Skip to content

DPDP + AI Agents: Who's Liable When the Agent Acts?

our AI agent has no legal personality. Under the DPDP Act — now live and phasing in to May 2027 — liability tracks to the entity that set its purpose. There is no 'the agent did it' defence

Siddhesh Joglekar

· 4 min read

Blog image

This was a question on one Senior management class I took this past weekend on AI agents: when your AI agent reads a customer's personal data, decides something, and acts on it — and it gets that wrong — who does the regulator come for? The agent has no bank account, no board, and no legal personality. So the honest answer, under India's data-protection law, is uncomfortable and unambiguous. **You.** The entity that decided what the agent was for. The Digital Personal Data Protection Act does not let the autonomy of a tool dilute the accountability of its deployer, and as of FY27 that law is no longer a draft you can watch from a distance — it is live, phasing in, and pointed at you.

Why the agent is never the liable party

The Act is deliberately technology-neutral. It does not define "AI agent," "algorithm," "automated processing," or "model." That silence is not a loophole — it is the answer. Because the agent is invisible to the statute, the law reaches past it to the humans and entities in the chain, defined by two load-bearing terms:

- **Data Fiduciary (Section 2(i))** — "any person who alone or in conjunction with other persons *determines the purpose and means of processing* of personal data." This is the controller. This is who decided to point an agent at customer data.

- **Data Processor (Section 2(k))** — "any person who processes personal data *on behalf of* a Data Fiduciary." This is the vendor, the hosted model, the automation layer acting under instruction.

An autonomous AI agent is, in law, one of two things: it is the Data Fiduciary acting through software it controls, or it is a Data Processor (or a Processor's tool) engaged by one. There is no third box labelled "independent actor." Whichever box applies, the entity that *determined the purpose and means* is the Data Fiduciary — and that is where the liability sits.

The sentence that forecloses the defence

The operative line is Section 8(1), and it is worth quoting because it leaves no room:

"A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor."

Read the three words that do the work: *irrespective of any agreement to the contrary.* You can sign the tightest indemnity in the market with your AI vendor; it allocates cost between you two as a commercial matter, but it does not move statutory liability an inch. **Section 8(2)** reinforces this — a Data Fiduciary may engage a processor *only under a valid contract* — but that contract is a duty you owe, not a shield you hold. "Our model provider handled it" is not a defence the Data Protection Board is built to accept. Nor is "the agent decided that on its own." Autonomy of the tool is legally irrelevant; control of purpose and means is everything.

What this costs, and what to do this quarter

Blog image

The penalties live in the Schedule to the Act and are imposed by the Board under Section 33. They are caps, so read them as "up to" — but the ceilings are designed to be felt: 

up to ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach (the Section 8(5) duty); 

up to ₹200 crore for failing to notify a breach; 

up to ₹150 crore for breaching the extra obligations of a Significant Data Fiduciary (Section 10). Appeals go to the TDSAT. 

The action list for an operator running agents on personal data:

- Map every agent to a Data Fiduciary - For each AI agent or automation touching personal data, name the entity that determined its purpose. If that entity is you, the liability is yours — make that explicit on paper, not by accident.

- Get a Section 8(2) contract for every processor. Every external model, hosted agent, or automation vendor processing personal data on your behalf needs a valid processing contract before 13 May 2027 — and the contract must instruct, not merely indemnify.

- Pull security safeguards forward. The ₹250 crore exposure is tied to safeguards (Section 8(5)). Treat agent access to personal data as the highest-risk surface: least-privilege data access, logging, breach-detection, and retention limits, audited now.

- Check if you're a Significant Data Fiduciary. High-volume or high-sensitivity processing can pull you into Section 10 — DPO, independent audit, and a Data Protection Impact Assessment. Agents that scale processing volume can quietly push you across that line.

Under DPDP, there is no autonomous agent — only a Data Fiduciary that deployed one.

---

*This post is part of AI for Bharat Business — the Indian operator's AI desk on siddheshj.com. General information on regulatory developments; not legal advice. Consult qualified counsel before acting. 

Siddhesh Joglekar

Written by Siddhesh Joglekar

Fractional CMO and AI marketing consultant Siddhesh Joglekar helps founders and growth-stage teams build marketing engines that compound.

Book a Call (opens in a new tab)