Regulating AI Training Data in India: A Critical Analysis of the Draft Digital Personal Data Protection Rules, 2025

Published on: 18th August 2026

Authored by: Srishti Keshri
Amity University, Jharkhand

ABSTRACT

There have been many transformations that have been introduced in the field of healthcare, finance, education, governance, and e-commerce as a result of AI-based decision-making. However, the use of personal data for training AI models has brought about many legal problems that include matters such as privacy, consent, transparency, and accountability. The two major legal instruments that make up the legal framework that exists in India with regard to digital personal data protection are the Digital Personal Data Protection Act, 2023[1] and the Draft Digital Personal Data Protection Rules, 2025.[2] Even though data protection is being reinforced through the introduction of some requirements of consent and security through the draft rules, they have not provided for the use of personal data for training AI models. In view of the above discussion, this article analyses the sufficiency of the Draft Digital Personal Data Protection Rules, 2025, as a regulatory regime for AI training data and assesses the developing law in India in the context of international best practices like GDPR[3] and the EU AI Act.[4]

I. INTRODUCTION

One of the most disruptive technologies that has transformed different fields, including healthcare, finance, education, administration, and e-commerce, in the digital age is Artificial Intelligence (AI). Machine learning and generative AI technologies are making rapid progress owing to huge amounts of data, much of which comprises personally identifiable data obtained from websites, online portals, and social media. While on the one hand, data collection makes AI systems highly effective and efficient, on the other hand, the process of collecting personal data from individuals also involves serious legal issues of privacy, consent, accountability, and transparency. Considering these legal issues, the Indian government has passed the Digital Personal Data Protection Act, 2023,[1] followed by the Draft Digital Personal Data Protection Rules, 2025.[2] While these Rules provide an effective governance mechanism for digital personal data, they do not cover the usage of personal data for training purposes of AI applications, raising doubts about whether there is any legal mechanism for collecting, processing, storing, and reusing the data. With respect to these issues, this article seeks to analyse the adequacy of the Draft Digital Personal Data Protection Rules, 2025 in regulating AI training data and the legal challenges it faces.

II. THE DRAFT DIGITAL PERSONAL DATA PROTECTION RULES, 2025 AND AI TRAINING DATA

The Draft Digital Personal Data Protection Rules, 2025,[2] formulated under the provisions of the Digital Personal Data Protection Act, 2023,[1] is an important initiative towards operationalising India’s digital privacy framework through providing a procedure for obtaining consent, data processing, security measures, breach notification and protection of rights of Data Principals. Despite making a lot of improvements to India’s digital data governance infrastructure, there are still many areas where the Draft Rules have not been successful in addressing. The most glaring gap in these Rules pertains to the lack of any provisions pertaining to one of the most crucial issues facing the digital space in India in terms of regulation, which is the use of personal data to train Artificial Intelligence (AI) models. It needs to be noted that modern-day AI models require huge amounts of data, some of which may even contain personal data obtained from websites and public forums, but the Rules do not make any provisions about how to legally collect and retain that data. The resulting legal uncertainty regarding consent, web scraping, purpose limitation, and secondary data processing can cause several problems.

III. LEGAL ANALYSIS

Consent and AI Training Data
“Consent” is one of the central concepts of both the Digital Personal Data Protection Act, 2023[1] and the Draft Digital Personal Data Protection Rules, 2025,[2] mandating the requirement for Data Fiduciaries to acquire prior and explicit consent of individuals for any kind of personal data processing, with a few statutory exceptions. Applying this concept to AI training, however, poses considerable legal problems. AI models are created by being fed with large volumes of data gathered from various digital platforms throughout time, which makes it practically impossible to obtain new consent from every individual whose personal data is used to create a dataset, especially if the data was obtained via publicly available sources. While developers of AI may consider such data to be legally obtained, people could expect that their personal information would not be used for other purposes. It is unclear whether the consent already provided extends to AI model training or whether it is necessary to get a second consent for this secondary processing of personal data.

Web Scraping and Publicly Available Data
Web scraping has been extensively practised by AI practitioners for gathering huge amounts of data from websites that are publicly available to train AI models. Even though the data is publicly available, there could be instances where the data contains personal data which falls under the purview of the Digital Personal Data Protection Act, 2023.[1] There is no clarity in the Draft Digital Personal Data Protection Rules, 2025,[2] about the use of public data in AI training without the need for seeking new consent. There is thus a grey area regarding the usage of web-scraped data.

Purpose Limitation and Data Minimisation
The principle of purpose limitation and data minimisation, as enshrined in the Digital Personal Data Protection Act, 2023,[1] and Draft Digital Personal Data Protection Rules, 2025,[2] implies that personal data can only be processed for an identified purpose and for that sole purpose only. Nevertheless, these two principles are rather hard to implement when it comes to the training of AI algorithms, which rely on big sets of personal data that are not necessarily collected for the training process itself. The further use of this data might constitute the secondary processing of data, and this, in turn, would lead to the issues of unnecessary retention of data and over-processing. Given that the Draft Rules do not specify how these two principles shall be applied to AI training sets, there exists uncertainty about the legal use and retention of personal data. As a result, India must adopt AI-specific standards in terms of secondary data use and retention.

Cross-Border Data Transfers
The global nature of AI involves the transfer of personal data across borders for processing, storing, and training machine learning models via cloud computing and international data centres. Although the transfer of data across borders is an important step towards innovation, it creates issues around data security, privacy, and compliance. As per the Digital Personal Data Protection Act, 2023,[1] cross-border transfer of data is permitted only based on restrictions prescribed by the Central Government, while the Draft Digital Personal Data Protection Rules, 2025[2] lay down certain obligations of compliance. Nonetheless, there are no regulations in these statutes that provide protections for cross-border transfer of data related to AI training. Thereby, this creates an opportunity for violations of security, data privacy, and a lack of adequate legal recourse. Hence, there needs to be some standards in India for cross-border AI data transfer.

Regulatory Gaps and Recommendations
While the Draft Digital Personal Data Protection Rules, 2025[2] have improved upon India’s data protection legislation, they fail to account for the special legal problems posed by the training of AI models. These Rules are mostly technology-neutral and make no mention of issues related to web scraping, secondary usage of personal data, automated decision-making, or algorithmic accountability. This is problematic since this lacuna leaves developers of AI unsure of their obligations and does not offer enough protection to the individuals whose personal data is being used by the AI models. In light of the above, there is a need for AI-specific guidelines under India’s data protection legislation. These guidelines would clarify the legal requirements for the processing of personal data for the training of AI models, increase transparency obligations, regulate public data usage, and create safeguards for high-risk AI models.

IV. SUPPORTING AUTHORITIES

Constitutional Right to Privacy and the Puttaswamy Judgment
Discussion on regulating the AI training data needs to take into consideration the landmark judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India,[5] wherein the court held that the right to privacy is an essential element of the Right to Life and Personal Liberty under Article 21 of the Constitution.[6] It includes the right to informational privacy.

The above principles of the Constitution will apply very well in regulating the operation of AI since the latter is an entity that deals with the processing of personal data on a large scale. Though the Digital Personal Data Protection Act, 2023[1] and the Draft Digital Personal Data Protection Rules, 2025[2] have made a great improvement in data protection in India, it does not regulate the training data of AI.

Statutory Framework
The main law on the subject of protection of personal data in India is the Digital Personal Data Protection Act, 2023,[1] which provides the rights of the Data Principal and obligations of the Data Fiduciary relating to the processing of digital personal data. The Draft Digital Personal Data Protection Rules, 2025[2] provide the procedure in respect of obtaining consent, giving of notice, security, retention and reporting of data breaches. Although the laws are significant in developing data protection laws in India, they do not address the use, reuse, and processing of personal data in training artificial intelligence.

Comparative Perspective: The GDPR and the EU AI Act
A juxtaposition of international regulatory standards reveals that the Indian approach towards AI training data is yet to mature. The GDPR[3] lays down important principles like the principle of lawful processing, the principle of purpose limitation, the principle of data minimisation, the principle of transparency, and the principle of accountability, mandating organisations to guarantee an adequate legal basis for the processing of personal data. In addition to the above, the EU AI Act[4] has taken a risk-based approach and has laid down certain obligations on developers of high-risk AI systems.

Concerning this, when dealing with Draft Digital Personal Data Protection Rules, 2025,[2] one can notice that the rules focus mainly on data protection but do not have any guidelines for dealing with AI in connection with the use of datasets. The result is that some key problems are ignored, such as web scraping, personal data reuse, and algorithmic transparency. In this regard, it may be useful to take into consideration some of the best practices adopted in the GDPR[3] and EU AI Act.[4]

V. CONCLUSION

The coming into being of Artificial Intelligence has revolutionised the digital world in such a way that the need for regulation of the data used in training AI systems has become one of the foremost concerns of the twenty-first century. The Digital Personal Data Protection Act, 2023,[1] and the Draft Digital Personal Data Protection Rules, 2025[2] mark a definite move on the part of the Indian Government to bolster its data protection regime; however, there is much more that needs to be done to address the legal problems associated with AI training, which include consent, web scraping, re-use of personal data, etc. Considering the continuing emergence of AI-centric laws across the globe, even within the European Union, it is high time for India to move from its neutral stance towards technology and develop a suitable legal framework regulating issues related to the gathering, processing, and application of training data for AI technology. This legal framework should be grounded in such basic principles of privacy, transparency, accountability, and proportionality which have been enshrined in the decision of Justice K.S. Puttaswamy (Retd.) v. Union of India.[5] Striking a balance between technological progress and human rights protection will help not only to ensure an ethical development of AI technology but also to place India among the world leaders in this sphere.

REFERENCES

[1] Digital Personal Data Protection Act, No. 22 of 2023, INDIA CODE (2023).
[2] Draft Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, Govt. of India (2025).
[3] Council Regulation 2016/679, General Data Protection Regulation, 2016 O.J. (L 119) 1 (EU).
[4] Regulation 2024/1689, Artificial Intelligence Act, 2024 O.J. (L 2024/1689) (EU).
[5] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).
[6] INDIA CONST. art. 21.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top