DRMLAW
Knowledge Article

DPDPA and AI Governance in India: A Balanced Reading

By Rupak Ranjan Mukherjee, BE,CCLP,C.DPO.DA, Founder Partner · 2026-08-26 · Data Protection & Privacy

DPDPA and AI Governance in India: A Balanced Reading

Fiduciary Duties, Principal Rights, and the Trust Dividend Businesses Are Leaving on the Table

By Rupak Ranjan Mukherjee, Founder, DRMLAW LLP — DPDPA Compliance Architect & AI Governance Strategist

Two Statutes for the Price of One: Duty and Right in the Same Section

India has deliberately declined to enact a dedicated AI law. MeitY's India AI Governance Guidelines (November 2025) and the RBI's FREE-AI Committee report (August 2025) are both voluntary, principles-based frameworks — no binding obligations, no penalty schedule. That leaves the Digital Personal Data Protection Act, 2023, operationalised through the DPDP Rules, 2025, as the only statute with enforceable teeth — statutory penalties up to ₹250 crore — wherever an AI system ingests, scores, profiles, or decides using personal data.

It is accurate to call DPDPA India's de facto AI governance law in that narrow but important sense. What is easy to lose in that framing, however, is that DPDPA was never written as an AI statute. It is, at its core, a relationship statute between two parties — the Data Fiduciary who processes personal data, and the Data Principal whose data it is. Every obligation the Act places on a business exists because it corresponds to a right the Act gives the individual. Reading DPDPA purely as a compliance risk to be managed misses the more useful reading: it is a map of the trust a fiduciary owes its customers, employees, and users — and AI is simply the newest, highest-stakes place that trust gets tested.

Duty and Right, Side by Side

DPDPA Provision

Data Fiduciary's Duty

Data Principal's Corresponding Right

Section 6 (Consent)

Obtain valid, specific, informed, unambiguous consent before using personal data to train, fine-tune, or feed an AI system; keep the consent notice free of dark patterns

The right to know exactly what data is being collected and for what AI-related purpose, and to refuse or withdraw consent without being denied service unfairly

Section 8(5)–(6) (Security & breach)

Secure model weights, prompt logs, training pipelines, and inference outputs to the same standard as any other repository of personal data; notify the Board and affected principals on breach

The right to be informed promptly if an AI system's data has been compromised, and to expect that a fiduciary treats AI infrastructure as seriously as its core databases

Rule 13 (SDF obligations)

Where classified as a Significant Data Fiduciary, run algorithmic impact assessments, annual DPIAs, and independent audits of AI/ML systems that process personal data at scale

The right to expect that large-scale automated processing affecting many people has been proactively tested for fairness and accuracy — not just legally permitted

Sections 11–13 (Access, correction, erasure)

Provide a workable mechanism for a principal to access their data, correct inaccuracies, and request erasure — including data that has fed into an AI system

The right to see, correct, and (subject to technical and legal limits discussed below) request erasure of personal data used by an AI system

Section 16 (Cross-border transfer)

Disclose and restrict transfer of personal data to foreign AI/cloud infrastructure in line with the negative-list regime

The right to know where their data physically goes when it is processed by a third-party AI tool, including foreign-hosted LLM APIs

Read left to right, this is a compliance checklist. Read right to left, it is a customer trust charter — and the businesses that internalise the second reading tend to find the first reading easier, not harder, to satisfy.

Where the Case for DPDPA-as-AI-Law Needs Careful Qualification

A rigorous reading of DPDPA against AI deployment also requires being honest about where the analogy to GDPR overstates India's current statutory position, and where DPDPA does not operate alone. Overstating the law helps no one — a business that over-promises “explainable AI” rights to customers it cannot legally or technically deliver creates its own liability. Three qualifications matter.

1. DPDPA does not yet grant a standalone “right to explanation.” Sections 11–13 give a Data Principal the right to access, correct, and erase their personal data — not, as GDPR Article 22 does for the EU, an explicit statutory right to a meaningful explanation of the logic behind an automated decision. In practice, a business that cannot explain its model's data lineage still carries real exposure — it cannot honour a correction request it doesn't understand, and it cannot survive a Rule 13 algorithmic impact assessment or SDF audit with a black box. But the legal hook for that exposure is the SDF audit and due-diligence standard, not a direct “right to explanation” claim from an individual. DRMLAW advises clients to build explainability as an operational necessity and an audit-readiness measure, without overselling it in customer-facing terms as a statutory guarantee DPDPA does not yet make explicit.

2. “Erasure” against a trained model is a genuine technical constraint, not just a compliance checkbox. Once personal data has been absorbed into a trained model's weights, selectively “forgetting” that one person's data — true machine unlearning — is, with current technology, difficult and often practically equivalent to retraining the model from scratch. A fiduciary's good-faith duty under Sections 11–13 is to act on a valid erasure request within its technical means — typically by purging the data from source datasets and retraining pipelines going forward, deleting it from any retrievable store, and documenting why full retroactive unlearning from a live model is not currently feasible where that is genuinely true. The honest position for a business to take with regulators and customers alike is to disclose this constraint upfront in its AI privacy notice, rather than promise an erasure capability it cannot deliver.

3. DPDPA does not operate in a vacuum — sectoral regulators stack their own AI expectations on top of it. RBI's model risk management directions for NBFCs and banks, SEBI's algorithmic trading and advisory rules, IRDAI's guidelines for insurers, and the Medical Council's telemedicine and diagnostic norms all impose their own AI-adjacent obligations — vendor risk assessments, model validation, audit trails — independent of DPDPA. A business that treats DPDPA compliance as the whole of its AI governance obligation, rather than the personal-data layer of a broader sectoral compliance stack, will still find gaps. DRMLAW's advisory work maps DPDPA obligations alongside the relevant sectoral overlay for each client, rather than treating the two as substitutes.

What GDPR Enforcement Still Teaches — With the Same Caveats Applied

The European cases that best illustrate this risk were themselves brought under GDPR — the general data protection law — not the EU AI Act, which reinforces the article's core point: a data protection statute, not a dedicated AI law, is doing the enforcement work. The same duty/right framing applies to each.

Deliveroo and Foodinho (Italy, Garante, 2021 and 2024). Fines of €2.5 million and €2.6 million (a further €5 million in 2024) for algorithmic rider management with no meaningful human review and no contest mechanism. The fiduciary's duty failure was concrete: no DPIA before deployment, no proof the scoring model wasn't discriminatory. The principal's right that was denied was equally concrete — the right to contest a decision that affected their livelihood. Indian NBFC credit-scoring and gig-platform account decisions sit in the same fact pattern.

Uber (Netherlands, Autoriteit Persoonsgegevens) — €825 million. The larger share of this fine was for unlawful cross-border data transfers, with automated driver deactivation as a contributing finding. The Dutch regulator's 2025 clarification — that a human reviewer must have genuine authority to overturn an algorithm, not merely rubber-stamp it — is the operative lesson for any Indian platform using AI to terminate accounts, deny claims, or decline credit.

Clearview AI (France, Italy, Netherlands, UK — cumulative fines exceeding €100 million). AI trained on billions of scraped images with no consent and no lawful basis. Regulators found the violation at the point of unlawful collection and training — not merely at the point of commercial use. Indian real-estate lead aggregation and any biometric/facial-match feature built on purchased or scraped datasets carry the identical exposure under Section 6.

In each case, the fine was for a failed duty; the underlying harm was a denied right. That pairing — not the size of the number — is the transferable lesson for India.

Five Sectors: Where Duty, Right, and Trust Meet

The same tension — what the fiduciary must do, what the principal is entitled to, and what genuinely earns customer trust beyond the legal minimum — plays out differently by sector.

1. NBFC / Lending

2. Education / EdTech

3. Real Estate / PropTech

4. Healthcare / Health-Tech

5. E-commerce / Retail

Why Now: The Window to Get the Balance Right Pre-Emptively

India's DPDPA enforcement architecture is due to be fully operational by May 2027. That is better read as a design window than a grace period. The businesses that use it well are not the ones scrambling to minimise fiduciary duty — they are the ones building principal-facing rights (access, correction, meaningful human review, honest disclosure of technical limits) into their AI products now, while the cost of doing so is a design choice rather than a retrofit forced by a regulator, a rejected customer, or a breach.

The DRMLAW Position: Advising the Tradeoff, Not Just the Rule

DPDPA compliance and AI governance are not two engagements, and they are not a one-directional list of obligations to minimise. They are a single techno-legal exercise in balancing what a Data Fiduciary must do, what a Data Principal is entitled to, what is technically achievable today, and what a sectoral regulator separately expects — before the Data Protection Board or a sectoral regulator forces the question.

DRMLAW LLP's advisory approach is built on that balance rather than a checklist. Combining DPO-as-a-Service, DPDPA compliance advisory, and AI/digital forensics capability under one roof — with the technical grounding of 25+ years in enterprise cloud and AI infrastructure alongside GDPR-honed privacy engineering — DRMLAW works with clients to distinguish genuine statutory exposure from overstated risk, to be candid about technical constraints like machine unlearning rather than promise what current AI systems cannot deliver, and to map the sectoral regulatory overlay (RBI, SEBI, IRDAI) that sits alongside DPDPA rather than treating either in isolation. The result is an AI governance posture that satisfies the regulator, is technically honest with the customer, and is defensible — not just documented — when it is tested.

DRMLAW LLP — D.R. Mukherjee & Co. Advocates | Kolkata | Bengaluru

This article is for general informational purposes and does not constitute legal advice. Organisations should seek jurisdiction- and sector-specific counsel before implementing AI governance or DPDPA compliance programmes.