Generative AI products create two distinct DPDP consent questions: whether users validly consented to how their prompts and uploads are processed, and whether they consented to their inputs being used to improve or retrain your model. Under S.6 of the DPDP Act, consent must be free, informed, specific and unambiguous — a buried clause allowing you to train on user inputs is unlikely to qualify. If you route prompts to a third-party model provider, you also need a data processing agreement and to account for cross-border transfer rules. This checker assesses your GenAI consent and data-use posture across these dimensions.
Generative AI raises unique consent questions — on prompt data, on retraining, and on third-party model calls. Check whether your product meets DPDP.
Under S.6 of the DPDP Act, consent must be free, informed, specific, unambiguous, and given through a clear affirmative action. For a generative AI product, that standard has to be met for each distinct data use. Processing a user's prompt to return an answer is one use; retaining that prompt to retrain or fine-tune your model is a different use that most users would not expect and would not have agreed to unless told plainly. A single checkbox at signup that references a lengthy policy does not carry the specificity the Act requires for these separate purposes.
The practical fix is to separate the uses and get consent for each where relevant. A clear notice at the point of interaction, an explicit opt-in for any training or improvement use, and an easy way to withdraw consent later together form a defensible posture. Niti Bharat helps generative AI teams design consent flows that are both compliant under DPDP and usable, so the compliance layer does not break the product experience or bury the meaningful choice.
Most generative AI products call an external model provider, which means user prompts and uploads — often containing personal data — leave your systems. Under DPDP, the provider is your data processor and you remain the accountable data fiduciary. You need a written data processing agreement binding the provider to appropriate obligations, and if processing happens outside India you must also account for the cross-border transfer rules under the DPDP Rules 2025. Sending personal data to an external model with no agreement in place is a common and avoidable gap.
Retention is the second quiet risk. Storing full prompt and conversation histories indefinitely expands both your breach exposure and your rights obligations — a data principal can request erasure under S.12, and you cannot honour that if there is no deletion path. Retaining only what you need, for as long as you need it, reduces risk on both fronts. Niti Bharat's fixed-price DPDP work for AI products covers processor agreements, transfer assessment and retention design together, ahead of full enforcement expected around May 2027.
Sample consent language for a generative AI product, a prompt-data retention worksheet, and a third-party-model checklist covering data processing agreements and transfer rules.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.