Training and serving large models on personal data raises lawful-basis, purpose and cross-border questions the Act takes seriously, with no settled AI rule yet.
In short
There is no dedicated Indian AI statute yet, so foundation-model providers work under the DPDP Act general rules: personal data used to train or serve models needs a lawful basis, is bound by its original purpose. Large providers are likely SDF candidates once designation begins. Penalties reach ₹250 crore.
What changes for this niche, and the specific rule it turns on.
Personal data used to train models needs consent or a valid legitimate use, not mere availability on the web.
Data collected for one purpose cannot silently become training data for another without a fresh basis.
Prefer anonymised or synthetic data; strip identifiers you do not need.
Individuals can get a summary of their personal data and processing under Section 11; the Act creates no standalone right to a model's logic. SDF designation would add algorithmic due-diligence duties.
The DPDP cross-border default is permissive, but design for a future Section 16 restriction or an SDF localisation direction.
Short, cite-able answers, mirrored in FAQPage schema.
Fix the lawful basis for training data and purpose limits first.
The readiness check flags basis, purpose and cross-border gaps in AI use.
Take the readiness check →