Compliance & Regulation

DPDP Act for AI Products

Training data, public data, model APIs hosted abroad, deletion requests and automated decisions. What the DPDP Act means for teams building AI products in India.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
8 min read
Abstract visual of an AI model

The DPDP Act does not mention artificial intelligence, but it governs the personal data that AI products collect, send to model providers and train on. For AI teams the questions are practical: what can we train on, where can we send prompts and what happens when a user asks to be deleted.

01

Publicly available data

The Act does not apply to personal data that is made publicly available by the person it relates to, or by someone under a legal obligation to publish it. This helps with data people have chosen to publish themselves. It does not cover personal data that others posted about a person, data behind a login, or data scraped in breach of a site's terms. Record where each training source came from and why you believe it falls within the exemption.

02

Training on your users' data

Consent is tied to a specified purpose. Data collected to provide a service cannot be reused to train a model unless the notice said so and the user agreed. Make model training a separate, optional purpose, and build the ability to exclude a user's data from future training runs.

If you cannot say which users' data is in a training set, you cannot honour a deletion request.

Separate purposeModel improvement listed in the notice with its own choice
Opt-out honoured in pipelinesA flag that training jobs actually check
Minimise before trainingRemove names, numbers and identifiers that the model does not need
Dataset lineageWhich users' data went into which dataset version
03

Sending data to model APIs

When your product sends prompts containing personal data to a hosted model, the provider is your Data Processor and you remain responsible. If the provider's servers are outside India, it is also a cross-border transfer. The Act permits transfers abroad except to countries or under conditions the government restricts, and Significant Data Fiduciaries may be told to keep specified data in India.

Processor agreementNo training on your data, security safeguards, breach notice, deletion
Redaction layerStrip or tokenise identifiers before the prompt leaves your system
Zero-retention optionsUse them where the provider offers them
Region choicePrefer Indian regions for sensitive workloads
Prompt and response logsTreated as personal data, with access control and retention limits
04

Erasure and correction

Users can ask for their data to be corrected or erased. Deleting rows from a database is straightforward; removing their influence from a trained model is not. The defensible approach is to delete source data and derived records, remove the data from retrieval indexes and vector stores immediately, exclude it from future training, and retrain or retire models on a defined schedule. Design retrieval-based systems where possible, because deleting a document from an index is immediate.

Delete from vector storesDelete from fine-tuning setsExclude from future trainingScheduled retrainingDeletion log
05

Research exemption and children

The Act exempts processing necessary for research, archiving or statistical purposes where the data is not used to take a decision specific to a person and the processing follows standards set out in the Rules. This may cover some model development, but not a product that makes decisions about individuals. For children, the ban on tracking, behavioural monitoring and targeted advertising applies to AI features as much as any other, so recommendation and personalisation for under-18 users need particular care.

06

Automated decisions and large platforms

The Act has no general right to object to automated decisions, unlike GDPR. But Significant Data Fiduciaries must verify that algorithmic software they use to process personal data is not likely to pose a risk to users' rights, and carry out an annual data protection impact assessment and audit. Sector regulators also expect explainability in areas such as lending. Keep decision logs, the inputs used and the model version for every automated decision about a person.

Purpose
Training needs its own consent
Processor
What a model API provider is to you
Lineage
Know whose data is in each dataset
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact