NEWS ANALYSIS4 mins

DPDP Act vs AI Trade Secrets: Quantifying Contingent Liabilities for Enterprises

A growing conflict between the DPDP Act 2023 and intellectual property rights threatens to expose AI trade secrets. We analyse the financial and regulatory exposure for enterprise CFOs facing this compliance dilemma.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

A recent Nasscom community publication outlines a growing legal conflict between the Digital Personal Data Protection Act, 2023, and the protection of Artificial Intelligence trade secrets in India. The report notes that the DPDP framework shifts the legal philosophy from property rights, where companies assume ownership of datasets, to dignity rights that grant individuals control over their digital footprint. As MeitY operationalises the Data Protection Board of India, established following the Justice B.N. Srikrishna Committee recommendations, debates regarding the board's independence and powers continue. The publication highlights a critical gap in the current framework: the absence of a specific trade secret carve-out for Data Fiduciaries handling access requests.

Does the DPDP Act apply here?

The statutory scope under Section 3 of the DPDP Act firmly encompasses AI training datasets if they contain digital personal data. The Act applies to the processing of digital personal data within the territory of India, as well as processing outside India if connected to offering goods or services to Data Principals within India. While Section 3 exempts personal data made publicly available by the Data Principal themselves or under a legal obligation, massive AI datasets often rely on broader web scraping that does not automatically qualify for this exemption. For finance leaders evaluating the total cost of ownership for AI investments, any system ingesting personal data without explicit exemption creates immediate compliance obligations.

Legal implications under DPDP

Section 4 of the Act dictates that a person may process personal data only for a lawful purpose where consent is the primary basis for processing, except where Section 7 legitimate uses apply. The core conflict arises when fulfilling rights requests governed by the DPDP Rules 2025. When a Data Principal exercises their right to access, the Data Fiduciary must provide a summary of the personal data and the processing activities. Because the Act lacks an intellectual property exemption, complying with a detailed access request might force an enterprise to expose proprietary AI logic and algorithms. This presents CFOs with a severe conflict of laws: disclose core trade secrets that drive enterprise value, or withhold the information and face a massive contingent liability from DPBI penalties.

Could this happen to you

If your enterprise is deploying proprietary AI models or relying on third-party AI vendors, this conflict directly impacts your risk profile and EBITDA. When an access request arrives, relying on fragmented, manual compliance processes means your team will struggle to separate personal data from proprietary training logic within the mandated timelines. The DPBI will demand verifiable evidence of your data lineage and processing purposes. Failing to produce this due to intellectual property concerns triggers penalty exposures of up to 250 crore rupees per breach. For a CFO, this unquantified risk can immediately spike cyber insurance premiums and complicate external audit fees. Consolidating these requirements into an automated platform is not just another recurring software cost, but a necessary strategy to cap contingent liabilities and protect enterprise valuation.

What companies should do in the next 30 days

1. Direct the procurement and legal teams to review all contracts with AI vendors to identify who holds the primary Data Fiduciary liability for access requests.

2. Quantify the potential financial exposure of failing to fulfill data access requests versus the cost of intellectual property leakage, presenting this variance to the board.

3. Evaluate your current cyber insurance policy to confirm whether fines levied by the DPBI for non-compliance are covered, and adjust provisioning accordingly.

4. Initiate a vendor consolidation exercise to replace manual, fragmented compliance tracking with a unified data mapping tool that provides clear evidence trails for auditors without exposing trade secrets.

What to watch

The industry is actively awaiting MeitY and the DPBI to clarify a middle-path approach that balances individual dignity rights with intellectual property protection. With exactly 273 days remaining until the DPDP hard compliance deadline of 13 May 2027, enterprise finance leaders must ensure their compliance budgets are finalised and actively deployed. Tooling that automates consent records, access request workflows, and data mapping will be critical to satisfying DPBI demands efficiently. To evaluate your organisation's current gap between AI deployment and DPDP readiness without incurring initial consulting fees, run a baseline assessment at freescan.complydp.com today.

Sources

Frequently asked questions

Does the DPDP Act apply to AI training data?

Yes, Section 3 of the DPDP Act applies to the processing of digital personal data within India, including data used for AI training. There is no blanket exemption for scraped data unless it was made publicly available directly by the Data Principal or under a legal obligation.

How does the DPDP Act impact intellectual property like AI algorithms?

The DPDP Act currently lacks a trade secret carve-out for data access requests. This creates a risk where fulfilling a Data Principal's request under the DPDP Rules 2025 might require an enterprise to expose proprietary AI logic to explain the processing.

What are the financial risks of ignoring DPDP compliance for AI systems?

Non-compliance creates massive contingent liabilities, with DPBI penalties reaching up to 250 crore rupees for severe breaches. This exposure directly impacts enterprise EBITDA, increases audit fees, and can significantly raise cyber insurance premiums.

How should a CFO budget for DPDP compliance?

CFOs should view compliance tooling as a vendor consolidation opportunity that reduces overall total cost of ownership. Automating evidence trails and consent records costs a fraction of manual legal reviews and unmitigated penalty exposures.

When is the deadline to comply with the DPDP Act?

The hard compliance deadline is 13 May 2027, leaving exactly 273 days for enterprises to map their data flows and establish compliance frameworks. Financial provisioning and tool procurement should be finalized well before this date.