News Analysis • 4 min read
Privacy vs AI Training: Navigating the DPDP Act Risk for BFSI Enterprises
An analysis of the NASSCOM report detailing the legal conflict between AI data scraping, copyright allowances, and the strict consent and purpose limitation mandates of the DPDP Act 2023.
Last updated:
What happened
A recent report from the NASSCOM community titled Privacy, Copyright, and Trade Secret highlights a growing legal conflict between AI data scraping practices and privacy laws in India. The publication details the tension between copyright allowances, which might permit scraping public content like online interviews, and the strict consent and purpose limitation mandates of the Digital Personal Data Protection Act, 2023. The report notes that debates persist regarding the independence and enforcement powers of the Data Protection Board of India, originally proposed by the Justice B.N. Srikrishna Committee. These ongoing debates suggest it may take time for the DPBI to achieve the regulatory harmonization targeted by MeitY.
Does the DPDP Act apply here?
The DPDP Act governs digital personal data processed within India, and processing outside India if connected to offering goods or services to Data Principals in India. AI developers and financial institutions often assume that any publicly available data is exempt from privacy regulations. Section 3 of the Act clarifies that personal data is only exempt if it is made publicly available by the Data Principal to whom it relates, or by another person under a legal obligation to do so. If an AI company or a bank scrapes an online interview published by a media outlet, and that publication was not a statutory obligation, the scraped personal data falls squarely within the scope of the Act.
Legal implications under DPDP
Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Training commercial language models on scraped personal data requires a lawful purpose, meaning explicit, itemised consent must be obtained for that exact use case. Using data initially gathered for public reporting to instead train commercial AI models violates the core principle of purpose limitation. Furthermore, the DPDP Rules 2025 require organizations to maintain verifiable records of this consent. Relying on copyright exceptions to justify scraping personal data does not bypass the distinct privacy obligations established by MeitY, exposing data fiduciaries to severe compliance risks.
Could this happen to you
For a Chief Financial Officer in the BFSI sector, this AI data scraping conflict represents a massive unquantified contingent liability. Banks and non-banking financial companies are rapidly integrating AI into credit scoring, customer service chatbots, and fraud detection. If your external vendor consolidates datasets by scraping web data or repurposing legacy KYC data lakes for AI training without purpose-specific consent, your institution bears the regulatory risk. The DPBI is empowered to levy penalties up to Rs 250 crore for significant breaches. Such an event would immediately inflate audit fees, trigger board-level scrutiny, and likely cause a sharp increase in your cyber insurance premium, directly impacting your EBITDA.
What companies should do in the next 30 days
1. The CFO and Chief Compliance Officer must jointly audit the data supply chain for all internally developed and vendor-provided AI models to identify scraped personal datasets.
2. Financial leaders should evaluate the TCO of implementing automated consent management and data lineage tools to replace manual error-prone compliance tracking.
3. The legal team must update processor contracts to enforce strict purpose limitation, providing the foundation for vendor consolidation around compliant AI partners.
4. Finance and risk teams should model the penalty exposure in rupee terms to justify compliance budgeting and adjust provisioning for potential regulatory actions.
5. Review current cyber insurance policies to ensure coverage for DPBI investigations and the 72-hour breach notification workflows mandated by the DPDP Rules 2025.
What to watch
Industry leaders will be closely monitoring how the Data Protection Board of India navigates its mandate amid ongoing debates over its independence and enforcement powers. The speed at which the DPBI aligns with MeitY on regulatory harmonization will dictate the immediate risk environment for AI deployments. Organizations cannot wait for these debates to settle, as exactly 267 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess your institution's exposure to AI data processing risks, finance and compliance teams can utilize the self-assessment tools available at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act restrict scraping publicly available data for AI?
Yes. Section 3 of the Act exempts publicly available data only if it was published by the Data Principal themselves or under a legal obligation. Scraping personal data from other public sources without consent falls under the Act.
Can BFSI firms repurpose legacy KYC data to train internal AI models?
No. Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Training AI requires specific consent, and repurposing KYC data violates the strict purpose limitation mandates.
What is the financial exposure for non-compliance in AI data usage?
Organizations face a massive contingent liability with penalties reaching up to Rs 250 crore per breach. This scale of exposure necessitates careful provisioning and directly impacts cyber insurance premiums and overall EBITDA.
How do the DPDP Rules 2025 impact AI vendor management?
The Rules mandate stringent processor oversight, verifiable consent records, and a detailed breach reporting workflow to the DPBI within 72 hours. Financial institutions must drive vendor consolidation to ensure third-party AI partners meet these standards.
How much time is left to align our AI data supply chain with the DPDP Act?
Exactly 267 days remain until the 13 May 2027 hard deadline. CFOs should immediately assess the TCO of automated compliance tooling to prepare their institutions ahead of enforcement.
ComplyDP