A chatbot that collects personal data — names, contact details, account information, or anything users type into it — is a data-collection point under the DPDP Act, and the same obligations apply as to any web form. You need a clear notice about what data the chatbot collects and why (S.5), a lawful basis such as consent for that collection (S.6), a defined retention period, and a way to honour data principal rights over the transcripts you store. Chatbots are especially prone to over-collecting because users volunteer far more than a structured form would ask. This checker assesses your chatbot's data-collection compliance.
Chatbots collect personal data the moment a user starts typing. Check whether your bot's notice, consent, retention and rights handling meet DPDP.
Chatbots invite disclosure in a way structured forms do not. A form asks for specific fields; a conversational interface invites users to type freely, and they routinely volunteer far more personal data than the bot needs — account numbers, health details, family information, complaints naming other people. Everything a user types into a chatbot that identifies an individual is personal data you are now collecting and storing, and under the DPDP Act you are the data fiduciary responsible for it. The conversational, low-friction feel of a chatbot masks the fact that it is one of the highest-volume, least-controlled data-collection points a company can operate.
This makes notice, consent, and minimisation especially important for chatbots. A short, specific notice at the start of the chat, an explicit consent step, and a bot configured not to solicit unnecessary personal data together keep collection lawful and proportionate. Niti Bharat helps companies deploying customer-facing chatbots and AI assistants get this design right, so a helpful support tool does not quietly become a compliance and breach-exposure liability.
Transcripts are the part of a chatbot deployment teams most often forget. Once a conversation ends, the transcript — frequently containing personal data — sits in logs or a database, and if no retention rule exists it accumulates indefinitely. Under DPDP's storage-limitation expectation, personal data should be kept only as long as needed for the purpose it was collected for, and indefinite retention of chat logs is hard to justify. Every retained transcript also enlarges the pool of data exposed in a breach, and security-safeguard failures leading to a breach carry the highest penalties under the Act, up to ₹250 crore.
A defensible approach defines a retention period tied to the business purpose, deletes or anonymises transcripts after it lapses, masks sensitive fields before storage, and keeps transcripts within properly access-controlled systems. Data principals also retain rights over this data, including erasure under S.12, which is only possible if you can locate and delete a specific user's transcripts. Niti Bharat's fixed-price DPDP engagements cover chatbot notice, consent, retention and rights handling as a package, ahead of full enforcement expected around May 2027.
A practical checklist and sample chatbot notice for making a customer or AI chatbot DPDP-compliant — notice, consent, minimisation, retention and children's-data handling.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.