
Enterprise AI Governance After India’s DPDP Rules
Enterprise AI Governance for India
Hero artwork: AI-generated brand illustration using Parikshit Khanna’s likeness.
India’s Digital Personal Data Protection Rules, 2025 turned the DPDP framework into a phased implementation programme. Enterprise AI teams should respond by replacing informal experimentation with documented controls.
As of October 2026, the final Rules are notified but do not all commence together. Rules 1, 2 and 17–21 began at notification; Rule 4 was scheduled one year after publication; and Rules 3, 5–16, 22 and 23 were scheduled after eighteen months. Organisations should confirm applicable dates and duties with counsel.

AI governance must begin with data flow
For every system, document what information enters, where it is processed, what the provider retains, who can access the output and whether the result feeds another system.
Create an AI use-case register containing the business purpose, data categories, accountable owner, provider, model, location, users, review requirements and legal assessment. Include employee use of public tools; unsanctioned experimentation is still part of the organisation’s real risk surface.
Connect purpose, notice and tool design
The final DPDP Rules describe clear, standalone notices with an itemised account of personal data and specified purposes. That has a practical design implication: do not reuse customer or employee information in an AI workflow merely because the organisation already holds it.
Ask whether the use fits the communicated purpose and lawful basis, whether a new notice or consent flow is needed, and whether less data could work. Masking names may help, but context can still expose a person. Privacy, legal and product owners should review the workflow before deployment.
Treat AI providers as part of the control environment
Procurement should obtain clear answers on model training, retention, sub-processors, security, access logs, data location, incident support, deletion and export. The final Rules require contractual provision for reasonable security safeguards where a Data Processor is involved.
An enterprise licence can improve controls, but the organisation remains responsible for configuration and use. Disable unnecessary integrations, apply least-privilege access and review connectors that allow a model to search email, drives, chats or business systems.
Build security and incident readiness together
The notified Rules describe safeguards including encryption or comparable protection, access control, logs, monitoring and backups. They also set a breach-intimation structure: affected Data Principals and the Board receive initial notice without delay, with detailed information to the Board within seventy-two hours, subject to the Rule’s terms and commencement.
AI incident exercises should therefore test more than a conventional breach. Include accidental prompt disclosure, an over-permissioned connector, sensitive information reproduced in an output, a vendor outage, a poisoned knowledge source and an automated action taken without approval.
Put human accountability around consequential work
Not every AI output needs the same review. A first draft of an internal agenda is different from a credit decision, employment recommendation, medical communication or regulatory filing.
Classify workflows by impact. High-impact work needs qualified review, source evidence, an override route and a decision record. Human review is meaningful only when the reviewer has time, authority and relevant competence.
Practical governance tips
Publish an approved-tool list and a prohibited-data list.
Assign both a business owner and a control owner to every material use case.
Test with sanitised data before connecting production systems.
Keep prompt, source, output and approval evidence for high-impact workflows.
Re-test after material model, vendor or configuration changes.
Practise breach and harmful-output scenarios with named responders.
Set a retirement process for failed or unused AI systems.
Commercial governance plan
Stage | Timeline | Scope | Deliverables | Fee basis |
Readiness assessment | 2 weeks | Use-case, data-flow, policy and vendor review | Gap register, risk heatmap and priority plan | Bespoke after discovery |
Governance design | 3–4 weeks | Roles, approvals, controls and evidence standards | AI policy, use-case register, review matrix and templates | Bespoke |
Control pilot | 4–6 weeks | Apply governance to two live workflows | Test evidence, incident exercise and remediation plan | Bespoke |
Assurance cycle | Quarterly | Metrics, exceptions, vendor changes and retraining | Governance report, updated register and action log | Bespoke retainer |
This work supports operational readiness; it does not replace legal advice, a statutory audit or specialist cybersecurity testing.
About Parikshit Khanna
Parikshit Khanna is the founder of Digital Training Jet, an AI trainer and strategic consultant listed by Masters’ Union, and a TEDx speaker. His public work centres on practical AI adoption, prompt engineering and professional learning. Governance engagements should be coordinated with the client’s legal, privacy, risk and security specialists.
Build a governed AI adoption programme
To discuss an AI governance workshop, readiness assessment or controlled pilot, get in touch with Parikshit Khanna. Include your sector, team size, current tools and the workflows that handle personal or confidential data.
Frequently asked questions
Do the DPDP Rules ban the use of Generative AI?
No. The framework governs processing of digital personal data; it does not impose a general ban on Generative AI. Each workflow still needs an appropriate purpose, data controls and compliance analysis.
Are all DPDP provisions already in force?
No. The 2025 notifications use phased commencement. Check the official notification and obtain current legal advice for the provision relevant to your organisation.
Is masking personal data enough?
Not always. Context can re-identify a person, and a workflow may process confidential information that is not personal data. Use minimisation, access controls, contractual safeguards and purpose review together.
Who should own enterprise AI governance?
Ownership should be cross-functional. Business leaders own outcomes; technology teams manage systems; legal and privacy teams interpret obligations; security manages technical risk; and users remain responsible for following the operating process.