DPDP Compliance for AI Apps: What to Fix Before May 2027

DPDP compliance for AI apps: isometric shield protecting a phone and cloud server, with consent toggle, padlock and data cubes on a navy background

DPDP compliance for AI apps: isometric shield protecting a phone and cloud server, with consent toggle, padlock and data cubes on a navy background

If your app or AI chatbot handles personal data of people in India, DPDP compliance for AI apps is now a build question, not a legal footnote. A lot of founders have heard that 13 November 2026 is the DPDP deadline. It is a real date, but it only switches on the rules for Consent Managers. The obligations that hit ordinary apps, SaaS products and AI assistants start on 13 May 2027, which is roughly seven months away.

Seven months sounds like plenty. It isn’t, once you count where an AI system copies personal data: prompts, chat history, vector indexes, logs, analytics and every model vendor in between. This guide explains what actually changes on each date and what to fix in your product first.

Key takeaways

  • The DPDP Rules, 2025 were notified on 13 November 2025 and commence in three phases: Board rules immediately, Consent Manager rules after one year (13 November 2026), and most business duties after 18 months (13 May 2027).
  • India has no separate AI law. Any AI feature that processes digital personal data falls under the DPDP Act like any other software.
  • From May 2027 you need itemised consent notices, security safeguards with one year of processing logs, breach reports to the Board within 72 hours, and parental consent for children’s data, per Rules 3, 6, 7, 8 and 10.
  • Penalties in the Act’s Schedule go up to ₹250 crore for failing to take reasonable security safeguards.
  • Most of the fix is engineering: map data flows, tag consent and purpose, make erasure reach every store, and put contracts in place with each AI vendor.

In this guide

What changes on 13 November 2026 vs 13 May 2027

Short answer: 13 November 2026 matters only if you want to become a registered Consent Manager. For everyone else, the binding date is 13 May 2027. Rule 1 of the notified Rules says Rules 1, 2 and 17 to 21 apply from publication, Rule 4 one year later, and Rules 3, 5 to 16, 22 and 23 eighteen months later. The government’s own explainer describes this as an eighteen-month phased compliance period.

DateWhat switches onWho it affects
13 Nov 2025Definitions; setting up and running the Data Protection Board (Rules 1, 2, 17–21)The government and the Board
13 Nov 2026Registration and obligations of Consent Managers (Rule 4, First Schedule)Companies that want to run a consent-management platform. They must be incorporated in India with a net worth of at least ₹2 crore
13 May 2027Notice, security safeguards, breach intimation, retention and erasure, contact person, children’s data, Significant Data Fiduciary duties, user rights, cross-border transfers (Rules 3, 5–16, 22, 23)Every business that processes digital personal data, including your app and AI features

Two things could still move. In January 2026, Business Standard reported that MeitY proposed cutting the window to 12 months for Significant Data Fiduciaries (large platforms, banks and insurers). As of late September 2026, regulatory trackers show no amending notification, so 13 May 2027 stands. MeitY Secretary S. Krishnan has also said the timelines will not be extended. Plan for May 2027 and do not count on extra time.

The Act also reaches beyond India. Section 3 of the DPDP Act applies to processing outside India when it is connected to offering goods or services to people in India. A US or UAE SaaS with Indian users is in scope too.

Where personal data hides in an AI app

The short answer: in far more places than your users table. A classic app stores personal data in a database you can query. An AI app copies it into prompts, embeddings, conversation memory, traces and third-party APIs. Each copy has to respect consent, security, retention and erasure.

How personal data flows through an AI app: chat input, vector index, AI model, cloud vendor and logs, each with a padlock or erase marker
Every stop in an AI pipeline is a copy of personal data that needs protection, a retention rule and a way to erase it.
Where it sitsTypical exampleDPDP question to answer
Prompts and chat historyA support bot stores full conversations with names, phone numbers, order IDsIs this covered by the consent notice, and can you delete one user’s history?
Vector index (RAG)Customer emails or tickets embedded for retrievalCan you find and remove one person’s chunks on request?
Agent memoryAn assistant remembers preferences across sessionsIs the purpose clear, and does it expire when no longer needed?
Logs and tracesObservability tools capture raw prompts and outputsAre logs access-controlled and kept for one year, then erased (Rules 6 and 8)?
Model and tool vendorsLLM API, speech-to-text, hosted vector databaseIs there a valid contract with security terms (Section 8(2), Rule 6(1)(f))?
Fine-tuning or training setsPast chats used to tune a modelDid consent cover this purpose? Removing data from weights is hard, so avoid putting it there.

If you run agents that take actions, such as booking, refunding or updating CRM records, the same map applies to every tool they call. Our AI agents in 2026 overview explains how those flows are usually wired.

Not sure where personal data sits in your AI stack? Eoxys can map your app’s data flows against the DPDP Rules and scope the fixes. Get a real project estimate within 24 hours. NDA on request.

DPDP compliance checklist for AI apps

Here is what the Rules require from May 2027, translated into product and engineering work. Treat it as a technical starting point and confirm the legal reading with your counsel.

Requirement (source)What the Rules sayWhat to build in an AI app
Consent notice (Rule 3)Standalone notice in plain language with an itemised list of data and the specific purpose; withdrawal as easy as giving consentPer-feature consent screens (for example, ‘chat history is used to answer your support questions’); a one-tap withdraw option in settings
Security safeguards (Rule 6)Encryption, masking or tokenisation; access control; logs and monitoring; backups; security clauses in processor contractsMask or tokenise PII before it reaches the LLM where possible; role-based access to transcripts; encrypted vector stores
Breach intimation (Rule 7)Tell affected users without delay; send the Board a detailed report within 72 hoursAn incident runbook, alerting on unusual access, and a template message you can send through the app
Retention and logs (Rule 8)Keep processing logs for at least one year; large e-commerce, gaming and social platforms erase inactive users’ data after three years with 48 hours’ noticeRetention policies per store (chats, embeddings, traces), scheduled deletion jobs, and the warning email
Contact person (Rule 9)Publish who answers questions about processingA visible privacy contact in the app and on the website
Children’s data (Rule 10)Verifiable parental consent before processing a child’s dataAge gating and a parent-verification flow, critical for EdTech and gaming apps
User rights (Rule 14)Publish how to request access, correction or erasure; answer grievances within 90 days at mostA self-serve privacy centre that triggers erasure across the database, vector index, memory and vendor stores

Penalties are set by the Act’s Schedule: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a breach, up to ₹200 crore for breaching children’s data duties, and up to ₹50 crore for other breaches. The Board decides the actual amount case by case.

A seven-month plan to get ready

The fastest route is to fix the architecture once rather than patching each feature. Here is the sequence we would follow for a typical app with an AI chatbot or RAG feature. Timings are estimates, not quotes, and depend on how many systems hold personal data.

  1. Month 1: Data inventory. List every place personal data lands, including AI vendors, logs and analytics. Classify each as needed, nice to have, or remove.
  2. Month 2: Consent and notices. Rewrite consent flows per purpose, add withdrawal in settings, and record consent with a timestamp and version so you can prove it later.
  3. Months 2–3: Minimise what the model sees. Add a PII redaction or tokenisation step before prompts reach the LLM. If you are still choosing a model, our GPT-6.1 Sol vs Claude Sonnet 5.5 comparison covers data residency and cloud options.
  4. Months 3–4: Erasure that reaches everything. Tag records with a user ID across the database, vector index and memory so one request deletes everywhere. Set retention timers for chats and traces.
  5. Months 4–5: Security and logging. Encrypt stores, tighten access to transcripts, centralise access logs and keep them for one year.
  6. Months 5–6: Vendors and contracts. Sign data processing terms with each AI and cloud vendor and check where they store and process data.
  7. Month 7: Drill and document. Run a mock breach against the 72-hour clock, test a full erasure request end to end, and publish the privacy contact and grievance process.

Eoxys does this work as part of our AI and machine learning solutions and mobile and web app development projects, including chatbot rebuilds through our AI chatbot developers and data-store hardening through cloud services. For cost drivers, see our guide to AI integration costs.

Risks, penalties and grey areas

  • Training on user data: once personal data is inside model weights, erasing it on request is very hard. Prefer retrieval (RAG) over fine-tuning on personal data, and keep training sets de-identified.
  • Vendor sprawl: every new AI tool a team adds is another processor that needs a contract. Keep an approved-vendor list.
  • Automated decisions: Section 8(3) of the Act requires completeness, accuracy and consistency when personal data is used to make a decision that affects the person. That reaches AI outputs used in lending, insurance or hiring, so add human review and audit trails.
  • Cross-border transfers: the Rules allow transfers outside India subject to requirements the government may set, and Significant Data Fiduciaries may face localisation for specified data. Track notifications before you lock in a region.
  • Overlapping laws: if you also serve the EU, GDPR and the EU AI Act apply on top of DPDP. Design one privacy layer that satisfies the strictest rule you face.
  • This is not legal advice: use this guide to scope the engineering, and have a lawyer confirm your obligations, especially whether you could be a Significant Data Fiduciary.

Frequently asked questions

Do I need to be DPDP compliant by 13 November 2026?

Only if you plan to register as a Consent Manager. That date brings in Rule 4. Notices, security safeguards, breach reporting, retention, children’s data and user rights apply from 13 May 2027 under Rule 1(4). Start now, because AI systems keep copies of data in many places.

Does the DPDP Act apply to AI chatbots and RAG apps?

Yes. India has no separate AI law, so a chatbot, RAG search or AI agent that processes digital personal data is treated like any other software under the DPDP Act. Prompts, stored chats, embeddings and logs that identify a person all count as personal data.

We are a US company with Indian users. Does DPDP apply to us?

Very likely. Section 3 of the Act covers processing outside India when it is connected to offering goods or services to people in India. If your app signs up Indian users, plan for DPDP alongside GDPR or US state privacy laws.

How much does it cost to make an AI app DPDP ready?

It depends on how many systems hold personal data and whether consent and erasure were designed in from the start. A small app with one chatbot is a much lighter job than a platform with several AI vendors. Share your stack and we will send a real project estimate within 24 hours. NDA on request.

Get your AI app ready before May 2027

The DPDP Rules turn privacy into product work: clear consent, data you can find, erasure that reaches every AI store, and vendors under contract. Teams that start now can fix the architecture once instead of patching under deadline pressure. Eoxys IT Solution has built software from Jaipur since 2009, with 700+ projects delivered across fintech, health, EdTech and e-commerce. See our portfolio for examples.

Talk to our AI developers about a DPDP review of your app, or get a real project estimate within 24 hours. NDA on request.

Related reading:

Sources

Shiv Kumawat

Executive Director & CEO

Shiv Kumawat is the CEO of Eoxys IT Solution LLP, the Jaipur-based IT and GenAI development company he has led since 2009. Eoxys builds custom AI, web and mobile applications for businesses worldwide. Shiv writes about AI app development, generative AI for business, and building software products that deliver real results. Connect with him on LinkedIn: https://www.linkedin.com/in/shiv-kumawat-eoxys/

Latest Posts

GPT-6.1 Sol vs Claude Sonnet 5.5: isometric illustration of two AI model cubes connected by a data stream on a navy background

GPT-6.1 Sol vs Claude Sonnet 5.5: Which Model for Your App?

GPT-6.1 Sol vs Claude Sonnet 5.5 is the mid-tier choice most founders are making right now. Both models launched in…

Shiv Kumawat
October 9, 2026
Siri AI integration for iOS apps: isometric illustration of an iPhone app connected to a glowing assistant orb and app action tiles

Siri AI Integration for iOS Apps: How to Get Your App Ready

Siri AI started rolling out in mid-September with iOS 27, and it can now find content inside apps and act…

Shiv Kumawat
October 8, 2026
Isometric illustration of an online store connected to three AI shopping agents handling product discovery, chat and checkout

AI Shopping Agents for E-commerce: Get Your Store Ready Now

This is the first holiday season where AI shopping agents are a real sales channel. Shopify’s 2026 holiday research, published…

Shiv Kumawat
October 7, 2026

Leave a Reply

Your email address will not be published. Required fields are marked *