DPDP Act ChatGPT compliance: what it means for AI tools
7 min read · Reference · Updated October 3, 2026 · Not legal advice
Yes, the DPDP Act applies to ChatGPT and every other AI tool, the moment an employee enters the personal data of Indian residents. The Act is technology-neutral, so the company is processing that data and disclosing it to a third party whichever tool is used. NexusNest helps support the technical safeguards the DPDP Rules, 2025 describe, including redaction before the prompt reaches the AI provider.
India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 made under it put real obligations on every company that handles that data. Neither singles out AI tools by name, but the obligations apply to ChatGPT, Claude, Gemini and any other third-party service. For what each AI provider says about its own data handling, see ChatGPT, Claude, Gemini and Copilot data privacy.
This article is a plain-English orientation, not legal advice. Get qualified Indian counsel before relying on it for compliance decisions.
Where this sits in the timeline
The DPDP Rules, 2025 were notified in November 2025 with an 18-month phase-in. The operative provisions, including the security-safeguard requirements in Rule 6, take effect around May 2027. Penalties for failing to take reasonable security safeguards under the Act run up to ₹250 crore per instance. Companies that wait until the deadline to start building controls will be starting late.
Rule 6: what it asks for, mapped to AI usage
Rule 6 of the DPDP Rules, 2025 sets out the reasonable security safeguards a Data Fiduciary must take. Three of its clauses map directly onto what a governance layer for employee AI usage does:
- Rule 6(a) calls for “masking or the use of a derived virtual token” to protect personal data. PromptWall is that control for AI usage - it replaces personal data with a placeholder before the prompt reaches the AI provider.
- Rule 6(c) calls for “logs, monitoring and review to ensure visibility” into how personal data is processed. NetLens is that visibility layer - it shows how AI is being used across the company, on redacted text only, without reading anyone's raw prompts.
- Rule 6(e) calls for “logs and retention of such data for one year” to support monitoring and breach investigation. An exportable audit trail is that record - which employee, which tool, which categories, when.
Why AI usage falls under this at all
The Act applies to any digital personal data processed for any lawful purpose. The moment an employee pastes a customer phone number, email, PAN, or financial detail into an AI tool, a company is processing that data, disclosing it to a third party (the AI provider and any sub-processors), and - if the provider is non-Indian - transferring it outside India. All three trigger duties under the Act, and the consent the person originally gave almost certainly didn't list “may be pasted into ChatGPT to draft a support reply”.
What this does not require
- Banning AI tools. The Act doesn't care what tool is used, only what data flows into it.
- Self-hosting everything. Cloud-hosted AI is fine as long as the personal data going to it is minimised - which redaction handles.
- India-only data residency for all data. The Act allows cross-border transfers; it imposes accountability, not a blanket localisation requirement.
The short version
If a regulator ever asks how a company satisfies Rule 6 for AI tool usage, “we have a policy that asks employees not to” isn't a technical control. Redaction before the prompt reaches the AI, visibility into how AI is used, and an AI audit trail are.
Building DPDP-ready AI governance? NexusNest helps support the technical safeguards organisations need for employee AI usage. Overall compliance also depends on organisational, legal and operational measures. See how it maps to Rule 6 →
Frequently asked questions
Does the DPDP Act apply to ChatGPT?
The DPDP Act is technology-neutral. If an employee enters the personal data of Indian residents into ChatGPT, the company is processing that data and disclosing it to a third party, so the obligations apply to the company whichever tool is used.
What does DPDP Rule 6 ask for?
Rule 6 sets out the reasonable security safeguards a Data Fiduciary must take. It includes “masking or the use of a derived virtual token”, logs, monitoring and review to ensure visibility, and logs and retention for one year. For AI tools, redaction before the prompt is sent, visibility into usage and an exportable audit trail map to these clauses.
When does Rule 6 take effect?
The DPDP Rules 2025 were notified in November 2025 with an 18-month phase-in, which puts the security safeguards in Rule 6 at around May 2027. Penalties for failing to take reasonable security safeguards run up to 250 crore rupees.
Do we have to ban ChatGPT to follow the DPDP Act?
No. The Act cares about what personal data flows into a tool, not which tool is used. Redacting personal data before it reaches the AI provider lets people keep using AI.
Does NexusNest make a company DPDP compliant?
No tool does that on its own. NexusNest helps support the technical safeguards in Rule 6 for employee AI usage. Overall compliance also depends on organisational, legal and operational measures.
Sources
- MeitY - Digital Personal Data Protection Act, 2023 (official page)
- DPDP Act 2023 - full text (PDF)
- Government of India - e-Gazette publication (search "DPDP Rules 2025")
- IAPP - overview of the DPDP Act
This article paraphrases the Act and Rules for an operator audience and is not legal advice. Rule numbers reference the DPDP Rules, 2025 as published; the Board's subordinate guidance may add detail or revise specifics before the Rules take effect.Overall compliance also depends on organisational, legal and operational measures.
Related
Product
- DPDP and workplace AI How NexusNest maps to Rule 6 of the DPDP Rules 2025.
- PromptWall Redacts sensitive data before it reaches the AI tool.
- NetLens How AI is really used, on redacted text only.
- Pricing Plans for every team size.
Keep reading
- ChatGPT, Claude, Gemini and Copilot data privacy What each provider says about training and retention.
- Stop employees pasting data into ChatGPT A playbook that does not block productivity.
- Redact sensitive data before ChatGPT and Claude What redaction software works with AI tools.