# DPDP Act 2023 and Your AI Product: What Engineering Teams Actually Need to Know

> India's Digital Personal Data Protection Act 2023 has direct implications for any product that processes personal data through AI inference. Most engineering teams do not know where their prompts go, who processes them, and whether they qualify as personal data under Indian law. This guide breaks it down in plain terms.

- Author: Tensor Machine
- Published: 2025-12-05
- Tag: Compliance
- URL: https://tensormachine.ai/blog/dpdp-act-2023-ai-inference-developers-guide

---

## What the DPDP Act Actually Is

The Digital Personal Data Protection Act 2023 received Presidential assent on 11 August 2023. It is India's first comprehensive data protection legislation and creates a framework for how personal data of Indian residents must be collected, stored, processed, and transferred. The Act applies to any organisation that processes digital personal data in India or processes data of Indian residents from outside India — including SaaS companies, AI platforms, and their downstream customers.

## How AI Inference Touches Personal Data

Here is where engineering teams often get caught out. A prompt sent to an AI model can contain personal data. A customer support prompt may include a user's name, account number, or medical history. A document summarisation prompt may include employee records or client contracts. Under Section 8 of the DPDP Act, if you transfer this data to a foreign AI provider, you must ensure your Data Processor meets the Act's obligations — and under Section 16, cross-border transfers of personal data are subject to the restrictions notified by the Central Government.

The DPDP Act defines personal data as any data about an identifiable natural person. Prompts containing names, contact details, financial information, health data, or combinations that could identify an individual qualify. Whether embeddings derived from personal data qualify depends on whether the embedding can reasonably be used to identify the individual — a point legal counsel should assess for your specific use case.

## Data Fiduciary vs Data Processor — Where AI Providers Fit

The DPDP Act distinguishes between Data Fiduciaries — entities that determine the purpose and means of processing personal data — and Data Processors, who process data on behalf of Fiduciaries. If you build an AI product, you are likely a Data Fiduciary. Your AI inference provider is a Data Processor. Under Section 8(2), Data Fiduciaries are responsible for ensuring their Data Processors comply with the Act's provisions, including through contractual obligations.

## What Compliance Actually Requires

For most AI-enabled products, DPDP compliance requires four things. First: a lawful basis for processing — typically consent obtained in the manner prescribed under Section 6, or a legitimate use recognised under Section 7. Second: a Data Processing Agreement with your AI inference provider committing them to process data only as directed, maintain appropriate security safeguards, and not use data for any other purpose including model training. Third: implementing data localisation to the extent required by notifications under Section 16. Fourth: the ability to honour Data Principal rights — right to access, correction, erasure, and grievance redressal — which requires traceability of where personal data was processed.

For regulated industries specifically — BFSI regulated by RBI, insurance by IRDAI, healthcare — sector-specific guidelines effectively require AI inference to happen within India for data classified as sensitive. The RBI circular on outsourcing of IT services (2023) and IRDAI guidelines on cloud adoption both require data to remain within Indian jurisdiction for regulated workloads. This is an audit point, not just best practice.

## A Practical Architecture Checklist

For your engineering and product teams: confirm your AI inference provider processes all data within India. Obtain a signed Data Processing Agreement before your next vendor audit. Establish what your provider retains by default, and whether retention is opt-in or opt-out — ask about logs, embeddings, and conversation history separately, and get the default in writing. Map which product features send personal data to AI and which do not. Implement consent flows for AI features that process identifiable user data. Document your AI vendor assessments and keep them current for your Data Protection Officer.

## How Tensor Machine Helps

Tensor Machine is designed from the ground up for DPDP compliance. All inference runs in Indian data centres. Content logging is off unless your organisation turns it on, and the router enforces that at the edge — retention is opt-in, not something you must remember to disable. We do not train on customer data and we do not sell it; the model provider serving a request necessarily receives the prompt, and no one else does. Data Processing Agreements are available to all paid customers. Our enterprise SLA includes compliance documentation packages for DPOs and legal teams, including evidence of data localisation and security controls.

If you are evaluating AI inference providers for a regulated use case — BFSI, healthcare, or government — we are happy to walk through our compliance posture in detail, including audit support. Reach out to our enterprise team.
