NEWS ANALYSIS4 min

DPDP Act vs AI Training: Balancing Personal Data Access Rights with Trade Secrets

Nasscom analysis reveals a critical compliance conflict between the DPDP Act 2023 and AI development. With no explicit trade secret carve-out, Heads of Compliance must find a way to honor data access requests without exposing proprietary algorithmic logic to DPBI penalties.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

An industry analysis by Nasscom highlighted a growing legal conflict between AI training requirements, proprietary trade secrets, and compliance with the Digital Personal Data Protection Act, 2023. The report notes the ongoing debates regarding the independence and enforcement powers of the newly established Data Protection Board of India. It also highlights the timeline to achieve regulatory harmonization goals amidst these technical complexities.

Does the DPDP Act apply here

Under Section 3, the DPDP Act applies to the processing of digital personal data within the territory of India, as well as processing outside India if connected to offering goods or services to Data Principals in India. AI developers often scrape or acquire datasets that blend personal data with non-personal corporate intellectual property. While anonymised data falls outside the scope of the Act, any AI training dataset containing identifiable digital personal data triggers full compliance obligations. For a Head of Compliance, distinguishing between regulated personal data and exempt proprietary logic within complex data lakes is a critical audit requirement.

Legal implications under DPDP

The Act shifts the legal treatment of personal data from a property rights model to an individual dignity model. Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. The core compliance friction arises because the DPDP Act currently lacks a specific trade secret carve-out. If a Data Principal exercises their right to access under the Act, AI companies face a direct conflict of laws. They must choose between exposing proprietary AI training logic to fulfill the access request or facing enforcement for non-compliance from the Data Protection Board of India.

Could this happen to you

If your enterprise uses AI tools trained on customer data, this conflict is already sitting in your risk register. Consider a scenario where an aggrieved user submits a data access request regarding how their information influenced an automated decision. If your compliance team cannot produce a clear audit trail that isolates personal data from the underlying proprietary AI weights, you cannot safely fulfill the request. Existing generic GRC tools often fail here because they lack the specific data mapping depth required for DPDP compliance. A credible solution must handle granular consent records and dynamic redaction, allowing you to provide regulator-ready evidence packs without leaking intellectual property.

What companies should do in the next 30 days

1. Instruct the control owner for data architecture to map all personal data currently used in AI training pipelines. This mapping must clearly identify where personal data enters the model.

2. Update the Record of Processing Activities to explicitly separate personal data inputs from proprietary algorithmic logic. This clear division is required to build a compliant audit trail.

3. Design an access request workflow that produces an itemised summary of personal data processed. The workflow must satisfy the Data Principal right to access without revealing corporate trade secrets.

4. Evaluate whether your current compliance platforms can generate automated, regulator-ready evidence packs. If they require massive manual team effort, you risk missing statutory response timelines.

What to watch

The compliance community is watching how the Data Protection Board of India will balance access rights with intellectual property protections in its early enforcement actions. Organizations must also prepare for the operational specifics introduced by the DPDP Rules, 2025, particularly regarding breach intimation workflows that require notifying affected Data Principals without delay and sending a detailed report to the DPBI within 72 hours. Exactly 268 days remain until the 13 May 2027 hard deadline. To assess how exposed your current AI data pipelines are to these new access requirements, run a baseline evaluation at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to AI training datasets?

Yes. Under Section 3, the Act applies to the processing of digital personal data within India or processing connected to offering services to Data Principals in India. If AI datasets contain identifiable personal data, they fall under the Act, even if mixed with corporate intellectual property.

Can we refuse a data access request to protect our AI trade secrets?

The DPDP Act currently lacks a specific trade secret carve-out. Organizations must find a middle path to fulfill the Data Principal right to access without exposing proprietary algorithmic logic, which creates significant compliance friction.

What are the DPDP Rules 2025 requirements for data breaches?

The Rules mandate breach intimation to affected Data Principals without delay and a detailed report to the Data Protection Board of India within 72 hours. Your compliance tools must be able to generate these regulator-ready breach reports automatically.

How does AI data processing interact with DPDP consent requirements?

Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. AI companies must ensure their consent artefacts cover complex algorithmic processing, which the Rules 2025 require to be explained via itemised notices.

Will our existing GRC tools handle DPDP AI compliance?

Generic GRC platforms often struggle to decouple personal data from proprietary logic for access requests. A dedicated solution must manage specific consent records and verifiable audit trails to satisfy DPBI scrutiny without immense manual team effort.