News Analysis • 4 mins
AI Training vs Data Principal Rights: Trade Secret Risks Under DPDP Act
A NASSCOM report highlights the regulatory conflict between corporate trade secrets and Data Principal access rights under the DPDP Act, creating compliance and liability challenges for EdTech legal leaders.
Last updated:
What happened
A recent article published on the NASSCOM community platform highlights a growing conflict between corporate trade secrets and data principal rights under the Digital Personal Data Protection Act, 2023. The analysis points to the absence of a specific trade secret carve-out in the current framework. This omission forces data fiduciaries into a difficult position when individuals exercise their right to access information. Companies training artificial intelligence models must weigh the risk of disclosing proprietary algorithmic logic against facing statutory penalties from the Data Protection Board of India for non-compliance. The report notes that this tension reflects a broader philosophical shift driven by the DPDP Act and the DPDP Rules, 2025, moving from property rights where companies own data to dignity rights where individuals control their personal information.
Does the DPDP Act apply here?
The applicability of this conflict hinges on whether the artificial intelligence models are trained using digital personal data. Under Section 3 of the DPDP Act, the framework applies to the processing of digital personal data within India, as well as processing outside India if connected to offering goods or services to Data Principals in India. For an EdTech General Counsel, this means any learner data fed into recommendation engines or adaptive algorithms falls squarely under the Act. However, Section 3 also specifies that the Act does not apply to personal data made publicly available by the Data Principal. The critical challenge arises with proprietary datasets generated internally, where learner interactions are logged, processed, and embedded into AI models without clear exemptions for the underlying corporate intellectual property.
Legal implications under DPDP
The legal friction centers on how data fiduciaries fulfill access requests without compromising intellectual property. Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. When an EdTech platform processes children's data, this requires strict verifiable parental consent workflows under the DPDP Rules, 2025. If a parent exercises the right to access the personal data and the summary of its processing, the General Counsel faces a conflict of laws. Complying fully might require explaining how a proprietary AI model evaluated the student, risking trade secret exposure. Furthermore, the Rules mandate itemised notices before consent is obtained, meaning legal teams must prospectively declare how AI processing works without revealing technical secrets that would harm defensibility.
Could this happen to you
This exact conflict is highly likely for large EdTech enterprises deploying adaptive learning algorithms. If a parent disputes a profiling outcome and files a grievance, or if an AI vendor suffers a breach necessitating intimation to affected Data Principals and a detailed report to the DPBI within 72 hours per the Rules, 2025, your processing records will be scrutinized. Your outside counsel would immediately ask if you can isolate the personal data from the algorithm's logic. If your systems treat user data and the algorithmic weights as an inseparable mass, you cannot safely fulfill the access request. The DPBI will not accept intellectual property concerns as a shield if it means denying a statutory right, exposing your enterprise to significant compliance risk and necessitating immediate review of indemnities with third-party AI vendors.
What companies should do in the next 30 days
1. Legal Heads must audit all vendor contracts supplying AI or recommendation features to enforce strict indemnities regarding data access requests. 2. Chief Product Officers need to document where algorithmic logic and learner data intersect, creating a privileged review artifact for outside counsel. 3. Compliance teams must implement Rule 10 workflows that secure verifiable parental consent specifically for automated processing, ensuring the language in the itemised notice protects trade secrets while remaining transparent. 4. General Counsel should draft standard operating procedures for handling complex right-to-access requests, establishing a defensible middle path that satisfies the Data Principal without disclosing source code.
What to watch
The NASSCOM report highlights ongoing debates regarding the independence and powers of the Data Protection Board of India, which could delay efforts by MeitY to harmonize these overlapping regulatory domains. Legal teams must monitor whether the DPBI issues specific guidance or safe harbour provisions for trade secrets in AI training. With exactly 271 days remaining until the DPDP hard compliance deadline of 13 May 2027, General Counsel cannot wait for regulatory clarity to secure their AI supply chains or allocate liability. Start mapping your algorithmic data flows and testing your verifiable parental consent mechanics today. Visit freescan.complydp.com to evaluate if your current consent and access workflows expose your trade secrets.
Sources
Frequently asked questions
Does the DPDP Act provide an exemption for proprietary AI algorithms or trade secrets?
Currently, the DPDP Act 2023 lacks a specific carve-out for trade secrets. This creates a legal conflict where businesses must balance fulfilling a Data Principal's right to access against protecting their proprietary algorithmic logic.
How does the DPDP Act impact EdTech platforms using AI for student recommendations?
EdTech platforms must obtain verifiable parental consent under the DPDP Rules 2025 before processing children's data for algorithms. If a parent exercises their right to access, the platform must provide a summary of the processing without unlawfully withholding information or exposing internal IP.
Can we refuse a Data Principal access request if it risks exposing our source code?
Refusing a valid access request solely on the grounds of trade secret protection carries significant regulatory risk, as the DPDP Act does not currently recognize intellectual property as a valid reason to deny Data Principal rights. General Counsel should establish privileged review processes to safely isolate personal data from core IP.
How should General Counsel mitigate AI vendor risks under the DPDP Act?
General Counsel should immediately review limitation of liability clauses and require strict indemnities from AI vendors. Contracts must clearly define accountability for fulfilling access requests and managing breach notifications, including the requirement to report incidents to the DPBI within 72 hours.
When is the hard deadline for DPDP Act compliance?
Organizations must fully align their data processing, consent workflows, and vendor contracts with the DPDP Act 2023 and the DPDP Rules 2025 before the hard compliance deadline of 13 May 2027.
ComplyDP