DPDP Rule 6 and AI Governance: What Indian Enterprises Must Fix Before May 2027
By Privy
Jun 24, 2026

DPDP Rule 6 and AI Governance: What Indian Enterprises Must Fix Before May 2027

Your employees may already be sending personal data into AI tools your privacy team has never reviewed. A customer transcript pasted into a chatbot, a claims file summarised by an AI assistant, or a CRM list uploaded into a segmentation tool can all create DPDP exposure, even before anyone calls it a breach. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. Most operational obligations, including the security safeguards under Rule 6, take effect roughly 18 months later, putting the practical readiness deadline around May 2027. That feels distant. For any enterprise that has rolled out AI copilots, embedded LLMs into customer workflows, or let teams use vendor AI tools, it isn't. AI did not change what DPDP requires. It changed where personal data flows, who can touch it, and how hard it is to prove what happened. Rule 6 is where those two worlds collide.

Why AI Usage Creates New DPDP Compliance Risk

DPDP governs the processing of digital personal data, and AI systems are processing engines. When a fintech support team feeds customer chat transcripts into a summarisation model, when an insurer's underwriting copilot reads claimant medical notes, or when a marketing team uploads a customer list to an AI segmentation tool, personal data is being processed, often outside the controls the compliance team assumes are in place.

The risk is not that AI is inherently non-compliant. It is that AI widens the surface area of processing while reducing visibility over it. Data moves into prompts, vector stores, model logs, and third-party APIs that rarely appear on a data inventory.

What Rule 6 Actually Requires

Rule 6 obliges every Data Fiduciary to protect personal data in its possession or control, including data processed on its behalf, by implementing reasonable security safeguards to prevent a personal data breach. These safeguards must include, at a minimum: appropriate data security measures such as encryption, obfuscation, masking, or virtual tokens; access controls over the computer resources used; visibility into who accesses personal data through logs, monitoring, and review; and reasonable measures to continue processing if data is compromised.

Two details matter for AI specifically. First, the obligation extends to processing done on your behalf, so a vendor AI tool does not move the risk off your books. You cannot outsource the liability. Second, processing logs and related records must be retained for a minimum of one year to support detection, investigation, and remediation. The penalty for failing on security safeguards is severe: up to ₹250 crore per incident under Section 8(5). Put simply, Rule 6 demands that you encrypt personal data, control who can reach it, log access in a reviewable way, keep those logs, and ensure your processors do the same.

DPDP Act Rule 6

Each row is a place where encryption, access control, logging, or processor obligations under Rule 6 can quietly fail.

The Real AI Risk: Someone Already Pasted Customer Data Into a Chatbot

The most common AI exposure in Indian enterprises is mundane. An employee pastes a spreadsheet of customer PAN numbers, or a claimant's medical history, into a public AI tool to draft something faster. That single action can constitute unauthorised processing, send personal data to an unvetted processor, and leave no audit trail you control. Organisations should assess whether their acceptable use policies, data loss controls, and access logging actually capture this behaviour, because policy text alone will not satisfy Rule 6's evidentiary expectations.

How AI Touches Every DPDP Obligation

AI rarely breaks one rule cleanly. It strains the whole framework.

  • Notice and consent. If personal data collected for one purpose is reused to train or prompt a model, the original notice and consent may not cover it.
  • Purpose limitation. Feeding CRM data into an AI tool for a new use may exceed the stated purpose.
  • Processor contracts. Vendor AI tools must be bound by contracts requiring equivalent safeguards, as Rule 6 anticipates.
  • Breach detection. A model leaking personal data in its outputs may meet the definition of a breach, triggering Rule 7's tight notification timeline.
  • Access controls and logging. AI pipelines often bypass the access management and logging that protect production systems.
  • Data Principal rights. When data sits inside embeddings and model logs, fulfilling access, correction, or erasure requests becomes genuinely hard.

Why Checklists Are Not Enough

A static DPDP checklist assumes you can point to a fixed set of systems and confirm controls once. AI workflows are dynamic. New tools appear weekly, data flows shift, and prompts are unpredictable. Compliance for AI has to be continuous and evidence-generating, not a one-time attestation. The question a regulator or auditor asks is not "do you have a policy"; it is "show me the proof."

SDFs and Rule 13(3) Algorithmic Due Diligence

Enterprises designated as Significant Data Fiduciaries (SDFs) face a far more demanding set of obligations that require immediate technical readiness. Under Rule 13(1) of the DPDP Rules, 2025, SDFs are legally mandated to conduct a comprehensive Data Protection Impact Assessment (DPIA) and an independent privacy audit at least once every twelve months, with the significant findings reported directly to the Data Protection Board (DPB).

For organizations running AI at scale, however, the real operational hurdle is Rule 13(3). This rule shifts the burden of proof firmly onto the enterprise, strictly requiring SDFs to observe continuous due diligence to verify that any technical measures, including algorithmic software adopted for hosting, displaying, caching, or sharing personal data, are not likely to pose a risk to the rights of Data Principals.

When applied to enterprise AI, this legal expectation fundamentally changes the game:

  • The Model Training & Log Floor: Under Rule 8(3), all associated traffic data, model inputs, and processing logs must be retained for a minimum period of one year from the date of processing to enable compliance mapping and breach tracing. You can no longer clear cache or purge inference logs dynamically without a structured legal floor
  • The 90-Day Rights SLA: If an algorithm generates a biased profile, hallucinates PII, or processes data beyond the consented scope, Rule 14(3) establishes a strict 90-day hard ceiling for the grievance redressal system to completely investigate and resolve the issue. Finding and unlinking data within complex vector databases and RAG pipelines to fulfill an erasure or correction request must be fully orchestrated within this timeline
  • The 72-Hour Breach Containment: If an AI model inadvertently exposes sensitive personal data in its outputs, Rule 7(2) mandates that a detailed factual description, mitigation report, and remedial plan be submitted to the DPB within 72 hours of becoming aware of the incident.

How Privy Automates SDF Compliance

Point-in-time, manual checklists cannot handle the fluid nature of LLMs and changing user journeys. Privy by IDfy moves SDFs from policy-level intent to continuous, evidence-driven compliance:

  • Continuous Algorithmic Scanning via InspectAI: Instead of a static annual check, Privy’s AI Co-pilot continuously scans and analyzes digital journeys, onboarding flows, and processing scripts to map personal data directly to an automated Record of Processing Activities (RoPA). It instantly flags deviations such as an unrecorded AI tool absorbing customer identifiers before it triggers regulatory risk
  • Automated DPIA Lifecycle Workflows: Privy provides specialized, customizable assessment templates that evaluate risk calculation, assign clear internal team ownership, and dynamically link evidence (like consent receipts and vendor contracts) to generate regulator-ready audit packs.
  • Downstream Deletion Orchestration: When a customer triggers a deletion or revocation request through the multilingual Data Principal Rights Management (DPRM) portal, Privy routes and tracks the request downstream to internal systems and third-party processors, collecting verifiable certificates of deletion to safeguard your 90-day SLA.

The DPDP and AI governance checklist

  1. Discover every place personal data enters AI systems, including prompts, vector stores, and vendor APIs.
  2. Classify that data by sensitivity to set proportionate controls.
  3. Map the lawful basis for each AI use, and confirm notice and consent cover it.
  4. Bind vendors with processor contracts requiring Rule 6 equivalent safeguards.
  5. Enforce access controls and encryption across AI pipelines.
  6. Log AI access to personal data and retain logs for at least one year.
  7. Run PIAs and DPIAs on high-risk AI systems, and add algorithmic due diligence for SDFs.
  8. Wire breach detection to cover AI-originated exposure with Rule 7 timelines.
  9. Operationalise Data Principal rights across AI-held data.
  10. Keep evidence of every control, ready for audit.

What To Look For In A DPDP Compliance Platform For The AI Era

Policy-level compliance is no longer the bar. Enterprises should look for a platform that discovers personal data wherever it lives, manages consent and purpose at scale, operationalises Data Principal rights, governs third-party and AI risk, detects and reports breaches, and, critically, generates a continuous audit trail that turns claims into proof.

How Privy by IDfy Helps

Privy by IDfy is a full-stack DPDP compliance and privacy governance platform built for Indian enterprises. It is designed to move organisations from policy-level intent to operational, evidence-backed compliance.

Across the AI risk surface, Privy provides the operational layer: personal data discovery and classification through Data Compass to find data flowing into AI tools, consent management to keep purpose and consent aligned, Data Principal Rights Management to fulfil access and erasure requests even across complex data stores, Third Party Risk Management to govern vendor AI processors, incident and breach management mapped to DPDP timelines, PIA and DPIA workflows including support for algorithmic due diligence, and a unified audit trail and evidence layer spanning these workflows through InspectAI.

Privy gives privacy, security, and legal teams the workflows, accountability, and proof needed to demonstrate DPDP readiness, so that when May 2027 arrives, your controls are not just written down. They are running, logged, and defensible. To know more about these DPDPA solutions, contact shivani@idfy.com. See how Privy by IDfy helps enterprises discover personal data, govern AI risk, manage consent, fulfil rights, and build audit-ready DPDP evidence before May 2027.

"Book Demo"

DPDP compliance checklist for AI tools

FAQ’s

What is DPDP Rule 6? 

Rule 6 requires Data Fiduciaries to implement reasonable security safeguards, including encryption, access controls, monitoring and logging, and continuity measures, to prevent personal data breaches.

Does Rule 6 apply to AI tools? 

Yes. Rule 6 covers personal data processed by you or on your behalf, which includes vendor AI tools and internal models processing personal data.

When does DPDP Rule 6 take effect?

 The Rules were notified on 13 November 2025, with core operational obligations including security safeguards taking effect roughly 18 months later, around May 2027.

What is the penalty for failing Rule 6? 

Failure to implement reasonable security safeguards can attract a penalty of up to ₹250 crore per incident under Section 8(5).

How long must logs be retained under Rule 6?

 Processing and access logs must be retained for a minimum of one year to support breach detection and investigation.

What is algorithmic due diligence under DPDP?

 For Significant Data Fiduciaries, it means assessing whether algorithms and AI systems risk harming Data Principals' rights, alongside mandatory DPIAs and annual audits.

Can a DPDP compliance platform guarantee compliance? 

No platform can guarantee compliance. A good platform operationalises controls and generates the evidence needed to demonstrate readiness.

What should enterprises fix first for AI compliance?

 Start with discovery: find where personal data enters AI systems, then layer on access controls, logging, and lawful basis mapping.


Search Here

Reach out to us

Explore More

DPDPA for Marketers: The 2026 Guide to Consent-Led Digital Marketing
DPDP Rules

Jul 06, 2026

DPDPA for Marketers: The 2026 Guide to Consent-Led Digital Marketing

DPDPA Rule 3 Decoded: Consent Notice Requirements
DPDP Rules

Jun 10, 2026

DPDPA Rule 3 Decoded: Consent Notice Requirements

Share