Skip to main content
Finin2minCurrent Action Brief · 13 Aug 2026
DPDP, Privacy & AI GovernanceUpdated 5 October 2026

Personal Data in LLM Prompts: Enterprise Redaction, Logging and Retention Workflow

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

2-minute summary

Current position

The DPDP Act and Rules have staggered commencement. Most core processing duties are scheduled for eighteen months after 13 November 2025, so 5 October 2026 is a transition period. Organisations should use it to establish prompt-data minimisation, approved AI tools, retention settings and access controls while also complying with current confidentiality, banking, employment and contractual restrictions.

Control and evidence map

#Control / evidence requirement
1Define prohibited prompt classes such as full identity documents, credentials, health records or unredacted customer case files unless specifically approved.
2Use deterministic masking/tokenisation for names, account numbers and identifiers before prompt submission.
3Restrict enterprise AI to contracted tools with known retention/training settings; block unmanaged consumer accounts for sensitive work.
4Design logs to capture user/tool/purpose and risk events without storing full prompt text by default.
5Create an exception process for cases that genuinely require identifiable data and document the reason.

Worked example

A support analyst wants help summarising a complaint and pastes a full KYC packet into a public AI chat. A safer workflow extracts the complaint facts, substitutes customer identifiers with tokens and uses an approved enterprise tool whose retention and training settings have been reviewed. The mapping back to the customer remains inside the company system.

Common mistakes

  1. Redacting only the final AI answer.
  2. Logging every prompt forever for “audit”.
  3. Assuming enterprise branding means the vendor never trains on data.
  4. Allowing browser extensions to send page content to unapproved models.

Frequently asked questions

When should redaction occur?

Before data is submitted to the model.

Should full prompts always be logged?

No; logging itself should follow data-minimisation and security principles.

Are all DPDP processing duties live in October 2026?

No.

What is the first control?

Approved-tool policy plus technical blocking/redaction for high-risk data classes.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, policy/contract and facts before acting; obtain professional advice for material or disputed matters.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.