India Digital Personal Data Protection Act 2023 (DPDPA): AI Compliance Requirements
India's Digital Personal Data Protection Act 2023 (DPDPA) is the most significant Indian data law since IT Act 2000. The implementing DPDP Rules were FINALIZED 2025-11-13 (CYCLE 4: previously described as still in draft) on a phased timeline — Data Protection Board of India (DPBI) establishment rules took force immediately, consent-manager rules apply from 2026-11-13, and the remaining Rules take full effect 2027-05-13. CYCLE 20 CORRECTION (2026-08-22): "DPBI is now formally established" is legally true but materially incomplete — verified via LiveLaw, Mondaq ("The Enforcer That Isn't There Yet"), SFLC.in ("A watchdog without teeth"), and MeitY's own notification F.No. 2(1)/2026-Pers.I — the Board exists only on paper. As of this cycle, NO Chairperson and NO Members have been appointed; MeitY only opened applications for these posts on 2026-05-06 (follow-up notification 2026-06-06), with selection run by a Cabinet-Secretary-chaired search committee still in the nomination phase. This directly explains why no DPBI enforcement action exists on record (see enforcementActions) — there is currently no one to hear a complaint or issue an order. The Act applies to any organization processing digital personal data of individuals in India, regardless of where the organization is located. AI systems using Indian personal data face consent, transparency, and data localization obligations. Significant Data Fiduciaries (SDFs) — high-volume or high-risk processors, expected to include major platforms (Meta, Google, Amazon, Microsoft per 2026 MeitY consultations) and most BFSI institutions — face enhanced obligations including mandatory Data Protection Impact Assessments (DPIAs) and algorithmic accountability.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
August 11, 2023
January 1, 2025
₹250 Crore (~$30M USD) maximum — but the Schedule sets DIFFERENT caps per violation type, which can stack: ₹250 Cr for failure to implement reasonable security safeguards (Sec. 8(5)); ₹200 Cr for failure to notify a breach to DPBI/Data Principals (Sec. 8(6)); ₹200 Cr for children's-data non-compliance (Sec. 9); ₹150 Cr for SDF-obligation failures (Sec. 10). The Data Protection Board must weigh mitigating/aggravating factors — penalties are not automatically set at the maximum. The previously stated "up to ₹500 Crore for repeat violations" figure could not be corroborated this cycle and has been removed.
What Your Business Must Do
5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Consent and Notice Before Data Processing (Section 6)
CriticalDPDPA Section 6 requires Data Fiduciaries to give data principals a clear notice before or at the time of seeking consent, describing what personal data is being collected and the purpose. AI systems must present this notice in plain language. Consent must be free, specific, informed, unconditional, and unambiguous. Consent managers may be used for consumer-facing AI applications.
Deadline: August 11, 2023
DPDPA 2023, § 6Data Principal Rights (Access, Correction, Erasure, Grievance)
CriticalDPDPA Sections 11-13 grant Indian residents rights to access their data summary, correct inaccuracies, erase data (right to be forgotten), and nominate a representative. AI systems must implement mechanisms for data principals to exercise these rights. A grievance officer must be designated and respond within timeframes set by DPBI rules.
Significant Data Fiduciary (SDF) Enhanced Obligations (Section 10)
High PriorityDPDPA Section 10 empowers the government to designate high-volume or high-risk processors as Significant Data Fiduciaries. SDFs must: appoint an Indian Data Protection Officer, appoint an Indian-resident MD or CEO as compliance officer, conduct annual Data Protection Impact Assessments, and engage independent data auditors. AI systems with large Indian user bases are likely SDF candidates. CYCLE 4 (2026-08-22): major platforms (Meta, Google, Amazon, Microsoft) and most BFSI institutions are expected SDF candidates per 2026 MeitY consultations.
Children's Data and AI Restrictions (Section 9)
High PriorityDPDPA Section 9 prohibits processing of children's data (under 18) without verifiable parental consent and prohibits behavioral monitoring or targeted advertising to children. AI systems that may interact with Indian minors must implement age verification and explicit parental consent mechanisms before any data processing.
Data Breach Notification to DPBI and Data Principals
High PriorityDPDPA Section 8(6) requires Data Fiduciaries to notify the Data Protection Board of India (DPBI) and affected Data Principals of any personal data breach, in such form and manner as prescribed by rules. CYCLE 4 (2026-08-22): the DPDP Rules were FINALIZED 2025-11-13 (previously described as still draft) — the 72-hour notification proposal is now part of the finalized Rules framework, on the phased timeline described in the jurisdiction summary. AI system compromises, unauthorized model access, and inference attacks disclosing personal data are all potential breach triggers. Maintain a breach log.
Who Does This Apply To?
The DPDPA applies to the processing of digital personal data of Data Principals (individuals) who are in India, regardless of whether processing occurs within or outside India. Extraterritorial: a foreign SaaS company with Indian users is a Data Fiduciary under DPDPA from the moment it collects personal data from Indian residents. The Central Government may exempt certain classes of Data Fiduciaries by notification — in particular, start-ups and small businesses may receive simplified obligations (draft rules expected to define thresholds). Significant Data Fiduciaries (SDFs) face enhanced obligations: SDF designation criteria include processing personal data of large volumes of Data Principals, processing sensitive personal data, handling data with potential national security implications, or operating a social media intermediary with significant Indian presence. R{cycle6} CORRECTION (web-verified 2026-08-22): the DPDPA Rules are no longer in draft — they were FINALIZED and gazetted 2025-11-13 (G.S.R. 846(E)) on a phased timeline (Board-establishment provisions immediate; consent-manager rules from 2026-11-13; full remaining Rules from 2027-05-13), clarifying SDF designation thresholds, consent notice formats, and grievance officer response timelines. A MeitY proposal floated 2026-01-23 to compress the SDF compliance window from 18 to 12 months (moving the SDF deadline from 2027-05-13 to 2026-11-13) has NOT been formally gazetted as of this cycle — 2027-05-13 remains the operative SDF deadline; treat the earlier date as a monitoring item, not confirmed law.
Recent Regulatory Guidance
DPDP Rules — Consent Notice and Breach Notification (MeitY, finalized 2025-11-13)
MeitY published draft DPDPA Rules in November 2024 covering: (1) Consent notice format — must be in English and any scheduled Indian language, plain language, itemized list of purposes; (2) Breach notification — 72 hours to DPBI, simultaneous notification to affected Data Principals for high-severity breaches; (3) Grievance Officer — must respond within 48 hours and resolve within 30 days; (4) Consent Manager framework — accredited intermediaries who manage user consent across multiple Data Fiduciaries. CYCLE 4 UPDATE (2026-08-22): verified this cycle (IAPP, Baker Botts, EY India) — the Rules were FINALIZED and notified 2025-11-13, on a phased timeline: Board-establishment provisions took force immediately; consent-manager rules apply from 2026-11-13; the remaining Rules (including the operational detail of these consent-notice/breach-notification provisions) take full effect 2027-05-13. Organizations should treat the draft-stage content above as materially confirmed by the final Rules pending independent line-by-line verification of the gazetted text, not fetched this cycle.
MeitY Guidance: AI and DPDPA — Processing Children's Data (February 2025)
MeitY issued targeted guidance on AI systems and children's data under DPDPA Section 9: AI features must not infer or process age-related information to serve targeted content to users who may be minors. Age-agnostic AI (e.g., a general productivity tool) does not require age verification unless the AI feature itself serves content that could harm minors. Consumer-facing AI apps with content that could harm minors (social features, behavioral personalization, health advice) must implement verifiable parental consent. The guidance confirmed that the 18-year age threshold is strict — 17-year-olds are children under DPDPA.
Key Case Law & Precedent
Shreya Singhal v. Union of India (IT Act, 2015) — DPDPA Interpretive Baseline
Supreme Court of India · 2015Outcome: Section 66A struck down; Section 79 read down (landmark digital free-speech precedent).
Case referenceQuarterly Enforcement Digest
CYCLE 20 UPDATE (2026-08-22): the DPBI remains UNSTAFFED — no Chairperson or Members appointed as of this cycle; MeitY only opened applications 2026-05-06 via a Cabinet-Secretary-led search committee. Practical effect: no enforcement body currently exists to hear complaints or issue orders, regardless of the substantive Rules being finalized. CYCLE 4 UPDATE (2026-08-22): removed a fabricated claim that "the DPBI issued its first formal notice in March 2025" — this was already identified as a phantom (unnamed respondent, no source) in caseCitations/enforcementActions by R133/R134, but had survived uncaught in this digest field until this cycle; no DPBI enforcement action against a named respondent is on public record as of this cycle. What IS real and verified this cycle: the DPDP Rules were FINALIZED 2025-11-13 (not merely "in consultation" as previously stated) on a phased timeline (Board rules immediate; consent-manager rules 2026-11-13; full regime 2027-05-13) — see deadlineCalendar. Key developments for SaaS companies: (1) Extraterritorial reach confirmed — any SaaS with Indian users is a Data Fiduciary; (2) AI training consent must be specific — "improve our services" is insufficient; (3) Children's data guidance confirmed strict 18-year threshold; (4) the 72-hour breach notification framework is now part of the finalized Rules, phasing in per the schedule above; (5) major platforms (Meta, Google, Amazon, Microsoft) and BFSI institutions are expected SDF candidates per 2026-01 MeitY consultations. Priority actions: deploy a DPDPA-compliant consent notice for Indian users, appoint a Grievance Officer with published contact info, and implement an AI-specific data processing register documenting all personal data used in AI models.
Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.
Industry Playbooks covering India Digital Personal Data Protection Act 2023 (DPDPA)
These industry playbooks include jurisdiction-specific checklist items and guidance for India Digital Personal Data Protection Act 2023 (DPDPA).
Frequently Asked Questions
Does India Digital Personal Data Protection Act 2023 (DPDPA) apply to my business?
India's Digital Personal Data Protection Act 2023 (DPDPA) is the most significant Indian data law since IT Act 2000. The implementing DPDP Rules were FINALIZED 2025-11-13 (CYCLE 4: previously described as still in draft) on a phased timeline — Data… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under India Digital Personal Data Protection Act 2023 (DPDPA) is: ₹250 Crore (~$30M USD) maximum — but the Schedule sets DIFFERENT caps per violation type, which can stack: ₹250 Cr for failure to implement reasonable security safeguards (Sec. 8(5)); ₹200 Cr for failure to notify a breach to DPBI/Data Principals (Sec. 8(6)); ₹200 Cr for children's-data non-compliance (Sec. 9); ₹150 Cr for SDF-obligation failures (Sec. 10). The Data Protection Board must weigh mitigating/aggravating factors — penalties are not automatically set at the maximum. The previously stated "up to ₹500 Crore for repeat violations" figure could not be corroborated this cycle and has been removed.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with India Digital Personal Data Protection Act 2023 (DPDPA)?
The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://meity.gov.in/writereaddata/files/Digital%20Personal%20Data%20Protection%20Act%202023.pdfLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan