What DPDP Act (India) means in practice
The Digital Personal Data Protection Act 2023 is India's first comprehensive data-protection law. It establishes consent as the default lawful basis for processing personal data of Indian data principals, treats health and financial data as a special category requiring explicit consent and stricter handling, mandates breach notification, and provides for a Data Protection Board with enforcement teeth. For AI systems the practical implications mirror GDPR: model training requires lawful basis, cross-border processing requires consent or an exception, and the sovereign-deployment pattern (data and model under the regulated entity's exclusive control) is the cleanest path to compliance for regulated workloads.
Related terms
GDPR →
The EU's General Data Protection Regulation — sets the rules for processing personal data of EU residents, with significant implications for AI systems that touch that data.
RBI Master Direction on IT Governance →
The Reserve Bank of India's master directive on IT governance for regulated entities — specifies that AI/ML model lifecycle artefacts must be hosted under the regulated entity's exclusive control.
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.