News Analysis4 min read

AI Training Under DPDP Act 2023: Navigating the Shift from Property to Dignity Rights

As the Data Protection Board of India establishes its enforcement scope, the DPDP Act 2023 shifts personal data from a corporate asset to a dignity right, directly impacting how enterprises govern AI training datasets.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

According to a report published on the NASSCOM Community platform, ongoing debates over the independence and regulatory powers of the newly established Data Protection Board of India (DPBI) are expected to delay regulatory harmonization efforts by the Ministry of Electronics and Information Technology (MeitY). The DPBI was originally established following recommendations from the Justice B.N. Srikrishna Committee report to serve as an enforcement body. The report highlights that alongside these institutional developments, the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025 introduce a paradigm shift in how data is legally treated for artificial intelligence training. Specifically, the framework transitions personal data from a corporate property right to a dignity right, giving individuals direct control over their personal data collection, processing, and storage.

Does The DPDP Act Apply Here

The DPDP Act, 2023 applies to the processing of digital personal data within India, as well as processing outside India if connected to offering goods or services to Data Principals in India. According to Section 3 of the Act, if your enterprise AI models scrape, ingest, or process digital personal data, the law strictly governs those activities. Crucially, the Act does not apply to personal data made publicly available by the Data Principal themselves, or by any other person who is under an obligation under any law to do so. However, enterprise compliance heads must ensure that data scraped from the internet for AI training falls cleanly into this exception, as distinguishing between user-published data and unauthorized third-party leaks is complex. Datasets that do not contain personal data remain outside the scope of the DPDP Act.

Legal Implications Under DPDP

Under Section 4 of the Act, processing the personal data of a Data Principal must be in accordance with the Act and for a lawful purpose, based either on verifiable consent or for certain legitimate uses. For enterprise AI developers, treating scraped personal data as corporate property is no longer legally permissible without a valid legal basis. The DPDP framework requires companies to transparently detail the purpose of data ingestion for AI models. Furthermore, purpose limitation dictates that data collected for a specific business transaction cannot be arbitrarily repurposed for machine learning without obtaining fresh consent artefacts. If a breach occurs within these AI datasets, the law mandates an intimation to affected Data Principals and a detailed incident report to the Data Protection Board of India in the prescribed manner.

Could This Happen To You

For a Head of Compliance at a large enterprise, undocumented AI training pipelines represent a critical regulatory blind spot. If an employee inputs customer data into an internal AI tool without authorization, or if a vendor scrapes data without a valid legal basis, your organization faces direct exposure. If the Data Protection Board of India investigates a complaint regarding unauthorised AI processing, they will request your consent artefacts and Records of Processing Activities. You will need to produce an audit trail demonstrating exactly how the data was sourced and what notice was presented to the Data Principal. Failing to maintain these regulator-ready controls exposes your enterprise to significant statutory penalties for data governance failures.

What Companies Should Do In The Next 30 Days

1. Map the exact flow of personal data across all internal and vendor-supplied AI models to ensure compliance with the DPDP Act. 2. Update your Records of Processing Activities to clearly document the legal basis (consent or legitimate uses) for any personal data used in machine learning environments. 3. Implement strict access controls and evidence trails, assigning a specific control owner to approve any new dataset introduced to your AI training pipelines. 4. Review vendor agreements to ensure they indemnify your enterprise against unauthorized data scraping and align with statutory breach reporting timelines. 5. Audit your consent mechanisms and notices to verify they explicitly cover AI training if personal data is utilised for that purpose.

What To Watch

As the Ministry of Electronics and Information Technology resolves the operational scope and independence of the Data Protection Board of India, expect heightened scrutiny on enterprise data pipelines. The DPDP Rules, 2025 will begin to shape enforcement precedents, particularly around how verifiable consent is collected for complex data processing like machine learning. Large enterprises must treat this harmonization period as a vital window to transition their data practices from property-based assumptions to compliant, consent-driven frameworks. Compliance teams must act swiftly to ensure readiness. To evaluate how your current AI data practices map against these upcoming regulatory requirements, run a confidential gap analysis at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to data scraped from the internet for AI training?

Yes, the DPDP Act applies to the processing of digital personal data within India, and processing outside India if connected to offering goods or services to Data Principals in India. It does not apply if the personal data was made publicly available by the Data Principal themselves or someone legally obligated to do so, but distinguishing this from third-party leaks requires strict oversight.

Can we use existing enterprise customer data to train our internal AI models?

Under Section 4 of the DPDP Act, 2023, you must have a valid legal basis for a lawful purpose. If your original notice and consent did not explicitly cover artificial intelligence training, you cannot arbitrarily repurpose that customer data. You must collect fresh consent artefacts from the Data Principals or establish a legitimate use before introducing it to your pipelines.

What happens if an AI vendor suffers a data breach involving our data?

Your enterprise remains accountable for the governance of personal data processed on your behalf. According to the DPDP framework, you must provide a breach intimation to affected Data Principals and submit a detailed incident report to the Data Protection Board of India within the statutory timelines prescribed by the rules.

How does the DPDP Act change the corporate ownership of personal data?

The DPDP Act shifts the legal philosophy from property rights to dignity rights. Companies can no longer treat lists of collected personal data as corporate assets to be freely mined for machine learning. Individuals retain control over their data, requiring enterprises to maintain continuous audit trails and verifiable consent records.

What is the financial risk for failing to secure AI data under the DPDP Act?

The Data Protection Board of India acts as an enforcement body with the power to impose substantial fines for non-compliance. Severe data governance failures, such as failing to prevent a personal data breach within your AI architecture, expose your organization to significant statutory penalties. Compliance teams must ensure their records are regulator-ready to mitigate this exposure.