Readiness assessment
SaaS & Technology · AI & ML

The DPDP Act for AI & ML

Training and running models on personal data raises consent, purpose and minimization questions the Act takes seriously.

In short

Using personal data to train or run models is processing like any other: it needs a lawful basis, it is bound by the purpose it was collected for, and Section 11 gives individuals a summary of their data and processing, not a right to the model's logic. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Lawful basis for training data

Personal data used to train models needs consent or a valid legitimate use, not just availability.

Purpose limitation

Data collected for one purpose cannot quietly become training data for another without a fresh basis.

Minimization and de-identification

Prefer anonymised or synthetic data; strip identifiers you do not need.

Transparency of automated use

Be able to describe how personal data feeds a model and its outputs.

Rights vs trained models

Plan how access, correction and erasure requests are handled where data has fed a model.

Model and data vendors

Foundation-model and data providers are processors; contract for their handling.

Go deeper

Niche guides for this area, each naming the specific regulation.

Check your AI data pipeline.

The readiness check surfaces basis, purpose and transparency gaps in AI use.

Take the readiness check