Using personal data to train AI under India's DPDP Act
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
The DPDP Act and Rules, SEBI CSCRF, RBI cyber security directions and CERT-In requirements.
Implementing it? See DPDP Act on QULDEX.
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
CERT-In's 2022 directions give most organisations in India six hours to report specified cyber incidents. That only works if the decision to report is made in the first hour.
India's DPDP Rules, 2025 phase in over 18 months. The Data Protection Board is already running; consent managers start in November 2026 and core obligations in May 2027.
Under SEBI's Cybersecurity and Cyber Resilience Framework, regulated entities need cyber audits by CERT-In empanelled auditors, half-yearly or yearly depending on their category.