person encounters the decision — a loan rejection screen, an application-status email, a flagged-account message — rather than buried in a privacy policy nobody reads. It deliberately avoids over-promising a full explanation of proprietary model logic, which is neither required nor advisable, while still giving the person meaningful information: the kind of data considered, that a human can review it, and how to ask. Getting this balance right is what makes a disclosure both compliant and safe to publish.
The transparency statement sits behind the short notice for those who want more, and for the record you keep internally. It describes the categories of personal data the automated system considers (financial history, behavioural signals, demographic profile, third-party or bureau data, inferred scores), the general purpose of the processing (for example, assessing creditworthiness or detecting fraud), and the safeguards around it — that the system is monitored, that humans can review outcomes, and that the decision is not the end of the road for the individual. It stops short of exposing the model's exact weights or logic, which would be both impractical and a security and IP risk, and instead focuses on the meaningful, understandable factors.
This statement is also where you address fairness honestly. If the system uses inferred scores or third-party data, the statement acknowledges that and points to the review and grievance path as the correction mechanism. Documenting what drives the decision internally — even beyond what you publish — is what lets you answer a Data Principal complaint or a Data Protection Board query about a specific automated outcome, rather than being unable to explain your own system when challenged.
Data driving the decision, selected for your kit:
As AI systems take over decisions that used to be made by people — approving loans, screening job applicants, flagging fraud, pricing insurance, moderating accounts — the question of what a person is owed when a machine decides about them becomes central. The DPDP Act 2023 does not regulate AI as a separate category, but its principles apply squarely: notice must be clear and specific about how personal data is used, and processing must be fair and accountable. A consequential decision made by an opaque automated system, with no notice that automation was involved and no way to seek review, sits uncomfortably against both principles. Disclosing that automation is involved, what broadly drives it, and how to challenge it is the practical way to keep AI-driven decisions on the right side of the law.
This is also increasingly what individuals and, over time, regulators expect as a matter of fairness. A person turned down for credit or screened out of a job by an algorithm reasonably wants to know that a machine was involved and to have a human look at it. Building that disclosure and review path in from the start is far easier than retrofitting it after a complaint, and it materially reduces the risk of an automated decision becoming a grievance that escalates to the Data Protection Board.
Disclosure alone is not enough — the disclosure has to lead somewhere. The strongest position for any organisation running consequential automated decisions is a documented human-review procedure (a real person can re-examine the outcome), a clear grievance path to the Grievance Officer, and an internal decision record that lets you explain a specific outcome after the fact. Together these turn a black-box decision into an accountable one: the individual has recourse, and you have the evidence to show a decision was fair, considered and reviewable if it is ever questioned. Where decisions touch sensitive attributes or affect minors, the safeguards tighten further, including Section 9's restrictions on tracking and targeting children.
With DPDP enforcement approaching in May 2027, organisations in lending, insurance, HR-tech and platforms that automate high-impact decisions should put these disclosures and review paths in place now. Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) that build automated-decision transparency and grievance handling into a broader compliance programme, so the disclosures connect to real governance rather than standing alone.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.