NEWS ANALYSIS4 mins

DPBI Enforcement Delays and AI Data Conflicts Under DPDP Act 2023

Debates over DPBI enforcement powers are causing regulatory delays just as AI data demands clash with the DPDP Act 2023. Compliance heads at D2C enterprises must unbundle consent and prepare 72-hour breach workflows.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

According to a Nasscom community report, debates surrounding the independence and powers of the Data Protection Board of India (DPBI) are causing delays in the harmonization goals of the Ministry of Electronics and Information Technology. The DPBI was established following the Justice B.N. Srikrishna Committee recommendations to provide active enforcement for the Digital Personal Data Protection Act, 2023. However, institutional friction regarding its specific powers suggests a prolonged timeline for regulatory stability. This friction coincides with rising concerns over how the DPDP Act and the DPDP Rules, 2025 will govern the massive datasets required for artificial intelligence model training.

Does the DPDP Act Apply Here

Yes, Section 3 of the Act clearly defines the scope of these emerging AI data conflicts. The Act applies to the processing of digital personal data within the territory of India, and processing outside India if connected to offering goods or services to Data Principals in India. AI models often scrape or ingest vast amounts of information, meaning if this dataset contains digital personal data, the DPDP Act applies. Importantly, Section 3(c)(ii) provides an exemption for personal data made publicly available by the Data Principal or under a legal obligation. For D2C and e-commerce enterprises utilizing AI to analyze customer buying patterns, distinguishing between publicly available data and privately collected shopping histories is a critical scoping exercise.

Legal Implications Under DPDP

Under Section 4 of the DPDP Act, a person may process the personal data of a Data Principal only for a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For e-commerce enterprises using customer data to train AI recommendations, this means relying on bundled consent is no longer legally defensible. The DPDP Rules, 2025 require itemised notices that clearly state the purpose of data collection, and Rule 3 mandates translating these privacy notices into up to 22 regional languages. If an AI engine uses marketing data mixed with shipping data without unbundled consent artefacts, the processing violates the core purpose limitation principle. Furthermore, cross-border transfers of AI training data are generally permitted unless the Central Government restricts transfer to notified countries.

Could This Happen to You

If a compliance head at a large enterprise ignores the intersection of AI tools and data privacy, the regulatory exposure is severe. Consider a scenario where your marketing team implements a third-party AI tool to optimize email campaigns, feeding it raw customer purchase data. The DPBI is designed to ask for immediate audit trails and DPIA records if a breach or complaint occurs. If the AI vendor suffers a breach, the DPDP Rules, 2025 dictate an intimation to affected Data Principals without delay, alongside a detailed report to the DPBI within 72 hours. An auditor will demand to see the control owner, the unbundled consent records, and proof that your data privacy notice was accessible in the languages spoken by your Tier-2 customers. A heavy banking GRC tool often fails to adapt to these fast-moving D2C marketing stacks, leaving a gap in your evidence pack.

What Companies Should Do in the Next 30 Days

1. Map all AI integrations in your marketing and operations stacks, assigning a clear control owner to each vendor.

2. Implement a consent unbundler to separate transactional shipping data from AI marketing data, ensuring clear opt-ins.

3. Audit your privacy notices against Rule 3 of the DPDP Rules, 2025 to ensure translation capabilities for 22 regional languages are mapped.

4. Prepare a 72-hour breach intimation workflow, verifying that you can extract affected Data Principal contact details rapidly if an AI vendor is compromised.

5. Test your current RoPA against the DPBI expected evidentiary standards, focusing on data extraction and retention limits for AI models.

What to Watch

The friction regarding the DPBI enforcement powers and independence will likely lead to early test cases once the board begins formal audits. Enterprises should monitor how the DPBI handles data scraping exemptions under Section 3(c)(ii) for AI training. In the meantime, the compliance clock continues to tick. Exactly 264 days remain until the DPDP hard compliance deadline of 13 May 2027. Compliance heads must use this window to transition from theoretical framework mapping to deploying regulator-ready, automated consent artefacts by running a gap assessment at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act restrict AI model training on customer data?

Yes. Processing customer data for AI training requires a lawful purpose under Section 4. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning bundled consent in website terms and conditions is insufficient.

How do the DPDP Rules 2025 affect our marketing privacy notices?

The Rules require itemised notices detailing the exact purpose of data collection. Additionally, Rule 3 mandates that these notices be available in up to 22 regional languages, which is critical for D2C brands targeting Tier-2 markets in India.

What is the breach reporting timeline if a third-party AI vendor is compromised?

Under the DPDP Rules 2025, you must provide an intimation to affected Data Principals without delay. Furthermore, a detailed report must be submitted to the Data Protection Board of India within 72 hours.

Can we use traditional banking GRC tools for DPDP compliance?

While possible, traditional GRC tools often struggle with the dynamic nature of D2C marketing stacks. Enterprises need specific capabilities like consent unbundling and automated multi-language notice translation rather than just static risk dashboards.

When is the final deadline to comply with the DPDP Act?

The Central Government has set a strict timeline. Exactly 264 days remain until the DPDP hard compliance deadline of 13 May 2027.