top of page

Enterprise AI Governance After India’s DPDP Rules

9 hours ago
4 min read

Enterprise AI Governance for India


Hero artwork: AI-generated brand illustration using Parikshit Khanna’s likeness.


India’s Digital Personal Data Protection Rules, 2025 turned the DPDP framework into a phased implementation programme. Enterprise AI teams should respond by replacing informal experimentation with documented controls.


As of October 2026, the final Rules are notified but do not all commence together. Rules 1, 2 and 17–21 began at notification; Rule 4 was scheduled one year after publication; and Rules 3, 5–16, 22 and 23 were scheduled after eighteen months. Organisations should confirm applicable dates and duties with counsel.


Parikshit Khanna leading an original AI training session
Original session photograph of Parikshit Khanna delivering practical AI training.

AI governance must begin with data flow


For every system, document what information enters, where it is processed, what the provider retains, who can access the output and whether the result feeds another system.


Create an AI use-case register containing the business purpose, data categories, accountable owner, provider, model, location, users, review requirements and legal assessment. Include employee use of public tools; unsanctioned experimentation is still part of the organisation’s real risk surface.


Connect purpose, notice and tool design


The final DPDP Rules describe clear, standalone notices with an itemised account of personal data and specified purposes. That has a practical design implication: do not reuse customer or employee information in an AI workflow merely because the organisation already holds it.


Ask whether the use fits the communicated purpose and lawful basis, whether a new notice or consent flow is needed, and whether less data could work. Masking names may help, but context can still expose a person. Privacy, legal and product owners should review the workflow before deployment.


Treat AI providers as part of the control environment


Procurement should obtain clear answers on model training, retention, sub-processors, security, access logs, data location, incident support, deletion and export. The final Rules require contractual provision for reasonable security safeguards where a Data Processor is involved.


An enterprise licence can improve controls, but the organisation remains responsible for configuration and use. Disable unnecessary integrations, apply least-privilege access and review connectors that allow a model to search email, drives, chats or business systems.


Build security and incident readiness together


The notified Rules describe safeguards including encryption or comparable protection, access control, logs, monitoring and backups. They also set a breach-intimation structure: affected Data Principals and the Board receive initial notice without delay, with detailed information to the Board within seventy-two hours, subject to the Rule’s terms and commencement.


AI incident exercises should therefore test more than a conventional breach. Include accidental prompt disclosure, an over-permissioned connector, sensitive information reproduced in an output, a vendor outage, a poisoned knowledge source and an automated action taken without approval.


Put human accountability around consequential work


Not every AI output needs the same review. A first draft of an internal agenda is different from a credit decision, employment recommendation, medical communication or regulatory filing.


Classify workflows by impact. High-impact work needs qualified review, source evidence, an override route and a decision record. Human review is meaningful only when the reviewer has time, authority and relevant competence.


Practical governance tips


  • Publish an approved-tool list and a prohibited-data list.

  • Assign both a business owner and a control owner to every material use case.

  • Test with sanitised data before connecting production systems.

  • Keep prompt, source, output and approval evidence for high-impact workflows.

  • Re-test after material model, vendor or configuration changes.

  • Practise breach and harmful-output scenarios with named responders.

  • Set a retirement process for failed or unused AI systems.


Commercial governance plan


Stage

Timeline

Scope

Deliverables

Fee basis

Readiness assessment

2 weeks

Use-case, data-flow, policy and vendor review

Gap register, risk heatmap and priority plan

Bespoke after discovery

Governance design

3–4 weeks

Roles, approvals, controls and evidence standards

AI policy, use-case register, review matrix and templates

Bespoke

Control pilot

4–6 weeks

Apply governance to two live workflows

Test evidence, incident exercise and remediation plan

Bespoke

Assurance cycle

Quarterly

Metrics, exceptions, vendor changes and retraining

Governance report, updated register and action log

Bespoke retainer


This work supports operational readiness; it does not replace legal advice, a statutory audit or specialist cybersecurity testing.


About Parikshit Khanna


Parikshit Khanna is the founder of Digital Training Jet, an AI trainer and strategic consultant listed by Masters’ Union, and a TEDx speaker. His public work centres on practical AI adoption, prompt engineering and professional learning. Governance engagements should be coordinated with the client’s legal, privacy, risk and security specialists.


Build a governed AI adoption programme


To discuss an AI governance workshop, readiness assessment or controlled pilot, get in touch with Parikshit Khanna. Include your sector, team size, current tools and the workflows that handle personal or confidential data.


Frequently asked questions


Do the DPDP Rules ban the use of Generative AI?

No. The framework governs processing of digital personal data; it does not impose a general ban on Generative AI. Each workflow still needs an appropriate purpose, data controls and compliance analysis.

Are all DPDP provisions already in force?

No. The 2025 notifications use phased commencement. Check the official notification and obtain current legal advice for the provision relevant to your organisation.

Is masking personal data enough?

Not always. Context can re-identify a person, and a workflow may process confidential information that is not personal data. Use minimisation, access controls, contractual safeguards and purpose review together.

Who should own enterprise AI governance?

Ownership should be cross-functional. Business leaders own outcomes; technology teams manage systems; legal and privacy teams interpret obligations; security manages technical risk; and users remain responsible for following the operating process.


Sources



bottom of page