If Your Product Uses AI, the DPDP Act Already Applies: What Indian SMEs Should Check Now
AI and the DPDP Act are now tied together for Indian businesses. Here is what algorithmic due diligence under Rule 13 and the EU AI Act's recalibrated 2026 timeline mean for SMEs and startups building AI features.
If your product uses AI and the DPDP Act feels like a problem for later, that gap is where most Indian SMEs are quietly building up risk. A support chatbot that reads customer tickets, a resume-screening tool, a recommendation engine, a fraud model that scores transactions: all of these run on personal data, and all of them sit squarely inside the Digital Personal Data Protection Act, 2023. There is no separate "AI exemption" and no lighter standard because the processing happens inside a model rather than a spreadsheet.
Two developments in the last few months make this worth a fresh look. India's DPDP Rules, 2025 were notified on 13 November 2025, and buried in Rule 13 is a duty that legal commentators have started calling India's first binding algorithmic accountability provision. At almost the same time, the EU quietly moved its own AI rulebook around, deferring the heaviest obligations for high-risk systems. The direction of travel is the same in both places, even if the timing now differs.
What Rule 13 actually says about algorithms
Rule 13 applies to Significant Data Fiduciaries (SDFs), a class the government will notify based on volume and sensitivity of data, risk to data principals, and similar factors. An SDF has to appoint a India-based Data Protection Officer, get an independent data audit and a Data Protection Impact Assessment done once every twelve months, and observe due diligence to verify that its algorithmic software is "not likely to pose a risk to the rights of Data Principals."
That last phrase is doing a lot of work. It reaches AI systems used for hosting, display, publishing, storage, and sharing of personal data. In plain terms: if you designate as an SDF and your product ranks, scores, filters, or recommends using personal data, you are expected to check that the algorithm itself does not harm the people whose data feeds it. As of now, no entity has been notified as an SDF, and the substantive SDF obligations are tied to the Rules' phased commencement, expected around mid-2027. So the deadline is not today. The homework, for anyone likely to cross that line, starts well before.
Why this matters even if you are not an SDF
Most startups and mid-sized firms will not be notified as SDFs. That does not put your AI features outside the Act. The ordinary obligations still bite, and they bite harder when a model is involved.
Purpose limitation is the first pinch point. Under the DPDP framework, you collect personal data for a specified purpose and use it for that purpose. Feeding customer data collected for order fulfilment into a new AI model that predicts churn or scores creditworthiness is a different purpose, and it usually needs its own notice and fresh consent. Teams that treat historical data as a free training corpus tend to miss this entirely.
Consent is the second. The DPDP standard is free, specific, informed, and unambiguous, with a plain-language notice and an easy way to withdraw. A pre-ticked box that quietly enrols users into "AI improvement" will not hold up. If withdrawal is meant to be as easy as giving consent, your model pipeline needs a way to stop using someone's data when they pull out.
Then there is data principal access. People can ask what personal data you hold and how it is being processed. "It went into the model" is not a satisfying answer, and it is not a defensible one. You need to know which datasets trained which system.
The global signal: the EU just recalibrated, not retreated
For Indian firms selling into Europe or using European vendors, the EU AI Act timeline shifted this year and it is worth getting right. The Act's general transparency duties under Article 50, such as telling people when they are interacting with an AI system, still apply from 2 August 2026. But the core obligations for high-risk Annex III systems (recruitment, credit scoring, biometric categorisation, and the like) were pushed back from 2 August 2026 to 2 December 2027 under the Digital Omnibus agreement reached in May 2026.
Read that as a schedule change, not a reprieve. Regulators bought builders about sixteen extra months to meet technical standards, and enforcement elsewhere has not slowed. Cumulative GDPR fines passed €6.31 billion across more than 3,200 cases by late August 2026 on the CMS Enforcement Tracker, and the EDPB's 2026 coordinated enforcement work has specifically flagged AI-assisted decision-making and employee monitoring. If your AI touches EU residents, the transparency clock is already running.
A practical checklist for the next quarter
You do not need a data science team to start. A few concrete steps go a long way.
Build an inventory of every AI or automated system that touches personal data, what data it uses, and why. Most firms are surprised by how long this list gets once they include vendor tools and internal scripts.
Trace each system back to a lawful basis under the DPDP Act. If a model uses data collected for another purpose, either fix the notice and consent or stop using that data.
Write down, in a page or two, how each significant model could affect the people in its dataset: wrong rejections, biased scoring, exposure of sensitive attributes. This is the muscle a full privacy impact assessment exercises, and starting early makes the formal version painless if you later designate as an SDF.
Decide who owns this. Whether or not you are legally required to appoint one yet, having a named person accountable for data and AI decisions is the difference between a policy and a practice. Our note on data protection officer services covers when the role becomes mandatory and what it involves.
Keep records. If a data principal or the Board asks how a model uses their data, you want an answer ready, not a scramble.
The penalties give this weight. The DPDP Act allows financial penalties up to ₹250 crore per instance, and the Data Protection Board is being assembled to hear complaints. A model that quietly misuses personal data is exactly the kind of thing that surfaces in a breach or a grievance. Getting ahead of it is cheaper than explaining it later. For the full picture of what applies to your business, our DPDP Act compliance overview is a good place to start.
This article is general guidance for Indian businesses and not legal advice; your obligations depend on your specific data, systems, and circumstances. For a structured starting point, use our DPDP compliance checklist, or get in touch to talk through your AI and data setup.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation