News Analysis4 min read

AI Training vs Privacy: The Evolving DPDP Challenge for E-Commerce Counsel

An analysis of the growing conflict between AI data requirements and the DPDP Act, 2023, focusing on consent unbundling and vendor liability for e-commerce General Counsel.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

According to recent legal reports, a growing conflict is emerging in India between personal data rights and the extensive data requirements of AI model training. Artificial intelligence developers and data processors face a rapidly shifting legal environment regarding how they source information. AI models inherently thrive on and require massive amounts of data, with their strength directly dependent on capturing larger datasets. This foundational necessity is now directly clashing with new privacy mandates, copyright protections, and trade secret limitations in the region.

Does The DPDP Act Apply Here

General Counsel at direct-to-consumer and e-commerce enterprises must carefully evaluate the origin of their AI training pipelines. Under Section 3 of the Digital Personal Data Protection Act, 2023, the law applies to the processing of digital personal data within the territory of India. If your storefront feeds customer purchase histories or digital behavioral data into an AI recommendation engine, that processing falls squarely under the Act.

However, Section 3(c)(ii) provides a critical exemption for personal data that is made publicly available by the Data Principal. If an artificial intelligence developer scrapes publicly accessible product reviews that users intentionally published, that specific data might avoid privacy restrictions, though copyright and trade secret concerns may still apply. Conversely, utilizing proprietary backend customer data to train models without explicit authorization creates immediate compliance and litigation risks.

Legal Implications Under DPDP

Under Section 4 of the Digital Personal Data Protection Act, 2023, a person may process personal data only in accordance with the Act and for a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For e-commerce platforms, this means historical practices of bundling a single terms of service agreement to cover shipping data, marketing emails, and AI training data are no longer legally defensible.

The DPDP Rules, 2025 heavily compound this challenge by requiring itemised notices before any processing occurs. These Rules also mandate that platforms provide options to access the privacy notice in multiple regional languages. General Counsel must ensure their digital infrastructure separates core fulfillment data from analytics data, securing distinct consent for each purpose to avoid penalties that can reach up to 250 crore rupees.

Could This Happen To You

If a customer alleges their digital footprint was unlawfully fed into an enterprise artificial intelligence model, the Data Protection Board of India will demand immediate proof of unbundled consent. For a legal head, the primary concern is whether your current consent management architecture provides a verifiable, time-stamped evidence trail. Without clear demarcations between shipping data and AI training data, your organization faces direct regulatory exposure and a failure in regulator engagement.

A secondary risk lies in vendor oversight and liability allocation. If a third-party AI provider processes your e-commerce data and suffers a breach, the Rules, 2025 require an intimation to affected Data Principals without delay, plus a detailed report to the Board within 72 hours. Your vendor contracts must contain strict indemnity clauses and clear limitation of liability carve-outs to protect the enterprise from third-party failures.

What Companies Should Do In The Next 30 Days

1. General Counsel must review all third-party AI vendor contracts to align indemnity clauses with the 72-hour breach notification timelines without escalating outside counsel spend. 2. Chief Marketing Officers and legal teams must audit current e-commerce checkout flows to separate shipping data from marketing and AI training consent. 3. Engineering teams must prepare backend architecture to support notice translations into regional languages for Tier-2 customers as mandated by the Rules, 2025.

What To Watch

As the regulatory framework matures, General Counsel should monitor how the Data Protection Board of India treats synthetic data and algorithmic disgorgement in cases of unlawful processing. Exactly 286 days remain until the 13 May 2027 hard deadline for full implementation. Organizations should act now to assess their existing consent architecture and third-party data processing agreements. To evaluate your e-commerce platform compliance and unbundle your consent flows, assess your exposure today at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to AI training datasets?

Yes, if the training dataset includes digital personal data processed within India, it is covered under Section 3 of the DPDP Act, 2023. Organizations must establish a lawful purpose for utilizing this data in AI models.

Can we scrape public internet data to train our AI?

Section 3(c)(ii) exempts personal data made publicly available by the Data Principal themselves. However, scraping data published by third parties without consent remains a significant compliance and copyright risk.

How does the DPDP Act change e-commerce consent mechanisms?

The Act prohibits bundling consent for unrelated purposes. Platforms must separate necessary shipping data from elective AI training or marketing data, providing an itemised notice as mandated by the DPDP Rules, 2025.

What happens if our third-party AI vendor suffers a data breach?

Under the DPDP Rules, 2025, the Data Fiduciary must intimate affected Data Principals without delay and report the breach to the Board within 72 hours. Enterprise General Counsel should ensure strict indemnity clauses are in place.

What is the penalty for failing to unbundle consent for AI training?

Processing personal data without valid, unbundled consent for a lawful purpose can result in financial penalties reaching up to 250 crore rupees under the DPDP Act, 2023.