News Analysis4 min read

AI Training Data and the DPDP Act: Navigating Scraping, Consent, and Purpose Limitation

A recent Nasscom report highlights the regulatory friction between commercial AI data scraping and the DPDP Act 2023. HealthTech compliance leaders must scrutinize data pipelines, enforce purpose limitation, and prepare audit-ready consent artefacts to mitigate DPBI exposure.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

Nasscom published an analysis highlighting the growing regulatory conflict between commercial AI model data scraping practices, copyright law, and the Digital Personal Data Protection Act, 2023. The report notes that scraping publicly available personal data, such as online interviews, for commercial AI training may violate privacy laws if conducted without a lawful purpose or explicit consent. The analysis emphasizes that the DPDP Act enforces strict purpose limitation, demanding personal data only be used for the precise purpose for which it was collected. Furthermore, ongoing debates surrounding the independence and enforcement powers of the Data Protection Board of India (DPBI) suggest potential delays in achieving the Ministry of Electronics and Information Technology's goals to harmonize the regulatory framework.

Does the DPDP Act Apply Here?

HealthTech compliance heads must carefully evaluate the origin of their AI training datasets. Under Section 3, the Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. A critical nuance exists regarding public data. Section 3(c)(ii) states the Act does not apply to personal data made publicly available by the Data Principal themselves. If a patient publicly posts a review of a clinic on an open forum, scraping it might fall under this exemption. However, as the Nasscom report illustrates, if an AI developer scrapes an online medical interview published by a third-party publication, the Act triggers unless that third party was legally obligated to make it public.

Legal Implications Under DPDP

For data that falls within the scope of the Act, Section 4 mandates that a person may process personal data only for a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. This creates a significant barrier for AI models reliant on historical or repurposed datasets. The DPDP Act enforces stringent purpose limitation. Patient data initially collected for a telemedicine consultation cannot be quietly redirected to train a predictive diagnostic AI model. To repurpose this data, organizations must deploy updated, itemised notices and utilize the verifiable consent mechanics established in the DPDP Rules, 2025. Without a definitive consent artefact mapped to the specific processing activity of AI training, ingesting this data violates core legislative tenets.

Could This Happen To You

Imagine your healthtech enterprise relies on a third-party vendor to build an AI diagnostic assistant, trained on a mix of scraped public medical forums and your own historical patient interaction logs. If a privacy complaint occurs, the DPBI will not accept a generic privacy policy as a defense. They will demand a comprehensive Record of Processing Activities (RoPA) and a formal Data Protection Impact Assessment (DPIA). If an unauthorized data scraping or processing breach occurs, the Rules, 2025 require intimation to affected Data Principals without delay and a detailed incident report to the DPBI within 72 hours. Compliance leaders must ask themselves if their current control environment could produce an audit trail mapping every data point to a valid consent artefact within that window. Failing to deliver these regulator-ready evidence packs risks severe financial penalties and a total loss of patient trust.

What Companies Should Do In The Next 30 Days

1. Map AI data supply chains. The compliance team and engineering leads must document the source of all AI training data, specifically identifying whether it was made public by the Data Principal or requires active consent collection.

2. Update itemised notices. Ensure your patient intake workflows explicitly state AI model training as a distinct processing purpose, integrating the verifiable consent mechanics defined by the DPDP Rules, 2025.

3. Review vendor contracts. Secure contractual attestations from all third-party AI developers, ensuring they comply with DPDP purpose limitation requirements, and log these within your GRC control environment.

4. Establish a breach workflow. Test your incident response plan to ensure cross-team accountability for meeting the 72-hour DPBI reporting requirement if an AI vendor compromises patient data.

What To Watch

Monitor how the central government resolves ongoing debates concerning the DPBI's operational independence, as this will shape the intensity of initial enforcement audits. Watch for early DPBI guidelines specifically targeting unauthorized data scraping and the unauthorized repurposing of datasets for commercial AI models. Time is running out for organizations to upgrade their data governance frameworks. Exactly 288 days remain until the DPDP hard compliance deadline of 13 May 2027. To evaluate if your AI data pipelines and consent artefacts can withstand regulatory scrutiny, test your exposure with a free diagnostic scan at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to publicly available personal data scraped for AI?

Section 3(c)(ii) provides an exemption if the personal data was made publicly available by the Data Principal themselves. However, if the data was published by a third party without a legal obligation to do so, scraping it for AI training requires a lawful purpose and typically explicit consent under the Act.

Can a healthtech platform use existing patient records to train new AI models?

The DPDP Act enforces strict purpose limitation. Personal data collected for medical consultations cannot be repurposed for AI training unless the organization issues a new itemised notice and secures verifiable consent for that specific processing activity, per the DPDP Rules, 2025.

What is the penalty risk for violating purpose limitation rules?

Failure to adhere to processing obligations, including purpose limitation and valid consent collection, exposes Data Fiduciaries to significant financial penalties under the DPDP Act. The exact penalty depends on the nature and gravity of the non-compliance determined by the DPBI.

What happens if a third-party AI vendor experiences a data breach?

Under the DPDP Rules, 2025, the Data Fiduciary is responsible for breach response. The organization must provide intimation to affected Data Principals without delay and submit a detailed incident report to the Data Protection Board of India within 72 hours.

What is the timeline for complying with the DPDP Act?

Organizations must urgently prepare their audit trails, consent artefacts, and compliance infrastructure. Exactly 288 days remain until the DPDP hard compliance deadline of 13 May 2027.