A note on scope: this is a practical readiness aid, not legal advice. Your exact obligations depend on your sector and the DPDP Rules as they apply to you, so confirm specifics with your own counsel. Where an item says architecture "supports" an obligation, that means it makes the obligation easier to meet and evidence. No product makes an organisation DPDP compliant on its own.

01

Know your personal data, including the AI shadow copies

The Act assumes you know what personal data you hold and where it goes. Most organisations know their official systems and forget the unofficial ones.

02

Notice and consent that a normal person can read

Consent buried in a wall of terms is not the consent the Act wants.

03

The AI boundary question

Under the Act you remain the Data Fiduciary for personal data your staff put into AI tools, wherever that tool processes it. "We did not know" is not a defence; it is the finding.

04

Security safeguards you can evidence

This is the obligation whose failure carries the headline penalty of up to ₹250 crore. The test is not whether you have controls; it is whether you can produce the evidence.

05

Breach readiness, rehearsed

Detection, containment and reporting to the Data Protection Board and affected individuals run on timelines. Your obligation does not pause while a vendor investigates.

06

Data principal rights, as a process

Access, correction, erasure and grievance handling should be a procedure someone runs, not a scramble someone survives.

07

Children's data, if you touch it

Anyone under eighteen is a child under the Act. Schools, universities, edtech, gaming, healthcare and many consumer businesses are in this section whether they planned to be or not.

08

If you are large: Significant Data Fiduciary duties

Organisations notified as Significant Data Fiduciaries carry extra duties. If you might be one, plan as if you are.


Notice a pattern in the hard rows. Items 03 and 04 get easy or hard depending on one architectural choice: where the AI runs. When it runs on somebody else's cloud, "where is this processed" is a clause you cite and hope holds up. When it runs inside your own boundary, it is a fact you show. A private deployment on your own infrastructure supports the boundary, safeguards and evidence rows by design; your notices, consent flows and policies still do the rest of the work. For the background, read the DPDP countdown to May 2027 and the eight questions your compliance team should ask, and see how ZenithAI supports each control in security and governance.