News Analysis4 mins

AI Data Scraping vs DPDP Act 2023: Assessing the Growing Legal Friction for Enterprise General Counsel

An analysis of the regulatory intersection between AI training requirements and India's DPDP Act, detailing how General Counsel must navigate data provenance, anonymization, and vendor indemnities ahead of the compliance deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

An analysis published on the Nasscom community platform details the growing conflict between artificial intelligence data requirements and privacy regulations under the Digital Personal Data Protection Act, 2023 and the notified DPDP Rules, 2025. The report highlights the structural enforcement landscape, noting the establishment of the Data Protection Board of India following the Justice B.N. Srikrishna Committee recommendations. Ongoing debates concerning the regulator's independence and enforcement powers suggest potential delays in achieving the Ministry of Electronics and Information Technology harmonization goals.

Does the DPDP Act apply here?

For General Counsel evaluating enterprise AI deployments, Section 3 of the DPDP Act establishes the jurisdictional baseline. The Act applies to the processing of digital personal data within India, and processing outside India connected to offering goods or services to Data Principals in India. Critically for AI model training, Section 3(c)(ii) provides an exemption for personal data made publicly available by the Data Principal to whom such data relates or under a legal obligation. General Counsel must ensure data sourcing strictly fits this exemption, as scraping internal enterprise datasets generally triggers full compliance obligations.

Legal implications under DPDP

Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. AI developers and enterprise adopters cannot bypass these requirements merely to achieve innovation or competitive advantage. The DPDP Rules, 2025 dictate strict operational controls for how data is handled, requiring itemised notices and specific processing grounds. While AI thrives on vast datasets, data fiduciaries must enforce strict data minimization principles. Removing unnecessary personal identifiers before training models is a critical operational step that reduces privacy risks and alleviates the broader compliance burden.

Could this happen to you

If your enterprise licenses a third-party AI tool trained on non-compliant data, the liability risk shifts rapidly to your organization as a Data Fiduciary. The Data Protection Board of India will not accept algorithmic complexity as an excuse for unlawful processing or lack of vendor oversight. In the event of an AI-linked data breach, the Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. General Counsel must evaluate if current vendor contracts offer sufficient limitation of liability and indemnities to absorb a penalty ceiling of up to 250 crore rupees. A defensible regulatory posture requires immediate access to data provenance logs and verifiable consent records.

What companies should do in the next 30 days

1. General Counsel must audit all existing AI vendor contracts to ensure robust indemnities and clear liability allocation for DPDP non-compliance. 2. Legal teams should mandate technical reviews of data ingestion pipelines to verify that personal identifiers are systematically stripped before AI training begins. 3. Compliance officers must establish clear evidence trails for consent and Section 7 legitimate uses, ensuring these records can be produced immediately during privileged review or regulator engagement.

What to watch

The trajectory of AI law in India will be determined at the intersection of privacy, copyright, and trade secret frameworks. Monitor the evolving regulatory landscape as the Data Protection Board of India operationalizes its enforcement mandate and clarifies evidence requirements for AI developers. Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal leaders should shift outside counsel spend toward operationalizing these compliance workflows immediately. To evaluate your current enterprise defensibility, visit freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act affect AI model training for enterprises?

The Act applies to digital personal data used in AI training if it involves Data Principals in India. Unless the data was made publicly available by the individual, processing requires valid consent or a Section 7 legitimate use.

What liability do enterprises face when using third-party AI vendors?

Enterprises acting as Data Fiduciaries are accountable for compliance even when using third-party AI processors. General Counsel must secure strong indemnities and limitation of liability clauses to mitigate risks of penalties reaching up to 250 crore rupees.

How can legal teams reduce the DPDP compliance burden for AI datasets?

Implementing rigorous data minimization by removing personal identifiers before model ingestion significantly reduces privacy risks. This operational step limits exposure and simplifies compliance workflows under the DPDP Rules, 2025.

What are the breach notification requirements if AI training data is compromised?

Under the DPDP Rules, 2025, a personal data breach requires intimation to affected Data Principals without delay. Additionally, the Data Fiduciary must submit a detailed breach report to the Data Protection Board of India within 72 hours.

When must enterprise legal teams fully comply with the DPDP Act?

Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal teams must finalize their regulatory engagement strategies and vendor contract remediations before this date.