News Analysis • 4 mins
AI Training vs Patient Privacy: DPBI Enforcement Risks for HealthTech Legal Leaders
As debates surround the DPBI's enforcement powers and AI data scraping, healthcare General Counsels must evaluate liability, consent records, and regulatory defensibility under the DPDP Act 2023 and Rules 2025.
Last updated:
What Happened
A recent report from the Nasscom community highlights the growing friction between Artificial Intelligence training and personal data rights in India. The analysis points to ongoing debates regarding the independence and enforcement powers of the Data Protection Board of India (DPBI), a body conceptualised following the Justice B.N. Srikrishna Committee report. AI models inherently rely on massive datasets to function, directly conflicting with the strict collection and processing regulations introduced by the Digital Personal Data Protection Act, 2023 and the upcoming Rules, 2025. Furthermore, structural debates surrounding the DPBI may delay the Ministry of Electronics and Information Technology (MeitY) in harmonising the broader regulatory framework.
Does The DPDP Act Apply Here
Under Section 3 of the Digital Personal Data Protection Act, 2023, the law applies to the processing of digital personal data within India, and processing outside India if connected to offering goods or services to Data Principals in India. A critical exemption exists under Section 3(c)(ii) for personal data made publicly available by the Data Principal or under a legal obligation. However, for General Counsels in healthcare and healthtech, patient records used for training diagnostic AI models are never legally public. Therefore, repurposing clinic data for algorithmic training falls squarely under the Act and requires clear regulatory defensibility.
Legal Implications Under DPDP
Section 4 dictates that processing must be for a lawful purpose, requiring clear alignment with statutory grounds. Under the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. For healthtech platforms feeding patient data into AI engines, relying on legacy terms of service will not survive regulatory engagement. The Rules, 2025 mandate verifiable, itemised notices before processing, alongside strict purpose limitation and data minimisation.
Could This Happen To You
If your hospital network or medical platform licenses patient data to an AI vendor, a data breach or unlawful processing complaint triggers immediate litigation risk. The DPBI will demand complete consent trails and data flow maps during their privileged review. If your compliance relies on manual spreadsheets, proving defensibility within the 72-hour breach window is impossible, exposing the organisation to massive penalty ceilings. Legal heads must closely examine vendor contracts to ensure comprehensive indemnity clauses and limitation of liability carve-outs for DPBI fines. Your board will ask how outside counsel spend and internal workflows protect against these exact AI processing failures.
What Companies Should Do In The Next 30 Days
1. Legal Heads must review all AI vendor contracts to allocate liability and secure indemnities for unlawful processing. Ensuring these clauses cover potential DPBI fines is critical for limiting financial exposure.
2. Compliance teams must map all patient data flows across the organisation. This verifies whether the data fed into AI models is genuinely anonymised or still qualifies as personal data requiring consent.
3. Medical directors must update patient intake forms to align with the Rules, 2025 itemised notice standards. This guarantees clear, verifiable consent is captured for any secondary processing like algorithm training.
4. Establish a 72-hour breach response protocol to prepare for regulatory engagement. The Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours if a vendor exposes patient records.
What To Watch
Legal teams must monitor MeitY notifications regarding DPBI operational guidelines and potential safe harbour provisions for health research. The outcome of debates surrounding the independence of the DPBI will dictate how aggressively enforcement actions are pursued against enterprise platforms. 265 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess your organisation's baseline readiness for these regulatory requirements, you can run a gap analysis at freescan.complydp.com.
Sources
Frequently asked questions
Can we use existing patient records to train our medical AI models under DPDP?
Under the Digital Personal Data Protection Act, 2023, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Using existing patient records for new AI training requires verifiable consent and itemised notice as prescribed by the Rules, 2025, unless the data is irreversibly anonymised.
How does the DPDP Act affect our AI vendor contracts?
General Counsels must update vendor contracts to include strict data handling protocols and clear liability allocation. If an AI vendor breaches data, the fiduciary remains accountable, making strong indemnity clauses critical for regulator defensibility.
What are the breach notification requirements if our AI provider suffers a cyber attack?
The Rules, 2025 mandate that personal data breaches must be reported to the DPBI within 72 hours. Additionally, you must send an intimation to affected Data Principals without delay, making automated evidence trails essential for compliance.
Does the DPDP Act treat medical data differently for AI processing?
The DPDP Act 2023 does not create a separate category for sensitive medical information, as the law applies uniformly to all digital personal data. However, the high volume and risk associated with patient data may lead to classification as a Significant Data Fiduciary, which carries stricter auditing obligations.
What is the deadline to comply with the DPDP Act and Rules?
Companies must prepare for enforcement as the regulatory framework crystallises and the DPBI becomes operational. Currently, 265 days remain until the DPDP hard compliance deadline of 13 May 2027, requiring immediate alignment of data practices.
ComplyDP