DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

When an AI or automated system makes or materially influences decisions about individuals — credit, hiring, insurance, eligibility, pricing — the DPDP Act applies to the personal data that feeds and results from those decisions. The Act requires that personal data used to make a decision affecting an individual is accurate and complete, gives data principals the right to correct inaccurate data (S.12), and requires clear notice about how their data is processed. This checker assesses whether your automated decision-making is transparent, uses accurate data, and lets individuals exercise their rights over decisions that affect them.

Automated Decision-Making DPDP Transparency Checker

If AI makes or shapes decisions about people, DPDP governs the data behind those decisions. Check your transparency, accuracy and rights handling.

Check your automated decision-making compliance

Making automated decision-making DPDP-defensible

What does DPDP require of automated decision-making?

The DPDP Act does not contain a standalone automated-decision article the way some other frameworks do, but its general obligations apply directly and meaningfully to AI-driven decisions about people. Three requirements matter most. First, notice under S.5 means individuals should understand how their personal data is processed, including where automated processing shapes decisions that affect them. Second, the expectation that personal data used to make a decision affecting an individual is accurate and complete puts a real obligation on the quality of the inputs a model relies on. Third, the right to correction under S.12 means an individual must be able to fix an inaccurate data point that could otherwise drive an unfair outcome.

Together these turn transparency and data accuracy from good practice into compliance requirements. A credit, hiring, insurance, or eligibility system that runs on unverified data, gives no notice that automation is involved, and offers no way to correct a wrong input is exposed on all three fronts. Niti Bharat helps organisations deploying automated decision-making map these obligations onto their actual decision pipelines, so the model can be explained, its inputs defended, and individual rights honoured.

Why is data accuracy the core issue for AI decisions?

Automated decisions are only as fair as the data they run on. When a model scores, ranks, or classifies a person using inaccurate or incomplete personal data, the resulting decision is not just poor — it can be a compliance failure, because the individual has a right to have inaccurate data corrected and to expect that data used in decisions about them is accurate. This is why systematic accuracy checks, a working correction channel, and documentation of what drives each decision are not optional refinements but the backbone of defensible automated decision-making under DPDP.

The exposure is highest where decisions are fully automated with no human review, because there is no human step to catch a wrong input before it becomes a consequence for the individual. Building in accuracy verification, an accessible correction mechanism, and a grievance route gives both the individual and the organisation a way to identify and fix errors. Niti Bharat's fixed-price DPDP engagements include reviewing automated decision pipelines for transparency, accuracy and rights handling, helping organisations get ahead of these obligations before full enforcement expected around May 2027.

Get the automated decision-making checklist (free)

A practical checklist for making AI-driven decisions DPDP-defensible — notice and transparency, data-accuracy verification, correction handling and grievance routes for automated decisions.

Frequently Asked Questions

Does DPDP ban fully automated decisions?+
No. The DPDP Act does not prohibit automated decision-making. What it requires is that the personal data driving decisions is accurate and complete, that individuals are given notice about how their data is processed, and that they can correct inaccurate data under S.12. The focus is on transparency and data quality, not a ban.
Do we have to explain how our AI model reached a decision?+
DPDP centres on transparency about how personal data is processed and on data accuracy rather than mandating a full technical explanation of a model. Practically, though, you should be able to document what data drives a decision so you can respond to a grievance and defend the outcome if it is challenged.
What if our model used inaccurate data to make a decision?+
The individual has a right under S.12 to have inaccurate personal data corrected. You should provide a working correction mechanism, and where an inaccurate input drove an adverse decision, be prepared to re-run or review that decision with corrected data. Systematic accuracy checks help prevent this in the first place.
Does human review remove our DPDP obligations?+
No, but it reduces risk. Whether a decision is fully automated or human-assisted, the personal data behind it must be accurate, individuals must be informed, and correction rights apply. Human review adds a checkpoint but does not exempt the underlying data processing from DPDP.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Ayushman Bharat Data PrivacyBest Consent Management Platform for DPDPBoard Awareness Briefing GuideLogistics Customer Data Protection IndiaSee all Reference & Checklists tools →📝 How to Implement Privacy By Design DPDP📝 DPDP for Law Firms