📣 Send us your press release
Site updates every 15 minutes
Technology

India's Data Law Faces AI Challenges: Discussion Highlights Gaps

A closed-door discussion in India on AI and privacy has highlighted the challenges facing the country's new data protection law in the context of AI training. A key debate centered on data ownership and access rights.

1 September 2026
India's Data Law Faces AI Challenges: Discussion Highlights Gaps
Image is an AI-generated illustration

A recent closed-door discussion in India focusing on artificial intelligence (AI) and privacy has brought to light fundamental questions regarding personal data ownership and how existing privacy principles apply to AI model training. The dialogue, conducted under Chatham House Rule, revealed significant disagreements on how India's Digital Personal Data Protection (DPDP) Act of 2023 applies to the data collection and usage demands of AI, especially as the law is not yet fully enforced.

Participants noted that the requirements for AI training conflict with traditional privacy principles designed for the Web 2.0 era. Challenges specifically arise from large-scale data scraping, the concurrent use of multiple legal bases for processing, and the principle of purpose limitation, which restricts the reuse of collected data. India's DPDP Act primarily offers two grounds for processing personal data: consent and specific "legitimate uses" outlined in the act, contrasting with, for example, the EU's GDPR, which recognizes six lawful bases. This gap could pose difficulties for AI developers.

Industry stakeholders, such as the Internet and Mobile Association of India (IAMAI), have already requested the government to permit the use of publicly available personal data for training AI models without separate consent, arguing that verifying data's public nature at AI training scale is impractical. The discussion also explored whether "ownership" is even the correct framework for personal data. One view suggested that individuals do not own their data in the same way they don't own a phone number, but rather have the right to control its use. Others countered that ignoring the concept of ownership risks undermining the individual's fundamental right to privacy.

Furthermore, the discussion touched upon the potential for AI training without direct access to raw personal data, such as by using pseudonymized or locally processed data. There was also consideration of whether India's Data Empowerment and Protection Architecture (DEPA) could be adapted for AI training as "tokenized" data. While India's DPDP Act has been enacted, its full implementation is still pending, with consent management systems estimated to become operational only by mid-2026. This delay creates uncertainty and challenges for the practical application of the legislation.

Original source: medianama.com