AMLEGALS — Strategic Lawyering
DPDPA and AI · Emerging

AI and data privacy in India: how the DPDPA applies

India does not yet have a dedicated AI statute. That does not leave AI unregulated where it touches personal data. An AI system that processes personal data is subject to the DPDPA like any other processing, and several of the Act’s duties are difficult to meet without deliberate design.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

A gold neural lattice resolving into ordered data nodes on a dark navy background
Short answer

There is no AI-specific law in force in India as of 2026; a Digital India Act has been discussed as a successor to the Information Technology Act, 2000, but it is not yet enacted. In the meantime, an organisation that uses AI to process personal data is a Data Fiduciary under the Digital Personal Data Protection Act, 2023 and must meet its obligations. That means a lawful basis under Section 4, which is consent under Section 6 or a legitimate use under Section 7; notice under Section 5; purpose limitation; the accuracy duty under Section 8(3), which matters for training data and model outputs; security safeguards under Section 8(5); and the ability to erase personal data under Section 8(7) when the purpose is served or consent is withdrawn. Importantly, the DPDPA does not contain a specific right against automated decision-making or profiling equivalent to Article 22 of the GDPR. The protections for AI therefore come from the general duties, applied carefully, rather than from a dedicated AI provision.

  • Artificial intelligence
  • Machine learning
  • Training data
  • Accuracy
  • Section 8
  • Governance
AI-specific law
None in force as of 2026
Lawful basis
Consent (Section 6) or legitimate use (Section 7)
Key duties
Accuracy (8(3)), safeguards (8(5)), erasure (8(7))
No equivalent to
A GDPR Article 22 automated-decision right

There is no AI law yet, but there is a data law

The question is often framed as “what does Indian AI law require”. The more accurate question today is “what does the DPDPA require of AI that uses personal data”. A Digital India Act has been discussed, but until it is enacted, the DPDPA is the operative statute for personal data in AI systems.

This matters because the DPDPA applies to the processing, whatever the technology. Training a model on personal data, running inference on personal data, and storing AI outputs that relate to identifiable people are all processing.

Lawful basis for training and inference

Section 4 requires a lawful basis for processing. For AI, the hard part is usually training data. Personal data used to train a model needs either consent under Section 6 or a legitimate use under Section 7, and the purpose stated in the Section 5 notice must actually cover model training.

A common gap is collecting data for one stated purpose and later using it to train a model for a different purpose. That reuse needs its own basis; it is not covered by the original consent simply because the organisation already holds the data.

Accuracy, erasure and the duties that bite

Two duties are particularly demanding for AI systems.

  • Accuracy, Section 8(3): where personal data is used to make a decision affecting a person, or is disclosed, it must be accurate and complete. AI outputs that assert facts about people engage this duty.
  • Erasure, Section 8(7): personal data must be erased when the purpose is no longer served or consent is withdrawn, unless retention is legally required. Designing erasure around training datasets and derived data takes planning.
  • Security, Section 8(5): reasonable safeguards must protect the personal data an AI system ingests and produces.
  • Correction, Section 12: a person can seek correction of inaccurate personal data, which an AI pipeline must be able to honour.

What the DPDPA does not give

The GDPR contains, in Article 22, a specific right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. The DPDPA does not contain an equivalent right.

This is a real difference for anyone adapting a GDPR programme. Under the DPDPA, the controls on automated decisions come from the general duties, notice, accuracy, grievance redress and the overall fairness of processing, rather than from a standalone automated-decision provision. Organisations that want to meet a higher standard can still build human review into significant automated decisions as a matter of governance.

How AMLEGALS advises on AI and data

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team reviews the lawful basis for training and inference, checks that notices cover model use, and designs accuracy, correction and erasure so that an AI pipeline can meet the Act’s duties.

Questions and answers

AI and Data Privacy in India: common questions

Is there an AI law in India?

Not as of 2026. A Digital India Act has been discussed, but it is not yet enacted. AI that processes personal data is governed by the DPDPA.

Can we train a model on data we already hold?

Only if training is covered by a lawful basis and the original notice. Reusing data for a new purpose such as model training generally needs its own basis.

Does the DPDPA have a right against automated decisions?

No. Unlike GDPR Article 22, the DPDPA has no specific automated-decision or profiling right. Protection comes from the general duties.

How does the accuracy duty affect AI outputs?

Section 8(3) requires personal data used for decisions or disclosed to be accurate and complete, which engages AI outputs that state facts about people.

Do people have rights over AI-held data?

Yes. Access, correction and erasure under Sections 11, 12 and the Section 8(7) duty apply to personal data within an AI system.

Contact

Make your AI use DPDPA-ready

Share how your AI uses personal data. The AMLEGALS data privacy team will review the lawful basis and the duties your pipeline must meet.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

AI and Data Privacy in India: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to AI and Data Privacy in India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on AI and Data Privacy in India under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on AI and Data Privacy in India under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on AI and Data Privacy in India?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for AI and Data Privacy in India rather than a generic checklist.

How do I get a first view of my DPDPA exposure on AI and Data Privacy in India?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about AI and Data Privacy in India · DPDPA Exposure Assessment