Checklists • 4 min read
DPDP AI and LLM Vendor Compliance Checklist for Legal Counsel
An actionable DPDP compliance checklist for General Counsel evaluating AI and LLM vendors, ensuring contract defensibility, retention limits, and breach readiness before enterprise deals stall.
Last updated:
When To Use This Checklist
Enterprise procurement teams are heavily scrutinising how B2B SaaS vendors handle data in AI pipelines. If you are a General Counsel or Legal Head approving an LLM tool that processes digital personal data, this checklist ensures contract defensibility. With exactly 280 days remaining until the DPDP hard compliance deadline of 13 May 2027, unvetted AI vendors will stall your enterprise deals.
Scope And Applicability
The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India, and processing outside India connected to offering goods or services to Data Principals in India. Before initiating procurement, Legal must confirm the mapped data inventory and the legal basis for processing. Consent is the primary basis for processing, except where Section 7 legitimate uses apply.
Step 1 Execute Section 8 Processor Contracts
Owner Legal. Action Execute a valid contract under Section 8(2) of the Act to ensure the vendor acts solely as a Data Processor. The contract must restrict the vendor from using personal data beyond your explicit instructions. Evidence Signed Data Processor Agreement outlining a clear limitation of liability and indemnities.
Step 2 Restrict Model Training
Owner Legal and Product. Action Contractually prohibit the vendor from using your digital personal data to train their base models or improve their services. Evidence Explicit opt-out clauses in the vendor agreement and API configuration records proving zero data retention for training purposes.
Step 3 Configure Retention Limits
Owner IT. Action Configure the LLM API to auto-delete personal data immediately upon session end. The vendor must provide mechanisms to securely erase data if a Data Principal withdraws consent. Evidence Exportable API configuration logs and published vendor data deletion guarantees.
Step 4 Establish Audit Trails
Owner Product. Action Implement system logging to track exactly what personal data is sent to the LLM processor. Evidence Exportable query logs linked to specific Data Principals to prove data minimisation principles are actively enforced.
DPBI Breach Intimation Requirements
Under Section 8, the Data Fiduciary remains fully liable for a vendor data breach, carrying penalties up to 250 crore rupees. The Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours. Your AI vendor contract must legally mandate incident notification to your team within 24 hours to ensure regulator defensibility.
Effort And Budget Reality
Manually reviewing AI vendor terms and reconciling API data flows takes 15 to 20 hours of outside counsel and internal engineering time per tool. A credible compliance platform automates vendor oversight, tracks consent records, and maintains exportable audit trails continuously. Transitioning from manual spreadsheets to automated mapping drastically reduces enterprise legal review burden.
Documentation Pack Updates
Incorporating an LLM requires updating your Record of Processing Activities to reflect the new data flows and subprocessors. You must also update your itemised notices under the Rules, 2025 to inform Data Principals about the AI processor. Incident response policies must be revised to include third-party LLM vendors in the escalation matrix.
Red Flags For Enterprise Audits
You are not ready for an enterprise audit if your AI vendor refuses limitation of liability clauses for data breaches. Other severe red flags include APIs lacking zero-retention settings and an inability to trace which specific Data Principal data was sent in an LLM prompt. These gaps destroy legal defensibility and invite regulatory scrutiny.
Next Steps
Stop guessing your AI vendor exposure and risking enterprise deals in procurement limbo. Run a baseline assessment at freescan.complydp.com to identify vendor contract gaps before your next audit.
Sources
Frequently asked questions
Does the DPDP Act restrict us from using AI tools to process digital personal data?
The Digital Personal Data Protection Act, 2023 does not restrict AI usage, but Section 8 requires a valid contract with any Data Processor. You must ensure the AI vendor processes data only on your instructions and provides sufficient breach defensibility.
What is the legal basis for sending user data to a third-party LLM?
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Your itemised notices under the Rules, 2025 must clearly disclose if third-party AI processors are used to handle digital personal data.
How quickly must we report if our AI vendor suffers a data breach?
Under the Rules, 2025, you must provide intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours. Your vendor contracts must guarantee rapid notification to your legal team to meet this stringent deadline.
Can an AI vendor process our data on servers located outside India?
Yes, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. You must ensure the vendor contract strictly enforces your DPDP obligations regardless of where the servers physically sit.
Who is liable if the AI processor misuses the data?
Under Section 8(1) of the Act, the Data Fiduciary remains fully responsible for complying with the law in respect of any processing undertaken by a Data Processor. This is why strong indemnities and limitation of liability clauses in vendor contracts are critical.
ComplyDP