There is no AI law yet, but there is a data law
The question is often framed as “what does Indian AI law require”. The more accurate question today is “what does the DPDPA require of AI that uses personal data”. A Digital India Act has been discussed, but until it is enacted, the DPDPA is the operative statute for personal data in AI systems.
This matters because the DPDPA applies to the processing, whatever the technology. Training a model on personal data, running inference on personal data, and storing AI outputs that relate to identifiable people are all processing.
Lawful basis for training and inference
Section 4 requires a lawful basis for processing. For AI, the hard part is usually training data. Personal data used to train a model needs either consent under Section 6 or a legitimate use under Section 7, and the purpose stated in the Section 5 notice must actually cover model training.
A common gap is collecting data for one stated purpose and later using it to train a model for a different purpose. That reuse needs its own basis; it is not covered by the original consent simply because the organisation already holds the data.
Accuracy, erasure and the duties that bite
Two duties are particularly demanding for AI systems.
- Accuracy, Section 8(3): where personal data is used to make a decision affecting a person, or is disclosed, it must be accurate and complete. AI outputs that assert facts about people engage this duty.
- Erasure, Section 8(7): personal data must be erased when the purpose is no longer served or consent is withdrawn, unless retention is legally required. Designing erasure around training datasets and derived data takes planning.
- Security, Section 8(5): reasonable safeguards must protect the personal data an AI system ingests and produces.
- Correction, Section 12: a person can seek correction of inaccurate personal data, which an AI pipeline must be able to honour.
What the DPDPA does not give
The GDPR contains, in Article 22, a specific right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. The DPDPA does not contain an equivalent right.
This is a real difference for anyone adapting a GDPR programme. Under the DPDPA, the controls on automated decisions come from the general duties, notice, accuracy, grievance redress and the overall fairness of processing, rather than from a standalone automated-decision provision. Organisations that want to meet a higher standard can still build human review into significant automated decisions as a matter of governance.
How AMLEGALS advises on AI and data
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team reviews the lawful basis for training and inference, checks that notices cover model use, and designs accuracy, correction and erasure so that an AI pipeline can meet the Act’s duties.

