DPDP Act AI compliance.
Why cloud-routed AI fails the test.
The Digital Personal Data Protection Act 2023 mandates that personal and health data be processed in India. Every AI deployment that routes your customer data to external cloud servers is a compliance liability, regardless of which model it uses.
The Statute
What DPDP Act 2023 says about AI.
Two things are worth stating plainly, because they are widely misreported. First, the DPDP Act does not carve out a “sensitive personal data” category the way the older SPDI Rules did — it applies one standard to all digital personal data, with heightened duties for children's data and for Significant Data Fiduciaries. Second, Section 16 is a restriction list, not a localisation mandate: transfers abroad are permitted unless the Central Government notifies a country as restricted. Stricter localisation obligations, where they apply to you, come from sectoral regulators rather than from DPDP itself.
What DPDP does impose on you as a data fiduciary is substantive: a lawful basis for processing, notice and consent, purpose limitation, security safeguards, breach notification, and the ability to honour a Data Principal's rights. Those duties do not disappear when the processing happens inside a vendor's model. They follow the data.
Penalties under the Schedule
The Schedule to the Act sets a maximum of ₹250 crore for failing to take reasonable security safeguards, with separate caps for other breaches. Penalties are levied on the data fiduciary as an entity by the Data Protection Board. Obligations commence on the timetable in the DPDP Rules — check the current phase against your own compliance calendar.
Compliance Checklist
What passes. What doesn't.
AI data routed to external cloud servers
Processing moves to servers you do not control. Lawful if you have the contracts, notices and audit rights to back it, but the obligation and the penalty exposure of up to ₹250 crore stay with you.
AI that routes calls to external cloud APIs
Every conversation leaves your network, whichever model is behind the endpoint. Residency then rests on your provider's contractual commitments rather than on your own architecture.
SaaS AI platform with shared cloud
Multi-tenant infrastructure: your healthcare or financial data shares servers with other companies.
AntEngage on-premise LLM deployment
Models run on servers inside your office or data centre. No outbound calls, no egress, which removes the cross-border and processor questions from your assessment. Your other DPDP duties still apply.
Sector-Specific Risk
Where DPDP bites hardest.
Healthcare
DPDP + HIPAA + NABH
Patient records attract DPDP duties plus NABH documentation standards, and HIPAA where US patients are involved. Sending a transcript to a third-party API is processing by a processor: permitted, but yours to paper, audit and defend.
NBFC / Fintech
DPDP + RBI Data Localisation
RBI's 2018 directive requires payment system data to be stored in India, with processing abroad allowed only if the data is brought back within 24 hours. Keeping inference in-house removes that round trip.
EdTech
DPDP: Children's Data
Processing a child's data requires verifiable parental consent, and bars tracking and behavioural advertising directed at children. Every additional processor is another place that consent has to hold.
Insurance
DPDP + IRDAI
IRDAI regulations govern where policyholder records are held and for how long. On-premise inference keeps the AI layer out of that assessment altogether.
The AntEngage Solution
Compliant by architecture.
Not by configuration.
AntEngage deploys AI models directly inside your infrastructure, on-premise or in your private cloud. Proprietary or third-party, your data never crosses your boundary. DPDP compliance is not a checkbox. It's the default.
Ask us about your deploymentThis page is a plain-language summary of published legislation and regulator guidance, current as of the date shown. It is general information, not legal advice, and it does not create a solicitor–client relationship. Obligations turn on your own facts — take advice from qualified counsel before relying on any of it.