News Analysis • 4 minutes
AI Training vs Trade Secrets: Navigating the DPDP Access Right Dilemma
A recent analysis highlights a growing conflict between the DPDP Act 2023 access rights and trade secret protections for AI models. Fintech legal teams face a dilemma: disclose proprietary logic to fulfill data principal requests or risk severe non-compliance penalties.
Last updated:
What Happened
A recent analysis published on the NASSCOM community portal highlighted an escalating conflict between artificial intelligence training requirements, trade secret protections, and compliance obligations under the Digital Personal Data Protection Act, 2023.
The report notes that the Data Protection Board of India, conceptualised from the Justice B.N. Srikrishna Committee recommendations, faces ongoing debates over its independence and enforcement powers.
These debates are expected to delay Ministry of Electronics and Information Technology efforts to harmonise the regulatory environment.
The core issue centres on a regulatory gap where companies are forced to choose between fulfilling data access requests and protecting proprietary AI algorithms.
Does The DPDP Act Apply Here?
Under Section 3 of the DPDP Act, 2023, the law applies to the processing of digital personal data within India, or processing outside India if it is in connection with offering goods or services to Data Principals in India.
Fintech lending models heavily rely on personal data for underwriting, including account aggregator API inputs and payment histories.
If this data is used to train proprietary credit scoring models, the activity falls squarely within the scope of the Act.
The legislation makes no distinction for data used in machine learning, meaning anonymised corporate intellectual property is exempt, but the underlying personal data points used to train the model remain fully regulated.
Legal Implications Under DPDP
The DPDP Act, 2023 and the operational specifics of the DPDP Rules, 2025 represent a shift from a property rights model of corporate data ownership to a dignity rights framework focused on individual control.
Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning fintech general counsels must ensure AI training is explicitly covered in itemised notices.
The source text flags a critical omission as the Act currently lacks a specific trade secret carve out.
Under Section 11, Data Principals have the right to request a summary of personal data being processed and the identities of all data fiduciaries with whom it was shared.
Responding to these requests without exposing proprietary logic creates severe friction, testing limitation of liability clauses in outside vendor contracts.
Could This Happen To You
Fintech legal teams regularly sign off on third party AI tools for fraud detection and risk modeling in rapid product cycles.
If a Data Principal submits an access request regarding a loan rejection, the DPDP Rules, 2025 require verifiable and prompt compliance.
Refusing to provide algorithmic transparency could trigger a DPBI inquiry, while full disclosure might compromise your startup's core intellectual property.
An auditor or the DPBI will demand a clear evidence trail showing how access requests are handled, logged, and fulfilled without breaching trade secret protections.
Failure to manage this conflict exposes the firm to penalties up to 250 crore rupees for breaching fiduciary obligations.
What Companies Should Do In The Next 30 Days
1. Map AI data flows. The legal team must audit all third party AI vendors to distinguish between digital personal data and anonymised training inputs.
2. Update itemised notices. Ensure your privacy notices explicitly state if personal data is processed for machine learning, securing consent records required by the Rules, 2025.
3. Draft access request protocols. Work with product leads to design a response workflow that satisfies Section 11 obligations without exposing proprietary underwriting logic.
4. Review vendor indemnities. Update limitation of liability clauses in your AI contracts to clearly allocate risk for data handling.
5. Enforce breach protocols. Ensure vendor contracts mandate breach intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours, per the Rules, 2025.
What To Watch
General counsels must monitor how the Data Protection Board of India handles early enforcement actions involving algorithmic transparency.
Legal teams should watch for any official MeitY guidelines addressing the trade secret conflict, potentially offering a safe harbour for proprietary logic.
It is critical to remember that exactly 282 days remain until the DPDP hard compliance deadline of 13 May 2027.
To evaluate your firm's exposure to access request failures and AI data handling risks, check your readiness at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to data used for AI training?
Yes. Under Section 3, the Act covers digital personal data processed within India, including data used for AI training. If fintech models use personal data for credit scoring, that processing is regulated.
Can we withhold proprietary AI logic when fulfilling a data access request?
This presents a conflict of laws as the DPDP Act, 2023 lacks a specific trade secret carve out. Legal teams must carefully structure responses to fulfill Section 11 access rights without compromising proprietary intellectual property.
What are the penalties for failing to fulfill data access requests?
Non compliance with data fiduciary obligations, including the failure to respond to access requests, can attract penalties up to 250 crore rupees. Firms must maintain automated, privileged review workflows to handle these requests defensively.
How do the DPDP Rules 2025 impact our AI vendor contracts?
The Rules, 2025 demand strict vendor oversight and verifiable evidence trails. Your contracts must clearly allocate liability and mandate breach intimation to Data Principals without delay plus a DPBI report within 72 hours.
What is the DPDP Act compliance deadline?
Exactly 282 days remain until the 13 May 2027 hard deadline. Legal heads should use this time to map data flows, secure consent records, and prepare compliant workflows to avoid heavy outside counsel spend later.
ComplyDP