NEWS ANALYSIS4 mins

AI Training and Trade Secrets: Managing DPDP Act 2023 Compliance Conflicts

An analysis of the emerging conflict between AI training data requirements and DPDP Act compliance, focusing on the right to access, trade secrets, and how compliance heads can prepare their consent architectures.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

A recent analysis outlines an emerging conflict between artificial intelligence training requirements and the Digital Personal Data Protection (DPDP) Act, 2023. The report notes that the DPDP Act and the DPDP Rules, 2025 shift the legal philosophy of personal data from a corporate property right (owning a list) to an individual dignity right granting individuals control over their personal data. Companies training AI models face a compliance dilemma because the Act lacks a specific 'trade secret carve-out', forcing a direct conflict of laws. Disclosing proprietary AI logic to satisfy a Data Principal's right to access could expose valuable trade secrets, while failing to do so invites strict penalties for non-compliance.

Does The DPDP Act Apply Here

Under Section 3, the Act applies to the processing of digital personal data within the territory of India, as well as processing outside India if connected to offering goods or services to Data Principals in India. For large enterprises, AI models powering product recommendations or personalized marketing rely heavily on massive customer datasets. One critical edge case is Section 3(c)(ii), which exempts personal data made publicly available by the Data Principal. However, internal customer transaction records and marketing profiles used to train proprietary recommendation engines remain fully regulated digital personal data.

Legal Implications Under DPDP

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For platforms relying on machine learning, this means valid consent is required to feed customer data into AI training models. If a customer exercises their right to access, the Data Fiduciary must provide a summary of the personal data processed and the underlying processing activities. Providing this access report without a trade secret exemption means compliance teams must carefully construct data extracts that satisfy the regulator without handing over proprietary algorithm logic. Furthermore, the Data Protection Board of India (DPBI) was established based on the Justice B.N. Srikrishna Committee report recommendations to act as the primary enforcement body. Ongoing debates over the DPBI's independence and powers directly affect MeitY's intent to harmonize AI innovation and data rights.

Could This Happen To You

If you manage compliance at a major data-driven enterprise, this conflict directly impacts your recommendation engines and marketing algorithms. A single access request from an unhappy user could trigger an internal scramble to produce a regulator-ready evidence pack explaining how your AI processed their data. If your marketing data is entangled with core operational data because you bundled consent, an auditor will flag this immediately. Furthermore, if an AI vendor suffers a data leak, the DPDP Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. You must ask whether your current GRC tools can produce that audit trail or if they are ill-suited for high-volume data requirements.

What Companies Should Do In The Next 30 Days

1. Map all AI and machine learning data pipelines in your Record of Processing Activities to identify exactly where personal data feeds algorithmic training. 2. Implement a consent unbundler to legally separate essential processing from optional AI analysis. 3. Update your privacy notices to meet the DPDP Rules, 2025 requirements, ensuring they are automatically translated into regional languages. 4. Draft a standardized access request response template with your legal counsel that fulfills data access obligations without exposing proprietary trade secrets. 5. Assign a control owner to review third-party AI vendor contracts for strict purpose limitation clauses and breach intimation workflows.

What To Watch

The industry is closely monitoring how regulators will interpret data access rights when they intersect with corporate intellectual property. A proposed 'middle-path approach' is becoming increasingly necessary to balance strict privacy enforcement with ongoing AI innovation. Enforcement actions regarding automated processing and AI will likely define the acceptable boundaries for data extraction summaries. Compliance heads must treat this as an immediate operational priority rather than a distant theoretical debate. Exactly 286 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess if your current consent architecture and AI data pipelines are compliant, run a diagnostic at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to AI training datasets?

Yes, if the dataset contains digital personal data processed within India or involves offering goods or services to Data Principals in India. The only major exception under Section 3 is if the Data Principal made the personal data publicly available themselves.

Can we bundle AI marketing consent with our general terms of service?

No, bundling consent is prohibited under the new framework. Consent must be free, specific, informed, and unconditional, meaning you must separate essential data consent from optional AI marketing analysis.

Are there exemptions for proprietary algorithms or trade secrets?

The DPDP Act, 2023 currently lacks a specific carve-out for trade secrets. When responding to a data access request, compliance teams must carefully balance providing a transparent processing summary without disclosing proprietary AI logic.

What happens if our AI data vendor experiences a security breach?

Under the DPDP Rules, 2025, the primary Data Fiduciary is responsible for breach intimation to affected Data Principals without delay. You must also submit a detailed breach report to the Data Protection Board of India within 72 hours, making robust vendor oversight critical.

How many languages do our privacy notices need to support?

The DPDP Rules, 2025 require itemised notices to be accessible in multiple languages specified in the Eighth Schedule of the Constitution. Translating these notices effectively is a mandatory compliance step to ensure valid consent across Indian markets.