News Analysis • 4 min read
DPDP Rules 2025 Force AI Scrape Reckoning for E-Commerce Data Exclusivity
The notification of the DPDP Rules 2025 exposes a tension between itemised consent mandates and the Section 3 public-data exemption. General Counsel must evaluate whether scraped e-commerce reviews and public profiles create downstream liability.
Last updated:
What happened
The Indian government formally notified the DPDP Rules in November 2025, activating specific consent and notice obligations for Data Fiduciaries. According to a report by The Wire, AI companies are heavily relying on a public-data exemption within the law to bypass these rules and acquire training data for their AI bots. The report highlights that unlike European citizens, data principals in India cannot file objections to halt this specific data usage. India's Data Protection Board is now beginning its work and faces an immediate test regarding how broadly this exemption applies.
Does the DPDP Act apply here?
Section 3 of the Act dictates that it applies to the processing of digital personal data within the territory of India. It also applies to processing outside India if such processing is in connection with offering goods or services to Data Principals in India. However, a critical carve-out exists under Section 3(c)(ii), stating the Act does not apply to personal data made publicly available by the Data Principal or another person under a legal obligation.
For General Counsel managing D2C and e-commerce platforms, customer product reviews, community forum posts, and public profile data sit in a highly contested gray area. If your platform terms compel users to make their reviews public, third-party AI scrapers claim exemption from the Act when they extract that data. The legal complexity arises when your Terms of Service forbid web scraping, forcing outside counsel to untangle contract law, intellectual property rights, and DPDP applicability all at once.
Legal implications under DPDP
Under the Act and the DPDP Rules 2025, consent is the primary basis for processing, except where Section 7 legitimate uses apply. When you collect data from a customer, Rule 3 mandates providing an itemised notice in English and any of the 22 languages specified in the Eighth Schedule to the Constitution. You are strictly accountable for ensuring the data is processed only for the stated lawful purpose and erased when consent is withdrawn.
The public-data exemption creates a significant enforcement void for platform operators. The Data Protection Board of India must determine if scraping a D2C site's public reviews constitutes processing of exempted data, or if the initial fiduciary still bears responsibility for failing to secure the personal data from unauthorized third-party extraction. The lack of a statutory objection right for users regarding AI scraping alters your corporate liability profile considerably, placing heavy emphasis on how you draft your privacy notices and platform terms.
Could this happen to you
Legal heads in D2C and e-commerce face immediate risk if their platforms rely on bundled consent, such as making users agree to marketing emails just to process a shipping order. The Act bans this practice. If a third party scrapes your user-generated content for AI training and a customer files a complaint, the DPBI will look directly at you as the Data Fiduciary. They will demand your itemised notices and verifiable consent records within days.
If you suffer an actual breach during this process, the Rules 2025 demand intimation to affected Data Principals without delay, followed by a detailed report to the DPBI within 72 hours. You cannot rely on a heavy banking governance tool to manage this specific D2C workflow. Your teams require systems that unbundle shipping data from marketing data and manage withdrawal of consent across multiple platforms seamlessly. A failure to produce defensible audit trails will severely impact outside counsel spend and enterprise deal negotiations.
What companies should do in the next 30 days
1. Legal teams must immediately audit Terms of Service to ensure explicit prohibitions against third-party data scraping. Update vendor indemnity clauses to clearly allocate liability if a processor exposes your platform's public-facing data.
2. Deploy a consent unbundler. Separate core e-commerce fulfillment data from optional marketing or public-profile data to ensure full compliance with Rule 3 itemised notice requirements.
3. Configure automated translations of your privacy notices into the 22 constitutional languages. This is a strict operational requirement under the newly notified Rules, and failure to comply creates an easily provable violation.
4. Establish a verifiable workflow for erasure requests. If a Data Principal withdraws consent, their data must be provably deleted from your active databases and downstream vendor systems to satisfy DPBI audits.
What to watch
The Data Protection Board of India is just beginning its work, and its initial rulings on the Section 3 public-data exemption will signal how aggressively it plans to pursue enforcement. General Counsel must monitor these proceedings closely to understand the standard of proof required for valid consent records and vendor oversight.
Exactly 261 days remain until the 13 May 2027 hard compliance deadline. Legal leaders must use this window to secure their platforms against unapproved data extraction and finalize compliant consent flows. To evaluate your platform's readiness for itemised consent, language translation requirements, and defensible audit trails, check your exposure at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to publicly available product reviews on our e-commerce platform?
Under Section 3, the Act does not apply to personal data made publicly available by the Data Principal. However, if your platform processes this data for targeted marketing before or alongside making it public, consent requirements and Rule 3 notice obligations still apply to your initial processing.
How do the DPDP Rules 2025 impact our current bundled consent practices?
The Rules ban bundled consent outright. You must separate essential shipping data from optional marketing data. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, and requires a clear, itemised notice for each specific purpose.
What happens if a third-party vendor suffers a data breach exposing our customers' data?
As the Data Fiduciary, you hold primary liability for the protection of that data. The Rules 2025 mandate intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours. General Counsel must ensure vendor contracts contain strong indemnity clauses.
Can we transfer our e-commerce customer data to servers outside India?
Yes, cross-border transfers are generally permitted under the Act unless the Central Government restricts transfers to specific countries through a notified negative list. Legal teams should ensure data transfer agreements reflect this framework.
Do we need to translate our privacy notices into multiple languages?
Yes. Under the DPDP Rules 2025, Data Principals must be given the option to access the itemised notice in English or any of the 22 languages specified in the Eighth Schedule to the Constitution.
ComplyDP