ABSTRACT
Artificial Intelligence (AI) and machine learning have transformed the manner in which personal data is collected, processed, analysed, and utilised. AI systems depend heavily upon large datasets, many of which contain information capable of identifying individuals. This creates significant legal concerns relating to privacy, consent, transparency, accountability, data security, and individual autonomy. India has attempted to address these concerns through the Digital Personal Data Protection Act, 2023 (DPDP Act), which establishes a statutory framework for the processing of digital personal data. The constitutional foundation for this framework can be traced to Justice K.S. Puttaswamy (Retd.) v. Union of India, where the Supreme Court recognised privacy as a fundamental right under Article 21 of the Constitution.
This article examines whether the DPDP Act provides an adequate legal framework for protecting individuals against privacy risks created by AI and machine-learning technologies. It analyses the concepts of Data Principal, Data Fiduciary, consent, legitimate uses, rights of individuals, data security, and governmental exemptions. The article also comparatively examines the European Union's General Data Protection Regulation (GDPR). It argues that although the DPDP Act represents an important development in Indian data-protection law, AI presents challenges that require stronger transparency, accountability, human oversight, and safeguards against automated decision-making. The article concludes by proposing measures to ensure that technological innovation and individual privacy can coexist within India's emerging digital economy.
Keywords: Artificial Intelligence, Machine Learning, Data Protection, DPDP Act, Privacy, Article 21, GDPR, Data Principal.
1. INTRODUCTION
Artificial Intelligence has become an increasingly important part of modern society. AI-powered systems are used in banking, healthcare, education, advertising, employment, law enforcement, social media, and online commerce. Machine-learning systems, in particular, require large quantities of data to train models, identify patterns, and generate predictions. Personal data therefore constitutes an important resource for the development and operation of modern AI systems.[1]
The increasing dependence of AI on personal data creates a legal tension between technological innovation and individual privacy. An AI system may collect information from users, combine information from different sources, infer characteristics about individuals, and use those inferences to make predictions or recommendations. In some situations, individuals may not even be aware that their information is being processed or that an algorithm has influenced a decision concerning them.[2]
The legal importance of privacy in India was firmly established by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India. The nine-judge Constitution Bench recognised privacy as a fundamental right protected by the Constitution. The Court connected privacy with dignity, liberty, and individual autonomy. It further established that restrictions upon privacy must satisfy requirements of legality, legitimate State aim, and proportionality.[3]
The enactment of the Digital Personal Data Protection Act, 2023 represents a significant legislative response to India's growing digital economy. The Act regulates the processing of digital personal data and creates rights and obligations for Data Principals and Data Fiduciaries. The Central Government subsequently notified the Digital Personal Data Protection Rules, 2025, providing additional details concerning implementation of the statutory framework.[4]
However, AI presents unique problems that cannot always be addressed through traditional data-protection principles. The central question is therefore whether India's present data-protection framework is sufficiently equipped to regulate the processing of personal data by AI systems.
2. RESEARCH QUESTIONS
This article addresses the following research questions:
Whether the Digital Personal Data Protection Act, 2023 provides adequate protection against privacy risks arising from AI and machine-learning systems?
Whether the consent and purpose-based framework of the DPDP Act is sufficient for AI systems that process large and continuously evolving datasets?
What constitutional principles emerging from Puttaswamy should guide AI-related processing of personal data?
What lessons can India draw from the European Union's GDPR to strengthen AI and data-protection regulation?
3. OBJECTIVES AND METHODOLOGY
The primary objective of this research is to critically examine the relationship between AI and India's data-protection framework. The article evaluates the relevant provisions of the DPDP Act, constitutional principles relating to privacy, and selected judicial developments.
The research adopts a doctrinal and analytical methodology. Primary legal materials, including legislation, judicial decisions, and regulatory instruments, form the principal sources of research. Secondary sources are used to understand contemporary debates surrounding AI, privacy, and data governance. A comparative approach is also adopted by examining selected principles of the GDPR.
4. ARTIFICIAL INTELLIGENCE AND THE GROWING IMPORTANCE OF PERSONAL DATA
AI systems function through the collection and processing of information. Machine-learning models are trained using datasets that may include names, locations, purchasing behaviour, photographs, online activity, financial information, and other forms of personal information.[5]
The problem is not limited to the initial collection of data. AI can generate new information from existing datasets. For example, an algorithm may analyse an individual's browsing behaviour and predict preferences, financial characteristics, or behavioural patterns. Such inferences can have real-world consequences even when the individual never directly supplied the inferred information.[6]
Another difficulty is the scale of AI processing. Traditional data-processing activities may involve a clearly defined purpose. AI development, however, may involve experimentation, model training, testing, retraining, and deployment. Data initially collected for one purpose may subsequently become useful for another AI-related purpose.[7]
This creates challenges for the principles of transparency and purpose limitation. Individuals may provide information in circumstances where they understand one immediate purpose but do not anticipate future AI-based processing.
AI systems may also create risks through automated profiling and discriminatory outcomes. If training datasets contain historical biases, an algorithm may reproduce or amplify those biases. Consequently, data protection cannot be viewed only as a question of cybersecurity. It also involves questions of fairness, accountability, autonomy, and human dignity.
5. CONSTITUTIONAL FOUNDATION: PRIVACY UNDER ARTICLE 21
The constitutional foundation of India's data-protection framework is closely connected with Article 21 of the Constitution.
In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court unanimously recognised privacy as a fundamental right. The judgment treated privacy as an essential component of liberty and dignity. It also recognised informational privacy as an important dimension of the right to privacy.[8]
The Court clarified that privacy is not an absolute right. However, any invasion of privacy must satisfy constitutional requirements. The Supreme Court's proportionality framework requires legality, a legitimate State aim, and proportionality between the objective pursued and the means adopted.[9]
This principle has considerable relevance to AI. Government agencies increasingly use automated technologies for administration, identification, security, and service delivery. Private entities also use algorithms for advertising, credit assessment, and consumer profiling. Whenever personal information is processed in a manner affecting an individual's fundamental interests, constitutional safeguards become relevant.
The Puttaswamy judgment therefore provides an important constitutional standard against which India's statutory data-protection framework can be assessed.
6. THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023
The DPDP Act regulates the processing of digital personal data within India and, in specified circumstances, processing outside India connected with offering goods or services to individuals in India. The Act defines personal data as data about an individual who is identifiable by or in relation to such data.[10]
The Act distinguishes between a Data Principal and a Data Fiduciary. The Data Principal is the individual to whom the personal data relates, while the Data Fiduciary determines the purpose and means of processing personal data.[11]
This distinction is particularly important in the AI ecosystem. An organisation developing or deploying an AI system may determine what data is collected, why it is processed, and how it is used. Such an organisation may therefore have significant responsibilities under the data-protection framework.
6.1 Consent
Consent is one of the important foundations of the DPDP framework. Individuals should receive information concerning the processing of their personal data and should be able to exercise their statutory rights.
The DPDP Rules, 2025 further provide requirements relating to notices. The Rules require notices to be understandable independently and to provide a clear account of relevant information, including the personal data involved and the specified purposes of processing.[12]
However, the effectiveness of consent in AI environments is debatable. AI systems may have complex and evolving uses that are difficult to explain to ordinary users. A person may understand that data is being collected for a particular online service without understanding that the same data may contribute to training or improving an AI model.
Therefore, meaningful consent requires more than lengthy privacy policies. It requires clear communication and genuine choice.
6.2 Rights of Data Principals
The DPDP framework provides individuals with rights concerning their personal data. Such rights are important because AI systems may retain information for extended periods and may use information to produce predictions and inferences.
6.3 Data Security and Accountability
AI systems may process large quantities of personal data, making security particularly important. A data breach involving an AI platform could expose significant amounts of personal information.
Data Fiduciaries therefore have obligations relating to appropriate safeguards and the handling of personal-data breaches. Strong security practices are essential because AI models can themselves become targets for attacks, data extraction, or unauthorised access.[13]
7. AI-SPECIFIC LIMITATIONS OF THE DPDP FRAMEWORK
Although the DPDP Act is an important legislative development, several issues remain concerning AI.
First, the Act is primarily a data-protection framework, rather than a comprehensive AI-governance statute. It regulates personal-data processing but does not comprehensively regulate algorithmic fairness, explainability, bias, or every form of automated decision-making.[14]
Second, consent may not always provide meaningful protection. AI developers may not know every future application of a dataset when information is initially collected. Consequently, the individual may be asked to provide consent without possessing sufficient knowledge about future uses.
Third, AI creates difficulties concerning explainability. A complex machine-learning system may produce an output that is difficult for ordinary users to understand. Even if the underlying data processing is legally authorised, the individual may not understand why a particular result was generated.[15]
Fourth, AI can create privacy risks through inference. Personal data protection must therefore consider not only information directly supplied by individuals but also information generated or inferred from datasets.
Finally, the role of the State requires careful scrutiny. The DPDP Act contains exemptions relating to specified State activities, including circumstances involving sovereignty, security, and public order. Such exemptions must operate consistently with constitutional privacy principles.[16]
The concern is particularly significant because the Supreme Court's proportionality framework requires restrictions on privacy to have a lawful basis, pursue a legitimate aim, and maintain a rational relationship between the objective and the means adopted.
8. COMPARATIVE ANALYSIS: DPDP ACT AND GDPR
The European Union's General Data Protection Regulation provides a useful comparative framework. The GDPR contains detailed principles governing the processing of personal data, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability.[17]
One significant difference is the level of detail. The GDPR expressly establishes data-minimisation and purpose-limitation principles. These principles are particularly relevant to AI because machine-learning systems often favour large datasets.
The GDPR also provides a broader regulatory architecture concerning individual rights and accountability. Its approach demonstrates the importance of placing obligations upon organisations rather than relying entirely upon individual consent.
For India, the GDPR should not be copied mechanically. India's digital economy, institutional structure, and constitutional framework are different. Nevertheless, the European model demonstrates the value of detailed accountability requirements and stronger transparency obligations.
India's approach can therefore combine the flexibility of the DPDP framework with stronger AI-specific safeguards.
9. FINDINGS AND DISCUSSION
The research demonstrates that the DPDP Act represents a significant step towards protecting personal data in India's digital economy. It establishes a statutory framework where previously data protection depended on a combination of constitutional principles, sector-specific rules, and other legal mechanisms.
However, AI changes the nature of data processing. Traditional data protection assumes that individuals can understand what information is being collected and why. AI complicates this assumption because data can be combined, analysed, and transformed into new predictions.
The research therefore finds that data protection and AI governance cannot remain completely separate.
The DPDP Act can provide the foundation for responsible AI, but additional regulatory mechanisms are required to address AI-specific risks. These mechanisms should focus upon transparency, accountability, human oversight, algorithmic fairness, and privacy-by-design.
The constitutional principle established in Puttaswamy should remain central. Technological efficiency cannot by itself justify an unrestricted invasion of privacy. Any governmental or private processing that significantly affects individual privacy should satisfy legality, necessity, and proportionality.
11. CONCLUSION
Artificial Intelligence presents enormous opportunities for India's economy and society, but its dependence upon personal data creates significant legal and constitutional challenges. The Digital Personal Data Protection Act, 2023 is an important milestone because it establishes a dedicated statutory framework for digital personal data.
Nevertheless, AI demonstrates that data protection cannot be limited to the traditional question of whether an organisation obtained information lawfully. Modern regulation must also consider how information is combined, analysed, inferred, and used to influence individuals.
The constitutional right to privacy recognised in Justice K.S. Puttaswamy (Retd.) v. Union of India provides the foundation for addressing these challenges. Privacy, dignity, and autonomy must remain relevant even when decisions are increasingly mediated by algorithms.
The DPDP Act should therefore be viewed as the foundation rather than the final stage of India's AI governance framework. The next stage should incorporate stronger transparency, accountability, human oversight, privacy-by-design, and safeguards against discriminatory or unjustified automated decision-making. India does not need to choose between AI innovation and privacy protection. A carefully designed regulatory framework can support both. The objective should be to create an ecosystem in which AI can develop responsibly while individuals retain meaningful control over their personal information and fundamental rights.
Reference
[1] Digital Personal Data Protection Act, 2023, Ministry of Electronics and Information Technology, Government of India, 2023.
[2] Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, Government of India, 2025.
[3] Justice K.S. Puttaswamy (Retd.) and Anr. v. Union of India and Ors. (2017) 10 SCC 1.
[4] Digital Personal Data Protection Rules, 2025.
[5] Digital Personal Data Protection Act, 2023.
[6] Justice K.S. Puttaswamy (Retd.) and Anr. v. Union of India and Ors. (2017) 10 SCC 1.
[7] Digital Personal Data Protection Act, 2023.
[8] Justice K.S. Puttaswamy (Retd.) and Anr. v. Union of India and Ors. (2017) 10 SCC 1.
[9] Ibid.
[10] Digital Personal Data Protection Act, 2023.
[11] Ibid.
[12] Digital Personal Data Protection Rules, 2025.
[13] Digital Personal Data Protection Act, 2023.
[14] Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), 27 April 2016, EUR-Lex.
[15] Digital Personal Data Protection Act, 2023.
[16] Justice K.S. Puttaswamy (Retd.) and Anr. v. Union of India and Ors. (2017) 10 SCC 1.
[17] Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), 27 April 2016, EUR-Lex.