Data Protection and Privacy 2025

INDIA Trends and Developments Contributed by: Vikram Jeet Singh and Kalindhi Bhatia, BTG Advaya

tain Personal Data (as identified by the govern - ment, but as yet unspecified) is not transferred outside India. The wild card: privacy v artificial intelligence A crucial aspect of the new DPDPA is how it will impact emerging sectors and technologies. Over the last few years, artificial intelligence (AI) has become more and more integral to vari - ous businesses. As AI continues to evolve and develop, applying laws such as the DPDPA to its systems and processes becomes a challenge in itself. The Indian government has repeatedly confirmed that it is not planning to regulate AI as a product or service. An EU-style AI law is not currently contemplated, but sectoral laws and the new privacy statute will impact how busi - nesses can use AI. There are quite a few touchpoints between Per - sonal Data and AI. In the first instance, Personal Data is often used to train AI models. The Delhi High Court is currently hearing a challenge to OpenAI’s use of copyrighted content to train its AI models. Similar issues may arise if Per - sonal Data of Indian individuals is used to train or otherwise develop AI – it is unclear if this fits into any of the current legitimate uses under the DPDPA. But without any alternative routes, AI companies may continue to access Personal Data of individuals to train their models. On the other hand, AI tools can be applied to Personal Data sets and used to analyse, forecast and make automated decisions about individu - als. Automated data processing and decision- making is often faster and cheaper, and does

away with the need for human factors. But at the same time, such processing and decision-mak - ing remain susceptible to biases, discrimination and abuse. Such processing may also violate the principles that underline the DPDPA, including “data minimisation”. Finally, unlike in cases where Personal Data is processed by human agents, it is often difficult to identify and control processing activity that is carried out by automated systems. As such, the interplay of the DPDPA and AI will depend heavily on how the government and the new Data Protection Board view and prescribe such interplay. It will be up to the regulators to inter - pret the DPDPA in ways that do not hinder AI development, while at the same time working to protect the interests of individual data subjects. That said, it is undeniable that not all answers to this conundrum are evident at this time. What companies need to do With the DPDPA close to implementation, Indian businesses will need to make a start on data privacy compliance. Most Indian businesses will have obligations under the new DPDPA, mainly relating to securing data, obtaining clear consent from data principals, managing data breaches, and protecting vulnerable groups such as chil - dren. Companies that are well prepared not only minimise the risk of legal fines and enforcement, but also foster greater trust among their custom - ers and stakeholders. To stay ahead, businesses active in India should start conducting a “gap analysis” and data audits to assess their current readiness and address any gaps before the rules are enforced.

209 CHAMBERS.COM

Powered by