Sovereignty & Data Residency
DPDP Obligations for AI Agents: A Checklist
· 11 minute read
Agents process personal data in ways a form never did. This is the checklist we use with departmental DPOs before a pilot is allowed to touch production records.
A web form collects named fields. An agent collects a goal, then goes looking. That is why DPOs cannot reuse a 2011 SPDI checklist and call it done. Use this against every agent workflow, including the unofficial ones officers already run on public chatbots with official PDFs.
The checklist is ordered the way a file should be built. Do not skip to the security annex because it feels more technical. The first failures we see are purpose and role, not encryption.
Print it. Mark red, amber, green. A single red on purpose, children, or undeclared transfer is a stop, not a score of 9 out of 10.
1. Before anyone connects a database
- Name the Data Fiduciary in writing. Usually the department, board or university, not the vendor and not the SI.
- Name every joint fiduciary if two entities set purpose together. Shared resident desks and exam systems are the usual suspects.
- Name every processor: platform, SI, cloud, model host, annotation vendor, evaluation lab, hosted OCR, hosted speech, hosted guardrail.
- Write the specified purpose in one sentence a citizen would understand. If you need a paragraph, you have more than one purpose.
- Pick the lawful basis: consent, or a named limb of Section 7. Do not write both and hope.
- List personal data classes, including free text, voice, images, embeddings, plan traces and reviewer notes.
- Mark children's data. Verifiable parental consent is a different project, not a toggle.
- Mark payment, health, exam and telecom classes that have sector overlays on top of DPDP.
If this page cannot be filled in a sitting, the use case is not scoped. Scope it before you book GPUs.
2. Notice and consent
Section 5 notice has to say who you are, what you take, why, and how the person complains. An agent that later starts reading family-member fields because it seemed useful has left the notice. Retrain the workflow or issue a new notice. Do not hide new purposes inside a model update.
Consent, where used, must be free, specific, informed, unconditional and unambiguous, with a yes that is as easy as a no. Pre-ticked boxes and bundled app permissions fail that test. For State benefits, you may have a Section 7 path. Document it. Do not pretend it is consent. Citizens can tell the difference, and so can the Board.
Withdrawal has to stop the machine. That includes the queue, the embedding index, the reviewer inbox and any scheduled tool call. A ticket that says withdrawn while the agent still emails is a defect, not a process nuance.
- Every workflow has a purpose tag the runtime can enforce.
- Every new tool inherits the parent purpose or is blocked.
- The public notice and the machine tag use the same words.
- There is a stop hook that cancels in-flight work, not only future work.
3. Processor and security
The fiduciary stays accountable for processing done on its behalf. That sentence is why a two-page NDA is not a DPA. The contract has to limit the processor to documented instructions and has to survive a change of account manager.
- A written contract that limits the processor to your instructions, with change control for new tools and new data classes.
- A ban on training foundation models, and on evaluating shared models, on your prompts, documents or tool results.
- Encryption, access control and an audit log the fiduciary can export without the vendor's portal.
- Sub-processor disclosure, including model APIs, OCR, speech, guardrails and overseas support, with countries.
- A breach clock that matches DPDP Rules and any CERT-In six-hour duty that also applies.
- A support-access rule: time-bound, ticketed, recorded, no standing god user.
4. Rights and retention
Once operational provisions commence, Data Principals can seek access, correction, erasure and nomination. Erasure is the hard one for agents. A row in a database can be deleted. A vector, a cached plan and a fine-tune cannot, unless you designed for it.
| Store | What access looks like | What erasure looks like |
|---|---|---|
| System of record | The ticket or file the officer already knows | Ordinary application delete plus legal-hold rules |
| Chunk store | The passages retrieved for that person | Delete chunks and rebuild only what remains |
| Vector index | Vectors keyed to that document or person | Delete vectors; do not only delete the PDF |
| Plan traces | The agent's working memory for that case | Delete the trace and any screenshot copies |
| Fine-tune / adapter | Usually cannot isolate one person | Do not put unique personal data into the train set, or be ready to retrain |
| Backups | Restore test, not a search UI | Delete on the next cycle; certificate the date |
If you cannot erase, do not collect, or isolate that workflow from personal data. This is the conversation to have before the pilot, not after the first rights request in 2027.
5. If you may be a Significant Data Fiduciary
The Central Government can designate Significant Data Fiduciaries using volume, sensitivity and impact tests in Section 10. An SDF faces extra duties under Rule 13, including a Data Protection Officer, independent audit and a Data Protection Impact Assessment on a twelve-month cycle.
Large citizen-facing agent programmes should assume they will be looked at, even before a designation letter arrives. Build the DPIA now. It is the same document a careful DPO would write anyway: purpose, data classes, risks, transfers, children, and residual risk the secretary accepts.
6. Children and other special cases
Processing of children's data needs verifiable parental consent except where the government provides otherwise. School systems, scholarship portals, sports hostels and some university first-year workflows will see minors. A checkbox that says I am 18 is not verifiable parental consent.
Dark patterns that make withdrawal harder than consent will not survive the Board or a newspaper. Neither will an agent that upsells a paid service inside a statutory benefit flow.
7. What to attach to the note
A one-page role map, a data-class inventory, the lawful-basis table, the processor list, and the erasure method for each store. Add the egress allow-list from staging. That packet is more useful than a 40-slide compliance deck. It is also what an auditor will ask for first.
How to run the checklist as a gate
A checklist that everyone marks green is a poster. A checklist that can stop a go-live is a control. Give the DPO a written veto on production personal data. Give the CISO a written veto on undeclared egress. Give the application owner a written duty to keep the inventory true. Three signatures. No signature, no connection.
Re-run the checklist when a tool is added, when a model is swapped, when a sub-processor changes, and when a pilot becomes a programme. The first run is the cheapest. The skipped run is the one that appears in the incident file.
Red, amber, green — and what each means
- Red: stop. Purpose missing, children unmarked, undeclared transfer, no processor contract, no erasure method for a store that holds personal data.
- Amber: condition. Artefact exists but is incomplete — a DPA without subprocessors, a notice that does not match the tool list. Fix before go-live or time-box the fix in the note.
- Green: artefact seen by the DPO, dated, filed. Not green because the vendor said so in a meeting.
The evidence pack you will wish you had in May 2027
When operational duties commence, you will be asked to show what you already decided. Keep a folder per workflow: role map, basis table, notice text, processor list, egress allow-list, erasure methods, last checklist with signatures. That folder is cheaper than a consultancy in April 2027. It is also how you prove you were not asleep while the Board already existed.
Name the folder owner. Folders without owners become shared drives. Shared drives become archaeology.
Turn the checklist into a standing operating procedure
A checklist used once is a workshop. A checklist used on every change is a control. Write an SOP of two pages. Who fills the form. Who signs red, amber, green. How long amber may live. What happens on red. Where the signed form is filed. Who re-runs it when a tool is added.
Train three people to fill it, not one. DPOs go on leave. A single-person control is an absence waiting to happen. Pair the DPO with the application owner so the form is not a legal monologue.
Publish a monthly list of workflows and their last colour. Leadership that never sees red will assume everything is fine. A visible red on unofficial public-chatbot use is more useful than a green on a sandbox nobody runs.
- No production personal data on amber older than fourteen days without a secretary-level exception.
- No new connector without a fresh form.
- No vendor release that adds a tool without a fresh form.
- Keep the 2027 evidence pack as the same folder, not a separate archaeology project.
Objections you will hear — and what to do with them
Teams will say May 2027 is far. The Board exists now. Unofficial public chatbots exist now. Sector circulars exist now. Far is not a finding.
Vendors will offer a compliance pack that marks every row green. Green without your DPO's signature is vendor marketing. Use their pack as input. Do not use it as the form.
Application owners will say they cannot inventory unofficial use. They can ask. They can look at DNS. They can look at expense claims for AI subscriptions. Perfect inventory is not required. Honest effort is.
Someone will want a 90-page DPIA instead of the one-page packet. Write the packet first. The DPIA can wait a cycle. A 90-page document that nobody signed does not beat a one-page form that stopped a go-live.
Leadership will override a red because a launch date is public. Public dates are not lawful bases. If they override, take the exception in writing, with a named officer and an end date. Invisible overrides kill gates.
Use this checklist against Prcept AI. If we cannot populate a row, the row is not green. Green is the only colour that connects to production.
Questions this usually raises
- Do we wait until May 2027 to start this checklist?
- No. The Board exists now. Sector rules already apply. Standing up roles, inventories and processor contracts in 2026 is how you avoid a scramble in 2027.
- Are government departments exempt?
- The State has specific legitimate uses under Section 7. That is not a general exemption from security, purpose limitation, or processor control.
- Does a sandbox with production data count as a pilot exception?
- No. If the data is personal, the duties attach. Use synthetic or properly anonymised sets until the checklist is green.
- What is the first artefact an auditor will ask for?
- The role map, the data-class inventory, the lawful-basis table, the processor list, and the erasure method for each store. Not the compliance deck.