News Analysis • 3 min read
DPDP Act Enforces Strict Consent for AI Training: Assessing BFSI Exposure
India's approach to AI governance relies on the DPDP Act, 2023, requiring explicit consent for model training and classifying large-scale processors as Significant Data Fiduciaries. We analyse the cross-border and consent implications for BFSI compliance leaders.
Last updated:
What happened
According to a recent legal analysis published on JD Supra, India is governing the rapid expansion of AI technology through existing frameworks like the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, rather than introducing a dedicated AI statute. The report highlights that AI developers and service providers face specific compliance requirements under the DPDP Act. Specifically, the analysis notes that training AI models requires explicit consent for processing personal data, including data scraped from public sources, as such processing falls outside predefined legitimate uses.
Does the DPDP Act apply here?
The extraterritorial reach of the DPDP Act is a critical factor for global financial institutions and their AI vendors. Under Section 3, the Act applies to processing digital personal data outside India if it is connected to offering goods or services to Data Principals within India. For a bank or insurer using a foreign AI vendor for underwriting or customer support, the offshore processor falls squarely within the regulatory perimeter. Furthermore, the Act explicitly limits its exemption for publicly available data under Section 3(c)(ii) to data made public by the Data Principal themselves or under a legal obligation. General web scraping of third-party public data for AI training does not automatically escape the Act.
Legal implications under DPDP
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The closed list of legitimate uses covers scenarios like employment or medical emergencies but excludes broad commercial activities like model training. When financial institutions process customer data to train proprietary credit or fraud models, they must issue itemised notices as prescribed by the DPDP Rules, 2025 and obtain verifiable consent. Additionally, entities processing large volumes of personal data will likely be classified as Significant Data Fiduciaries. This designation triggers mandatory obligations to conduct periodic Data Protection Impact Assessments and appoint an independent Data Protection Officer based in India.
Could this happen to you
Chief Compliance Officers at BFSI enterprises must recognise that their AI vendor stack is a massive compliance blind spot. If an AI processor suffers a breach or processes data without proper consent artefacts, the Data Protection Board of India will hold your institution accountable as the Data Fiduciary. In the event of a breach, the DPDP Rules, 2025 mandate an intimation to affected Data Principals without delay, followed by a detailed report to the DPBI within 72 hours. An auditor will immediately demand your evidence pack, including the Data Protection Impact Assessment for the AI tool, the underlying processor agreements, and proof that the training data had a lawful basis. Failure to produce a regulator-ready audit trail exposes the board to penalty ceilings of up to 250 crore rupees.
What companies should do in the next 30 days
1. The Chief Compliance Officer must direct control owners to update the Record of Processing Activities to explicitly include any personal data ingested by AI models, mapping each feed to a specific consent record.
2. The legal team should review all third-party AI vendor contracts to ensure cross-border data flows align with Section 16, under which transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories.
3. The Data Protection Officer must initiate a Data Protection Impact Assessment for any automated decision-making systems used in credit scoring or claims processing to satisfy anticipated Significant Data Fiduciary obligations.
What to watch
The DPBI enforcement strategy regarding AI model training and data scraping is expected to tighten as the implementation timeline progresses. Compliance heads should closely monitor how the DPBI interprets the intersection of verifiable consent and legacy data lakes used for machine learning. Exactly 279 days remain until the DPDP hard compliance deadline of 13 May 2027. Institutions unsure if their AI supply chain creates hidden DPBI exposure should evaluate their readiness today. Assess your regulatory gaps and start building your evidence pack at freescan.complydp.com before an auditor asks for it.
Sources
Frequently asked questions
Does the DPDP Act apply to foreign AI vendors processing data of Data Principals in India?
Yes. Under Section 3, the Act applies to processing digital personal data outside the territory of India if it is connected to offering goods or services to Data Principals within India. Foreign AI processors must comply with the Act when handling such data.
Can we use Section 7 legitimate uses to train AI models on customer data?
No. The DPDP Act features a closed list of legitimate uses, such as medical emergencies or employment purposes. AI model training does not fall under these categories, meaning consent is the primary basis for processing this data.
Are we allowed to scrape publicly available personal data for AI training?
The Act only exempts publicly available personal data if it was made public by the Data Principal to whom it relates, or under a legal obligation. Scraping third-party public data that does not meet this specific criteria requires valid consent.
What happens if our AI vendor suffers a data breach?
As the Data Fiduciary, your institution is ultimately responsible for the compliance of your processors. The DPDP Rules, 2025 require you to send an intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours, backed by a regulator-ready audit trail.
What is the penalty for failing to comply with these AI data processing rules?
Failing to secure lawful consent or manage vendor breaches can expose the board to significant financial risk. The Data Protection Board can levy penalties up to 250 crore rupees for severe compliance failures under the Act.
ComplyDP