News Analysis • 4 min read
AI Trade Secrets vs Data Rights: Navigating the DPDP Conflict for HealthTech General Counsels
The DPDP Act currently lacks a trade secret exemption, creating a compliance dilemma for HealthTech companies training AI models. General Counsels must balance patient data access rights against protecting proprietary algorithms.
Last updated:
What Happened
A recent report by Nasscom titled Privacy, Copyright, and Trade Secret: The Growing Conflict Between Personal Data Rights and AI Training in India highlights a critical legal gap for organizations developing artificial intelligence. The Data Protection Board of India and the Ministry of Electronics and Information Technology are navigating a clash between individual personal data rights and corporate intellectual property. The DPDP Act, 2023 currently lacks a specific carve-out for trade secrets, creating significant legal friction for companies training algorithms. This omission forces organizations to choose between fulfilling data access requests or protecting their proprietary logic. Furthermore, ongoing debates regarding the independence and powers of the Data Protection Board of India are causing delays in harmonizing this regulatory framework.
Does the DPDP Act Apply Here
Section 3 of the Digital Personal Data Protection Act, 2023 applies to digital personal data processed within the territory of India, as well as processing outside India if such processing is in connection with offering goods or services to Data Principals within India. For a General Counsel at a large HealthTech enterprise, this application is direct and unavoidable. When medical directors feed diagnostic logs or patient histories into predictive models, they are processing personal data. While Section 3 exempts personal data made publicly available by the Data Principal, proprietary health datasets are strictly private. If these datasets are not irreversibly anonymised before training begins, the Act fully applies to the entire machine learning pipeline.
Legal Implications Under DPDP
Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. The philosophical shift of the Digital Personal Data Protection Act, 2023 moves data from a traditional corporate property right to an individual dignity right. This creates severe conflict of law risks for General Counsels evaluating indemnity and liability allocation in vendor contracts. If a patient exercises their right to access, the DPDP Rules, 2025 require detailed, itemised disclosures regarding how their data is processed. A Data Fiduciary might be forced to reveal the proprietary logic of their AI model to satisfy this right, or face penalties up to 250 crore rupees for non-compliance. Where offshore AI servers are used, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories.
Could This Happen To You
The omission of a trade secret exemption is a massive vulnerability for HealthTech platforms, especially those evaluated as Significant Data Fiduciary candidates. If a patient files a grievance regarding AI diagnostic processing, regulator defensibility becomes your immediate problem. Your outside counsel must be able to prove that your algorithms do not misuse personal data, without having to expose the underlying code to the public. If an AI training pipeline inadvertently leaks identifiable medical records, the DPDP Rules, 2025 mandate intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours. During an investigation, an auditor will demand granular consent records mapping exact patient data flows into your AI models.
What Companies Should Do In The Next 30 Days
Legal heads must operationalize their regulator defensibility immediately to limit liability.
1. Map all patient data flows intersecting with your AI training environments to isolate personal data from proprietary algorithmic logic.
2. Revise limitation of liability and indemnity clauses in contracts with third-party AI processors to specifically account for the cost of DPDP data access requests.
3. Review the itemised notices mandated by the DPDP Rules, 2025 to ensure algorithmic processing purposes are disclosed clearly enough to satisfy the regulator, but broadly enough to protect trade secrets.
4. Establish a privileged review workflow between compliance and engineering teams to handle any data access requests involving AI outputs.
What To Watch
Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal heads should monitor the Data Protection Board of India for initial enforcement precedents involving AI processors and trade secrets. We also await potential guidance from the Ministry of Electronics and Information Technology on a middle-path approach that balances intellectual property innovation with strict privacy mandates. Until notified rules provide a safe harbour for AI training data, HealthTech enterprises must meticulously secure their data processing agreements. Evaluate your current vendor contracts and mapping capabilities using the free scan at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act allow HealthTech companies to withhold data access to protect AI trade secrets?
Currently, the DPDP Act, 2023 lacks a specific exemption for trade secrets. General Counsels face a compliance conflict where fulfilling a Data Principal's right to access could risk exposing proprietary algorithmic logic.
What is the financial risk of failing to provide data access under the DPDP Act?
Failing to observe the duties of a Data Fiduciary, including fulfilling data access rights, can attract penalties up to 250 crore rupees. Legal teams must carefully negotiate limitation of liability clauses to mitigate this exposure.
Are we allowed to train AI models on personal data under the DPDP Act?
Yes, provided you establish a lawful basis. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDP Rules, 2025 also require itemised notices detailing the purpose of processing.
How do the DPDP Rules 2025 impact AI data breach reporting?
If an AI pipeline leaks personal data, the DPDP Rules, 2025 mandate intimation to affected Data Principals without delay. Furthermore, a detailed report must be submitted to the Data Protection Board of India within 72 hours.
Can we transfer patient data to offshore AI servers for processing?
Cross-border transfers are generally permitted under the DPDP Act unless the Central Government restricts transfer to a negative list of notified countries or territories. Contracts must strictly allocate liability for these transfers.
ComplyDP