DPDP compliance

AI governance and compliance

How the Digital Personal Data Protection Act, 2023 and the IT Act apply when a business uses artificial intelligence: an AI use policy for staff, AI vendor contracts and procurement checks, AI tools in hiring and lending decisions, training data, and responding to deepfakes. India has no separate AI statute yet; these entries apply the laws that already govern the data.

18 matters from the DPDP compliance index. Each entry sets out the problem, the law, the forum, the procedure, the documents usually needed and the limitation clock. General information only — verify the current position on your facts before acting.

Contents

AI use policy and staff practice

  1. AI use policy for the office — which tools, which data, who approves
  2. Hallucination SOP — AI output never goes to court or client unverified
  3. Shadow IT — personal Gmail, free bots and USB models with customer data
  4. Prompts and recordings stored — AI retention breach hiding in chat history

AI vendor contracts and procurement

  1. AI vendor contracts — no-train clause for AI SaaS handling your data
  2. AI procurement checklist — DPDP + security before purchase
  3. AI support agents — notice + consent for recorded helpdesk calls/chats

AI decisions, training data and datasets

  1. Hiring-AI review — DPIA-style check before CV screening tools decide
  2. Automated decisions — loan, screening or pricing tools and s.8(3) accuracy
  3. Employee data for AI training — s.7(i) does not mean free corpus
  4. Training-data deletion pipeline — honouring s.12/s.8(7) inside ML systems
  5. Scraped-data licensing — copyright + DPDP lawful purpose together
  6. Research datasets — s.17(2)(b) archive/research/statistical path for AI data

Deepfakes, voice clones and AI calls

  1. Deepfake response sprint — first 24 hours for a Kerala victim
  2. Brand deepfake — company director faked for fraud or defamation
  3. School deepfake — minor targeted; child-safety overlay
  4. Voice-clone consent — using a person's voice in AI content
  5. Telecom UCC — promotional calls/SMS, DLT and consent proof

AI use policy and staff practice

AI use policy for the office — which tools, which data, who approves

Staff paste client/customer data into public AI chatbots; no record of what went where.

What it involvesDPDP ss.4–8 (lawful purpose, notice, consent limit, s.8(5) safeguards, s.8(2) processor need, s.16 if tool hosts abroad) applied to AI-tool facts.
Relevant lawDPDP ss.4, 6, 8(1)–(2), 8(5)–(7), 16; IT Act s.43A stands omitted once DPDP s.44(2)(a) commences — 18 months from 13.11.2025 (G.S.R. 843(E)); DPDP prevails on conflict (s.38).
ForumInternal policy + vendor DPA; Board only on complaint/breach.
Procedure & stageClassify data (no personal data in public prompts by default) → allowlist tools with DPAs → approval + logging → train + audit → breach-intimation path (s.8(6)).
RemedyControlled rollout + mitigation evidence; pasting history needs deletion requests + vendor confirmation.
High Court connectionClient-loss from AI leakage is a Kerala civil/professional-negligence matter; DPDP breach track runs to Board in parallel.
Documents normally requiredTool list + hosting locations, DPA/no-train terms, prompt-log samples, training record.
LimitationImmediate hygiene + May 2027 posture.
Free chatbot says it does not train — enough?
Only with a written DPA-grade commitment covering your data, retention and sub-processors. Marketing copy is not a contract.

Hallucination SOP — AI output never goes to court or client unverified

AI-drafted notice, reply or case note with invented sections or citations reaches a client or forum.

What it involvesProfessional verification discipline + DPDP s.8(3) accuracy where personal data feeds decisions.
Relevant lawDPDP s.8(3)–(4) (accuracy/organisational measures); Advocates Act, 1961 + BCI Rules on professional standards (general reference, no advertisement); Evidence/court procedure for the filing's own validity.
ForumChamber quality control; courts test the filing, not the tool.
Procedure & stageAI draft → human source-check every citation/section → second-eyes sign-off → file/log sources → never cite AI output as authority.
RemedyError contained pre-filing; post-filing errors need prompt correction + apology on record.
High Court connectionKerala courts (including HC) act against false citations irrespective of tool used. The SOP protects practice, not just DPDP.
Documents normally requiredSOP, check log, source bundle per draft.
LimitationEvery draft, every time.
Disclose AI use in filings?
Courts test correctness, not drafting method. Disclose per court direction if any; always verify regardless.

Shadow IT — personal Gmail, free bots and USB models with customer data

Staff use personal accounts and free AI tools for official data to "work faster."

What it involvess.8(1) (fiduciary owns processor/defaults), s.8(2) (no valid contract = no processing), s.8(5)–(6) (safeguards/breach).
Relevant lawDPDP ss.8(1)–(2), 8(5)–(6).
ForumInternal audit; Board on breach/complaint.
Procedure & stageAmnesty inventory → blocklist/allowlist → migrate to contracted tools → delete + confirm where possible → train + re-audit.
RemedyClosed shadow flows + evidence; lingering copies handled under the erasure cascade (s.8(7)(b)).
High Court connectionEmployee-discipline aspects per Kerala Shops/standing-orders/contract; DPDP breach track separate.
Documents normally requiredInventory, migration log, deletion confirmations, policy acknowledgement.
LimitationImmediate + May 2027.
Delete from personal account — done?
Only with confirmation + vendor-side deletion where data left your control. Record attempts honestly; "deleted" without proof fails s.6(10)/s.8 scrutiny.

Prompts and recordings stored — AI retention breach hiding in chat history

Support chatbot, transcription or "AI notetaker" keeps prompts/recordings with names, numbers and health/financial details indefinitely.

What it involvesPrompts/recordings = digital personal data → ss.5–6 (notice/consent for that purpose), s.8(7) (erase when purpose over), s.12(3) (erasure requests), s.8(2) vendor chain.
Relevant lawDPDP ss.5, 6, 8(2)/(7), 12(3).
ForumProduct configuration; Board on complaint.
Procedure & stageDisclose logging in notice (EN+ML) → shortest retention + auto-purge → per-thread deletion on request → vendor purge confirmation.
RemedyRetention-fixed product + cascade proof.
High Court connectionRecording-consent (telegraph/telecom courtesy + DPDP notice) handled together; DPDP merits go Board → TDSAT.
Documents normally requiredLogging disclosure, retention setting proof, deletion confirmations.
LimitationErase when the purpose is served (s.8(7)) but keep processing logs at least 1 year (Rules r.8(3)); e-commerce and social-media platforms with 2 crore+ registered users and online-gaming intermediaries with 50 lakh+: 3-year inactivity erasure with 48-hr prior warning (r.8(1)–(2), Third Schedule); in force May 2027.
Keep chats to improve the bot?
Only with a fresh, stated purpose + basis (consent or fitting s.7/17 ground) and retention. Silent reuse fails ss.4–6.

AI vendor contracts and procurement

AI vendor contracts — no-train clause for AI SaaS handling your data

CRM, support or transcription SaaS reuses Kerala customer data to train models.

What it involvess.8(2) instructions-only processing + purpose limitation (s.4) + s.16 hosting disclosure.
Relevant lawDPDP ss.4, 8(1)–(2), 8(7), 16.
ForumProcurement negotiation; Board on complaint; civil suit for breach of DPA.
Procedure & stageNo-train + no-retain-for-training + no-human-review-without-consent + hosting/sub-processor list + audit + return/delete → redline order forms that contradict the DPA.
RemedyContractual bar + deletion evidence; training misuse becomes a Board + civil matter.
High Court connectionDPA breach recovery in Kerala civil courts/arbitration per clause; Board decides DPDP breach.
Documents normally requiredDPA redline, order-form precedence clause, hosting/sub-processor schedule.
LimitationBefore data flows; re-paper live vendors now.
Toggle in settings enough?
No. Settings change; contracts bind. Get the no-train term + precedence in the signed DPA.

AI procurement checklist — DPDP + security before purchase

Purchase committee buys on demo quality without data-flow, hosting or retention answers.

What it involvesss.4–8 + s.11–13 readiness (DSAR/correction/grievance handling through the tool) + s.16 destinations.
Relevant lawDPDP ss.4–8, 11–13, 16; s.33(2) mitigation value of diligence.
ForumProcurement file; Board evidence later.
Procedure & stageData-flow + hosting list → basis per purpose → DPA/no-train → safeguards + breach-assist SLA → DSAR/erasure support → retention/return → pilot → sign.
RemedyComparable-vendor record + clean file; weak answers become negotiation or rejection reasons.
High Court connectionProcurement disputes per tender/contract law in Kerala fora; DPDP diligence feeds Board mitigation.
Documents normally requiredChecklist responses, DPAs, pilot results, approval note.
LimitationPre-purchase; live tools re-checked by May 2027.
Startup vendor, no DPA template — proceed?
Only with your DPA floor (instructions-only, no-train, breach-assist, audit, return/delete). No DPA, no data.

AI decisions, training data and datasets

Hiring-AI review — DPIA-style check before CV screening tools decide

Kerala business buys CV-screening/video-interview AI with no purpose, accuracy or retention review.

What it involvesDPDP ss.4–6 (basis: s.7(i) employment vs s.6 consent for extras), s.8(3) (decisions affecting persons → complete/accurate/consistent), s.8(5)/(7) (safeguards/retention), SDF DPIA vocabulary (s.10) as method even for non-SDFs (say so).
Relevant lawDPDP ss.4–8, 10(2)(c)(i) (method reference); labour/anti-discrimination backdrop pleaded separately, not as DPDP text.
ForumPre-procurement review; Board on candidate complaint; labour/civil fora for hiring-dispute merits.
Procedure & stagePurpose + necessity → accuracy/bias testing + human-in-loop → candidate notice (EN+ML) → retention/deletion → vendor DPA + no-train clause.
RemedyDeploy-only-if-justified note or safer configuration.
High Court connectionHiring-merits disputes in Kerala fora; DPDP accuracy/retention layer goes Board → TDSAT.
Documents normally requiredVendor model card/bias note, notice copy, DPA, retention setting.
LimitationPre-deployment + May 2027.
Vendor says model is unbiased — accept?
No. Ask for test scope, data and limits in writing; run a human-in-loop pilot and record outcomes.

Automated decisions — loan, screening or pricing tools and s.8(3) accuracy

AI score auto-rejects applications on stale or inconsistent data with no human check.

What it involvess.8(3): data likely to drive a decision affecting the principal (or shared onward) must be complete/accurate/consistent; ss.11–12 correction/access feed the fix.
Relevant lawDPDP ss.8(3), 11–12; sectoral lending/hiring rules continue (s.38).
ForumModel/process fix; Board on complaint; sectoral regulator/court for the loan/hiring merits.
Procedure & stageDecision-field register → source-verify + refresh → pre-decision check + human-in-loop for adverse actions → reasons + correction path → log.
RemedyProcess compliance + correction; wrongful-decision loss by civil/sectoral claim.
High Court connectionLoan/employment merits in Kerala sectoral/civil fora; DPDP accuracy layer Board → TDSAT.
Documents normally requiredField register, verification cadence, adverse-action logs, correction trail.
LimitationContinuous.
Fully automated rejection with an appeal link — enough?
An appeal link helps but does not cure s.8(3) input failure. Fix accuracy + human review for adverse decisions.

Employee data for AI training — s.7(i) does not mean free corpus

Business fine-tunes a model on staff emails/chats under "employment purpose."

What it involvess.7(i) bounded to employment/safeguarding necessity; training a general model is a new purpose needing s.5 notice + s.6 consent (or another fitting basis).
Relevant lawDPDP ss.4–7(i), 8; s.17 where genuinely applicable (rare for this fact).
ForumInternal review; Board on employee complaint; labour fora for employment merits.
Procedure & stagePurpose-separation memo → consent track for training corpus (voluntary, withdrawable) → de-identification where possible (honestly described) → retention/deletion.
RemedyLawful corpus or no corpus.
High Court connectionKerala labour/civil disputes decide employment fallout; DPDP basis decided Board → TDSAT.
Documents normally requiredPurpose memo, consent texts, de-identification method note, deletion log.
LimitationPre-training.
Anonymised, so no DPDP?
Only if truly non-identifiable (state method + re-identification test). Pseudonymised data that can be re-linked stays personal data. Do not overclaim.

Training-data deletion pipeline — honouring s.12/s.8(7) inside ML systems

Erasure request answered "deleted from database" while vectors, embeddings and evaluation splits retain the person.

What it involvess.12(3)/s.8(7) erasure + s.8(7)(b) processor cascade + s.6(6) post-withdrawal stop, applied to datasets, features and model artefacts.
Relevant lawDPDP ss.6(6), 8(7), 12(3).
ForumEngineering + legal pipeline; Board on complaint.
Procedure & stageLineage map (raw → clean → features → splits → artefacts) → delete + suppress/retrain policy → vendor/pipeline confirmations → reply with scope + technical limits stated plainly.
RemedyDemonstrable pipeline; "cannot from trained weights" needs an honest technical note + forward-fix (unlearning/suppression/retrain cadence), not bare refusal.
High Court connectionTechnical feasibility is Board fact-finding; writ only for process error.
Documents normally requiredLineage map, deletion tickets, retrain/suppression policy, reply copy.
LimitationReasonable time (s.6(6)); an unresolved request can be taken up as a grievance (s.13(1)), answerable within the published period (max 90 days, r.14(3)); Rules r.8(3) 1-year log retention applies.
Retrain from scratch every request?
Proportionality matters. Show lineage + suppression + retrain cadence + timelines. Blanket "impossible" without a plan fails.

Research datasets — s.17(2)(b) archive/research/statistical path for AI data

University/startup builds an AI evaluation dataset from personal data and claims "research, so no DPDP."

What it involvess.17(2)(b): Act does not apply where processing is necessary for research/archiving/statistical purposes IF data is not used for a decision specific to a principal AND processing follows prescribed standards. Both limbs + standards required.
Relevant laws.17(2)(b); DPDP Rules r.16 + Second Schedule standards (lawful, purpose-limited, data-minimised, accuracy efforts, retention limits, security safeguards, accountability); ss.4–8 revive if either limb fails.
ForumDataset review; Board on complaint.
Procedure & stageNecessity memo → no-decision-specific-use bar (technical + contractual) → prescribed-standards file → re-test before any productisation (product use exits the exemption).
RemedyExemption only within both limbs + standards; otherwise full ss.4–8 compliance.
High Court connectionStandards/exemption disputes go Board → TDSAT; writ only for legality.
Documents normally requiredResearch protocol, no-decision-use controls, standards compliance file.
LimitationDuration of the qualifying research only.
Publish the dataset openly as 'research'?
Open release rarely survives the no-decision-specific-use + standards test. Get a dataset-specific review before publishing.

Deepfakes, voice clones and AI calls

Deepfake response sprint — first 24 hours for a Kerala victim

Morphed video/audio of a person circulates on social apps and mirrors.

What it involvesParallel tracks: (a) platform report + intermediary/GAC clock (2 hrs for intimate-image/impersonation complaints incl. morphed images, r.3(2)(b)); (b) police complaint (BNS + IT Act provisions as applicable: impersonation/privacy/defamation/obscenity facts); (c) DPDP only if personal-data processing triggers it (often secondary here — say so).
Relevant lawIT Act ss.66D/67/67A (as facts fit), BNS ss.336/340/356 and kindred provisions (as facts fit), IT Intermediary Rules, 2021 as amended 10.02.2026 (G.S.R. 120(E), w.e.f. 20.02.2026) — SGI labelling/removal r.3(3); DPDP ss.8/27 only where a fiduciary-breach fact exists.
ForumPlatform → GAC; Kerala police cyber cell; Magistrate/court for criminal process; civil court for injunction/damages.
Procedure & stagePreserve (URLs, hashes, timestamps; do not amplify) → platform reports (IDs) → police complaint with artefacts → injunction/damages advice → support/safety note for victim.
RemedyTakedown + investigation + injunctive/damages relief. DPDP Board is not the primary forum for third-party morphing — say so.
High Court connectionUrgent injunctive relief via competent Kerala civil court; writ only for State/platform-process illegality or Art.21 urgency within Kerala jurisdiction.
Documents normally requiredURL/hash log, ID proof, platform receipts, police acknowledgement.
LimitationHours, not weeks — platforms must act within 2 hrs on intimate-image/impersonation complaints (r.3(2)(b)) and 3 hrs on court/authorised Government orders (r.3(1)(d)); police track immediately.
DPDP complaint will remove it fastest?
Usually no. Platform + police + injunction move faster for third-party fakes. Use DPDP only for its own fiduciary-breach facts.

Brand deepfake — company director faked for fraud or defamation

Fake director video pushes investments or defames the brand; customers lose money.

What it involvesSame sprint as a personal deepfake + brand/trademark overlay (Trade Marks Act, 1999 where registered) + customer-warning + civil recovery.
Relevant lawIT Act/BNS as facts fit; IT Rules 2021 as amended 10.02.2026 (G.S.R. 120(E), w.e.f. 20.02.2026) — SGI labelling/removal r.3(3); Trade Marks Act, 1999 (where applicable); civil injunction/damages law.
ForumPlatform/police/civil court; INDRP only if a lookalike domain is involved.
Procedure & stageSprint (preserve → report → police) → measured customer advisory (no DPDP-breach admission you did not cause) → injunction + damages file → domain track if needed.
RemedyTakedown + prosecution + injunction/damages. No DPDP penalty against the victim-brand on these facts.
High Court connectionCommercial/injunction suits in Kerala competent courts; writ only for process illegality.
Documents normally requiredFake vs real comparison log, loss trail, platform/police papers, trademark proof.
LimitationImmediate.
Sue the platform for the fake?
Intermediary safe-harbour (IT Act s.79 + Rules compliance) decides that. Report properly first; liability turns on non-compliance + knowledge procedure. Take advice.

School deepfake — minor targeted; child-safety overlay

Morphed image/video of a minor circulates in school groups.

What it involvesChild-safety priority: platform + police immediacy; POCSO/IT/BNS overlays as facts fit; DPDP s.9 sensitivity noted but criminal/protection track leads.
Relevant lawPOCSO Act, 2012 + IT Act + BNS as facts fit (fact-specific); IT Rules 2021 as amended 10.02.2026 (G.S.R. 120(E), w.e.f. 20.02.2026) — SGI labelling/removal r.3(3); DPDP s.9 backdrop for school-vendor hygiene.
ForumPlatform + Kerala police (special juvenile/child-welfare procedure) + courts; school internal safeguarding in parallel.
Procedure & stageSafeguard the child first → preserve → report → police → school protocol (no victim-blaming, limited circulation) → counselling/legal support note.
RemedyTakedown + protection + prosecution; school process fix.
High Court connectionUrgent protection/injunction via competent Kerala courts; writ only for process/rights urgency within jurisdiction.
Documents normally requiredPreserved artefacts (handled sensitively, minimal holders), reports, police papers, school incident log.
LimitationImmediate; child-safety clock overrides all others.
School can handle internally only?
No. Criminal/child-protection reporting duties run regardless of internal discipline. Act on both tracks.

FAQ

AI governance and compliance: common questions

Does India have an AI law?
There is no separate artificial intelligence statute in force. AI use by a business is governed by the laws that already apply to the data and the conduct: the DPDP Act, 2023 for personal data, the IT Act and IT Rules for platforms and synthetic content, and contract and copyright law for vendors and training material.
We need an AI use policy for our office. What should it cover?
Which AI tools staff may use, which data may go into them, who approves new tools, and how outputs are checked before they reach a client or a court. Customer and client personal data pasted into public chatbots is processing under the DPDP Act, so the policy ties into notices, security safeguards and vendor contracts.
What should an AI vendor contract say about our data?
A no-train clause that stops the vendor using your customers’ data to train its models, plus data location, retention, deletion on exit and breach reporting. Under Section 8 of the DPDP Act the business stays answerable for what its processor does, so these terms are settled before data flows.

Contact

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. In keeping with the Bar Council of India Rules, this website provides information about Adv. K J Muhammed Aslam, and general legal information, only to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.