News Analysis • 5 mins
ANI v. OpenAI Delhi High Court Case Exposes DPDP Act Risks in AI Data Ingestion
Analysis of the Delhi High Court's ANI v. OpenAI judgement reveals that ingesting third-party data for AI models triggers stringent data protection obligations under the DPDP Act 2023, requiring fintech compliance teams to audit their data supply chains.
Last updated:
What happened
An article examining the Delhi High Court judgement in ANI v. Open AI argues that the legal reasoning extends significantly beyond copyright law. The analysis connects AI data ingestion practices directly to the Digital Personal Data Protection Act, 2023. By evaluating the intersection of foundational AI training models and publisher data, the court proceedings highlight how intellectual property rights and data privacy obligations overlap in India.
Does the DPDP Act apply here
For large enterprises, particularly in fintech where data-driven credit and fraud models rely heavily on external datasets, the application of Section 3 of the Act is a critical risk factor. Section 3(a) states that the Act applies to the processing of digital personal data within the territory of India. Crucially, Section 3(c)(ii) clarifies that the Act only exempts personal data made publicly available by the Data Principal themselves, or by a person under a legal obligation to publish it. Scraping personal data embedded within copyrighted news articles or third-party registries does not automatically exempt that data from DPDP Act coverage.
Legal implications under DPDP
Under Section 4 of the DPDP Act 2023, consent is the primary basis for processing, except where Section 7 legitimate uses apply. If an AI model ingests digital personal data, the data fiduciary must either secure consent or establish a valid legitimate use. The DPDP Rules, 2025 further specify how itemised notices must be presented to obtain verifiable consent artefacts. Ingesting third-party databases without serving these itemised notices or proving a Section 7 exemption leaves the organization unable to demonstrate a legal basis for processing.
Could this happen to you
In the rapid product cycles of a fintech startup, alternative credit scoring models often ingest vast amounts of external unstructured data. If your engineering teams scrape public profiles or purchase third-party datasets to train these models, your data supply chain is highly exposed. In the event of a regulatory inquiry, the Data Protection Board of India (DPBI) will demand a complete Record of Processing Activities (RoPA) and a robust evidence pack demonstrating the legal basis for processing that specific data. Furthermore, if that AI training database suffers a compromise, the DPDP Rules, 2025 mandate intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. Failing to manage this pipeline carries severe financial risk, with penalty ceilings up to 250 crore rupees for data breach failures.
What companies should do in the next 30 days
Heads of Compliance must collaborate with product leads to audit all AI data ingestion pipelines and secure their rapid release cycles.
1. Update the RoPA to include all external data sources used for machine learning models, mapping the specific legal basis for each pipeline. Owner: Product Lead.
2. Conduct a Data Protection Impact Assessment (DPIA) on alternative credit scoring algorithms to evaluate the risk of ingesting non-exempt public personal data. Owner: Head of Compliance.
3. Review vendor agreements with third-party data providers to mandate contractual attestations that their data collection mechanisms comply with DPDP Rules, 2025 notice requirements. Owner: Legal Team.
What to watch
The interplay between copyright enforcement and DPBI mandates will shape how foundational AI models operate on Indian digital personal data. Compliance teams should watch for further adjudications clarifying the strict boundaries of Section 3(c)(ii) exemptions. Exactly 276 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess whether your rapid product cycles and external data pipelines expose your enterprise to regulatory action, evaluate your compliance posture today at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to publicly available personal data scraped for AI?
Yes, in most cases. Section 3 of the DPDP Act 2023 only exempts personal data made publicly available directly by the Data Principal or under a legal obligation. Scraping personal data from third-party websites or articles typically falls under full DPDP Act compliance requirements.
How does AI data ingestion affect fintech credit scoring models?
Fintech companies using external datasets for alternative credit scoring must justify the processing of any embedded personal data. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. If the data is not exempt, you must issue itemised notices per the DPDP Rules, 2025.
What evidence will the DPBI demand if our AI models ingest non-compliant data?
The Data Protection Board of India will require a comprehensive Record of Processing Activities (RoPA) and a clear audit trail of consent artefacts. Your enterprise must produce an evidence pack demonstrating that a valid legal basis exists for every dataset processed within your infrastructure.
What are the financial penalties for failing to secure AI data pipelines?
The DPDP Act prescribes severe financial penalties for compliance failures. Companies can face penalty ceilings up to 250 crore rupees for failing to observe reasonable security safeguards that prevent a personal data breach.
When must we report a breach involving our AI training datasets?
Under the DPDP Rules, 2025, any personal data breach must be reported to the DPBI within 72 hours. You must also provide intimation to the affected Data Principals without delay, outlining the nature of the breach and remediation steps.
ComplyDP