Skip to content
AI Automation

India's DPDP Act AI Compliance: What Businesses Must Do

By the Techprime team · · 8 min read

Written for: India

Key takeaways

  • India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to businesses using AI automation that processes customer personal data, including WhatsApp chatbots and CRM workflows.
  • Consent needs to be specific and informed, which means a WhatsApp chatbot's opening message matters more than a buried privacy policy link.
  • Data minimisation, purpose limitation and retention limits apply directly to how much a chatbot asks and how long chat logs are kept.
  • Businesses acting as Data Fiduciaries remain responsible for data even when an AI vendor (Data Processor) handles it on their behalf.
  • This is general information, not legal advice; confirm specifics with an Indian lawyer familiar with the DPDP Act.
On this page (9)
  1. Who does the DPDP Act apply to?
  2. What counts as consent under the DPDP Act for a chatbot?
  3. What is a Data Fiduciary and how does it relate to AI vendors?
  4. What does data minimisation mean in practice for AI workflows?
  5. What steps should a business take to become DPDP-ready for AI automation?
  6. How does this apply specifically to WhatsApp AI chatbots?
  7. What are the penalties for non-compliance?
  8. What role does human oversight play in AI workflows under DPDP?
  9. Next step

India's DPDP Act (Digital Personal Data Protection Act, 2023) compliance for AI automation requires businesses using WhatsApp chatbots, lead qualification bots and AI-driven CRM workflows to collect personal data only with a valid basis such as consent, tell customers clearly what is collected and why, limit use to the stated purpose, and not retain data longer than necessary, applying the same core obligations that apply to any other digital data collection.

Who does the DPDP Act apply to?

The DPDP Act applies to any business (a Data Fiduciary, in the Act's terms) that processes digital personal data of individuals in India, which covers essentially every business running a WhatsApp AI chatbot, website lead form, or CRM that stores customer names, phone numbers or other identifying details, regardless of company size.

This is a genuinely broad scope. A single-location retail shop running a WhatsApp AI chatbot for order updates is just as much a Data Fiduciary under the Act as a large enterprise, even though the compliance effort involved will look very different in practice — a small business mainly needs a clear notice, sensible retention, and a vetted vendor, while a larger business handling higher volumes or more sensitive data typically needs more formal governance around it.

Consent under the DPDP Act needs to be free, specific, informed, unconditional and unambiguous, which for a WhatsApp AI chatbot practically means the opening message or a linked notice should clearly state what data is being collected (name, phone number, order details) and for what purpose, rather than relying on a generic terms-and-conditions link the customer never opens.

  1. State clearly, early in the conversation, what data the bot collects and why (order processing, callback, quotation).
  2. Avoid pre-ticked consent or assumed consent from continued messaging alone where the purpose isn't obvious.
  3. Keep a record of when and how consent was given, especially for marketing-related data use.
  4. Provide a simple way for a customer to ask what data is held or request deletion.
  5. If the purpose changes (for example, moving from order support to marketing), get fresh consent for the new purpose.

What is a Data Fiduciary and how does it relate to AI vendors?

A Data Fiduciary is the business that determines the purpose and means of processing personal data, and it remains legally responsible for that data even when a third-party AI automation vendor (a Data Processor) is actually running the chatbot or workflow, which means the contract with an automation vendor matters: it should set out data handling responsibilities, storage location, and security obligations clearly.

In practice, this means a business cannot simply hand its WhatsApp chatbot or lead-qualification workflow to an AI vendor and treat compliance as the vendor's problem from that point on. The business stays accountable to its customers and, ultimately, to the Data Protection Board of India, for how that data is handled, which is why choosing an automation vendor with clear, written data handling terms is a compliance decision, not just a technical one.

What does data minimisation mean in practice for AI workflows?

Data minimisation means an AI automation workflow should only ask for and store data it genuinely needs for its stated purpose, so a support chatbot resolving a delivery query needs an order number and phone number, not a customer's full address history or unrelated personal details gathered because the conversation happened to drift there.

DPDP Act-relevant checklist for AI automation in India
  • Lawful basis / consent

    Practical action
    Get clear, specific consent before or at data collection; avoid vague or bundled consent.
  • Notice

    Practical action
    State what is collected and why in plain language, early in the interaction.
  • Purpose limitation

    Practical action
    Match each data field collected to a specific, stated purpose.
  • Data minimisation

    Practical action
    Review chatbot and workflow scripts to remove unnecessary data requests.
  • Retention

    Practical action
    Define how long chat logs and lead data are kept; delete or anonymise after that period.
  • Vendor contracts

    Practical action
    Set data handling terms clearly with any AI automation or hosting vendor.
  • Data principal rights

    Practical action
    Provide a simple way for customers to ask about or request deletion of their data.
  • Human oversight

    Practical action
    Keep a human review path for decisions with real consequences for the customer.

What steps should a business take to become DPDP-ready for AI automation?

Getting DPDP-ready for AI automation is a structured exercise: map what each workflow collects, decide the lawful basis, write the notice, and set retention limits, before the workflow goes anywhere near real customer conversations.

  1. List every AI workflow (WhatsApp bot, website form, CRM automation) and the personal data each one touches.
  2. Write a short, plain-language notice for each collection point, stating what is collected and why.
  3. Confirm consent is genuinely free and specific for each purpose, not bundled into one broad blanket consent.
  4. Review chatbot scripts for questions that go beyond what the specific task needs, and remove them.
  5. Set and document a retention period for chat logs and lead records.
  6. Put data handling terms in writing with any AI vendor or hosting provider used.
  7. Set up a simple process for customers to ask what data is held or request deletion.
  8. Document a human escalation path for decisions with real consequences for a customer.

How does this apply specifically to WhatsApp AI chatbots?

For a WhatsApp AI chatbot, the practical DPDP Act steps are: a clear opening notice about data use, avoiding collection of data beyond what the conversation's purpose requires, and a defined retention period for chat history rather than keeping every conversation indefinitely by default. See WhatsApp AI chatbot for business in India for setup detail, and AI automation for small businesses in India for how this fits into a broader rollout.

What are the penalties for non-compliance?

The DPDP Act sets out financial penalties for non-compliance that can be significant, with the exact amount depending on the nature and severity of the breach as determined by the Data Protection Board of India; rather than treating specific penalty figures as fixed (since enforcement detail continues to develop), businesses should treat compliance as a genuine operational requirement, not a low-risk box to tick.

Beyond the direct financial risk, a data breach or a visibly careless AI chatbot (one that clearly over-collects information or handles a customer's data request poorly) carries a reputational cost that can matter more to a small business than the penalty itself, since trust is harder to rebuild with customers than a compliance gap is to fix technically. Treating DPDP Act compliance as part of good product design, rather than a separate legal exercise bolted on afterward, tends to produce both better compliance and a better customer experience.

One practical detail worth planning for is that the DPDP Act's obligations do not stop at the point data is collected; they extend to how it is stored, secured, and eventually deleted. Businesses should confirm their AI vendor encrypts data both in transit and at rest, restricts internal access to what is genuinely needed, and can produce evidence of when and how a customer's data was deleted if asked, rather than assuming this is handled correctly by default without checking.

What role does human oversight play in AI workflows under DPDP?

Human oversight matters because the DPDP Act's principles around fair and transparent processing sit more comfortably with AI workflows that have a documented escalation path for sensitive decisions, rather than a fully automated system making consequential decisions about a customer with no review step. See human-in-the-loop AI automation and the AI automation security checklist for practical patterns.

Next step

We build AI automation for Indian businesses with DPDP Act basics considered from the start — clear consent flows, sensible retention, and vetted vendor terms. See AI automation services or book a discovery call, and confirm specifics with your own legal counsel.

Questions, answered.

Does the DPDP Act apply to small businesses using WhatsApp chatbots?

Yes, the DPDP Act applies regardless of business size whenever digital personal data of individuals in India is processed, which includes small businesses running WhatsApp AI chatbots that collect names, phone numbers or order details.

What consent language should a WhatsApp AI chatbot use in India?

It should clearly state, early in the conversation, what data is being collected and for what purpose, in plain language the customer will actually read, rather than relying only on a linked privacy policy the customer is unlikely to open.

Is the business or the AI vendor responsible for DPDP Act compliance?

The business (Data Fiduciary) remains responsible even when an AI vendor processes the data on its behalf, though the vendor has its own obligations as a Data Processor. A clear contract between the two should define data handling responsibilities.

How long can a business keep WhatsApp chatbot conversation logs?

The DPDP Act does not fix one universal retention period; businesses should define a retention period matched to their actual purpose (support history, dispute resolution) and delete or anonymise data once that purpose no longer applies, rather than keeping logs indefinitely by default.

Can customers ask what data an AI chatbot has collected about them?

Under the DPDP Act, data principals (individuals) generally have rights to information about their data, so businesses should provide a simple way for customers to ask what is held and request correction or deletion where applicable.

Is this article a substitute for legal advice on DPDP Act compliance?

No, this is general practical guidance for businesses deploying AI automation. DPDP Act compliance details depend on specific business circumstances, so confirming with an Indian lawyer familiar with the Act is recommended before finalising a compliance approach.

Book a discovery call

Let's automate it.