NEWS ANALYSIS4 minutes

Trade Secrets vs Data Rights: The AI Compliance Dilemma Under the DPDP Act

An analysis highlights the conflict between individual data access rights under the DPDP Act and corporate trade secrets in AI training. Enterprise compliance heads must unbundle consent and prepare regulator-ready evidence trails before the deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

An analysis published on the Nasscom Community platform highlighted a growing conflict between individual data access rights and corporate trade secrets in artificial intelligence training. The report notes that the Digital Personal Data Protection Act, 2023 and the notified DPDP Rules, 2025 shift Indian legal philosophy from property rights to dignity rights. Companies no longer own datasets; individuals now control their personal data. While the Data Protection Board of India was established based on the Justice B.N. Srikrishna Committee report, ongoing debates regarding its independence suggest harmonisation with broader enforcement goals will take time.

Does The DPDP Act Apply Here

Under Section 3 of the DPDP Act, the framework applies to processing digital personal data within India, and processing outside India connected to offering goods or services to Data Principals in India. For large D2C and e-commerce enterprises, this intersects directly with how consumer data fuels recommendation engines, marketing algorithms, and AI models. If your platform uses past purchase history and browser behaviour to train models, that digital personal data falls squarely under the Act and requires a robust compliance foundation.

Legal Implications Under DPDP

The primary compliance hurdle is a severe conflict of laws surrounding transparency. Section 4 states that consent is the primary basis for processing, except where Section 7 legitimate uses apply. When individuals exercise their right to access, data fiduciaries must provide a summary of personal data processed. However, the DPDP Act 2023 currently lacks a trade secret carve-out. Fulfilling an access request could force AI and e-commerce companies to reveal proprietary training logic or face statutory penalties. Furthermore, under the DPDP Rules, 2025, consent notices for these algorithmic uses must be itemised and made available in up to 22 regional languages, complicating the collection phase for tier-2 markets.

Could This Happen To You

E-commerce compliance heads must evaluate their exposure immediately. If a consumer files an access request regarding how their data influences your marketing AI, refusing them risks a DPBI inquiry. If an inquiry triggers, the DPBI will demand your RoPA, consent artefacts, and control owner attestations. Bundling consent into general terms and conditions is no longer viable for D2C brands. A credible compliance solution must separate essential shipping data from optional marketing data, generating an audit-ready evidence pack without relying on a heavy, rigid banking GRC tool that creates friction for your CMO.

What Companies Should Do In The Next 30 Days

1. The Head of Compliance must mandate a data mapping exercise to identify all customer data fed into AI training environments, yielding an updated RoPA.

2. The CTO and CMO must deploy a consent unbundler to separate transactional shipping data from algorithmic marketing data, generating verifiable consent artefacts.

3. Legal teams must draft itemised notices compliant with the DPDP Rules, 2025, ensuring translation workflows are operational for regional users.

4. The DPO must establish a clear protocol for access requests that balances transparency with trade secret protection, preparing a regulator-ready defence if challenged.

What To Watch

Legal teams should track DPBI enforcement proceedings to see if the government adopts a middle-path approach regarding trade secrets. Note that in the event of an AI system security failure, the Rules, 2025 mandate intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027.

Time is running out to replace legacy systems with specific DPDP workflows. Assess your evidence readiness and pinpoint consent gaps before the DPBI asks for your records with a free scan at freescan.complydp.com today.

Sources

Frequently asked questions

Does the DPDP Act apply to AI training using customer data?

Yes, under Section 3 of the DPDP Act, processing digital personal data within India for AI models falls under the framework. E-commerce platforms must secure valid consent before feeding consumer histories into marketing algorithms.

Can we rely on general terms and conditions for marketing AI consent?

No. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDP Rules, 2025 require itemised notices, meaning necessary shipping data must be unbundled from optional marketing data.

Are trade secrets protected when consumers request data access?

This is currently a major operational hurdle. The DPDP Act lacks a specific trade secret carve-out, creating a conflict where fulfilling an access request might expose proprietary AI logic and refusing invites DPBI scrutiny.

What happens if an AI data repository suffers a breach?

Under the DPDP Rules, 2025, you must send an intimation to affected Data Principals without delay. You are also required to submit a detailed incident report to the Data Protection Board of India within 72 hours.

When is the final deadline for DPDP Act compliance?

The enforcement timeline is tightening rapidly for data fiduciaries. Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027, requiring immediate deployment of consent and RoPA tooling.