Using personal data to train AI under India's DPDP Act
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
Team · Audit and compliance research
The QULDEX editorial team writes and maintains practical guidance on audit execution, evidence governance and multi-framework compliance. Every article is reviewed against the source standard before publication.
Articles
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
ISO 42001 asks you to assess how an AI system could affect people and society, not only your organisation. This worked example uses a CV-screening model.
Sample sizes for testing controls depend mainly on how often the control runs. Here are the sizes auditors commonly use, and how to handle an exception.
CERT-In's 2022 directions give most organisations in India six hours to report specified cyber incidents. That only works if the decision to report is made in the first hour.
India's DPDP Rules, 2025 phase in over 18 months. The Data Protection Board is already running; consent managers start in November 2026 and core obligations in May 2027.
The Digital Omnibus pushed the EU AI Act's high-risk rules to December 2027 and August 2028. Transparency duties did not move, and some already apply.
Since 11 September 2026, anyone placing software or connected products on the EU market must report exploited vulnerabilities and severe incidents within 24 hours. Here is the runbook.
Whether a finding is major or minor decides whether you get certified on schedule. The difference is about the management system, not the size of the mistake.
Every ISO 9001:2015 certificate must move to the 2026 edition by 30 September 2029. For certification bodies that means three years of transition audits to schedule, staff and evidence.
CSF 2.0 added Govern as a sixth function. It covers strategy, roles, policy, oversight and supply chain risk, and it is where most organisations have the least evidence.
Two PCI DSS v4 requirements target attacks that skim card data from payment pages in the browser. Here is what each asks for, who it applies to and what assessors want to see.
Under SEBI's Cybersecurity and Cyber Resilience Framework, regulated entities need cyber audits by CERT-In empanelled auditors, half-yearly or yearly depending on their category.
A bridge letter covers the gap between the end of your last SOC 2 period and your next report. Customers usually accept one for a few months, not longer.
ISO/IEC 42001 applies management-system discipline to AI. If you already run an ISO 27001 ISMS, most of the scaffolding exists.
Evidence that cannot be found, dated or traced to a control gets requested again. A five-part file name fixes most of that before any tool is involved.
Three, six or twelve months: the right first observation window depends on how long your controls have run, what your buyers will accept and when you need the report.
The 2022 revision regrouped Annex A into four themes and added 11 controls. Here is what that means for your Statement of Applicability and your next surveillance audit.
DORA requires financial entities to maintain a register of all contractual arrangements with ICT third-party service providers, in a standard format supervisors can collect.