NEWS ANALYSIS4 mins

DPDP Act and AI Overlap: Managing Financial Exposure for Children's Data Processing

Emerging regulations and the DPDP Act 2023 impose strict constraints on AI processing of children's data. BFSI finance leaders must evaluate their contingent liability and vendor TCO as scrutiny increases on automated systems interacting with minors.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

A recent analysis by LiveLaw highlights an emerging regulatory challenge for Indian policymakers regarding the intersection of artificial intelligence and children's digital rights. The report notes that current frameworks, including the Digital Personal Data Protection Act, 2023, primarily address static data collection rather than adaptive, relationship-simulating AI technologies. Consequently, there are growing calls to introduce specific design obligations for AI products used by minors to ensure safe interactions. Simultaneously, IT Rules amendments anticipated in 2026 will introduce labelling requirements for AI-generated content and faster takedown timelines. At the state level, Karnataka's draft Responsible Social Media and Digital Safety Bill is currently before the state legislature's law department for review.

Does The DPDP Act Apply Here

Under Section 3 of the Digital Personal Data Protection Act, 2023, the law applies to the processing of digital personal data within the territory of India. It also covers processing outside India connected to offering goods or services to Data Principals in India. For a Chief Financial Officer at a bank or NBFC, this applicability extends directly to retail banking operations, specifically junior savings accounts, student education loans, and the deployment of AI-driven customer support channels. If a minor interacts with a financial institution's AI chatbot, the data processed falls squarely within the scope of the Act. The distinction between general corporate IP and personal data is critical here, as conversational AI ingests user inputs that qualify as personal data under the statute.

Legal Implications Under DPDP

Section 9 of the Act establishes strict rules for processing children's data. Financial institutions must obtain verifiable parental consent before processing such data, utilizing the specific mechanics detailed in the DPDP Rules, 2025. While consent is the primary basis for processing, except where Section 7 legitimate uses apply, the Act imposes hard prohibitions regardless of consent. Specifically, a Data Fiduciary cannot undertake tracking, behavioral monitoring, or targeted advertising directed at children. For adaptive AI systems, this creates a severe compliance hurdle. If a bank's conversational AI uses a child's interaction history to personalize financial product recommendations, it risks violating the behavioral monitoring prohibition. Furthermore, the Rules, 2025 require a detailed report to the Data Protection Board of India within 72 hours in the event of a personal data breach, demanding rapid oversight of any AI processors utilized.

Could This Happen To You

As a CFO managing EBITDA impacts, deploying third-party AI chatbots across your banking platforms without reviewing their data handling models creates immediate contingent liability. If an AI processor inadvertently tracks a minor's financial inquiries to optimize responses, the resultant Section 9 violation carries a penalty ceiling of up to INR 200 crore. During an audit, the DPBI would demand proof of verifiable parental consent records and the technical safeguards preventing behavioral monitoring. Failure to produce this evidence not only triggers regulatory fines but also threatens to inflate your cyber insurance premium and increase external audit fees. Managing these obligations piecemeal across different AI vendors inflates the Total Cost of Ownership and complicates compliance provisioning.

What Companies Should Do In The Next 30 Days

1. Direct the procurement team to initiate a vendor consolidation review of all AI processors and chatbot providers currently deployed across retail banking channels.

2. Require the Chief Compliance Officer to map existing junior account onboarding flows against the verifiable parental consent mechanics prescribed in the DPDP Rules, 2025.

3. Quantify the contingent liability exposure related to AI data processing to ensure appropriate provisioning in the upcoming quarterly budget.

4. Request a formal review of your current cyber insurance policy to determine how a DPBI penalty for Section 9 violations would impact future coverage and premiums.

What To Watch

Regulatory scrutiny on AI and children's data is accelerating at both the state and federal levels. Keep monitoring the progression of Karnataka's draft digital safety bill and the MeitY IT Rules amendments moving through 2026. However, the most critical metric for finance leaders is the overarching DPDP compliance timeline. Exactly 275 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess your institution's current penalty exposure and evaluate audit-readiness without committing to a multi-year GRC overhaul, finance and compliance teams can run a preliminary evaluation at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act restrict our bank's AI chatbots from interacting with minors?

Under Section 9 of the DPDP Act, financial institutions must obtain verifiable parental consent before processing a child's data. The Act also explicitly prohibits the tracking or behavioral monitoring of minors, which heavily restricts how adaptive AI systems can operate during such interactions.

What is the financial exposure for violating children's data provisions under the DPDP Act?

Non-compliance with the obligations related to children under Section 9 carries a maximum penalty ceiling of INR 200 crore per instance. CFOs must treat this as a significant contingent liability when provisioning for regulatory risks and budgeting for compliance.

Do we need verifiable consent for every single AI interaction with a customer?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. However, when processing the digital personal data of minors, verifiable parental consent is explicitly required, and the DPDP Rules, 2025 mandate specific technical mechanics to achieve and record this.

How does an AI vendor data leak affect our compliance obligations?

The DPDP Rules, 2025 require the Data Fiduciary to notify affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours. Your institution remains liable for the breach, which makes strict oversight of your AI vendors critical to controlling your cyber insurance premiums.

When do we need to finalize our vendor consolidation and compliance budgets?

Budgeting and implementation must be finalized quickly, as exactly 275 days remain until the DPDP hard compliance deadline of 13 May 2027. Consolidating vendors and securing audit-ready workflows now will help control your Total Cost of Ownership.