NEWS ANALYSIS • 4 min
AI Training and DPDP 2025 Rules: Managing Contingent Liability in E-Commerce
As debates over the Data Protection Board's enforcement powers emerge, CFOs in the D2C sector must evaluate their exposure regarding AI data processing, bundled consent risks, and compliance budgeting under the DPDP Act 2023.
Last updated:
What Happened
According to a recent report hosted on the NASSCOM Community, debates are emerging regarding the operational independence and enforcement powers of the Data Protection Board of India. The DPBI, established based on recommendations from the Justice B.N. Srikrishna Committee report, is preparing to regulate personal data collection for artificial intelligence training under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The Ministry of Electronics and Information Technology asserts the government intends to harmonise this framework to protect data rights without stifling innovation. However, ongoing debates suggest achieving this alignment will take time, leaving corporate leaders to navigate the immediate regulatory expectations.
Does The DPDP Act Apply Here
The intersection of artificial intelligence and personal data directly triggers Section 3 of the DPDP Act, 2023. The Act applies to digital personal data processed within the territory of India, and processing outside India if connected to offering goods or services to Data Principals in India. For D2C and e-commerce companies using customer datasets to train product recommendation engines, this data falls strictly under the regulatory purview regardless of where the servers sit. However, Section 3(c)(ii) provides an exception for personal data made publicly available by the Data Principal themselves, creating a narrow carve-out for certain publicly scraped datasets. Corporate intellectual property or anonymised transaction trends are not covered by the Act.
Legal Implications Under DPDP
Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. For e-commerce leaders, this means bundling AI training permissions with general terms of service is no longer permitted. The DPDP Rules, 2025, notified in November 2025, mandate itemised notices specifying exactly what data is collected and for what purpose. Cross-border transfers of datasets for global AI processing are generally permitted unless the Central Government restricts transfer to notified countries via a negative list. If an AI dataset containing personal data is breached, companies must provide intimation to affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours.
Could This Happen To You
For a CFO in the D2C space, non-compliant AI data processing represents a significant contingent liability. If the DPBI initiates an inquiry into how your recommendation models are trained, an inability to produce verifiable consent trails will directly impact your EBITDA. Penalties can reach up to 250 crore rupees for data breaches, heavily influencing cyber insurance premium calculations. Furthermore, relying on bundled consent for shipping and marketing exposes the enterprise to immediate regulatory action. Using heavy banking GRC platforms to manage this often inflates your Total Cost of Ownership without solving the specific e-commerce need of dynamic consumer consent.
What Companies Should Do In The Next 30 Days
CFOs and compliance leaders must initiate immediate provisioning and process adjustments to mitigate penalty exposure and manage audit fees. 1. Conduct a data mapping exercise to separate core shipping data from marketing and AI training datasets. 2. Implement a consent unbundler to ensure customers can opt out of AI training without losing access to basic e-commerce services. 3. Prepare to translate your privacy notices into 22 regional languages as required by Rule 3 of the DPDP Rules, 2025 to serve Tier-2 markets. 4. Drive vendor consolidation by replacing fragmented compliance point solutions with unified platforms tailored for high-volume consumer transactions.
What To Watch
As MeitY continues its harmonization efforts, the operational mechanics of the DPBI will become clearer through early enforcement actions and the release of the negative list for cross-border data transfers. Organizations must monitor how the Board interprets the boundary between anonymised models and personal data. Exactly 276 days remain until the 13 May 2027 hard compliance deadline. To assess your contingent liability and current compliance posture without inflating consulting budgets, run a self-assessment at freescan.complydp.com today.
Sources
Frequently asked questions
Does the DPDP Act apply to customer datasets used for AI training?
Yes. The Digital Personal Data Protection Act, 2023 applies to digital personal data processed within India, including data collected for AI models. The primary exception is data made publicly available by the Data Principal.
Can e-commerce companies bundle AI consent with shipping terms?
No. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDP Rules, 2025 require clear, itemised notices, meaning consent for AI training cannot be bundled with core shipping or service terms.
What is the financial risk of non-compliant data processing for a CFO?
CFOs face significant contingent liability, with penalty ceilings reaching up to 250 crore rupees for data breach failures. These risks directly impact EBITDA margins and drive up cyber insurance premium costs.
How should D2C companies handle privacy notices across different Indian regions?
Under Rule 3 of the DPDP Rules, 2025, companies must provide the option to view privacy notices in 22 regional languages. High-volume e-commerce firms should automate these translations to reduce Total Cost of Ownership.
What are the DPDP breach reporting timelines if AI training data is compromised?
The DPDP Rules, 2025 mandate intimation to affected Data Principals without delay. Additionally, a detailed breach report must be submitted to the Data Protection Board of India within 72 hours.
ComplyDP