Regulation · India

DPDP Rules 2025: what changes for AI chatbots and voice agents

In short

India's DPDP Rules were notified on 14 November 2025 and phase in over 18 months. From 14 May 2027, any chatbot or voice agent that handles personal data needs clear notice and consent, security safeguards, retention limits and a breach process that reports to the Data Protection Board within 72 hours.

The timeline

The Rules arrive in three steps. The Data Protection Board was set up when the Rules were notified on 14 November 2025. Consent managers can register from 14 November 2026. The core duties of data fiduciaries apply from 14 May 2027.

  • 14 November 2025: Rules notified; Data Protection Board established.
  • 14 November 2026: consent manager registration and operating rules.
  • 14 May 2027: notice, consent, security, retention, children's data and breach reporting.

What it means for chatbots

A chatbot that answers from employee or customer records processes personal data. Three duties matter most:

  • Notice and consent. People must know what is collected and why, in plain language, before the conversation relies on their data.
  • Security safeguards. Access controls, logging and encryption around every place the data flows, including model inputs and conversation logs.
  • Retention. Data must not be kept longer than the purpose needs, and conversation logs count.

What it means for voice agents

Call recordings and transcripts are personal data too. A voice agent should open with a notice, offer a way to continue without recording, and keep the consent record with the call. Transcripts need the same retention rules as the recording.

The simplest way to evidence security and retention is to keep the whole AI system, including logs, on infrastructure you control.

Breach reporting

If personal data is breached, affected people must be informed without delay, and a detailed report must reach the Board within 72 hours. Complete logs of which sources and records an AI system touched make that report possible in time. Penalties can reach ₹250 crore per breach, graded by severity.

Does the data have to stay in India?

Not across the board. The Act allows transfers except to countries the government restricts, and sector rules can be stricter: RBI requires payment system data to be stored only in India. Running AI on infrastructure in India avoids the question for every data type at once.

What to do before May 2027

  1. Map every place your AI systems touch personal data, including logs and model inputs.
  2. Write notices for chat and voice channels, in the languages your users speak.
  3. Set retention periods per source and per log type.
  4. Rehearse a 72-hour breach report using your real logs.
  5. Decide which agents need children's-data safeguards.

Source: DPDP Rules 2025 overview. See also our India compliance page.

General information, not legal advice. Questions? Write to sales@deepvox.ai.