NEWS ANALYSIS4 mins

DPDP Access Rights vs. AI Trade Secrets: Liability Risks for BFSI Legal Heads

While industry analysis suggests a conflict between DPDP Act data access rights and AI trade secrets, Section 11(1) clarifies that organizations only need to provide processing summaries. The real challenge lies in meeting the strict procedural rules and timelines mandated by the DPDP Rules 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

A recent analysis published in the NASSCOM community highlights a perceived legal conflict between individual data access rights under the Digital Personal Data Protection (DPDP) Act, 2023, and the protection of artificial intelligence trade secrets. The report contextualizes the Data Protection Board of India (DPBI) as the primary enforcement body. However, it is critical to correct a common historical inaccuracy: the Justice B.N. Srikrishna Committee originally recommended a Data Protection Authority; the current DPBI structure was actually introduced later in the 2022 legislative draft. Under the DPDP Act, the framework shifts the philosophical and legal paradigm from corporate property rights - where companies own a data list - to individual dignity rights, giving individuals control over their personal data. The source argues that because the DPDP Act lacks a specific 'trade secret carve-out', companies developing AI face a severe conflict of laws, allegedly forced to choose between disclosing proprietary logic or risking penalties.

Does the DPDP Act apply here?

Section 3(a) of the Act confirms applicability to the processing of digital personal data within the territory of India if collected in digital form or digitized subsequently. Section 3(b) extends this to processing outside India if connected to offering goods or services to Data Principals within India. For institutions deploying AI for underwriting, KYC verification, or fraud detection, the data fed into these models is invariably digital personal data. The legal friction arises at the intersection of this personal data and the proprietary models processing it. While the underlying AI logic may be guarded as intellectual property, the data inputs relate directly to the individual, bringing the processing pipeline securely under the purview of the DPDP Act.

Legal implications under DPDP

Under Section 4(1), a person may process personal data only in accordance with the Act and for a lawful purpose - specifically where the Data Principal has given consent, or for certain legitimate uses. Section 4(2) clarifies that a lawful purpose is any purpose not expressly forbidden by law. When a Data Principal exercises their right to obtain information, the source's claim of a fundamental trade secret conflict fundamentally misrepresents the Right to Access under the DPDP Act. Section 11(1) only requires providing a summary of personal data and processing activities, not the proprietary logic of automated decision-making (unlike GDPR Article 15(1)(h)). The real operational challenge is not a forced disclosure of algorithmic intellectual property, but rather strictly adhering to the procedural rules and timelines mandated for fulfilling these requests under the DPDP Rules 2025.

Could this happen to you

If your organization relies on third-party AI models for automated decisions, data access requests represent an immediate procedural liability. Imagine a user filing a formal access request regarding the data used in an AI-driven decision. If your compliance team cannot cleanly separate the applicant's personal data summary from the vendor's proprietary algorithmic logic within the tight procedural rules and timelines mandated by the DPDP Rules 2025, you risk a direct regulatory breach. The DPBI will expect clear evidence trails of what personal data was processed and prompt delivery of the summary. This creates immense friction for General Counsel managing vendor indemnities and attempting to enforce rapid turnaround times from third-party processors.

What companies should do in the next 30 days

1. General Counsel must immediately review all third-party AI processing agreements to insert DPDP-specific clauses ensuring vendors support access request fulfillment within the timelines mandated by the DPDP Rules 2025.

2. Compliance teams should map exactly where personal data intersects with proprietary models to ensure accurate Section 11(1) summaries can be rapidly generated.

3. Legal and IT departments must jointly design an access request workflow that satisfies the DPDP obligation to provide processing summaries without needlessly probing into underlying algorithmic trade secrets.

4. Establish stringent vendor oversight protocols to ensure processors can isolate and return personal data summaries efficiently to prevent regulatory timeline breaches.

What to watch

Ongoing debates regarding the DPBI's independence and powers indicate a potential delay in the Ministry of Electronics and Information Technology's (MeitY) broader efforts to harmonize technology laws. Legal teams should monitor early adjudicatory precedents from the DPBI regarding access requests and the enforcement of procedural rules and timelines mandated by the DPDP Rules 2025. As the source notes, India will likely need a 'middle-path' approach to reconcile individual privacy rights with the protection of AI trade secrets at a broader policy level. Under Section 1(2) of the DPDP Act, provisions will come into force on dates appointed by the Central Government; establishing defensible data summary workflows now is a priority to minimize regulatory exposure when enforcement officially begins.

Sources

Frequently asked questions

Does the DPDP Act force companies to expose AI trade secrets to fulfill access requests?

No. This is a common misconception that falsely equates the DPDP Act with European frameworks. Section 11(1) of the DPDP Act only requires Data Fiduciaries to provide a summary of personal data and processing activities, not the proprietary logic of automated decision-making (unlike GDPR Article 15(1)(h)).

What is the primary compliance risk for AI data access requests under the DPDP Act?

The primary risk is failing to adhere to the procedural rules and timelines mandated for fulfilling these requests under the DPDP Rules 2025. If a Data Fiduciary cannot swiftly extract a personal data summary from a third-party AI vendor within the regulatory timeframe, they face strict non-compliance penalties.

How should legal teams handle AI vendor contracts under the DPDP Act?

Legal teams must update vendor agreements to include robust data access clauses that align with the procedural rules and timelines mandated by the DPDP Rules 2025. Vendors must be contractually obligated to promptly isolate and return personal data summaries to the Data Fiduciary without needing to expose proprietary logic.

When does the DPDP Act come into force regarding these access rights?

Under Section 1(2) of the Act, provisions shall come into force on such dates as the Central Government appoints by notification in the Official Gazette. Different dates may be appointed for different provisions, making it essential for compliance leaders to establish defensible access workflows preemptively.