Can India’s DPDP framework keep up with the rise of autonomous AI?

DPDP Bill Charts a New Course for Corps in the Digital Age

Enterprises are moving from generative AI assistants that answer prompts to autonomous agents that retrieve data, call tools across systems and act with limited human oversight. The Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025 are technology-neutral, which is largely a strength. The harder question is operational: when an agent decides at runtime what data to fetch, combine or infer, can a Data Fiduciary still demonstrate purpose limitation, valid consent and accountability? The answer depends less on new law than on where controls are placed. A lifecycle view, such as the PERAI (Privacy Enhancing & Responsible AI) framework, organises those controls across five stages. 

1. Data Collection: Quantify Before Collecting 

Section 6 requires consent that is free, specific, informed and limited to personal data necessary for the stated purpose. Section 5 requires a notice describing that purpose. Agents strain this because a purpose fixed at collection may not anticipate what an agent later does with the data. Privacy threat modelling at intake, which simulates singling-out, linkage and inference attacks and produces a measurable exposure score, gives the fiduciary evidence of what is actually “necessary”. For Significant Data Fiduciaries, Section 10 mandates Data Protection Impact Assessments. An agentic DPIA, revisited as agent scope and tool access change, keeps the assessment a living record rather than a one-time document. 

2. Data-in-Use Protection: Minimise by Design 

The Act does not use the term “data minimisation”, but the necessity test in Section 6 and the erasure obligation in Section 8(7) imply it. Agents with broad, standing access to data work against both. Consent-based access control, where consent and purpose metadata travel with the dataset, lets policy be enforced at the point of use. Anonymisation, differential privacy for aggregate queries and synthetic data for development and testing reduce how much identifiable data an agent ever sees. Synthetic data is not private by default, so empirical leakage checks remain necessary. 

3. AI Assessment: Test Before Deployment 

Section 8(3) requires completeness, accuracy and consistency where personal data is used to make a decision affecting a Data Principal, and Section 8(5) requires reasonable security safeguards. Static test suites do not scale to agents that plan multi-step actions. Agentic red teaming, using autonomous adversarial agents to probe for prompt injection, cross-context leakage, bias and harmful output, produces quantified risk scores and attack libraries. These artefacts serve as audit evidence, and for Significant Data Fiduciaries they support the periodic audits Section 10 requires. 

4. AI Inference: Enforce at Runtime 

Most privacy failures in agentic systems occur at inference, when prompts and retrieved context carry live personal data. Runtime controls include prompt-level PII detection, redaction, tokenisation with secure detokenisation, and format-preserving encryption, so raw identifiers do not reach the model. A security gate can score prompts for jailbreak and injection patterns, and a safety layer can enforce refusal or redaction on outputs. Logging of these events supports breach detection and intimation under Section 8(6). It also supports the log-retention and monitoring expectations in the Rules’ security safeguards provisions. 

5. Agentic Systems: Govern the Ecosystem 

Section 8(1) makes the Data Fiduciary responsible for processing undertaken by a Data Processor on its behalf, and Section 8(2) requires a valid contract for any such engagement. An agent that invokes third-party tools through protocols such as MCP effectively creates dynamic processor relationships. Threats such as tool poisoning, rug pulls and cross-agent context injection sit outside traditional vendor review. Two guardrails address this: an MCP security layer that inspects tool descriptions and payloads, and a context boundary layer that limits what information propagates between agents. Over time, red-teaming results can feed a behavioural trust profile, so only agents meeting defined thresholds participate in sensitive workflows. 

Are current controls sufficient? 

The DPDP principles hold up. What does not hold up is reliance on static controls: one-time consent screens, annual assessments and contractual assurances. Autonomy makes purpose and data flow dynamic, so evidence must be dynamic too. Rights under Sections 11 to 14 illustrate this. A Data Principal’s request for access, correction or erasure is only answerable if the organisation can trace which agents touched which data, for what purpose, and where inferences were stored. 

Organisations should therefore build several capabilities into agentic systems from the outset: 

  • Purpose-bound, time-limited access rather than standing permissions 
  • Continuous risk quantification, not point-in-time assessment 
  • Runtime enforcement with tamper-evident audit trails 
  • Defined human review points for consequential decisions 
  • The ability to suspend or roll back an agent 
  • Clear ownership under the fiduciary’s accountability 

Regulatory guidance on inferred data, automated decision-making and processor status for AI tools would help the ecosystem. Until then, a lifecycle approach lets organisations demonstrate compliance as autonomy increases, rather than assert it. 

Authored by Abilash Soundararajan, Founder & CEO of PrivaSapien

Share on