NEWS ANALYSIS • 4 min read
AI Training and Trade Secrets: Navigating the Missing Exemption in the DPDP Act
An analysis of the conflict between AI training, trade secret protections, and DPDP Act compliance, focusing on financial exposure for EdTech enterprises lacking algorithmic carve-outs.
Last updated:
What happened
A Nasscom community analysis highlights an emerging legal conflict between AI training requirements, trade secret protections, and compliance obligations under the Digital Personal Data Protection Act, 2023. The report notes that the Data Protection Board of India was established following the Justice B.N. Srikrishna Committee report to enforce the framework, though current debates regarding the Board's independence may delay harmonization goals by the Ministry of Electronics and Information Technology. Critically, the analysis identifies that the current framework lacks a specific trade secret carve-out for data access rights. This omission forces companies to choose between disclosing proprietary logic to satisfy an individual's right to access or facing regulatory penalties for non-compliance.
Does the DPDP Act apply here?
Under Section 3, the Act applies to the processing of digital personal data within the territory of India, and processing outside India connected to offering goods or services to Data Principals in India. For an EdTech enterprise, this means any proprietary recommendation algorithm or adaptive learning model trained on digital student data falls squarely under this jurisdiction. While the Act exempts data made publicly available by the Data Principal, typical telemetry and behavioral profiles generated by learning platforms are strictly regulated. The shift from treating data as corporate property to protecting it as a dignity right means your company cannot simply claim ownership over ingested training datasets to bypass compliance.
Legal implications under DPDP
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Under the DPDP Rules, 2025, EdTech platforms face the added complexity of implementing verifiable parental consent mechanics before processing data of individuals under eighteen. Once data is collected, Data Principals hold a statutory right to request information about how their personal data is processed. The critical issue is the absence of a trade secret exemption in the DPDP Act, 2023 to limit these disclosures. If a parent demands details on how an AI engine processes their child's behavioral data, EdTech companies risk exposing proprietary logic to fulfill the access mandate.
Could this happen to you
If the Data Protection Board of India examines your EdTech platform today, they will demand an audit trail proving how parental consent tokens govern your AI data flows. Without a statutory trade secret carve-out, your Chief Product Officer faces a serious operational dilemma regarding access requests. Refusing a legitimate request to protect adaptive learning intellectual property could trigger penalty ceilings up to 250 crore rupees. Financial leaders must budget for this contingent liability, as unresolved data compliance gaps directly increase cyber insurance premiums and threaten EBITDA during enterprise vendor consolidation.
What companies should do in the next 30 days
1. The CFO and Head of Legal must review the compliance budget to provision for total cost of ownership regarding automated consent workflows, minimizing manual data extraction costs.
2. The Chief Product Officer should map all AI recommendation engines to identify exact points where personal data processing intersects with proprietary trade secrets.
3. Implement Rule 10 workflows for verifiable parental consent that integrate smoothly with existing user onboarding processes, preventing significant drop-off rates.
4. Consolidate your vendor stack by selecting compliance platforms that natively handle both itemised notices and the mandatory 72-hour breach reporting to the DPBI required by the Rules, 2025.
What to watch
Financial officers should monitor MeitY for any future guidance that resolves the friction between AI innovation and data privacy enforcement. We expect the DPBI to eventually clarify its stance on intellectual property protections as enforcement actions begin. Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess your immediate contingent liability regarding verifiable parental consent and AI data processing, start with a gap analysis at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to AI training models in the EdTech sector?
Yes. The Act covers digital personal data processed within the territory of India, and processing outside India connected to offering goods or services to Data Principals in India. Any AI processing student or behavioral data falls under this jurisdiction.
Can we withhold proprietary algorithms when responding to data access requests?
Currently, the DPDP Act, 2023 lacks a specific trade secret exemption. Companies must balance the statutory duty to fulfill Data Principal access rights against protecting their intellectual property, pending further regulatory clarification.
What are the financial risks of ignoring DPDP compliance in AI deployments?
Failing to fulfill access rights or mishandling children's data exposes enterprises to penalty ceilings of up to 250 crore rupees. This contingent liability directly impacts EBITDA and drives up cyber insurance premiums.
How do the DPDP Rules, 2025 affect EdTech user onboarding?
The Rules mandate verifiable parental consent mechanics before processing the data of individuals under eighteen. EdTech platforms must implement specialized workflows that secure this consent without breaking the user experience.
What is the notification timeline if our AI dataset suffers a breach?
The DPDP Rules, 2025 require intimation to affected Data Principals without delay. Additionally, you must submit a detailed breach report to the Data Protection Board of India within 72 hours.
ComplyDP