DPDP 2023 — data-protection rules for conversational-ad targeting
The Digital Personal Data Protection Act 2023 is the law that decides whether a ChatGPT Ad can legally use someone's conversation history to target them — and for healthcare advertisers, it stacks on top of NMC Section 6 and ASCI Chapter III rather than replacing either. This page sets out what the Act actually says, how it applies specifically to conversational-ad copy structured around a chat thread rather than a static banner, and the checklist ICG runs before any healthcare ChatGPT Ad goes live. It is the compliance companion to our broader Healthcare ChatGPT Ads practice and sits alongside our compliance hub.
What the rule actually says
The Digital Personal Data Protection Act 2023 received presidential assent in August 2023 and governs the processing of "digital personal data" of individuals located in India, whether that processing happens inside India or abroad in connection with offering goods or services to Indian users. The Act defines a Data Fiduciary as the entity that determines the purpose and means of processing, and a Data Principal as the individual whose data is processed — in a ChatGPT Ads context, the person having the conversation is the Data Principal, and both OpenAI's ad infrastructure and the advertiser directing the targeting can sit inside the Data Fiduciary chain, depending on how the platform's data-sharing terms allocate control.
Section 6 of the Act sets the consent standard: consent must be free, specific, informed, unconditional, and unambiguous, given through clear affirmative action, and accompanied by a notice in plain language stating what personal data is collected and for what purpose. Section 8 layers on general obligations — a fiduciary must process data only for the purpose consented to, must not retain it longer than necessary for that purpose, and must implement reasonable security safeguards. Section 16 addresses cross-border transfer, permitting it by default to any country except one the Central Government restricts by notification — a deliberate departure from the hard data-localisation requirements that appeared in earlier legislative drafts going back to 2018 and 2019.
The Act does not carry a standalone "sensitive personal data" category the way the 2019 draft bill did, which sometimes leads advertisers to assume health-adjacent conversation data gets no special treatment. That reading is incomplete. Section 9 imposes heightened restrictions on processing children's data, and the Data Protection Board of India can notify a fiduciary as a "Significant Data Fiduciary" under Section 10, triggering additional obligations — data protection officer appointment, data protection impact assessments, and independent data audits — based on factors including the volume and sensitivity of data processed. A healthcare advertiser running conversation-history-based targeting at scale sits squarely in the profile the Board is expected to scrutinise for that designation, notification or not. Penalties for non-compliance, set out in the Act's schedule, run up to Rs 250 crore per instance for serious breaches such as failure to take reasonable security safeguards, enforced by the Data Protection Board of India established under Section 18. (Source: Digital Personal Data Protection Act 2023, Sections 6, 8, 9, 10, 16, 18, and Schedule — Ministry of Electronics and Information Technology, Government of India.)
How it applies to conversational-ad copy specifically
A static Google Search or Meta feed ad is targeted against a keyword, a demographic bucket, or a behavioural signal derived from past clicks and page visits — data that is real but structurally shallow. A ChatGPT Ad is targeted, in part, against the substance of a conversation: what the person actually typed, asked, and revealed across a multi-turn exchange before the sponsored response appeared. That is a categorically deeper data input, and DPDP 2023's purpose-limitation and consent-specificity requirements bite harder on it than they do on a conventional keyword-match placement.
Consider the practical difference. A Google Ads campaign for a fertility clinic can be lawfully targeted against the search term "IVF clinic near me" with no meaningful personal-data exposure beyond the query itself, entered fresh at the moment of intent. A ChatGPT Ads campaign for the same clinic may be surfaced in response to a conversation that started three turns earlier with "I've been trying to conceive for 14 months and I'm scared something's wrong," moved through follow-up questions about symptoms and timelines, and only then reached a point where a sponsored response became contextually relevant. The ad is the same destination, but the data trail behind the targeting decision is an entire personal narrative, not a single query — and DPDP's definition of personal data covers exactly that trail.
This matters for three specific mechanics unique to conversational ads. First, attribution runs on conversation-completion events rather than clicks, which means the platform and the advertiser are both processing data about how the conversation resolved, not just whether a link was tapped — a second layer of processing beyond the targeting decision itself, and one that needs its own purpose justification under Section 8. Second, the auction is intent-first rather than keyword-first, which means bid and placement logic is inferring intent stage from conversational context — an inference process that is itself a form of processing personal data, even before any ad renders. Third, the healthcare compliance overlay (NMC Section 6, ASCI Chapter III, DPDP 2023, and where relevant the ART Act 2021 or DCGI/UCPMP 2024) has to be checked against the ad copy and against the targeting logic separately, because a claims-compliant ad shown to the wrong inferred audience through non-consensual health-data inference is still a DPDP problem even when ASCI has no objection to the copy itself.
The practical consequence for advertisers is that "our ad copy is compliant" and "our targeting is compliant" are two separate sign-offs, not one. ICG's healthcare ChatGPT Ads accounts carry both checks as distinct line items in every campaign-launch review, because a regulator investigating a complaint will ask about the targeting mechanism first — how did this person come to see this ad — before it ever reaches the question of whether the ad's language was accurate.
Common violations and how to avoid them
Most DPDP exposure ICG has found in healthcare ChatGPT Ads reviews falls into a small number of recurring patterns, not exotic edge cases. Naming no client or brand, the shapes below recur often enough across categories — fertility, oncology, aesthetic, and diagnostics — that they are worth stating as generic failure modes.
Violation one — consent inherited from the platform, not obtained by the advertiser. A brand assumes that because a user is already inside ChatGPT and has agreed to OpenAI's terms of service, no separate consent step is needed for the advertiser's use of conversation-derived targeting signals. This conflates platform-level consent (covering OpenAI's own processing) with advertiser-level consent (covering what the advertiser does with signals it receives). DPDP 2023's specificity requirement in Section 6 means consent for one purpose does not carry over to a different fiduciary's different purpose. The fix is contractual and structural: confirm, in writing from the ad platform, exactly what consent language the underlying product presents to users before any conversation-derived targeting is used, and do not launch until that language names the advertiser's use case specifically.
Violation two — retention without a stated limit. A brand's ad-ops team exports conversation-derived audience segments into a CRM or retargeting pool and keeps them indefinitely "in case they're useful later." Section 8's storage-limitation principle requires data be retained only as long as necessary for the stated purpose. An audience segment built for a Q1 campaign that is still sitting in a retargeting pool in Q4 with no active purpose is a live violation waiting for an audit to surface it. The fix is a retention schedule tied to campaign lifecycle, with automatic purge dates set at segment creation, not left to manual cleanup.
Violation three — inferred health category treated as "just interest data." A brand's targeting logic buckets users by inferred condition — "oncology-adjacent," "fertility-stage-two" — and treats these buckets the same as generic interest categories like "sports enthusiast," on the theory that no explicit diagnosis was stated. This misreads the spirit of the Act's heightened treatment of sensitive processing contexts even absent a formal sensitive-category list; a bucket built from health-adjacent conversational inference carries materially higher risk than a lifestyle-interest bucket, and treating it identically under-protects the Data Principal. The fix is a tiered internal classification — health-adjacent buckets get the strictest consent language, the shortest retention window, and the fewest downstream sharing permissions, regardless of what the platform's own default bucket taxonomy suggests.
Violation four — no grievance-redressal path visible to the user. Section 13 requires a Data Fiduciary to provide a readily available means for a Data Principal to raise a grievance. A brand runs ChatGPT Ads at scale with no visible privacy contact, no data-principal rights page, and no defined response window, on the assumption that the ad platform handles all of that upstream. It does not, for the advertiser's own processing of received signals. The fix is a published grievance contact and a documented internal SLA for responding to data-principal requests, referenced from the landing page every ChatGPT Ad routes to.
Violation five — cross-border transfer with no disclosure trail. Because Section 16 permits transfer by default, some brands treat cross-border movement of conversation-derived data as a non-issue requiring no documentation at all. Permitted-by-default is not the same as undocumented; if a Board inquiry asks where the data went, "we assumed it was fine" is not an adequate answer. The fix is a simple internal record — which vendors, which jurisdictions, which data categories — maintained as a living document, not reconstructed after the fact.
What "clean copy" looks like inside a ChatGPT Ad for this domain
Clean copy in a DPDP-compliant ChatGPT Ad is less about the words in the sponsored response and more about what data justification sits behind why that response was shown to that person — but the copy itself does carry a few structural markers of a well-governed campaign, and they are worth showing worked, in generic form.
Example — cardiology practice, stage-one bucket (symptom-adjacent, no diagnosis inferred). A user asks ChatGPT a general question about chest discomfort and exercise tolerance. A non-compliant ad response infers a cardiac-risk profile from the phrasing and serves copy like "Concerned about your heart? Book a cardiac screening today" — copy that implicitly confirms to the platform and any downstream logging that this user was bucketed into a health-risk-inferred audience, without the user ever having consented to that inference being made or acted on commercially. Clean copy for the same placement responds to the informational intent without confirming or acting on an inferred diagnosis: "General information on when chest discomfort during exercise warrants a medical check-in — from a cardiology practice." The targeting signal used should be the topical relevance of the conversation, not a stored, reusable "this user = cardiac risk" flag persisted beyond the single response.
Example — fertility clinic, stage-two bucket (active research, no personal history confirmed). Non-compliant: an ad that references specifics the user shared three turns earlier — "Since you mentioned trying for over a year, here's a fertility assessment package" — which both violates ASCI's prohibition on implied medical urgency and confirms that personal conversational detail was retained and reused across turns in a way well beyond the single-response context DPDP's purpose limitation would support. Clean: "IVF and fertility treatment options explained — timelines, success-rate ranges, and what a first consultation covers," a response scoped to the topic the user is currently exploring, with no persistent memory of prior personal disclosures feeding the ad copy itself.
Example — diagnostics chain, stage-three bucket (comparison-stage, near purchase decision). Non-compliant: copy assembled from an inferred symptom cluster presented as a diagnosis-adjacent recommendation — "Your symptoms suggest you should get a full-body checkup now" — which is both a claims problem under NMC Section 6 and a data-use problem, since it discloses back to the user (and implicitly confirms to any auditor) that a health inference was drawn and acted on commercially. Clean: "Compare full-body health checkup packages and what each one screens for," framed around the comparison the user is doing rather than a conclusion drawn about their body from the conversation.
The common thread across all three: clean copy never echoes back a personal or health-specific detail the user shared earlier in the conversation, never implies a diagnosis or risk conclusion was derived from that detail, and stays scoped to the topic rather than the person. That discipline satisfies ASCI Chapter III's ban on fear-based and diagnostic-implication advertising and DPDP's purpose-limitation principle simultaneously, which is precisely why ICG treats them as one review pass rather than two.
ICG's compliance checklist before every ChatGPT Ad push
Every healthcare ChatGPT Ads account ICG manages runs through the same documented checklist before a campaign goes live, and again before any structural change — new bucket, new landing page, new audience segment. This is the checklist referenced across ICG's healthcare ChatGPT Ads pages, applied identically whether the client is a hospital, a diagnostics chain, an IVF clinic, or a wellness DTC brand.
| Check | What ICG verifies |
|---|---|
| Consent notice language | The platform's user-facing consent notice specifically names the advertiser's use case for conversation-derived targeting — not a generic platform terms-of-service reference. |
| Purpose limitation | Every targeting signal requested from the ad platform maps to a stated campaign purpose; no signal is pulled "in case it's useful." |
| Data-processing agreement | A written DPA with the ad platform specifies retention windows, sub-processor disclosure, and breach-notification terms. |
| Retention schedule | Every audience segment and conversion pool carries an explicit purge date tied to campaign lifecycle, set at creation. |
| Health-inference tiering | Health-adjacent buckets are flagged internally and carry stricter consent, shorter retention, and no downstream sharing, distinct from generic interest buckets. |
| Cross-border disclosure record | A living document lists every vendor, jurisdiction, and data category the conversation-derived data touches. |
| Grievance-redressal contact | A published contact and internal SLA for data-principal requests, linked from every ChatGPT Ad landing page. |
| Copy dual-check | Ad copy is reviewed against NMC Section 6 / ASCI Chapter III (claims) and DPDP 2023 (data use) as two separate sign-offs, not one combined pass. |
| Diagnostic-implication scan | No ad copy echoes back a user's prior conversational disclosure or implies a diagnosis derived from it. |
| Sign-off log | Every launch and structural change is timestamped and signed off by name, creating an audit trail before any Board inquiry would require one. |
This checklist runs as a gate, not a suggestion — a campaign does not go live until every row is closed, and the sign-off log itself becomes the first document ICG produces if a client is ever asked to demonstrate compliance posture during an audit or a platform review.
What happens if you're audited
An audit or inquiry under DPDP 2023 can originate from three directions: a complaint filed by a Data Principal directly with the Data Protection Board, a Board-initiated inquiry triggered by a pattern of complaints or a breach disclosure, or a downstream consequence of an unrelated regulatory action — an NMC or ASCI complaint that, once investigators start pulling the file, surfaces a data-use question alongside the claims question. Healthcare advertisers should plan for the second and third paths as much as the first, since they arrive with less warning.
The Board's process, as structured under the Act, begins with a notice requesting information and documentation from the Data Fiduciary — this is where the sign-off log, the retention schedule, and the DPA with the ad platform stop being internal housekeeping and become the evidence file. A brand that can produce a dated, named sign-off for every campaign launch and structural change closes an inquiry faster and with a materially different posture than one reconstructing its data practices retroactively under Board scrutiny. ICG structures every client's compliance documentation with this scenario in mind from day one, not as a response drafted after a notice arrives.
Consequences scale with severity and cooperation. At the lower end, the Board can direct a fiduciary to take corrective action — adjusting consent flows, purging a non-compliant data pool, revising a retention schedule — within a set timeframe. At the higher end, for serious or repeated failures such as inadequate security safeguards or a pattern of non-consensual processing, the schedule's penalty ceiling of Rs 250 crore per instance becomes a live number, and the Board can also direct that specific processing cease altogether, which for a ChatGPT Ads account means the campaign — and potentially the underlying platform relationship — stops. The reputational cost for a healthcare brand of a public Board finding typically outweighs even a substantial monetary penalty, since patients and referring physicians read "data protection violation" and "healthcare provider" as a combination that erodes trust well beyond the ad channel involved.
ICG's role in an audit scenario is to have already done the work that makes the audit short: the checklist above, applied and logged before launch, is the difference between an inquiry that closes in weeks with corrective adjustments and one that escalates because the documentation simply does not exist. Clients on ICG's healthcare ChatGPT Ads retainers receive this documentation as a standing deliverable, refreshed at every campaign change, specifically so it is never something built under pressure.
Get your ChatGPT Ads account DPDP-reviewed before your next campaign push.
Book a 30-minute discovery WhatsApp Co-FounderThis page reflects ICG's interpretation of the Digital Personal Data Protection Act 2023 as applied to conversational-ad targeting and is not legal advice; healthcare brands should route final compliance sign-off through their own legal counsel. See also our broader Healthcare ChatGPT Ads practice and the compliance hub covering NMC Section 6, ASCI Chapter III, DCGI/UCPMP 2024, and AYUSH.