azyware
Technology

AI Customer Service Agent, security and the DPDP Act: a compliance checklist

EZ
Eazyware
· 7 min read
Quick answer

Is AI customer service agent compliant with the DPDP Act?

An AI customer service agent is not compliant or non-compliant by nature; your deployment of it is. Under the DPDP Act, 2023 you need a lawful basis and notice for the conversation data, redaction before it leaves your boundary, a retention clock, erasure on request, and processor terms with every model vendor.

An AI customer service agent is not compliant or non-compliant by nature; your deployment of it is. Under India's Digital Personal Data Protection Act, 2023 you need a lawful basis and clear notice for the conversation data, redaction before it leaves your boundary, a retention clock, working erasure on request, and processor terms with every model vendor in the chain.

That is the short answer. The rest of this article turns each obligation into an architectural decision, adds the sector rules that sit on top for finance and healthcare, covers the security failures specific to agents that can act, and closes with a checklist you can hand to a reviewer.

What the DPDP Act actually asks of a support agent

The Digital Personal Data Protection Act, 2023, published by the Ministry of Electronics and Information Technology and available at meity.gov.in, makes the organisation deciding why and how personal data is processed the data fiduciary. If you deploy the agent, that is you. Every model provider, vector database and transcription service the agent touches is a data processor working under your instructions and your contract.

Support conversations are unusually rich personal data. A single thread can contain a name, a phone number, an address, an order history, a payment reference and, in regulated sectors, health or credit information the customer volunteered without being asked. The agent's job amplifies this, because unlike a human reading one ticket, the system retrieves, embeds and logs at scale.

The plain-language walkthrough of the Act for Indian companies building AI is in DPDP Act 2023 and AI: what Indian companies must do, and the definition sits in our glossary under DPDP Act 2023.

One framing helps more than any clause. Ask, for each piece of data the agent sees, three questions: why do we hold it, who can reach it, and when does it disappear. An agent design that can answer all three for transcripts, traces, embeddings and tool responses is most of the way to compliant. An agent design that cannot answer them for embeddings, which is the common case, has a gap that no policy document closes.

Obligation by obligation

ObligationWhat it means for a support agentHow it is implemented
Lawful basis and noticeCustomers must know their conversation is handled by an automated system and what happens to itDisclosure at the start of every session, logged with a version of the notice text
Purpose limitationTranscripts collected for support cannot silently become training dataContractual no-training terms with providers, plus a separate opt-in for any secondary use
Data minimisationThe agent retrieves only the fields the intent needsScoped tool contracts returning specific fields, never a full customer record
Storage limitationTranscripts and embeddings expireA retention clock on conversations, traces and the vector index, enforced by a job not a policy document
Correction and erasureA customer request must reach every copyA deletion path that covers the helpdesk, the trace store, the embeddings and any backups
Processor accountabilityYou remain responsible for your vendorsSigned data processing terms, documented regions, and a vendor register you can produce on request
Breach notificationIncidents must be reportableImmutable audit logs and alerting on anomalous retrieval or tool use

The architecture that satisfies it

Compliance is easier to engineer at the boundary than to retrofit as policy. Four components do most of the work.

Redaction before egress

Everything leaving your perimeter towards a hosted model passes through a redaction layer that replaces identifiers with stable tokens: the model sees customer 4471 and order A-2291, not a name and a phone number. The tokens are rehydrated on the way back so the customer still sees a natural reply. PII redaction is cheap to build and it converts a large class of privacy questions into a small one.

Permission-aware retrieval

The retrieval layer must filter by the requester's rights before ranking, not after. An agent serving a customer should be physically unable to retrieve another customer's record, and an agent-assist tool serving a human should respect that human's role. The pattern is set out in permission-aware retrieval.

Retention as a running job

Write the retention period into a scheduled deletion job on day one, covering the conversation store, the trace store and the vector index. Embeddings are the part teams forget: they are derived from personal data and they persist long after the transcript is gone. A deletion request that does not reindex is not a deletion.

An action ledger, not just a chat log

Every write the agent performs is recorded with the policy threshold it was checked against, the approver if there was one, and the resulting system state. This is what makes an automated refund defensible at an audit, and it is the single control that separates a governed agent from an unaccountable one.

Sector rules that sit on top

The DPDP Act does not impose blanket localisation, but sectoral regulators do more than it does. Banks and NBFCs operate under Reserve Bank of India outsourcing and storage directions that push customer data onshore and require audit rights over service providers. Insurers answer to IRDAI. Hospitals and diagnostics providers handling patient records have consent and access expectations that predate the Act and are stricter about who may read a record at all.

If you are in one of those sectors, decide residency before you choose a model, because it narrows the list to providers with an Indian region or to an open-weight model you run yourself. Where egress genuinely cannot be permitted, the deployment shape is self-hosted agentic AI from $31,500 or ₹20,80,000 plus infrastructure, rather than a managed build. Our NBFC work on KYC and loan onboarding, described in the document intelligence case study, took exactly that shape for exactly that reason.

Security beyond privacy: the failures specific to agents

Privacy compliance does not cover the security problems an agent introduces by being able to act. Two matter most in support.

The first is prompt injection. A customer can write instructions into a ticket, an attachment or a product review that the agent later retrieves and treats as direction. OWASP's Top 10 for large language model applications lists prompt injection as the leading risk class, and in a support agent the payoff for an attacker is concrete: issue a refund, change an email address, escalate an account tier. The defence is not a cleverer prompt. It is thresholds on every action, approval gates above them, and tool contracts narrow enough that the worst case is bounded.

The second is over-broad tools. A tool that accepts an arbitrary query against your customer database will eventually be induced to run one you did not intend. Expose verbs, not access: look up this order, refund up to this amount, reschedule within this window. The questions to put to any vendor on this are collected in a security questionnaire for AI vendors.

The checklist

  • Notice and disclosure shown at session start, versioned and logged.
  • No-training terms signed with every model and transcription provider, with the region documented.
  • Redaction layer between your systems and any hosted model, with tokens rehydrated on return.
  • Retention job running against conversations, traces and embeddings, with the period agreed by legal.
  • Erasure path tested end to end, including reindexing, before go-live rather than after the first request.
  • Permission filters applied inside retrieval, verified by an attempt to fetch another customer's record.
  • Action thresholds documented per intent, with a named owner who can change them.
  • Immutable audit log of retrievals and writes, retained for the period your regulator expects.
  • Vendor register listing every processor, its region and its contractual basis.
  • Injection test set in the eval suite, rerun on every prompt or model change.

Our own platform controls and sub-processor position are published on the trust and security page. The list above is deliberately short enough to be checked in an afternoon; a compliance artefact nobody finishes reading protects nobody.

Run it twice: once before go-live, and once ninety days later. The second pass catches the things that drift rather than the things that were missed. New intents get added, a provider changes region, somebody widens a tool contract to unblock a release, and the retention job silently fails on the vector index because the schema moved. Compliance for an agent is a recurring check, not a launch gate you pass once and file away.

When compliance means not building this

Sometimes the honest answer is no. If the only way to make an intent work is to give the agent unrestricted read access to a database that mixes customer classes, do not build that intent; fix the data model first. If your legal team cannot agree a retention period, you are not ready, because an agent without a retention clock accumulates liability every day it runs.

And if the business case depends on training a model on customer conversations that were collected for support, stop. Purpose limitation is not a formality, and re-consenting a support base for a training use is harder than the model gain is worth. We say this often enough that it has become part of how we scope engagements.

Cost and timeline

Privacy and security work is not a separate line item in our quotes; it is part of a build. An AI customer service agent runs from $12,500 or ₹8,00,000 to $42,000 or ₹28,00,000, with redaction, permission-aware retrieval, the action ledger and the injection test set included. A ten-day Sprint Zero at $3,250 or ₹2,00,000, credited to the build, is where the residency decision and the retention period get settled with your legal team present. Every published figure is on the pricing page.

AI governance for mid-size companies without a compliance team covers the operating model, and private AI for banks goes deeper on keeping data inside the perimeter when the regulator requires it.

Treat DPDP compliance as an architecture decision made before the first prompt, not a document written after the first incident.

Frequently asked questions

Is an AI customer service agent allowed under India's DPDP Act?

▾

Yes, provided you act as a responsible data fiduciary: give notice that an automated system is handling the conversation, process only what the intent needs, hold processor terms with every model vendor, apply a retention period to transcripts and embeddings, and honour correction and erasure requests across every copy of the data.

Do support transcripts have to stay in India?

▾

The DPDP Act does not impose blanket localisation, but sectoral rules can. Reserve Bank of India directions push financial customer data onshore, and insurance and healthcare bring their own expectations. If you are regulated, settle residency before choosing a model, since it narrows the list to Indian regions or self-hosted open-weight models.

What is the biggest security risk in an AI support agent?

▾

Prompt injection combined with over-broad tools. A customer can plant instructions in a ticket or attachment that the agent later retrieves and obeys. The mitigation is narrow tool contracts that expose specific verbs, action thresholds with approval gates above them, and injection cases held permanently in the evaluation suite.