News Analysis • 4 min read
Navigating the DPDP Act 2023 Conflict Between Data Access Rights and AI Trade Secrets
The lack of a trade secret carve-out in the DPDP Act 2023 creates operational friction for BFSI fiduciaries handling AI training. Learn how to balance Data Principal access rights under the DPDP Rules 2025 with proprietary algorithmic logic.
Last updated:
What Happened
According to a NASSCOM analysis, an operational conflict has surfaced between the individual right to access under the DPDP Act 2023 and corporate trade secrets in AI training. The Data Protection Board of India (DPBI), established following the Justice B.N. Srikrishna Committee recommendations, will enforce a framework that shifts legal philosophy from property rights to dignity rights. Debates surrounding the independence and powers of the DPBI indicate potential delays in achieving regulatory harmonization goals set by the Ministry of Electronics and Information Technology. This leaves a critical gap where proprietary AI training logic intersects with data access rights.
Does The DPDP Act Apply Here
Under Section 3 of the Act, the law applies to the processing of digital personal data within India, and processing outside India connected to offering goods or services to Data Principals in India. BFSI institutions heavily utilize AI models trained on vast datasets for credit scoring, KYC verification, and fraud detection. If these datasets include digital personal data, the Act applies fully. The legislation does not apply to anonymised data where the individual cannot be identified. For models processing personal data, consent is the primary basis for processing, except where Section 7 legitimate uses apply.
Legal Implications Under DPDP
The compliance friction centers on balancing Data Principal rights against intellectual property protection. The DPDP Act 2023 does not contain a specific trade secret carve-out. When a Data Principal exercises their right to access under the Act and the upcoming DPDP Rules 2025, fiduciaries must provide a summary of personal data and processing activities. For BFSI compliance teams, this creates a conflict of laws. You must choose between disclosing proprietary algorithmic logic to satisfy the access request or refusing it to protect trade secrets and facing penalties for non-compliance. Furthermore, if an AI model exposes personal data improperly, the Rules 2025 mandate intimation to affected Data Principals without delay, plus a detailed report to the DPBI within 72 hours.
Could This Happen To You
If a customer requests access to how their data was used in a loan approval AI model, your team must respond within the strict timelines set by the DPDP Rules 2025. An auditor or the DPBI would demand a clear evidence pack showing how the request was handled, authenticated, and fulfilled. If your current tool treats access requests as simple ticketing without linking them to a comprehensive Record of Processing Activities, you risk missing the disclosure threshold or over-disclosing proprietary algorithms. The penalty ceiling for failing to fulfill Data Principal obligations falls under the catch-all provision of up to rupees 50 crore, whereas the higher rupees 250 crore cap is exclusively reserved for security safeguard breaches. Managing this requires a regulator-ready workflow that generates an audit trail, not just another dashboard that overlaps with your existing GRC systems.
What Companies Should Do In The Next 30 Days
1. The Chief Compliance Officer must mandate a DPIA for all internal and third-party AI models processing personal data, assigning a clear control owner. 2. Update your RoPA to document exactly which data points feed into proprietary algorithms. 3. Define a standard operating procedure for handling access requests under the Rules 2025 that specifies how much processing logic is disclosed to the Data Principal. 4. Have legal counsel review this procedure to ensure it balances compliance with trade secret protection. 5. Verify that your consent artefacts explicitly cover AI processing purposes, ensuring you have an attestation ready for board reporting.
What To Watch
Monitor the ongoing debates regarding the independence and enforcement scope of the DPBI, which will dictate how aggressively access right violations are penalized. As the Ministry of Electronics and Information Technology works toward harmonizing this framework, further clarifications on the intersection of intellectual property and the DPDP Act 2023 may emerge. As per Section 1(2) of the Act, the exact enforcement dates are yet to be notified by the Central Government. To assess if your current consent and request workflows are audit-ready without requiring a multi-year GRC transformation, evaluate your exposure at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act cover AI training data?
Yes. If the AI training data includes digital personal data, the DPDP Act 2023 applies. Consent is the primary basis for processing, except where Section 7 legitimate uses apply.
Can we refuse a data access request to protect our trade secrets?
The DPDP Act 2023 does not contain a specific trade secret carve-out. Refusing a valid access request under the DPDP Rules 2025 to protect proprietary logic puts the organization at risk of penalties up to rupees 50 crore under the catch-all provision for failing to fulfill Data Principal obligations.
What happens if our AI model accidentally exposes personal data?
Such an exposure constitutes a personal data breach. Under the DPDP Rules 2025, you must provide intimation to affected Data Principals without delay, plus submit a detailed report to the DPBI within 72 hours.
How should BFSI compliance teams handle the overlap between GRC tools and DPDP access requests?
Organizations need a regulator-ready workflow that links access requests directly to a Record of Processing Activities. This ensures the correct level of data is disclosed without exposing underlying algorithmic trade secrets, generating a clear audit trail for the DPBI.
When is the deadline to comply with the DPDP Act 2023?
Organizations must align their data processing practices with the Act and the DPDP Rules 2025 before the enforcement dates. Under Section 1(2) of the Act, the exact commencement dates are yet to be notified by the Central Government.
ComplyDP