Mumbai, IndiaUpdated daily

DPDP News

Daily Intelligence on India's Data Law

Daily Briefing12 August 2026

DPDP Daily Brief — RBI Flags AI Risks, Right to Be Forgotten Gains Traction

By AI Editor5 min read

Top Story

RBI Governor Malhotra says DPDP compliance alone not enough for banks, identifies six AI risks

Today's Headlines

1. RBI Governor Malhotra says DPDP compliance alone not enough for banks, identifies six AI risks

Source: bfsi.economictimes.indiatimes.com | Read Original → RBI Governor Malhotra has issued a strong statement, advising banks that mere adherence to DPDP Act stipulations is insufficient, especially when dealing with Artificial Intelligence. He identified six distinct AI risks that financial institutions must proactively manage, underscoring the need for a comprehensive risk framework beyond basic legal compliance to meet their Section 8 (Data Fiduciary obligations). This directive signals heightened regulatory expectations for businesses deploying advanced technologies.

2. How India’s Right to Be Forgotten Will Change Digital Privacy

Source: TradeFlock | Read Original →

This article explores the transformative impact of India’s Right to Be Forgotten under the DPDP Act on digital privacy. It highlights that individuals now possess greater control over their digital footprint, enabling them to request the erasure or de-listing of personal data. Businesses must thus establish robust processes for handling such requests efficiently, aligning with Section 13 (Right to Correction and Erasure) to avoid non-compliance issues.

3. OpenAI flags possible critical cybersecurity risk in upcoming model, tightens controls

Source: The Hindu Tech | Read Original → OpenAI has announced the discovery of a potential critical cybersecurity risk within its next-generation AI model, prompting immediate, rigorous control enhancements. This incident serves as a stark reminder for all Data Fiduciaries in India about the inherent security challenges with AI, emphasizing the crucial need to implement and regularly review stringent reasonable security safeguards under Section 8(5) of the DPDP Act to protect personal data. Should such a risk lead to a breach involving Indian personal data, it would trigger Section 19 (Data Breach Notification) and potential penalties of up to ₹250 Cr.

4. APAAR Opt-Out Mandate And DPDP Act: Reinstating Parental Choice In Student Surveillance

Source: livelaw.in | Read Original →

The intersection of the APAAR initiative and the DPDP Act is spotlighted, specifically concerning the re-establishment of parental choice for opting out of student data collection. This development strongly reinforces the DPDP Act’s stringent requirements for processing children’s data, particularly Section 11 (Processing of Data of Children). Businesses and educational institutions must ensure explicit parental consent and provide clear, accessible mechanisms for managing data processing preferences for minors.

Stay Compliant

Not sure if your business meets DPDP standards? Start with a free check:

🔍 Run Your Free DPDP Audit →

16 questions. 60 seconds. Instant risk report.


Published by DPDP News, a Meridian Bridge Strategy initiative. For compliance consulting, book a free call.

Daily Email

Get DPDP News by email

One short email when a new DPDP briefing is published. No spam.