top of page

Consent by Default: How AI Platforms Use the DPDP Act to Fuel Their Models

by Khushi Chandak

Introduction

The Digital Personal Data Protection Act, 2023 came into force on November 13, 2025. This marked the country’s first comprehensive legislative framework for the personal data governance. The Act, 2023 has come at nascent stage where the data is being considered as an “asset.” This analogy is becoming more clearer with the intersection of Artificial Intelligence and the personal data. The urgency that arises with this intersection is that when the users provide data to the AI platforms for the purpose of generating output, the users unknowingly consent for their data to be used as a training dataset for refining the platforms. 


The Deemed Consent Data Trap

The DPDP Act, 2023 under Section 7 provides the concept of “deemed consent” as an expressly permitted ground of processing. This means where a data principal voluntarily provides personal data for a stated purpose, and where further processing is reasonably incidental to that purpose, the Act treats consent as having been granted. This gives a gateway to the AI companies whereby they are able to procure the data without being in contravention to any provision. 

The flow of the consent during the intersection of the AI and data follows the provision of Section 7 appropriately. This implies that when a user engages with an AI platform voluntarily providing data for the purpose of using the service, it is agreeing to the usage of data for the ancillary purposes at the same time. Training the underlying model is one such ancillary purpose because it improves the service. However, Section 7 must not be read in isolation but, with the foundational principles of purpose limitation and data minimisation. Using personal interactions to train the model, redefining the datasets which are subsequently commercialised by the third parties stretches the nexus well beyond the intention of the drafters of the legislation. 

The structural problem lies with respect to imposition of no obligations on fiduciaries to disclose AI training or in other words give “AI Disclaimer” to the data principals. The AI platforms do not disclose the processing purpose of the data which is distinct from general service improvement. This integration allows deemed consent to function as a substitute for genuine informed consent for the purpose of training dataset. The downstream uses of such data are open ender and are not specified in advance by the AI platforms. 


Europe’s Bold AI Transparency Blueprint

For the purpose of understanding how the development of AI and data protection can be coherently integrated within a single regulatory architecture, both the General Data Protection Regulation and the EU Artificial Intelligence Act, which has been in force since August 2024, need to be referred to and, more importantly, read together. The GDPR created the basic architecture of data rights that include lawful processing, purpose limitation, and the right to erasure. The EU AI Act was intended to complement it and address the AI-specific risks that a general data protection statute was either never conceived to address or was simply not equipped to address.

The EU AI Act categorizes AI systems based on risk levels and prescribes proportionate obligations for each category. Article 10 of the EU AI Act provides that high-risk AI systems need to ensure that the training datasets have quality, representativeness, and lack bias. General-purpose AI models need to be transparent about the datasets that have been used for their training. These are not aspirational but prescriptive obligations that India does not have.

Three principles of this combined framework are in urgent need of adaptation. Firstly, the need for AI training to be treated as a categorically distinct processing purpose, with its own specific disclosure rather than being incorporated into vague language around service improvements. Secondly, a proportionate approach to the governance of AI, used alongside the existing classification system under the DPDP Act of Significant Data Fiduciary, will ensure that the most impactful uses of AI are treated accordingly. Thirdly, the law must acknowledge the impossibility of erasure once personal data has been incorporated into a training set.


Reform: addressing AI & deemed consent

The DPDP Act is a genuine and meaningful step forward. However, it was drafted before large-scale generative AI became commercially mainstream, and this is reflected in the gap. The provisions of deemed consent in Section 7 of the DPDP Act, in conjunction with the absence of AI-specific disclosure obligations and the still incomplete framework of subordinate rulemaking, provide significant space in which AI companies can continue to accumulate Indian user data on terms that are legally defensible but normatively inadequate. The EU AI Act and GDPR, as an integrated whole, provide India with an integrated template to close this gap, not by copying it outright but by adapting it thoughtfully. 


 
 
 

Comments


Address

2nd & 4th Floor, Maharashtra National Law University Mumbai, MTNL Building, Technology Street, Powai, Mumbai. 

Our Socials

  • LinkedIn
  • Instagram

Contact

Convenor
Revant Sinha -  91 78270 76105

Associate Convenors
Om Dambhare - 91 93072 24566

Ritesh Karale - 91 93593 07137

bottom of page