DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Generative AI products create two distinct DPDP consent questions: whether users validly consented to how their prompts and uploads are processed, and whether they consented to their inputs being used to improve or retrain your model. Under S.6 of the DPDP Act, consent must be free, informed, specific and unambiguous — a buried clause allowing you to train on user inputs is unlikely to qualify. If you route prompts to a third-party model provider, you also need a data processing agreement and to account for cross-border transfer rules. This checker assesses your GenAI consent and data-use posture across these dimensions.

GenAI Consent & Data-Use Checker — DPDP for Generative AI

Generative AI raises unique consent questions — on prompt data, on retraining, and on third-party model calls. Check whether your product meets DPDP.

Check your GenAI consent and data-use posture

DPDP essentials for a generative AI product

What makes consent valid for a generative AI product under DPDP?

Under S.6 of the DPDP Act, consent must be free, informed, specific, unambiguous, and given through a clear affirmative action. For a generative AI product, that standard has to be met for each distinct data use. Processing a user's prompt to return an answer is one use; retaining that prompt to retrain or fine-tune your model is a different use that most users would not expect and would not have agreed to unless told plainly. A single checkbox at signup that references a lengthy policy does not carry the specificity the Act requires for these separate purposes.

The practical fix is to separate the uses and get consent for each where relevant. A clear notice at the point of interaction, an explicit opt-in for any training or improvement use, and an easy way to withdraw consent later together form a defensible posture. Niti Bharat helps generative AI teams design consent flows that are both compliant under DPDP and usable, so the compliance layer does not break the product experience or bury the meaningful choice.

What are the third-party and retention risks in generative AI?

Most generative AI products call an external model provider, which means user prompts and uploads — often containing personal data — leave your systems. Under DPDP, the provider is your data processor and you remain the accountable data fiduciary. You need a written data processing agreement binding the provider to appropriate obligations, and if processing happens outside India you must also account for the cross-border transfer rules under the DPDP Rules 2025. Sending personal data to an external model with no agreement in place is a common and avoidable gap.

Retention is the second quiet risk. Storing full prompt and conversation histories indefinitely expands both your breach exposure and your rights obligations — a data principal can request erasure under S.12, and you cannot honour that if there is no deletion path. Retaining only what you need, for as long as you need it, reduces risk on both fronts. Niti Bharat's fixed-price DPDP work for AI products covers processor agreements, transfer assessment and retention design together, ahead of full enforcement expected around May 2027.

Get the GenAI consent & data-use pack (free)

Sample consent language for a generative AI product, a prompt-data retention worksheet, and a third-party-model checklist covering data processing agreements and transfer rules.

Frequently Asked Questions

Can I train my model on user prompts if my terms allow it?+
Only if that use is covered by valid, specific consent. A clause tucked into your terms of service is unlikely to meet the DPDP standard of free, informed, specific and unambiguous consent for training. An explicit, separate opt-in for training use is the safer and more defensible approach.
Do I need a data processing agreement with my LLM provider?+
If you send personal data (including user prompts) to an external model provider, yes. Under DPDP the provider acts as your data processor, and processing must be governed by a written agreement. You should also assess whether the provider processes data outside India, which brings cross-border transfer rules into play.
Do users have the right to delete their conversation history?+
Data principals have a right to erasure of their personal data under S.12, subject to legal retention exceptions. For a generative AI product that stores prompts and conversations, that means you should provide a working deletion mechanism rather than retaining history indefinitely with no user control.
Is anonymising prompts enough to avoid DPDP?+
Only if the anonymisation is genuine and irreversible. Prompts frequently contain personal data that is hard to fully anonymise, and pseudonymised prompts that can still be linked back to a user remain personal data. Do not assume stripping names is sufficient — re-identification risk is what the law looks at.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Grievance Redressal Mechanism Under DPDP Act 2023Hospital Patient Consent Flow MapperHow to Choose a DPDP Consultant in IndiaDPDP Consent Withdrawal Mechanism CheckerSee all Reference & Checklists tools →📝 DPDP Apply to Employee Data HR📝 Consent Manager Registration DPDP