Training and running models on personal data raises consent, purpose and minimization questions the Act takes seriously.
In short
Using personal data to train or run models is processing like any other: it needs a lawful basis, it is bound by the purpose it was collected for, and Section 11 gives individuals a summary of their data and processing, not a right to the model's logic. Penalties reach ₹250 crore.
What changes for this sub-sector.
Personal data used to train models needs consent or a valid legitimate use, not just availability.
Data collected for one purpose cannot quietly become training data for another without a fresh basis.
Prefer anonymised or synthetic data; strip identifiers you do not need.
Be able to describe how personal data feeds a model and its outputs.
Plan how access, correction and erasure requests are handled where data has fed a model.
Foundation-model and data providers are processors; contract for their handling.
Niche guides for this area, each naming the specific regulation.
Fix the lawful basis for training data first, then minimise.
The readiness check surfaces basis, purpose and transparency gaps in AI use.
Take the readiness check →