DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

A chatbot that collects personal data — names, contact details, account information, or anything users type into it — is a data-collection point under the DPDP Act, and the same obligations apply as to any web form. You need a clear notice about what data the chatbot collects and why (S.5), a lawful basis such as consent for that collection (S.6), a defined retention period, and a way to honour data principal rights over the transcripts you store. Chatbots are especially prone to over-collecting because users volunteer far more than a structured form would ask. This checker assesses your chatbot's data-collection compliance.

Chatbot Data-Collection DPDP Compliance Checker

Chatbots collect personal data the moment a user starts typing. Check whether your bot's notice, consent, retention and rights handling meet DPDP.

Check your chatbot's data-collection compliance

Making a chatbot DPDP-compliant

Why are chatbots a distinct DPDP risk?

Chatbots invite disclosure in a way structured forms do not. A form asks for specific fields; a conversational interface invites users to type freely, and they routinely volunteer far more personal data than the bot needs — account numbers, health details, family information, complaints naming other people. Everything a user types into a chatbot that identifies an individual is personal data you are now collecting and storing, and under the DPDP Act you are the data fiduciary responsible for it. The conversational, low-friction feel of a chatbot masks the fact that it is one of the highest-volume, least-controlled data-collection points a company can operate.

This makes notice, consent, and minimisation especially important for chatbots. A short, specific notice at the start of the chat, an explicit consent step, and a bot configured not to solicit unnecessary personal data together keep collection lawful and proportionate. Niti Bharat helps companies deploying customer-facing chatbots and AI assistants get this design right, so a helpful support tool does not quietly become a compliance and breach-exposure liability.

How should chatbot transcripts be retained and secured?

Transcripts are the part of a chatbot deployment teams most often forget. Once a conversation ends, the transcript — frequently containing personal data — sits in logs or a database, and if no retention rule exists it accumulates indefinitely. Under DPDP's storage-limitation expectation, personal data should be kept only as long as needed for the purpose it was collected for, and indefinite retention of chat logs is hard to justify. Every retained transcript also enlarges the pool of data exposed in a breach, and security-safeguard failures leading to a breach carry the highest penalties under the Act, up to ₹250 crore.

A defensible approach defines a retention period tied to the business purpose, deletes or anonymises transcripts after it lapses, masks sensitive fields before storage, and keeps transcripts within properly access-controlled systems. Data principals also retain rights over this data, including erasure under S.12, which is only possible if you can locate and delete a specific user's transcripts. Niti Bharat's fixed-price DPDP engagements cover chatbot notice, consent, retention and rights handling as a package, ahead of full enforcement expected around May 2027.

Get the chatbot compliance checklist (free)

A practical checklist and sample chatbot notice for making a customer or AI chatbot DPDP-compliant — notice, consent, minimisation, retention and children's-data handling.

Frequently Asked Questions

Does DPDP treat a chatbot differently from a web form?+
No. Both are data-collection points, and the same obligations apply — notice, lawful basis, retention limits, security and data principal rights. The difference is practical: chatbots tend to collect more personal data, less predictably, because users volunteer information freely.
Is continuing to chat enough to imply consent?+
No. DPDP consent must be free, informed, specific and given through a clear affirmative action. Treating a user carrying on the conversation as consent does not meet that standard for collecting personal data. Add an explicit consent step before the bot collects personal data.
How long can we keep chatbot transcripts?+
Only as long as needed for the purpose you collected them for. There is no fixed universal period, but indefinite retention is hard to justify under the storage-limitation principle. Define a retention period tied to your business purpose, document it, and delete transcripts once it lapses.
What if a user types sensitive data we never asked for?+
You are still responsible for it once it is in your systems. Configure the bot to discourage unnecessary disclosure, mask or drop sensitive fields before storing transcripts, and apply strong security to what you do retain. Over-collection through a chatbot is a real and common exposure.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Children Data Protection CheckerClinical Data Retention Period CheckerConsent Manager Eligibility Checker IndiaCA Firm DPDP Audit ToolkitSee all Calculators tools →📝 DPDP Penalty Amount📝 DPDP Penalty Data Breach India