The Practice |
An organisation deploys an AI-powered chatbot for customer support. Every customer interaction — including names, account numbers, complaint details, and in some instances financial or health-related information — is logged and retained by the AI platform vendor. The organisation's privacy notice states that interactions are recorded for quality purposes but does not reference AI, identify the vendor, or specify retention duration.
Questions Raised for Compliance Review |
1. Is the current privacy notice adequate to support the lawful processing of customer data through the AI chatbot under DPDP?
2. What risks arise from data logging and retention by a third-party AI platform vendor?
3. What disclosures and contractual arrangements are required to make this deployment DPDP-compliant?
Is This Permitted Under DPDP? |
Not compliant as currently structured. The customers engaging with the chatbot are providing personal data — and in many cases sensitive personal data — in the reasonable expectation that it is being handled by the organisation. The involvement of a third-party AI platform as a data processor, the retention of conversation logs, and the potential use of that data for model improvement are material facts that must be disclosed. The current privacy notice does not meet DPDP's transparency requirements.
Where the Breach Risks Sit |
- Inadequate disclosure — Stating that interactions are 'recorded for quality purposes' does not constitute informed consent for AI processing. DPDP requires that consent be specific and that the data principal understand the nature of the processing — including the involvement of an AI system and the identity of the third-party vendor operating it.
- Unreviewed processor relationship — The AI chatbot vendor is a data processor under DPDP. If a formal Data Processing Agreement has not been executed, or if the existing agreement does not address DPDP-specific obligations — including breach notification timelines, data residency, and restrictions on model training — the processor relationship is ungoverned.
- Sensitive data in unstructured logs — Customers often disclose sensitive information during support interactions — financial details, health conditions, identity documents — without realising these are being retained. Unstructured conversation logs containing sensitive data that are held by a third-party vendor represent a significant and ongoing exposure.
- Model training on customer conversations — Many AI chatbot vendors retain conversation data to improve their models. If the vendor's terms permit this, the organisation's customers are effectively contributing personal data to a commercial AI training exercise without their knowledge or consent.
The Ideal Compliant Approach |
- Update the privacy notice comprehensively. The notice must explicitly state that an AI-powered chatbot is used for customer support, name the platform vendor, describe the categories of data logged, specify the retention period, and confirm whether data is used for model training and on what basis.
- Execute a DPDP-compliant Data Processing Agreement. The agreement with the chatbot vendor must address: data residency, retention and deletion timelines, restrictions on using customer data for model training, breach notification within 72 hours, and the vendor's security standards.
- Implement a data minimisation configuration. Configure the chatbot to avoid logging or retaining sensitive personal data beyond the session unless operationally necessary. Where retention is required, implement automatic deletion at the defined retention threshold.
- Provide an opt-out for AI interaction. Customers who prefer not to interact with an AI system should have a clear pathway to reach a human agent. This is both a transparency best practice and a meaningful consent mechanism.
DPDP Risk Summary |
| Element | Status | Recommended Action |
|---|---|---|
| Privacy notice omits AI and vendor disclosure | ✗ Non-compliant under DPDP | Update notice to name AI, vendor, purpose, and retention period |
| No DPA with chatbot vendor | ✗ Processor relationship ungoverned | Execute DPDP-compliant DPA before next deployment cycle |
| Sensitive data retained in conversation logs | ✗ High exposure | Configure data minimisation; restrict retention of sensitive fields |
| Vendor model training on customer data | ⚠ Requires explicit consent or opt-out | Review vendor terms; negotiate model training restriction |
| No opt-out for AI interaction | ⚠ Transparency gap | Implement clear pathway to human agent for all customers |