Compliance · India
DPDP-ready AI before the May 2027 deadline.
The DPDP Rules phase in over 18 months. Use the time to put notice, consent, retention and breach workflows around every AI system that touches personal data.
- Rules notified
- 14 November 2025
- Consent managers
- From 14 November 2026
- Core obligations
- From 14 May 2027
- Breach report
- Detailed report within 72 hours
In short
India’s Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 require notice and consent, purpose limits, security safeguards, retention limits, protections for children’s data and breach reporting. Core obligations apply from 14 May 2027. Running AI on infrastructure you control makes these duties easier to evidence.
What it asks
Requirements, and how we meet them.
| Requirement | How DeepVox addresses it |
|---|---|
| Notice and consent | Notices designed for chat and voice channels; consent logged with each call. |
| Security safeguards | Access control, logging and encryption options across sources, models and logs. |
| Retention and erasure | Retention periods set per source and log type. |
| Breach reporting | Inform affected people without delay; detailed report to the Board within 72 hours, supported by complete logs. |
| Children’s data | Agents handling children’s data are scoped for verifiable parental consent. |
Timeline
Phased over 18 months.
Rules notified
Data Protection Board established.
Consent managers
Registration and operating rules apply.
Core obligations
Notice, consent, security, retention, children’s data, breach reporting.
FAQ
Questions, answered.
Does the DPDP Act require data to stay in India?
Not across the board: transfers are allowed except to countries the government restricts, and sector rules such as RBI’s can be stricter. Keeping AI in India avoids the question.
What are the penalties?
Up to ₹250 crore per breach, graded by severity.
Related
RBI data localisation
RBI’s 2018 directive requires payment system providers to store the entire payment data in India.
Learn more →SEBI CSCRF
CSCRF controls are binding for SEBI-regulated entities.
Learn more →Other markets
Europe, the United States and India.
Learn more →General information, not legal advice. Have your counsel confirm how each rule applies to you. Sources: DPDP Rules 2025 overview (India Briefing). Updated October 2026.
Start with two weeks of evidence, not a sales call.
A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.