
The DPDP Act does not mention artificial intelligence, but it governs the personal data that AI products collect, send to model providers and train on. For AI teams the questions are practical: what can we train on, where can we send prompts and what happens when a user asks to be deleted.
Publicly available data
The Act does not apply to personal data that is made publicly available by the person it relates to, or by someone under a legal obligation to publish it. This helps with data people have chosen to publish themselves. It does not cover personal data that others posted about a person, data behind a login, or data scraped in breach of a site's terms. Record where each training source came from and why you believe it falls within the exemption.
Training on your users' data
Consent is tied to a specified purpose. Data collected to provide a service cannot be reused to train a model unless the notice said so and the user agreed. Make model training a separate, optional purpose, and build the ability to exclude a user's data from future training runs.
If you cannot say which users' data is in a training set, you cannot honour a deletion request.
Sending data to model APIs
When your product sends prompts containing personal data to a hosted model, the provider is your Data Processor and you remain responsible. If the provider's servers are outside India, it is also a cross-border transfer. The Act permits transfers abroad except to countries or under conditions the government restricts, and Significant Data Fiduciaries may be told to keep specified data in India.
Erasure and correction
Users can ask for their data to be corrected or erased. Deleting rows from a database is straightforward; removing their influence from a trained model is not. The defensible approach is to delete source data and derived records, remove the data from retrieval indexes and vector stores immediately, exclude it from future training, and retrain or retire models on a defined schedule. Design retrieval-based systems where possible, because deleting a document from an index is immediate.
Research exemption and children
The Act exempts processing necessary for research, archiving or statistical purposes where the data is not used to take a decision specific to a person and the processing follows standards set out in the Rules. This may cover some model development, but not a product that makes decisions about individuals. For children, the ban on tracking, behavioural monitoring and targeted advertising applies to AI features as much as any other, so recommendation and personalisation for under-18 users need particular care.
Automated decisions and large platforms
The Act has no general right to object to automated decisions, unlike GDPR. But Significant Data Fiduciaries must verify that algorithmic software they use to process personal data is not likely to pose a risk to users' rights, and carry out an annual data protection impact assessment and audit. Sector regulators also expect explainability in areas such as lending. Keep decision logs, the inputs used and the model version for every automated decision about a person.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





