Salhakar Logo
Data Privacy & Compliance / AI & Legal Tech

India's Digital Personal Data Protection Act 2023 Meets AI: What Lawyers Need to Know Right Now

S Naveen Gowda
May 23, 2026
6 min read
India's Digital Personal Data Protection Act 2023 Meets AI: What Lawyers Need to Know Right Now

India's Digital Personal Data Protection Act 2023 Meets AI: What Lawyers Need to Know Right Now

The Digital Personal Data Protection Act, 2023 (DPDP Act) represents India's most significant data protection legislation. While attention has focused on tech companies, the intersection of the DPDP Act with AI creates specific challenges for legal professionals requiring immediate attention.


Understanding the DPDP Act Framework


The Act applies to digital personal data processing within India and processing outside India relating to offering goods or services to Indian data principals.

Personal Data — Data about an identifiable individual, encompassing virtually all client information.

Data Fiduciary — Entity determining purpose and means of processing. Law firms are data fiduciaries with corresponding obligations.

Data Processor — Entity processing data on behalf of a fiduciary. AI service providers typically function as processors.


The AI–DPDP Intersection


01 — Lawful Grounds for Processing

Section 6 requires a lawful basis for processing. When lawyers input client information into AI, whose consent is needed?

BasisWhat It Means
Consent Based ProcessingIf data relates to clients, their consent is required. If it relates to opposing parties or witnesses, their consent may also be needed creating practical impossibilities
Legitimate UsesSection 7 provides alternatives including processing necessary for legal claims and legal compliance. Legal practice may qualify, but boundaries remain unclear

02 — Purpose Limitation and Data Minimisation

The Act requires data collection for specified purposes and processing only for those purposes (Section 4), plus data minimisation.

AI training often involves processing beyond original purposes. If vendors use inputs for model improvement, it's secondary processing requiring additional legal grounds typically consent.

Implication: Review vendor terms carefully. If vendors use inputs for training without consent, you may be in violation of the DPDP Act.


03 — Cross Border Data Transfers

Section 16 authorises restrictions on transfers to certain countries. Most AI platforms process data outside India, creating potential transfer issues.

  ChatGPT  ·  Claude  ·  Gemini  ——>  Data processed outside India  ——>  Potential transfer risk

While specific restrictions haven't been imposed, document where vendors process data to respond quickly if restrictions emerge.


04 — Data Security Obligations

Section 8 imposes security obligations on lawyers using AI platforms.

Safeguard TypeWhat Is Required
Technical SafeguardsPlatforms with SOC 2, ISO 27001, encryption, and access controls
Organisational MeasuresInternal policies training, access controls, anonymisation protocols
Breach NotificationReport to the Data Protection Board and affected individuals under Section 8(6) if a vendor breach occurs

05 — Data Principal Rights

The Act grants rights to access (Section 11), correction and erasure (Sections 12, 13), and grievance redressal (Section 9).

If client data has trained AI models, can it truly be erased? This creates practical challenges with no clear answers yet.


Current Legal Landscape


DPDP Act Rules: What We're Waiting For

Implementation depends on rules yet to be notified. Critical undefined aspects include:

  Consent Requirements  ·  Security Safeguards  ·  Breach Notification Formats  ·  Penalty Structures

You are implementing AI in a partially defined environment. Be conservative, document decisions, and monitor rule notifications closely.

Data Protection Board

The Board will have authority to investigate complaints and impose penalties up to ₹250 crores. Though not fully constituted, it represents new regulatory oversight over data handling including AI use.

Bar Council Positions

The Bar Council hasn't issued AI specific guidance, but existing rules remain applicable.

RuleImplication for AI Use
Rule 15 — ConfidentialityUsing AI platforms that don't protect client data likely violates this rule
Rule 12 — CompetenceUsing AI tools you don't understand may violate competence obligations

Practical Compliance Framework


Step 01 — Classify AI Use Cases

Risk LevelDescription
Low RiskLocal processing tools, minimal personal data, publicly available information
Medium RiskCloud based tools for research where data can be anonymised
High RiskProcessing sensitive client data on external platforms, especially outside India

Step 02 — Conduct Data Protection Impact Assessments

Identify what personal data will be processed, the lawful grounds, security measures, risks to data principals, and mitigation strategies. Document assessments and update them when use cases change.


Step 03 — Implement Privacy by Design

Data Minimisation — Before using AI, determine the minimum data needed. Redact everything else.

Anonymisation Protocols — Replace names with identifiers, remove contact, financial, and proprietary information, strip metadata.

Segregation — Keep highly sensitive matters off AI platforms entirely.


Step 04 — Vendor Due Diligence

Assess: Data storage location · Security certifications · Breach history · Retention policy · Use of data for training

Negotiate: DPDP Act aligned obligations · Prohibition on training use · Deletion rights · Breach notification within 24–48 hours · Audit rights · Indian governing law

Do not accept consumer terms for professional legal practice.


Step 05 — Client Communication and Consent

Engagement Letters — Add technology use language explaining AI use for research and analysis, lawyer review of all outputs, confidentiality measures, and the client's right to raise concerns.

Specific Consent — For high-risk processing, obtain explicit consent documenting the data to be processed, the AI tool used, storage location, safeguards, and right to withhold consent.


Step 06 — Internal Policies and Training

  Approved Tools  ·  Data Handling  ·  Anonymisation  ·  Verification  ·  Incident Reporting

Policies and training must cover DPDP Act fundamentals, data classification, anonymisation procedures, breach recognition and reporting, and client communication standards.


Step 07 — Monitoring and Audit

FrequencyActivity
OngoingLog all AI use, review vendor security, track incidents, monitor regulatory changes
QuarterlyCompliance reviews, vendor reassessment
AnnualComprehensive audits, review for new tools or regulatory updates

Emerging Issues to Watch


AI Model Transparency — Understanding how AI processes data may be required under Section 8(4)'s reasonable safeguards requirement.

Biometric Data — Section 3(23) classifies biometric data as sensitive. As AI increasingly involves facial recognition and voice analysis, heightened protection is required.

Children's Data — Section 9 imposes special obligations for processing data of individuals under 18. Family law, juvenile justice, and education matters require particular care.

Interplay with Other Regulations — Consider the IT Act 2000 (Section 43A), Bar Council Rules, and sector specific regulations alongside the DPDP Act.


The Bottom Line


  DPDP Act + AI  ————————————>  not a barrier
                 ——————————————————————————>  a framework for responsible practice

The DPDP Act doesn't prohibit AI use — it requires responsible use with appropriate data protections, fully aligning with existing professional obligations around confidentiality and competence.

Lawyers who thrive will view the DPDP Act not as an obstacle but as a framework for responsible AI use protecting clients, maintaining professional standards, and building trust in an AI-enabled legal profession.

Both AI and DPDP implementation are moving targets. In this environment, flexibility, caution, and continuous learning are essential. Document compliance efforts, implement reasonable safeguards, stay informed, and be prepared to adjust.


Salhakar · Your 360° Intelligent Legal Ecosystem · 2026