Why AI agents are a DPDP problem, not only a chatbot problem
A chatbot answers a question. An agent reads the customer's message, looks up their account, drafts a response, calls a system, writes a note and hands the case to a person. Each of those steps is processing under the Act, and each creates a copy of personal data somewhere: in a prompt, a vector index, a trace, a vendor's log.
Most teams have a data map for their core systems. Very few have one for their agents. That is the gap the Rules will expose, because the obligations follow the data, not the architecture diagram.
What the DPDP Rules actually require
The parts that matter most for AI, in plain language. Citations are to the summaries listed under Sources.
Itemised notice (Rule 3)
A standalone, plain-language notice with an itemised description of the personal data, the specific purpose, how to withdraw consent and how to complain to the Board 5.
Real consent, easy withdrawal (Section 6)
Free, specific, informed, unconditional and unambiguous, by clear affirmative action; withdrawing must be as easy as giving; the fiduciary must be able to prove it 6.
Security safeguards (Rule 6)
Reasonable safeguards including encryption, obfuscation or masking, or virtual tokens mapped to personal data; access control; logging and monitoring of access, with logs kept for at least a year 7.
Breach reporting (Rule 7)
Tell affected people and the Board without delay, then give the Board a detailed report within 72 hours covering cause, mitigation and prevention 8.
Children's data (Rules 10–11)
Verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising directed at children, subject to narrow exemptions 9.
Significant Data Fiduciaries (Rules 12–13)
Annual impact assessment and independent audit, and due diligence that technical measures, including algorithmic software, are not likely to pose a risk to data principals' rights 10.
Cross-border transfers (Section 16)
Permitted by default, except to countries the government restricts; the Act also allows additional restrictions for specified data held by Significant Data Fiduciaries 11.
Penalties (the Schedule)
Up to ₹250 crore for failing to take reasonable security safeguards; up to ₹200 crore each for breach-notification and children's-data failures; up to ₹150 crore for Significant Data Fiduciary duties 12.
Ten things to fix before May 2027
Ordered so that each fix makes the next one easier.
1 · Map the agent, not just the app
List every place personal data goes in each agent: prompts, retrieved context, tool calls, the model provider, logs, traces, embeddings, evaluation sets and human review queues.
2 · Bind each agent to a purpose
An agent built for grievance handling should not be able to read a customer's full profile for marketing. Scope its tools and data to the purpose in your notice.
3 · Mask before the model sees it
Rule 6 names masking and virtual tokens as safeguards. Tokenise account, card and phone numbers before the prompt leaves your boundary; redact what nothing downstream needs.
4 · Keep access logs, and make them tamper-evident
At least a year of logs of who and what accessed personal data, including each agent. Logs that the operating team can edit will not convince a Board investigating a breach.
5 · Make withdrawal and erasure reach the AI
When consent is withdrawn or erasure is due, the data must leave the vector index, caches, conversation memory and any fine-tuning set, not just the core database.
6 · Decide what you will never train on
Default to not training models on customer personal data. Where you must, record the basis, the purpose and the retention, and keep that dataset out of general use.
7 · Put AI into the breach playbook
An agent tricked into revealing another customer's data is a personal data breach. Your 72-hour process needs to know how to find, scope and report one.
8 · Route children's data differently
Detect when an interaction involves a child, apply parental-consent rules, and make sure no agent profiles or targets them.
9 · Contract with your AI processors
Know where your model provider processes and logs prompts, for how long, and who can read them. Put it in the contract; watch the government's transfer restrictions.
10 · If you are significant, inventory your models
Algorithmic due diligence starts with knowing which models run where, on whose data, with what evaluation evidence and which owner. Keep that inventory current.
The hardest two, in practice
Erasure that reaches the AI
Deleting a customer row is easy. Finding every embedding, cached conversation, trace and evaluation sample derived from it is not, unless the agent platform tracks where data went when it went there.
Design for it now: keep personal data out of long-lived AI stores where you can (masking helps), and index what you cannot avoid by data principal so erasure is a query, not a project.
Proving the safeguard worked
The Act puts the burden of proving valid consent on the fiduciary, and Rule 6 expects logs and monitoring. When something goes wrong, you will need to show what the agent saw and did.
A record written by the same system that failed is weak evidence. Signed, chained records that an outsider can verify are strong evidence, and they make the 72-hour report far easier to write.
Where AgentAnywhere fits
We built parts of our platform around exactly these duties. Veil masks personal and financial data by reversible tokenisation or irreversible redaction before any model, tool or embedding service sees it. The gateway enforces policy on every call. Every mask, call and approval writes a signed Trust Receipt, and Custodian keeps compliance evidence current. Our alignment to the DPDP Act is designed to support your own assessment, not to replace it.
If you want help mapping one agent end to end, talk to our compliance team.
What this guide is not
It is not legal advice, and it does not cover every obligation in the Act. Obligations depend on whether you are a data fiduciary, a processor or a Significant Data Fiduciary, and on sector rules from the RBI, IRDAI, SEBI and others. The Data Protection Board is established in law and its enforcement machinery is still being stood up; that is a reason to use the time well, not a reason to wait. Take your own counsel's view on anything that affects your organisation.
Frequently asked questions
Does the DPDP Act apply to AI and AI agents?
Yes. The DPDP Act and the DPDP Rules 2025 have no AI-specific chapter, but they apply to any processing of digital personal data, including wholly or partly automated processing. An AI agent that reads, retrieves, stores or sends personal data is processing it, and the data fiduciary behind the agent carries the obligations.
When do the DPDP Rules take effect?
The Rules were notified in November 2025. Provisions establishing the Data Protection Board applied immediately; consent-manager registration applies after twelve months, around November 2026; and the core obligations, including notice and consent, security safeguards, breach reporting, children's data, Significant Data Fiduciary duties and data-principal rights, apply after eighteen months, around May 2027.
Does DPDP require masking personal data before sending it to an AI model?
Rule 6 requires reasonable security safeguards and names encryption, obfuscation or masking, and virtual tokens mapped to personal data among them, along with access control and at least a year of access logs. Masking personal data before it reaches a model is one of the most direct ways to meet that duty for AI systems.
What is the breach-notification deadline under the DPDP Rules?
Affected data principals and the Data Protection Board must be informed without delay, and a detailed report must reach the Board within 72 hours, unless the Board allows longer. A failure to notify can attract a penalty of up to ₹200 crore.
Can personal data be sent to AI models hosted outside India?
Under Section 16, transfers are permitted by default except to countries the government notifies as restricted, and sector regulators or specific directions for Significant Data Fiduciaries can impose stricter limits. Check your sector's rules and your contracts before routing personal data to an overseas model.
Sources
Summaries of the Act and the Rules as published by law firms and government sources, accessed September 2026. Where sources differ, this guide uses the more conservative reading.
- 1Reed Smith — India in focus: data protection and AI.
- 2Khurana & Khurana — AI training data under India's DPDP regime.
- 3Shardul Amarchand Mangaldas — Enforcement of the DPDP Act and notification of the DPDP Rules.
- 4Press Information Bureau — DPDP Rules 2025.
- 5DPDPA.com — Rule 3, notice.
- 6DPDPA.com — Section 6, consent.
- 7DPDPA.com — Rule 6, security safeguards.
- 8DPDPA.com — Rule 7, breach intimation.
- 9DPDPA.com — Rule 10, children's data.
- 10DPDPA.com — Rule 12, Significant Data Fiduciaries.
- 11Mondaq — Cross-border data transfers under the DPDP Act.
- 12DPDPA.com — The Schedule, penalties.
Written by
AgentAnywhere Research
The team that builds the platform and the models
AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration or in preview, it says so.