2 Sources
[1]
DPDP rules will raise compliance bar for AI firms
Legal and AI-industry experts said the rules will spur more rigorous governance across AI pipelines, while creating opportunities for responsible innovation. India's newly notified Digital Personal Data Protection (DPDP) Rules are set to reshape how artificial intelligence companies collect,
[2]
How Will DPDP Rules Affect AI Models Collecting, Retaining Data?
India's new data protection regime is going to reshape how AI developers collect, train, and retain data, as the Digital Personal Data Protection (DPDP) Act, 2023, together with the DPDP Rules, 2025, introduces a consent-centric framework that applies to all digital personal data processed in
Share
Copy Link
India's Digital Personal Data Protection Rules introduce stringent consent-based frameworks that will significantly reshape how AI companies collect, process, and retain personal data, raising compliance standards across the industry.
India's newly notified Digital Personal Data Protection (DPDP) Rules are fundamentally transforming how artificial intelligence companies handle personal data, establishing stringent compliance requirements that will reshape the entire AI ecosystem. The rules, which work in conjunction with the DPDP Act 2023, introduce a consent-centric framework that applies to all digital personal data processed within India's jurisdiction
1
.
Source: ET
Legal and AI industry experts unanimously agree that these regulations will spur more rigorous governance across AI pipelines while creating new opportunities for responsible innovation. The framework requires companies to obtain free, specific, and informed consent for each specified purpose, fundamentally changing how AI training datasets are assembled and maintained
2
.IndiaAI Mission chief executive Abhishek Singh emphasized that developers using personal data for training must now implement anonymization and privacy-preserving processes in line with the Act's requirements. "If anyone is having any data for training AI models, if there are personal data attributes there, then they have to do anonymisation, they have to do privacy preservation and then only use it for AI training," Singh explained
1
.
Source: MediaNama
Supratim Chakraborty, partner at law firm Khaitan & Co, described the rules as marking a major shift for companies integrating AI into core products and workflows. "With AI now embedded in core systems, firms must rigorously audit how personal data is sourced, labelled, and used across model training and inference. Models that cannot evidence compliant data handling will not be viable in India's regulatory environment," he stated
1
.Related Stories
The new framework introduces significant technical challenges, particularly around data erasure and consent management. Companies must now design systems capable of selectively removing data from training pipelines when users withdraw consent, a requirement that could force fundamental changes in how AI models are developed and maintained
2
.Nikhil Jhanji, Senior Product Manager at IDfy, emphasized that "traceability and explainability is now non-negotiable," recommending that teams "embed logging directly into the data pipeline so every ingestion, preprocessing, or training event leaves a verifiable trail"
2
.Vaibhav Velhankar, cofounder and CTO at Segumento, highlighted the cultural shift required within the AI ecosystem. "Every dataset used in training must now have demonstrable consent, clear purpose limitation, proper labelling, traceability and secure handling. Models can no longer be trained on ambiguous datasets or undocumented workflows," he explained
1
.Summarized by
Navi
26 Aug 2026•Policy and Regulation

21 Oct 2024•Policy and Regulation

20 Sept 2024

1
Technology

2
Technology

3
Science and Research
