NEWS ANALYSIS4 mins

Intense Technologies Launches AI-Driven DPDP Governance Platform: Legal and Defensibility Implications for BFSI

Intense Technologies has introduced a DPDPA Governance Platform embedded with LLMs, aiming to expand beyond its BFSI base into broader B2C markets. For General Counsels, this highlights the urgent need to review vendor indemnities, legacy system integrations, and liability allocations under the strict timelines of the DPDP Rules, 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

Intense Technologies reported its Q1 FY27 financial results, as covered by Big News Network, highlighting the launch of a market-ready DPDPA Governance Platform. Built upon their existing customer communications infrastructure, the company is embedding Large Language Models across its platforms to enhance contextual capabilities. This strategic shift allows the vendor to expand beyond its traditional Banking, Financial Services, and Insurance sector clients to target organisations across all B2C industries facing new regulatory requirements.

Does the DPDP Act apply here?

The implementation of vendor compliance technology directly implicates the Digital Personal Data Protection Act, 2023. The Act governs digital personal data processed within India, as well as processing outside India if it is connected to offering goods or services to Data Principals in India. Under Section 4, a person may process personal data only in accordance with the Act and for a lawful purpose, where consent is the primary basis for processing, except where Section 7 legitimate uses apply. For a General Counsel evaluating these platforms, the core concern is that the enterprise remains the Data Fiduciary, holding ultimate liability for the processing activities executed by the vendor platform.

Legal implications under DPDP

Procuring an AI-driven governance tool requires strict alignment with the DPDP Rules, 2025. The Rules mandate verifiable consent mechanisms and itemised notices, which must remain transparent even when managed by an automated Large Language Model. Furthermore, BFSI entities frequently meet the criteria under Section 10 for designation as a Significant Data Fiduciary, determined by the volume and risk of personal data processed.

This designation mandates the appointment of an India-based Data Protection Officer and imposes heavier audit obligations. If the compliance platform suffers an incident or misroutes data, the Rules, 2025 enforce a strict timeline. The Data Fiduciary must provide intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours.

Could this happen to you

As a legal leader managing outside counsel spend and regulator engagement, deploying untested AI governance tools over legacy core banking systems introduces substantial risk. If a vendor platform fails to synchronise consent withdrawals with your primary databases, you risk processing data without a lawful basis. During an inquiry, the Data Protection Board of India will demand immutable logs proving compliance.

If those logs are contradictory or hallucinatory due to underlying AI errors, the enterprise faces severe defensibility challenges. The penalty ceilings under the Act are substantial, meaning poor limitation of liability clauses in your vendor contracts could leave your balance sheet fully exposed to regulatory fines.

What companies should do in the next 30 days

1. The General Counsel must initiate a privileged review of all vendor indemnity clauses to ensure liability is clearly allocated for automated compliance failures.

2. The legal and technology teams must map how legacy BFSI infrastructure will integrate with new consent management overlays to prevent isolated data silos.

3. Conduct a tabletop breach simulation with your compliance vendor to verify that your combined teams can produce the required DPBI notification artifacts within the strict 72-hour window.

What to watch

The market will likely see more communications vendors pivoting into statutory privacy governance to capture enterprise budgets. Legal teams should watch how the Data Protection Board treats automated consent processing during early enforcement actions. There are exactly 272 days remaining until the DPDP hard compliance deadline of 13 May 2027. Ensure your vendor selection and integration processes are defensively structured now. To assess your current operational readiness and vendor risk, evaluate your exposure at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act apply to BFSI legacy systems?

The Act governs all digital personal data processing within India. Legacy banking systems must be able to respect and operationalise consent signals, meaning any external governance layer must flawlessly sync with old infrastructure to maintain a lawful basis for processing.

Are we liable if our compliance vendor's AI makes an error?

Yes. As the Data Fiduciary, your enterprise holds ultimate statutory liability for violations caused by Data Processors. General Counsels must negotiate strict limitation of liability and indemnity clauses to protect the balance sheet against vendor-induced failures.

What are the DPDP breach reporting requirements if a vendor fails?

Under the DPDP Rules, 2025, if a breach occurs, the Data Fiduciary must provide intimation to affected Data Principals without delay. Additionally, a detailed report must be submitted to the Data Protection Board within 72 hours.

How does a company become a Significant Data Fiduciary?

Under Section 10 of the Act, the Central Government designates entities as Significant Data Fiduciaries based on factors such as the volume and risk of the personal data processed. This status requires appointing a resident Data Protection Officer and maintaining strict compliance audits.

Is consent required for every data processing activity under DPDP?

No. Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Legitimate uses include scenarios like medical emergencies, employment purposes, or complying with a legal obligation.