News Analysis • 4 mins
AI Training Data Collides with DPDP Act 2023: NASSCOM Highlights Privacy Conflict
A NASSCOM report underscores the friction between AI data harvesting and Indian privacy laws. Healthtech compliance heads must reconcile AI training models with strict DPDP Act 2023 obligations on consent, purpose limitation, and data minimization.
Last updated:
What Happened
A report published by the NASSCOM Community examined the growing conflict between personal data rights and Artificial Intelligence training practices in India. The report noted that Artificial Intelligence models rely heavily on data, with model strength increasing alongside dataset size. As the legal environment surrounding data in India rapidly changes, developers face increasing friction between scraping large volumes of data and adhering to emerging privacy frameworks. The analysis highlighted how the technical demand for vast datasets complicates regulatory compliance.
Does The DPDP Act Apply Here
The Digital Personal Data Protection Act, 2023 applies directly when AI models ingest digital personal data processed within the territory of India. Section 3 of the Act extends this scope to processing outside India if connected to offering goods or services to Data Principals in India. AI developers often argue that web-scraped data falls outside privacy laws, but Section 3 limits exemptions specifically to personal data made publicly available by the Data Principal themselves or someone under a legal obligation. If a healthtech platform uses patient records to train a diagnostic AI without explicit mapping, this falls squarely within the scope of the Act. Personal data within corporate databases remains fully protected, even if stripped of direct identifiers, unless it is anonymised beyond re-identification.
Legal Implications Under DPDP
Under Section 4 of the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Training an AI model requires itemised notices outlining this specific purpose before consent is obtained, as detailed in the DPDP Rules, 2025. Repurposing existing patient databases for machine learning violates the principle of purpose limitation if the original consent was only for medical treatment.
Furthermore, the Act mandates clear data minimization, which contradicts the technical premise that larger datasets create stronger models. If an AI platform transfers data for offshore model training, cross-border rules apply. Transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories via a negative list. Any unauthorized exposure of personal data during model training would trigger breach protocols under the Rules, 2025, requiring intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours.
Could This Happen To You
For a Head of Compliance at a large healthcare or healthtech enterprise, AI integration is a high-risk area. Your product teams are likely testing AI symptom checkers or predictive models using historical clinic data. If the Data Protection Board of India investigates your AI training pipeline, they will demand a clear audit trail linking every training data point back to specific consent artefacts.
The DPBI would look for a detailed Record of Processing Activities mapping how patient data flows from the clinic interface into the AI training server. Without these controls, you face significant penalty ceilings under the Act, potentially reaching up to 250 crore rupees for failing to secure personal data. This level of exposure makes board reporting difficult and risks enterprise deals with hospital networks that demand regulator-ready compliance evidence before integrating your healthtech tools.
What Companies Should Do In The Next 30 Days
1. The compliance lead must inventory all AI models currently in development or deployment across the organisation to document exactly what datasets feed these models.
2. The legal team must review all current patient and user notices to determine if AI training is explicitly stated as a purpose.
3. Work with engineering control owners to implement data minimization filters that strip identifiers before data enters the training environment.
4. Establish a formal attestation workflow where product managers sign off on the data source and consent mapping before launching any new AI feature.
What To Watch
The implementation of the DPDP Rules, 2025 will clarify specific technical standards for notice generation and verifiable parental consent mechanics in digital health platforms. The Data Protection Board is expected to issue early guidance on how purpose limitation applies to secondary data processing like machine learning. Healthcare Significant Data Fiduciaries should prepare for strict audit requirements regarding automated processing. 286 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess your organisation exposure to AI data risks and check your readiness, run a free self-assessment at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to publicly scraped data for AI training?
Yes, Section 3 of the DPDP Act 2023 applies unless the personal data was made publicly available directly by the Data Principal or by someone under a legal obligation. General web scraping of digital personal data still requires a lawful basis for processing.
How does the DPDP Act restrict AI model training in healthtech?
The Act enforces precise purpose limitation and data minimization. If patient data was collected for medical treatment, using it to train AI models requires fresh, itemised notice and verifiable consent under the DPDP Rules, 2025.
What happens if personal data is exposed during an AI platform breach?
Under the DPDP Rules, 2025, you must provide intimation to affected Data Principals without delay. A detailed incident report must also be submitted to the Data Protection Board within 72 hours, backed by comprehensive audit trails.
What are the financial risks of using unconsented data in AI models?
Failing to observe obligations to process personal data lawfully can result in severe financial consequences. The penalty ceilings under the DPDP Act reach up to 250 crore rupees for failing to take reasonable security safeguards.
Can we transfer patient data offshore to train our AI models?
Cross-border transfers are generally permitted unless the Central Government places the destination on a restricted negative list. However, you must still maintain regulator-ready evidence that the original consent permits offshore processing.
ComplyDP