News Analysis • 4 mins
DPDP Act vs AI Trade Secrets: The Compliance Dilemma for Fintech CFOs
An analysis highlights the conflict between a Data Principal's right to access personal data under the DPDP Act and a company's intellectual property. Fintech CFOs face a compliance dilemma with significant EBITDA implications.
Last updated:
What happened
An analysis published on the Nasscom community platform highlighted a growing legal conflict between artificial intelligence training practices and the Digital Personal Data Protection Act, 2023. The report notes a direct tension between an individual's right to access their personal data and a company's intellectual property, specifically trade secrets.
The analysis points out that the Data Protection Board of India (DPBI), established following recommendations from the Justice B.N. Srikrishna Committee report, is stepping into a complex enforcement environment. Debates over the DPBI's independence and exact regulatory powers indicate it will take longer to achieve the harmonization goals intended by MeitY.
Does the DPDP Act apply here?
Under Section 3, the DPDP Act applies to the processing of digital personal data within India, as well as processing outside India if connected to offering goods or services to Data Principals in India. If a fintech enterprise trains its proprietary credit scoring or fraud detection algorithms using such data, that activity is fully regulated.
The DPDP Act covers this personal data regardless of whether the output model is considered corporate intellectual property. It does not apply to non-personal or fully anonymised data, but the raw personal inputs feeding into these artificial intelligence systems remain strictly subject to the Act.
Legal implications under DPDP
The DPDP Act and the DPDP Rules, 2025 shift the underlying legal philosophy from property rights, where a company functionally owns a data list, to dignity rights, where individuals control their information. Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply.
The primary legal friction is the absence of a specific trade secret carve-out in the Act. When a Data Principal exercises their right to access under the Rules, 2025, Data Fiduciaries face a conflict of laws. They must choose between disclosing elements of proprietary algorithmic logic to satisfy the access request, or withholding it and facing penalties for non-compliance.
Cross-border transfers of this data for global artificial intelligence training are generally permitted unless the Central Government restricts transfer to notified countries or territories on a negative list. However, sending the data abroad does not extinguish the access rights of the Data Principal.
Could this happen to you
For a CFO at a high-growth fintech, this conflict of laws represents a material contingent liability. Payments and lending platforms operate under rapid product cycles that often outpace legal review, further complicated by overlapping RBI digital lending guidelines and account-aggregator API ingestion.
If users begin filing access requests to understand what data fed a loan rejection, the finance and product teams face a severe dilemma. Refusing the request risks DPBI penalties with a ceiling of up to 250 crore rupees per breach, directly threatening EBITDA and driving up cyber insurance premiums.
Conversely, over-disclosing to the user risks exposing the trade secrets that justify your enterprise valuation. An auditor or the DPBI will demand an itemised record of the access request workflow, requiring you to prove compliance without leaking corporate intellectual property.
Additionally, if this training data is compromised, the Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. Producing these forensic trails manually will result in soaring audit fees and massive operational drag.
What companies should do in the next 30 days
1. Quantify the total cost of ownership for compliance tooling versus the contingent liability of DPBI penalties, securing budget provisioning for an automated consent and access request platform.
2. Task the engineering and compliance leads to map exactly which digital personal data inputs feed into your proprietary machine learning models in short sprint cycles.
3. Establish a clear internal policy, documented by the legal team, defining the boundaries of data access responses to fulfill DPDP obligations without exposing algorithmic trade secrets.
4. Consolidate vendors by identifying a single platform capable of managing itemised notices, verifiable parental consent mechanics, and data access workflows as required by the Rules, 2025.
What to watch
270 days remain until the DPDP hard compliance deadline of 13 May 2027. Finance and compliance leaders must monitor the evolving enforcement posture of the DPBI and any future MeitY guidance on navigating this trade secret dilemma.
Analysts suggest a middle-path approach may eventually emerge to balance individual rights with corporate innovation. To evaluate your current exposure to these data access requirements and avoid compounding software line items, check your baseline readiness at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to AI training models in fintech?
Yes. Under Section 3, the Act applies to digital personal data processed within India. If your fintech trains models on personal data, that data is regulated, even if the resulting algorithm is a trade secret.
Can we refuse data access requests to protect our trade secrets?
The DPDP Act currently lacks a specific carve-out for trade secrets. Refusing a valid access request under the Rules, 2025 can trigger non-compliance proceedings, creating a significant contingent liability for the enterprise.
What are the financial risks of ignoring these data access obligations?
Non-compliance carries penalty ceilings of up to 250 crore rupees. For a CFO, this directly impacts EBITDA, inflates audit fees, and can severely increase cyber insurance premiums.
How does the DPDP Act handle cross-border data transfers for AI processing?
Transfers are generally permitted unless the Central Government restricts transfer to a notified negative list of countries. This flexibility allows global processing, provided all other DPDP obligations are met.
What are the breach notification requirements if our AI training data is compromised?
The DPDP Rules, 2025 mandate intimation to affected Data Principals without delay and a detailed report to the Data Protection Board of India within 72 hours.
ComplyDP