Home / Resources / Frameworks / DPDP Act
India's Digital Personal Data Protection Act: the compliance clock is running
India's first comprehensive data protection law governs every organization that processes digital personal data within India or serves Indian residents. The DPDP Rules are rolling out in three phases through May 2027, with penalties reaching Rs 250 crore per violation. For enterprises deploying AI agents, every prompt, inference, and automated decision that touches personal data falls within scope.
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's foundational data protection law, passed by Parliament in August 2023 and operationalized through the DPDP Rules notified on November 14, 2025. It establishes consent-based data processing, defines the rights of Data Principals (individuals), imposes obligations on Data Fiduciaries (organizations), and creates the Data Protection Board of India as an independent enforcement body. The government has indicated it does not plan a standalone AI law, making the DPDP Act the primary regulatory framework governing how AI systems handle personal data in India.
Rs 250 Cr
maximum penalty per violation for failure to implement reasonable security safeguards or comply with Board directions
DPDP Act, Schedule
72 hrs
deadline to submit a detailed breach report to the Data Protection Board after becoming aware of a personal data breach
DPDP Rules, Rule 8
May 2027
Phase 3 deadline when all remaining substantive obligations take effect, including full penalty enforcement
DPDP Rules phased rollout
Who must comply
All organizations processing personal data
Every private company, government body, and non-profit that processes digital personal data in India, regardless of size. Startups and MSMEs are not exempt, though the Board may consider organizational size when determining penalties.
DPDP Act, Sections 2-3
Foreign entities serving Indian residents
Organizations outside India that process personal data in connection with offering goods or services to individuals within India. The Act's extraterritorial scope covers offshore AI processing, cloud inference services, and cross-border data flows.
DPDP Act, Section 3
Significant Data Fiduciaries
The Central Government may designate organizations as SDFs based on volume and sensitivity of data processed, risk to Data Principals, and impact on sovereignty and security. SDFs face enhanced obligations including mandatory DPO appointment, annual DPIAs, independent audits, and algorithmic fairness assessments.
DPDP Act, Section 10
AI system deployers
All AI and ML systems processing personal data fall within scope, including training data, inference processing, automated decision-making, and AI agent interactions. Purpose limitation, consent management, and breach notification apply to every AI workflow that handles personal data.
DPDP Act, Sections 5-8
What you must do
Notice, consent, and purpose limitation
Sections 5-6: Provide a clear, itemized notice before collecting personal data. Consent must be free, specific, informed, unconditional, and unambiguous. Data may be processed only for the stated purpose. AI agents must be configured to handle only the data functions they are designed for; repurposing data requires separate consent.
Nexovern's telemetry records what personal data each AI agent accessed, for what purpose, and under which session, providing the evidence trail that purpose limitation compliance demands.
72-hour breach notification
Section 8(6), Rule 8: Notify the Data Protection Board without delay upon becoming aware of a personal data breach, with a detailed report within 72 hours. Notify each affected Data Principal with a plain-language description of the breach, data categories affected, potential consequences, and remedial steps. Penalty for non-compliance: up to Rs 200 crore.
Nexovern's agent-attributed data access records make "what personal data did the AI touch, and when?" a query you can answer within the 72-hour window, rather than a forensic project.
Reasonable security safeguards
Section 8(5): Implement reasonable security safeguards to prevent personal data breaches. This is the single most heavily penalized obligation, carrying up to Rs 250 crore. For AI systems, this includes securing training data, inference pipelines, API access, and model outputs against unauthorized exposure.
Nexovern discovers every AI endpoint in your environment and monitors what data flows through each session, catching unauthorized access and data exposure before they become breaches.
Data Principal rights
Sections 11-14: Rights to access a summary of personal data being processed, correct inaccurate data, erase data no longer needed, register grievances, and nominate someone to exercise rights on death or incapacity. AI systems must accommodate these rights, including disclosure of what data they hold, correction of inaccurate training data, and cessation of processing upon consent withdrawal.
Nexovern's identity-correlated records show exactly which AI systems processed a specific individual's data, supporting access, correction, and erasure requests with evidence rather than guesswork.
SDF obligations: DPO, DPIA, audits, algorithmic fairness
Section 10, Rule 13: Significant Data Fiduciaries must appoint an India-based DPO reporting to the board, conduct annual DPIAs, undergo annual independent data protection audits, and verify that algorithms do not endanger Data Principal rights. Regular fairness reviews and bias assessments of algorithmic systems are required.
Nexovern provides the continuous runtime data that DPIAs and audits require: which AI systems are operating, what data they process, and how their behavior maps against policy boundaries.
Children's data protection
Section 9: Verifiable parental consent required before processing any data of a child (under 18). No tracking, behavioral monitoring, or targeted advertising directed at children. AI agents interacting with users under 18 must not collect or process data beyond what parental consent specifically covers. Penalty: up to Rs 200 crore.
Nexovern's session-level visibility lets compliance teams verify that AI agents interacting with minors are operating within consent boundaries and not engaging in prohibited data collection.
Penalties for non-compliance
Up to Rs 250 crore (~US$30M)
For failure to comply with Board directions, or failure to implement reasonable security safeguards resulting in a personal data breach. The highest penalty tier in the Act.
DPDP Act, Section 34 & Section 8(5)
Up to Rs 200 crore (~US$24M)
For failure to notify the Board and affected individuals of a data breach, or breach of children's data protections (consent, tracking, and advertising restrictions).
DPDP Act, Sections 8(6) & 9
Up to Rs 150 crore (~US$18M)
For breach of Significant Data Fiduciary obligations, including failure to appoint a DPO, conduct DPIAs, perform audits, or ensure algorithmic fairness.
DPDP Act, Section 10
Penalties are cumulative
Multiple violations in a single incident result in separate, stacking penalties. The Board considers gravity, duration, repetitiveness, and whether the entity gained an advantage. Appeals go to TDSAT, then the Supreme Court.
DPDP Act, Section 33
Key dates
01
Aug 11, 2023: Presidential assent
The Digital Personal Data Protection Act, 2023 receives Presidential assent and is published in the Gazette of India, establishing India's first comprehensive data protection law.
02
Nov 14, 2025: Phase 1, Rules notified
The DPDP Rules take effect. The Data Protection Board of India is formally established. Definitions, procedural frameworks, and the Board's operational structure come into force.
03
Nov 12, 2026: Phase 2, Consent Managers
Consent Manager registration requirements activate. The interoperable consent management framework allows Data Principals to manage consent across multiple organizations through a single platform.
04
May 12, 2027: Phase 3, full compliance
All remaining substantive obligations take effect: notice and consent, security safeguards, 72-hour breach notification, children's data protections, SDF obligations (DPO, DPIA, audits, algorithmic fairness), Data Principal rights, cross-border transfer restrictions, and full penalty enforcement.
How Nexovern helps
- Personal data flow visibility: Discover every AI agent processing personal data across your environment, with identity-correlated records of what data each session accessed and for what purpose.
- Breach forensics under the 72-hour clock: When a breach involves an AI system, Nexovern's prompt-level and OS-layer telemetry answers "what data was exposed, by which agent, at what time" fast enough to meet the notification deadline.
- Purpose limitation evidence: Session-level records show whether each AI agent processed data only for the consented purpose, providing the audit evidence that purpose limitation compliance requires.
- DPIA and audit support: Continuous runtime data on AI system behavior, data access patterns, and policy adherence feeds directly into annual DPIAs and independent audit engagements.
- Algorithmic fairness baseline: Runtime telemetry on AI decision patterns provides the data foundation for fairness reviews and bias assessments that SDFs must conduct.
- Data Principal rights response: Identity-correlated records enable rapid identification of all AI systems that processed a specific individual's data, supporting access, correction, and erasure requests.
- Cross-border transfer awareness: Visibility into which AI agents send data to external endpoints, supporting compliance with sector-specific localization requirements (RBI, IRDAI, SEBI) that layer on top of the DPDP Act.
- Children's data safeguards: Session-level monitoring verifies that AI agents interacting with minors operate within the consent boundaries and do not engage in prohibited tracking or behavioral monitoring.
AI compliance under the DPDP Act starts with visibility
Every AI agent processing personal data in your environment is within scope. A Nexovern demo shows you where your AI systems interact with personal data today, and where the gaps are before May 2027.