News Analysis • 4 min read
Proofpoint Opens AI Security Hub: DPDP Act Defensibility for Enterprise AI Adoption
Proofpoint's new AI Security Hub in Hyderabad targets enterprise data sovereignty and DPDP Act compliance. General Counsels in the BFSI sector must ensure stringent processor agreements and 72-hour breach response workflows as AI adoption accelerates.
Last updated:
What happened
Proofpoint is establishing a new AI Security Hub in Hyderabad to assist Indian enterprises in safely adopting artificial intelligence while complying with the Digital Personal Data Protection Act, 2023. According to Whalesbook, the cybersecurity firm has seen its business in India triple over the past 12 months. This Center of Excellence will focus on securing corporate data for highly regulated sectors, including banking, defence, and public sector companies, as they integrate AI into their operational workflows. The facility will also integrate technologies from Proofpoint's recent acquisitions, such as Acuvity, to address data sovereignty and privacy requirements.
Does the DPDP Act apply here
The adoption of AI tools by banking and financial services firms directly implicates the DPDP Act when personal data is processed. While enterprise AI models often handle corporate intellectual property, the integration of customer profiles, KYC records, and financial transaction histories constitutes processing of digital personal data. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. General Counsels must separate corporate data ingestion from personal data processing, as the latter requires distinct technical controls and processor oversight.
Legal implications under DPDP
Section 8 of the Act imposes an unconditional obligation on Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. When banks use AI platforms, they must ensure these safeguards extend through their vendor ecosystem via robust data processor agreements. Under the DPDP Rules, 2025, any breach requires intimation to affected Data Principals without delay and a detailed report to the Data Protection Board of India within 72 hours. Furthermore, while Section 16 permits cross-border transfers unless the Central Government notifies a negative list of restricted countries, BFSI entities must still navigate overlapping RBI mandates alongside DPDP obligations. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning AI models cannot simply ingest customer data without an audit-ready legal basis.
Could this happen to you
For a Chief Compliance Officer or General Counsel at a bank, unauthorized personal data exposure through a third-party AI tool is a critical regulatory risk. If an employee inputs customer data into an unvetted AI prompt, the bank remains fully liable under the DPDP Act. The Data Protection Board of India would immediately demand evidence of technical safeguards, processor oversight logs, and breach response workflows. Without a defensible audit trail and strict limitation of liability and indemnity clauses in your vendor contracts, the financial exposure could reach the penalty ceiling of up to 250 crore rupees per breach. Defensibility hinges on proving you had technical controls and processor agreements mapped directly to the notified rules.
What companies should do in the next 30 days
1. Legal teams must conduct a privileged review of all enterprise AI tools to identify personal data ingestion flows.
2. Update data processor agreements to include clear indemnities, limitation of liability carve-outs for DPDP fines, and mandatory cooperation for 72-hour breach reporting.
3. Implement technical guardrails to prevent personal data from entering open AI models, ensuring compliance with Section 8 security safeguard requirements.
4. Establish a unified breach intimation workflow that aligns your internal IT response with outside counsel review to meet DPDP Rules 2025 timelines.
What to watch
Regulated entities must monitor the establishment of the Data Protection Board of India under Section 18, which will dictate regulator engagement protocols and enforcement priorities. Watch for further guidance under the DPDP Rules, 2025 regarding acceptable technical standards for reasonable security safeguards in automated processing environments. Financial institutions must balance innovation with strict regulatory defensibility to avoid severe penalties. Exactly 266 days remain until the 13 May 2027 hard deadline for full compliance. General Counsels can evaluate their current vendor agreements and AI risk exposure through a confidential assessment at freescan.complydp.com.
Sources
Frequently asked questions
How does the DPDP Act govern enterprise AI adoption in the banking sector?
The DPDP Act requires strict adherence to purpose limitation and reasonable security safeguards under Section 8 when processing personal data. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning banks must have an audit-ready legal basis before feeding customer data into AI models.
What are the breach notification timelines if an AI vendor exposes personal data?
Under the DPDP Rules, 2025, Data Fiduciaries must intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board of India within 72 hours. Banks must ensure processor contracts mandate immediate vendor cooperation to meet these strict regulator engagement timelines.
Are cross-border data transfers permitted for cloud-based AI tools under the DPDP Act?
Yes, cross-border transfers of personal data are generally permitted unless the Central Government restricts transfers to a notified negative list of countries under Section 16. However, banking entities must concurrently satisfy RBI data localization mandates alongside their DPDP Act obligations.
How should General Counsels manage vendor liability for AI data processing?
Legal teams must negotiate robust data processor agreements that include clear indemnities and carve-outs in the limitation of liability clauses for DPDP penalties. If a vendor breach occurs, the bank remains liable as the Data Fiduciary and could face statutory penalties of up to 250 crore rupees.
What technical evidence will the Data Protection Board of India require during an audit?
The DPBI will demand comprehensive logs of data processor oversight, verifiable consent records, and evidence of technical safeguards preventing unauthorized access. Demonstrating defensibility requires mapping your AI deployment controls directly to the standards established in the notified rules.
ComplyDP