Post

Navigating AI Training Data: DPDPA's Deemed Consent vs. Global Frameworks

Navigating AI Training Data: DPDPA's Deemed Consent vs. Global Frameworks

The burgeoning field of Artificial Intelligence (AI) relies heavily on vast datasets for training, posing significant questions for data protection regimes worldwide. As of July 2026, Indian businesses are grappling with the implications of the Digital Personal Data Protection Act, 2023 (DPDPA) for AI training data, often looking to global precedents like the GDPR and UK ICO guidance for clarity. A core tension lies in reconciling the extensive data requirements of AI with individual privacy rights, particularly concerning the lawful basis for processing.

The DPDPA primarily anchors data processing on the explicit consent of the Data Principal, as outlined in Section 6. However, it also introduces the concept of “deemed consent” under Section 7, allowing processing without explicit consent in specific circumstances. For AI training data, two clauses under deemed consent are particularly relevant: Section 7(a), which permits processing for purposes for which the Data Principal has voluntarily provided their data and has not indicated withdrawal of consent, implying a “reasonably expected” use; and Section 7(e), which allows processing for the legitimate interests of the Data Fiduciary, provided such interests are not overridden by the interests of the Data Principal.

While Section 7(e) conceptually aligns with the “legitimate interests” ground seen internationally, the DPDPA currently lacks specific guidance on how this “deemed consent” applies to the often opaque and large-scale data processing inherent in AI model training. This creates a “deemed-consent gap” for AI training data. Indian businesses face ambiguity regarding the scope of “legitimate interests” in this context, especially when original data collection purposes differ significantly from subsequent AI training. The onus is on the Data Fiduciary to demonstrate that AI training falls within a legitimate interest and does not disproportionately impact Data Principals. The IT Rules, 2021, particularly Rule 3(1)(a) requiring consent for sensitive personal data, remain relevant for specific data types, but DPDPA now provides the overarching framework.

GDPR’s Legitimate Interests: A Balancing Act

In contrast, the European Union’s General Data Protection Regulation (GDPR) offers a more established, albeit stringent, pathway for processing data for purposes like AI training through its “legitimate interests” ground under Article 6(1)(f). This article permits processing when it is “necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.”

The key difference here is the explicit requirement for a comprehensive “balancing test.” A data controller must identify a genuine legitimate interest (e.g., developing new AI products, improving services), demonstrate that the processing is necessary to achieve that interest, and critically, assess whether the individual’s rights and freedoms outweigh the controller’s interest. This often involves conducting a Legitimate Interest Assessment (LIA) and implementing safeguards like anonymization, pseudonymization, and robust security measures. While not explicitly mentioning AI, GDPR’s Article 6(1)(f) has been widely interpreted and applied to AI training scenarios, providing a clear, albeit demanding, legal basis.

UK ICO Guidance: Practicality and Risk Mitigation

The UK Information Commissioner’s Office (ICO), operating under the UK GDPR (which largely mirrors the EU GDPR), has provided more specific and practical guidance on data protection in the context of AI. The ICO’s approach emphasizes a risk-based methodology, encouraging AI developers to integrate data protection principles from the design stage. Similar to GDPR, the ICO recognizes “legitimate interests” as a potential lawful basis for AI training, but it stresses the importance of transparency, data minimization, and accountability.

The ICO’s guidance encourages organizations to consider the nature of the data, the specific purpose of the AI system, and the potential impact on individuals when selecting a lawful basis. It highlights the utility of privacy-enhancing technologies (PETs) and the need for Data Protection Impact Assessments (DPIAs) for high-risk AI processing. The UK ICO’s detailed recommendations offer practical steps for fulfilling the requirements of the legitimate interests ground, moving beyond mere legal interpretation to operational best practices.

Comparative Analysis: Stricter, Looser, or Silent?

Comparing these frameworks reveals distinct approaches to AI training data. The DPDPA, with its broad “deemed consent” for legitimate interests (Section 7(e)), appears conceptually aligned with GDPR’s Article 6(1)(f). However, the DPDPA is currently silent on specific interpretations or guidance for AI training, leaving Data Fiduciaries to navigate the “reasonably expected” (Section 7(a)) and “legitimate interests” clauses without detailed precedent. This ambiguity makes DPDPA potentially stricter in practice, as businesses may err on the side of caution and seek explicit consent, or risk non-compliance if their interpretation of “deemed consent” for AI training is later challenged by the Data Protection Board of India (DPBI).

GDPR and UK ICO guidance, while not explicitly naming “AI training,” have a more developed framework for applying “legitimate interests,” including the mandatory balancing test and extensive guidance on safeguards. This makes them appear looser in the sense of providing a clearer, albeit conditional, path for processing without explicit consent, but stricter in their demands for rigorous assessment and transparency. DPDPA’s framing of “legitimate interests” within deemed consent might imply a higher threshold or a narrower scope than GDPR’s standalone lawful basis, particularly concerning secondary data uses for AI. All three frameworks underscore transparency and data minimization, but the DPDPA’s emphasis on consent (deemed or explicit) feels more central to its philosophy compared to GDPR’s broader array of lawful bases.

Practical Takeaway

For Indian businesses, GCs, and DPOs engaged in AI development, the current landscape necessitates a cautious and proactive approach. While awaiting specific guidance from the DPBI, it is prudent to meticulously document the rationale for relying on “deemed consent” under Section 7(e) for AI training data. Conduct thorough assessments to demonstrate that the processing serves a genuine “legitimate interest” and does not unduly prejudice Data Principals. Where possible, and especially for sensitive personal data, prioritize obtaining explicit consent. Implement robust data minimization strategies, anonymization or pseudonymization techniques, and strong security measures. Furthermore, aligning internal practices with global best practices, particularly those articulated by the UK ICO regarding AI, can serve as a valuable benchmark for accountability and risk mitigation, positioning your organization for future compliance as DPDPA interpretations evolve.

This post is licensed under CC BY 4.0 by the author.