News Analysis4 mins

AI Scraping vs DPDP Act 2023: What Unmanaged Data Models Cost the Enterprise

A new analysis highlights the regulatory clash between AI data scraping and the DPDP Act 2023. For CFOs, shadow AI tools trained on personal data without purpose limitation create massive unprovisioned liabilities and threaten cyber insurance terms.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

A recent analysis published by the Nasscom community highlights the emerging legal friction between AI data scraping practices and India's Digital Personal Data Protection Act, 2023. The core issue involves the conflict between copyright laws, which may permit scraping public data like interviews for AI models, and privacy laws that demand strict purpose limitation. The report also notes that the Data Protection Board of India was established based on recommendations from the Justice B.N. Srikrishna Committee. Ongoing debates regarding the independence and powers of this Board are causing delays in the intention of the Ministry of Electronics and Information Technology to harmonize these digital regulations.

Does The DPDP Act Apply Here

Section 3 of the DPDP Act strictly applies to the processing of digital personal data within India, and processing outside India if connected to offering goods or services to Data Principals in India. A crucial carve-out exists under Section 3(c)(ii), which states the Act does not apply to personal data made publicly available by the Data Principal themselves or by someone under a legal obligation to do so. However, when AI companies scrape data published by third parties without the Data Principal's direct action, this exemption fails. For enterprise CFOs, this means any vendor using scraped personal data outside these narrow exemptions is generating a contingent liability on your balance sheet.

Legal Implications Under DPDP

The DPDP Act enforces the principle of purpose limitation under Section 4, requiring that personal data only be used for the specific purpose for which it was originally collected. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Furthermore, the DPDP Rules, 2025 introduce operational specifics that mandate clear, itemised notices before processing begins. If an AI vendor scrapes data without delivering this notice or securing verifiable consent, the enterprise using that AI model is exposed. A failure to prove compliance with these consent records can trigger penalty ceilings of up to 250 crore rupees, severely impacting enterprise EBITDA.

Could This Happen To You

Marketing, HR, and engineering teams frequently adopt AI scraping tools without proper procurement oversight. If one of these shadow AI tools ingests personal data without a lawful basis, your organization absorbs the regulatory risk. In the event of a breach or a regulatory audit, the DPDP Rules, 2025 require you to intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board of India within 72 hours. CFOs must ask if their current compliance stack can produce reliable consent and purpose limitation evidence in that 72-hour window. Failing this test instantly elevates audit fees, jeopardizes cyber insurance premiums, and complicates enterprise deal renewals.

What Companies Should Do In The Next 30 Days

1. Finance and procurement teams must conduct an immediate audit of all AI and data vendor contracts to identify shadow IT and unmapped contingent liabilities.

2. Legal and DPO functions must review all existing consent mechanisms against the itemised notice requirements specified in the DPDP Rules, 2025.

3. IT and compliance leaders must document a breach response workflow capable of generating a comprehensive DPBI report within the mandated 72-hour timeframe.

4. The CFO office must calculate the total cost of ownership for their current manual compliance efforts versus consolidating vendor oversight into a unified DPDP platform.

What To Watch

Exactly 268 days remain until the DPDP hard compliance deadline of 13 May 2027. During this countdown, enterprise leaders should closely monitor initial enforcement actions by the Data Protection Board of India, particularly regarding how they interpret the public data exemption for commercial AI models. Any regulatory clarification from MeitY will directly dictate compliance budgeting for the upcoming fiscal year. To evaluate your organization's exposure to unmapped data processing and audit readiness, run a self-guided assessment at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act impact our current AI vendor contracts?

The Act requires strict purpose limitation under Section 4. Finance teams must audit vendors to ensure they do not process scraped personal data without explicit consent or a valid Section 7 legitimate use, preventing unprovisioned contingent liabilities.

What happens if an AI tool we use breaches the DPDP Rules 2025?

Under the Rules 2025, you must intimate affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours. Failure to maintain these workflows risks regulatory penalties of up to 250 crore rupees.

Does the DPDP Act apply to publicly available data?

Section 3(c)(ii) exempts personal data made publicly available by the Data Principal themselves. However, data scraped from third parties who did not have the right to publish it remains subject to full DPDP compliance obligations.

How should we budget for DPDP compliance before the deadline?

With 268 days remaining until the 13 May 2027 deadline, CFOs should focus on vendor consolidation and automating consent records. Investing in a unified platform lowers total cost of ownership compared to fragmented manual audit fees.