NEWS ANALYSIS • 4 min read
DPBI Enforcement and AI Data: Managing Privacy Conflicts Under DPDP Rules 2025
As debates over DPBI independence and AI data processing escalate, BFSI Legal Heads must balance the operational need for large training datasets against strict consent and purpose limitation mandates in the DPDP Act 2023.
Last updated:
What happened
A NASSCOM community report highlights growing industry debates over the independence and enforcement powers of the Data Protection Board of India (DPBI). Emerging from the Justice B.N. Srikrishna Committee recommendations, the DPBI is designed as a living framework with active adjudication powers. Ongoing scrutiny regarding its regulatory independence suggests a delay in the Ministry of Electronics and Information Technology (MeitY) timeline for harmonising the legal ecosystem. Concurrently, the report highlights an escalating conflict between Artificial Intelligence development, which relies on vast datasets, and the strict data processing controls introduced by the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025.
Does the DPDP Act apply here?
General Counsels evaluating AI deployment must assess data sets against Section 3 of the DPDP Act. The Act applies to the processing of digital personal data within India, as well as processing outside India if connected to offering goods or services to Data Principals in India. AI training models often ingest massive volumes of scraped or legacy data. Under Section 3(c)(ii), the Act does not apply to personal data made publicly available by the Data Principal themselves or under a legal obligation. However, distinguishing between genuinely public data and inadvertently exposed personal data within proprietary BFSI systems requires rigorous legal review to avoid unauthorised processing claims.
Legal implications under DPDP
For BFSI institutions utilising AI for credit scoring or underwriting, data ingestion faces strict boundaries. Section 4 mandates that processing personal data requires a lawful purpose, where consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDP Rules, 2025 operationalize this by requiring itemised notices and specific consent logs. If a bank uses historical transaction data to train an AI model, repurposing that data without fresh consent or a valid Section 7 exemption constitutes a breach of purpose limitation. Additionally, AI vendors acting as Data Processors must be bound by contracts limiting their liability and data usage, while cross-border transfers for offshore AI computing are permitted unless the Central Government restricts transfer to a notified negative list of countries.
Could this happen to you
If an insurer or NBFC feeds legacy customer data into a third-party AI tool, the DPBI could initiate an inquiry upon receiving a complaint. The Board will demand evidence of lawful processing and purpose limitation. If a breach occurs at the AI vendor level, the DPDP Rules, 2025 require the Data Fiduciary to notify affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours. General Counsels must consider whether their current vendor contracts have adequate indemnity clauses and if their teams can produce audit-ready consent logs for every data point fed into an AI model. Failing to demonstrate this defensibility risks severe regulatory penalties and board-level scrutiny over compliance failures.
What companies should do in the next 30 days
1. The Legal Head must mandate a privileged review of all current and planned AI deployments to map the flow of personal data against DPDP exemptions.
2. The compliance team should update all Data Processor agreements with AI vendors to include explicit limitation of liability, indemnity clauses, and strict prohibitions on using BFSI customer data for training their own foundational models.
3. The Chief Compliance Officer must establish a verifiable consent architecture that captures granular, itemised consent for AI processing, mapping directly to the DPDP Rules, 2025 requirements.
4. Legal and IT teams must run a tabletop exercise simulating an AI vendor breach to ensure the capacity to meet the 72-hour DPBI reporting timeline.
What to watch
Scrutiny over the DPBI operational independence and the finalisation of MeitY guidelines will dictate the enforcement posture for the BFSI sector. Companies must monitor how the DPBI adjudicates early complaints regarding AI data scraping and purpose limitation violations. General Counsels should also watch for overlapping mandates between the DPBI, RBI, and IRDAI concerning automated decision-making and data localisation. Exactly 265 days remain until the 13 May 2027 hard deadline for DPDP compliance. Legal teams must finalize their defensive strategies and processor oversight frameworks well before the regulator begins active enforcement. Assess your institutional readiness and processor oversight with a confidential check at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to historical customer data used for AI training?
Yes, if the data is in digital form or digitized subsequently, it falls under the DPDP Act, 2023. Processing legacy BFSI data for new AI models requires assessing whether the original consent covers this new purpose, or if fresh consent is required.
What happens if an AI vendor breaches our customer data?
The Data Fiduciary holds primary liability. Under the DPDP Rules, 2025, you must intimate affected Data Principals without delay and file a detailed breach report to the DPBI within 72 hours. Your vendor contracts must contain strong indemnity clauses to manage this risk.
Are there restrictions on sending personal data offshore for AI processing?
Cross-border transfers are generally permitted under the DPDP Act unless the Central Government explicitly restricts transfers to a notified negative list of countries. General Counsels must still ensure these transfers comply with sector-specific RBI or IRDAI data localisation mandates.
Can we use publicly available personal data to train our underwriting models?
Section 3 exempts personal data made publicly available by the Data Principal themselves or by a person under a legal obligation. However, proving the data was made public by the Data Principal rather than inadvertently scraped requires rigorous evidence trails.
How should legal teams oversee AI vendors acting as Data Processors?
Data Fiduciaries must execute valid contracts restricting the Processor's data usage strictly to the agreed services. You must verify their capacity to support your obligations, including providing necessary logs for the 72-hour DPBI breach reporting timeline.
ComplyDP