How to Make ChatGPT DPDP Compliant
Many employees already use ChatGPT at work, often with customer data in their prompts. India's Digital Personal Data Protection (DPDP) Act makes your organisation responsible for that data. With Mavs Secure Chat, you can get a governed way to let your teams keep using ChatGPT models with full DPDP compliance.
From the Founders' Desk
By Manjul Kubde, Co-founder & Abeer Sehrawat • Sep 25, 2026

Can you use ChatGPT and stay DPDP compliant?
The Digital Personal Data Protection (DPDP) Act does not ban AI tools, but it does make you responsible for the data you share with a tool. If your organisation is the one deciding how customer data is used, the Act calls your organisation a Data Fiduciary. As the Data Fiduciary, your organisation is accountable for that data even when a vendor handles it (Section 8(1)).
So when an employee pastes a customer's details into ChatGPT, OpenAI processes that data on your behalf. If it leaks from OpenAI's systems, it is still your breach. You have to inform the Data Protection Board and every affected customer (Section 8(6)), and you can be fined up to ₹250 crore if you did not take reasonable security safeguards (Section 8(5)).
These rules apply from 13 May 2027, but data your employees paste into ChatGPT today may still be stored on OpenAI's systems then, and the rules will apply to it. You can only protect that data before it leaves your organisation, so the controls need to be in place now.
How to make ChatGPT usage DPDP compliant with Mavs Secure Chat

Mavs Secure Chat is a secure AI portal where your teams can use OpenAI's ChatGPT models without leaking your actual data to the model provider. It works as a governed AI workspace: Mavs checks every prompt at runtime for sensitive data before sending it to OpenAI, applies the policies you set and keeps a log of all AI interactions.
Here is what Mavs Secure Chat enables you to do:
- Compliant access to ChatGPT models. Assign any frontier model you want, including OpenAI's GPT-6 Astra, GPT-6 Sol and GPT-6 Luna, to different teams or employees based on each team's needs and tasks. Pay for only the OpenAI tokens you use.
- Set policy per team. Create separate workspaces for each team or task and choose how you want to treat sensitive data for those workspaces. The claims team and the marketing team, for example, can have different policies based on the kind of data they are dealing with.
- Audit log. Get DPDP-standard audit logs for every prompt and every replacement to prove your compliance to any auditor.
- Visibility on risk and productivity. See the risk trends and actions taken to safeguard AI usage across your organisation, as well as AI adoption and token consumption metrics.
- Token management. Set limits and keep track of token consumption to keep your AI costs and usage predictable.
- Prompt injection protection. Mavs detects and stops prompt injection and jailbreak attempts before they reach the model.
- Enable productivity without blocking prompts. Mavs identifies sensitive data in every prompt and file upload and replaces identified data with realistic stand-in values before anything is sent to OpenAI, then puts the real values back in the response. This means that you don't have to block work, while giving AI models a realistic version of the actual prompt to reason over. This ensures you have the technical safeguards required by Rule 6 of the DPDP Rules without blocking productivity or degrading model output quality.

Illustrative values. OpenAI receives and stores the stand-in name and ID. The real ones stay within the enterprise boundaries.
To learn more, read how we enabled DPDP compliance for a large Indian enterprise with Mavs Secure Chat, without blocking its employees' AI use.
What Indian data does Mavs identify and replace for making ChatGPT DPDP compliant?
Mavs identifies and replaces common Indian personal data, as well as confidential business information.
| Category | Examples |
|---|---|
| Government IDs | PAN, Aadhaar, voter ID, passport, driving licence |
| Financial data | Bank account and card numbers, UPI IDs, demat account numbers, loan and insurance policy numbers |
| Personal details | Names, addresses, phone numbers, email addresses |
| Health | Patient IDs, medical record numbers, health insurance claim numbers |
| Business information | Deal and project codenames, unannounced pricing, merger and acquisition terms, key accounts, unreleased roadmaps |
Business sensitive information isn't personal data, so the DPDP Act doesn't cover it. But sending it to a third-party model is a risk in itself, and some of it is regulated elsewhere, such as price-sensitive information under the Securities and Exchange Board of India (SEBI) insider trading rules, or client data covered by a non-disclosure agreement (NDA). Mavs Secure Chat also lets you secure your business sensitive data in addition to PII.
Frequently asked questions
Is ChatGPT DPDP compliant?
Under the DPDP Act, your organisation is responsible for the personal data it collects. If you share that data with ChatGPT, make sure you have guardrails in place to protect it before it reaches OpenAI, and log every prompt as evidence of your compliance.
Does ChatGPT have guardrails for personal data?
ChatGPT's built-in guardrails are set by OpenAI to handle harmful content. You don't control them, and they don't check prompts for customer personal data. Mavs Secure Chat adds guardrails you set for each team: it identifies and replaces personal data, stops prompt injection and logs every prompt.
Can employees use ChatGPT with customer data like Aadhaar or PAN?
Yes, if the data is protected before it reaches OpenAI. Your organisation stays accountable for customer data even after OpenAI holds it. If it leaks, you must report the breach to the Data Protection Board and to each affected customer, and you can be fined up to ₹250 crore if you didn't have reasonable safeguards in place. Mavs Secure Chat replaces names, Aadhaar, PAN and account numbers with realistic stand-in values before the prompt is sent, so the real data never leaves your organisation.
Which AI tools are DPDP compliant?
A DPDP compliant AI tool helps your organisation meet its obligations under the DPDP Act: it protects personal data before it reaches the model, sets policies for each team, keeps audit logs and lets you choose where data is stored. Mavs Secure Chat does all four. Your organisation also needs a privacy notice that covers the purpose, a contract with the vendor and a way to delete the data. Our complete guide to the DPDP Rules 2025 explains each obligation, and what DPDP Rule 6 requires when you use AI covers safeguards and logs.
How can we see what employees share on personal ChatGPT accounts?
You can't. There is no contract with OpenAI, admins have no view of what is shared, and conversations may be used to train OpenAI's models unless the user turns this off. Moving employees to a secure AI workspace such as Mavs Secure Chat fixes this. It logs every prompt, the data that was replaced and who sent it, and shows risk trends and AI adoption for each team.
How do I keep audit logs of ChatGPT usage for DPDP compliance?
Route ChatGPT usage through a workspace that logs every interaction. Rule 6 of the DPDP Rules asks you to keep logs that help detect and investigate unauthorised access to personal data, and to retain them for one year. Mavs Secure Chat logs every prompt, who sent it, what personal data was found and how it was replaced, so you can show an auditor how personal data was handled.
We already block ChatGPT. Do we still need this?
Blocking creates shadow AI. Employees move to personal ChatGPT accounts on their own phones and laptops, where you can't see or govern what they share. Mavs Secure Chat gives them GPT models in a workspace you control.



