News Analysis • 4 mins
AI Training and the DPDP Act: Legal Conflicts and Enforcement Delays
Assessing the legal tension between AI data requirements and the DPDP Act, alongside structural debates over the Data Protection Board of India.
Last updated:
What Happened
A recent report published on the Nasscom Community examines a growing conflict between artificial intelligence training data requirements and the Digital Personal Data Protection Act, 2023. Artificial intelligence models require massive datasets to function effectively, creating direct friction with the regulatory environment. According to the report, structural debates are surfacing regarding the independence and enforcement powers of the newly established Data Protection Board of India. The DPBI was formed following recommendations from the Justice B.N. Srikrishna Committee to ensure the Act functions as an active enforcement framework rather than a theoretical set of obligations. These operational debates suggest that the DPBI will take considerably longer to achieve the Ministry of Electronics and Information Technology goal of harmonizing regulations.
Does The DPDP Act Apply Here
General Counsel evaluating AI platforms must scrutinize whether the models process digital personal data within the territory of India. The Act also applies to processing outside India if connected to offering goods or services to Data Principals in India, under Section 3. If an AI vendor trains its models exclusively on fully anonymised datasets or corporate intellectual property, the DPDP Act does not apply. However, if healthtech data pipelines inadvertently feed identifiable patient records into machine learning models, those datasets fall squarely under the purview of the DPDP Act and the DPDP Rules, 2025. Healthcare platforms must treat this vendor data sharing as a regulated activity.
Legal Implications Under DPDP
The fundamental legal friction arises from how AI models aggregate data versus how the DPDP Act restricts data processing. Section 4 dictates that consent is the primary basis for processing, except where Section 7 legitimate uses apply. Training AI models on collected patient data fundamentally challenges purpose limitation principles if the original itemised notice did not explicitly cover algorithm training. If AI processing involves international data centers, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries. Legal heads must carefully draft contract clauses, including safe harbour provisions and limitation of liability, to handle these specific boundaries.
Could This Happen To You
Healthcare enterprises and healthtech platforms face severe litigation risk if third-party AI vendors train on identifiable patient data without verifiable consent records. Healthcare organizations are prime candidates for Significant Data Fiduciary designation based on processing risk and volume, requiring health-grade privacy workflows that maintain patient trust. If an AI vendor suffers a breach or misuses data, the DPDP Rules, 2025 demand an intimation to affected Data Principals without delay, plus a detailed report to the DPBI within 72 hours. A General Counsel facing this scenario would need immediate access to vendor processing agreements and evidence of regulator defensibility. Failing to demonstrate this accountability exposes the enterprise to penalty ceilings reaching 250 crore rupees.
What Companies Should Do In The Next 30 Days
1. The General Counsel must initiate a privileged review of all master service agreements with AI providers to ensure clear liability allocation and indemnity clauses. 2. The legal team should update patient privacy notices to explicitly state if personal data is used for machine learning purposes, aligning with the itemised notice requirements in the DPDP Rules, 2025. 3. Compliance officers must map existing data flows within 24 hours to verify that no unauthorized cross-border transfers are occurring to restricted territories. 4. Clinic owners and medical directors should establish breach response workflows that guarantee the ability to notify the DPBI within the 72-hour window.
What To Watch
Legal heads should monitor the evolving administrative structure of the DPBI and how MeitY resolves the current debates over enforcement powers. Outside counsel spend will likely increase as enforcement actions begin and the DPBI sets precedents on automated processing, vendor oversight, and purpose limitation. Defensibility will rely on having clean, auditable records of consent and continuous regulator engagement. Exactly 260 days remain until the 13 May 2027 hard compliance deadline. General Counsel looking to evaluate their legal review burden and map patient data flows can assess their exposure at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act restrict training AI models on patient data?
The Act requires a valid lawful purpose under Section 4, meaning consent is the primary basis for processing, except where Section 7 legitimate uses apply. If patient notices do not clearly state that data will be used for AI training, processing it for this purpose may violate purpose limitation principles.
What is the penalty for unauthorized processing under the DPDP Act?
The Act imposes financial penalties with ceilings up to 250 crore rupees for severe compliance failures. General Counsel must ensure limitation of liability and indemnity clauses in vendor contracts account for this high regulatory exposure.
How quickly must a healthtech platform report a data breach?
Under the DPDP Rules, 2025, fiduciaries must issue an intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board of India within 72 hours. This requires maintaining accessible audit trails and vendor processing agreements at all times.
Can healthcare enterprises transfer data to foreign AI vendors?
Cross-border transfers are generally permitted under the DPDP Act unless the Central Government restricts transfer to specific notified countries or territories. Enterprises must still enforce strong data handling clauses and safe harbour protections when contracting with foreign vendors.
ComplyDP