News Analysis4 min read

AI Training vs DPDP Act 2023: Navigating Regulatory Exposure and Board Accountability

Debates over the DPBI's enforcement powers suggest potential delays in regulatory harmonisation, but BFSI legal heads must still prepare for strict AI data rules under the DPDP Act 2023 and DPDP Rules 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

According to a report on the Nasscom community platform, ongoing debates surrounding the independence and enforcement powers of the Data Protection Board of India are creating potential delays in regulatory harmonisation by the Ministry of Electronics and Information Technology. The report highlights a growing conflict between artificial intelligence training requirements and the privacy mandates of the Digital Personal Data Protection Act, 2023. As developers ingest massive datasets, the intersection of privacy, copyright, and trade secrets is triggering intense regulatory scrutiny.

The DPBI, tracing its origins to the Justice B.N. Srikrishna Committee report, is meant to function as a living enforcement framework. However, current debates suggest a longer timeline for MeitY to finalise a unified regulatory approach just as the DPDP Rules, 2025 prepare to tighten compliance. This structural uncertainty creates a challenging environment for financial institutions attempting to map data governance frameworks to upcoming obligations.

Does the DPDP Act apply here?

General Counsel must evaluate Section 3 of the DPDP Act to determine applicability when enterprise AI models ingest data. The Act applies to the processing of digital personal data within the territory of India, as well as processing outside India if connected to offering goods or services to Data Principals in India. AI training models often rely on scraped or aggregated datasets, which frequently contain personal data.

Section 3 clarifies that the Act does not apply to personal data made publicly available by the Data Principal to whom it relates, or by a person under a legal obligation to do so. However, assuming all third-party training data falls under this exemption carries massive legal risk. If an internal AI model processes personal data that does not fit this narrow exemption, the full weight of the DPDP Act and the DPDP Rules, 2025 applies to the enterprise.

Legal implications under DPDP

When AI models process personal data, Section 4 dictates that processing is only lawful when based on valid grounds. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Financial institutions using customer data to train credit algorithms or fraud detection models must ensure the original consent explicitly covers AI training as a purpose.

Furthermore, cross-border transfers for offshore AI processing are generally permitted unless the Central Government restricts transfer to notified countries through a negative list. Legal heads must ensure their vendor contracts contain specific limitation of liability clauses and clear indemnities for processors handling this data. Failure to secure valid consent or properly document legitimate uses destroys defensibility during a regulatory audit.

Could this happen to you

For a large bank or insurer, the push to deploy artificial intelligence for underwriting or customer service creates immediate exposure. If a third-party AI vendor experiences a data breach or misuses training data, the DPBI will look directly at your financial institution as the accountable Data Fiduciary. Managing regulatory engagement under these conditions requires immediate, documented proof of processor oversight.

Under the DPDP Rules, 2025, you must provide intimation to affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours. Could your outside counsel or internal compliance team produce a complete audit trail of consent and a signed data processor agreement within that window? Without automated consent records and mapped processor oversight, a failure here risks penalties capped at 250 crore rupees per instance.

What companies should do in the next 30 days

1. Conduct a privileged review of all current and planned AI training datasets to identify digital personal data subject to the Act.

2. Update vendor processor agreements to include strict limitation of liability and indemnity clauses regarding AI model training and data handling.

3. Map existing customer consent logs to ensure AI development is explicitly stated as a purpose, avoiding reliance on implied consent.

4. Establish a breach workflow aligned with the DPDP Rules, 2025 that ensures the 72-hour DPBI reporting requirement can be met without heavy manual effort.

What to watch

General Counsel should monitor the resolution of debates surrounding the independence and powers of the DPBI. How these issues are settled will dictate the aggressiveness of initial regulatory enforcement. Companies must also watch for further clarifications from MeitY on the exact mechanics of the DPDP Rules, 2025 regarding automated processing and AI.

Exactly 277 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal teams must finalise their safe harbour strategies and compliance frameworks well before this date. To evaluate your current readiness and identify gaps in your AI data governance, take a baseline assessment at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act restrict the use of customer data for AI training?

Yes, under Section 4, processing requires a lawful purpose based on consent or a Section 7 legitimate use. General Counsel must ensure that legacy consent notices explicitly cover AI model training. Processing personal data without this explicit alignment creates major regulatory exposure.

Are web-scraped datasets exempt from the DPDP Act?

Section 3 exempts personal data made publicly available by the Data Principal to whom it relates or by someone under a legal obligation. However, assuming all scraped data meets this narrow criteria is dangerous. Unlawfully processing non-exempt personal data triggers severe penalties.

What happens if an offshore AI vendor experiences a data breach?

As the Data Fiduciary, your organisation is directly accountable to the Data Protection Board of India. The DPDP Rules, 2025 require you to intimate affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours. Strong indemnities and automated breach workflows are critical for defensibility.

What is the maximum penalty for failing to manage AI data compliance?

Penalties under the DPDP Act can reach up to 250 crore rupees for significant failures to prevent personal data breaches. Other violations, such as failing to obtain valid consent or missing breach reporting timelines, carry distinct multi-crore fines. This financial risk elevates DPDP compliance to a board-level issue.

Can my legal team manage DPDP compliance manually?

Managing consent mapping, vendor oversight, and breach reporting for massive AI datasets manually requires excessive outside counsel spend and internal hours. Meeting the 72-hour reporting window under the DPDP Rules, 2025 requires automated systems to maintain an audit-ready state.