Skip to content
Make in India OEM · INR-transparent · Pan-India onsite SLATalk to sales: +91 720 794 8743Sign in

The DPDP Act for AI Infrastructure: What It Requires and What It Does Not

Explainer Updated 19 Aug 2026 · 7 min read

Overview

The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive personal data law, and the DPDP Rules notified on 13 November 2025 make it operational on a staggered timetable. For teams planning AI infrastructure, the practical reading is this: the Act regulates how personal data is processed, secured and reported on – it does not tell you where your GPUs must sit. Cross-border transfer is permitted by default except to countries the Central Government restricts, while failing to maintain reasonable security safeguards carries the Act’s highest penalty, up to Rs 250 crore per instance. This article maps what that means for training data, shared infrastructure and siting decisions; it is general information for planning, not legal advice.

The DPDP Act for AI Infrastructure: What It Requires and What It Does Not
What you’ll learn: what the DPDP Act and the 2025 Rules actually require of organisations running AI workloads, what they do not require, how Significant Data Fiduciary designation raises the bar, and how the law should shape training data handling and GPU siting decisions.

Key takeaways

  • The DPDP Act does not impose blanket data localisation: transfers are permitted except to countries the Central Government restricts by notification.
  • Failure of reasonable security safeguards carries the Act’s highest penalty – up to Rs 250 crore per instance under the Schedule.
  • The DPDP Rules 2025 were notified on 13 November 2025 with staggered commencement, so substantive duties arrive in phases through 2026-2027.
  • Significant Data Fiduciaries face extra duties: a DPO based in India, annual DPIA and audit, algorithmic due diligence, and possible localisation of specifically notified data categories.
  • For GPU siting, the Act rewards infrastructure where access control, logging and breach response can be evidenced – it does not prescribe a geography or a deployment model.

What the Act is and where it stands

The DPDP Act received assent in August 2023, but it needed subordinate rules to operate. The Government notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025, as published by the Ministry of Electronics and Information Technology (MeitY). Commencement is staggered: consent-notice, security-safeguard and breach-reporting provisions phase in over roughly 12 to 18 months, and obligations specific to Significant Data Fiduciaries are reported to commence about eighteen months after notification. A Data Protection Board of India adjudicates breaches and imposes penalties.

The Act applies to digital personal data processed in India, and to processing outside India where it is connected with offering goods or services to individuals in India. It covers personal data – information that identifies a person – and does not cover data that has been genuinely anonymised, which matters for training corpora.

The duties that touch AI infrastructure

Most of the Act is about the relationship between a Data Fiduciary and the individual, but several duties land directly on the infrastructure team:

  • Reasonable security safeguards. The Rules list minimum measures as published: encryption, obfuscation or masking; access control for the computing resources that hold personal data; logging and monitoring with retained logs to enable breach detection and investigation; and backups to maintain continuity.
  • Breach notification. On becoming aware of a personal data breach, the fiduciary must intimate affected individuals and the Data Protection Board, with a detailed report to the Board within 72 hours as the Rules provide. This sits alongside the separate CERT-In six-hour incident reporting direction of 2022.
  • Erasure. Personal data must be erased when consent is withdrawn or the purpose is exhausted, which has real consequences for datasets, backups and derived artefacts.
  • Processor accountability. The fiduciary remains accountable for processing done by data processors – including a colocation provider, a managed GPU service or an annotation vendor – and must bind them by contract.

What the Act does not require

Precision matters here, because localisation is the most common misreading. Rule 15 adopts a negative-list model: personal data may be transferred to any country except those the Central Government specifically restricts, and subject to any conditions it notifies. The Act does not mandate that personal data, training data or AI compute remain in India as a general rule. Nor does it prefer on-premises over cloud – it is technology-neutral, and the compliance question is whether safeguards and accountability can be evidenced wherever the data sits.

Two genuine caveats: the Government may notify categories of personal data that Significant Data Fiduciaries must keep in India, and sector regulators can be stricter – the RBI has required payment system data to be stored only in India since 2018, a rule that predates and operates independently of DPDP. The interaction is examined in Where BFSI AI Compute Must Sit.

Penalties and why the Rs 250 crore figure matters

The Schedule to the Act sets monetary penalty caps per instance: up to Rs 250 crore for failing to take reasonable security safeguards, up to Rs 200 crore for failing to notify a breach, and lower caps for other duties. Unlike the GDPR, penalties are not a percentage of turnover, but the top caps are large enough that security-safeguard evidence – access logs, encryption posture, monitoring records – becomes board-level material. The Board weighs gravity, duration and repetitiveness when setting the amount, as the Act provides.

Significant Data Fiduciaries and the algorithm clause

The Government may designate a class of fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data, risk to individuals, and similar factors. SDFs must appoint a Data Protection Officer based in India who answers to the board, conduct an annual Data Protection Impact Assessment and an independent audit, and – most relevant to AI teams – undertake due diligence that their technical measures, including algorithmic software, do not pose a risk to the rights of individuals. Teams training or deploying models on personal data should expect that clause to be read against them and should keep model documentation, evaluation records and dataset lineage ready.

Training data and GPU siting in practice

For an AI infrastructure programme, the sensible response is evidence-first design rather than geography-first design. Inventory where personal data enters pipelines – raw corpora, fine-tuning sets, RAG stores, prompts and logs. Prefer de-identification before data reaches the training tier. Design erasure paths for datasets and backups from day one. Then choose siting on control grounds: an on-premises or private-hosted cluster makes it easier to evidence who accessed what, as argued in Training Behind Your Own Firewall, and a structured checklist approach is set out in DPDP-Ready AI Infrastructure Planning.

Common readings vs what the law provides

Common reading What the Act and Rules provide
DPDP forces all data to stay in India Transfers are permitted except to countries the Central Government restricts (Rule 15 negative list)
Cloud AI is non-compliant by default The law is technology-neutral; the duty is evidenced safeguards and accountability wherever data sits
Penalties are turnover-linked like GDPR Fixed caps per instance under the Schedule; the highest is Rs 250 crore for security-safeguard failure
Only large technology firms are covered All Data Fiduciaries processing digital personal data are covered; SDFs carry additional duties
Anonymised training data is regulated Genuinely anonymised data falls outside the Act; re-identifiable or pseudonymous data does not

Frequently asked questions

Does the DPDP Act require my GPU servers to be located in India?

No. The Act permits cross-border transfer of personal data except to countries the Central Government restricts. Localisation can arise from SDF-notified data categories or from sector rules such as the RBI’s payment data directive, not from the Act generally.

When do the DPDP obligations actually start applying?

The Rules were notified on 13 November 2025 with staggered commencement. Consent, security and breach provisions phase in over roughly 12 to 18 months, and SDF obligations are reported to commence around mid-2027. Confirm current dates against the notification before committing budgets.

Can we train AI models on personal data at all?

Yes, with valid consent or a recognised legitimate use, purpose limitation, and safeguards. De-identifying data before training reduces exposure, and erasure obligations should be designed into the dataset pipeline rather than retrofitted.

What is a Significant Data Fiduciary?

A class of fiduciaries notified by the Government based on data volume and sensitivity and risk factors. SDFs must appoint an India-based DPO, run annual DPIAs and audits, and verify that their algorithmic systems do not endanger individuals’ rights.

What should the infrastructure team do first?

Build a data map of where personal data touches AI pipelines, implement the Rule-level safeguards – encryption, access control, logging with retention, backups – and rehearse the 72-hour breach reporting path alongside the CERT-In six-hour duty.

Ready to deploy?

Talk to an RDP architect about power, cooling and lead time.

Request a Quote