top of page

Who Said Yes? DPDP Act consent, AI and the People Whose Data You Hold

Writer: BRB Legal
BRB Legal
Aug 28
10 min read

Somewhere in a hospital, a clinic, an office or an app, someone is about to tick a box. That tick is the entire legal foundation on which India's new data protection regime rests, and most people ticking it have no idea what they are agreeing to.


India's Digital Personal Data Protection Act, 2023 began coming into force in November 2025. It arrived at an awkward moment: exactly as artificial intelligence systems started consuming personal data at a scale no privacy law had previously contemplated. The Act was drafted before generative AI became ordinary. It is now being asked to govern it.


This piece looks at what the Act actually requires, why AI complicates it, and what it means for four groups of people whose data organisations routinely hold: minors, patients, clients and employees.



First, What Counts as "Data"?


The DPDP Act, 2023 governs digital personal data: any data about an identifiable individual, in digital form, or collected on paper and later digitised. That definition is broader than most people assume. A name and phone number qualify. So do a patient's diagnosis, an employee's leave records, a client's billing history, a child's school photograph and a browsing log tied to an account.


What the Act does not cover is equally worth knowing: data that is not personal at all, purely personal or domestic processing, and data made publicly available by the individual themselves or by someone under a legal obligation to publish it. That last exemption is narrower than it sounds, and it becomes very important once AI enters the picture.


The Act assigns three roles, and understanding which one you occupy determines everything else:


Role

Who it is

Core duty

Data Principal

The individual the data is about

Holds the rights: access, correction, erasure, grievance redressal, nomination

Data Fiduciary

Whoever decides why and how the data is processed

Carries the obligations: lawful basis, notice, security, breach reporting

Data Processor

Whoever processes data on a Fiduciary's instructions

Acts only within the contract; the Fiduciary stays accountable


These roles are situational rather than fixed. NABH's own Guidance on the DPDP Act, 2023 makes the point neatly for doctors: a physician running an independent practice is a Data Fiduciary; the same physician is a Data Principal when a hospital collects their professional records; and they become a Processor when handling patient data under a hospital's direction. Most organisations occupy more than one role at once.



Where AI Breaks the Model


Traditional data protection assumes data sits somewhere: in a table, a file, a server. You can find it, correct it, and delete it. Machine learning does not work that way. Training absorbs data into model weights, a statistical structure from which individual records cannot be cleanly extracted or removed.


That produces three specific collisions with the Act:


  • Lawful basis for training. Data scraped broadly from the internet was rarely made public for the purpose of training an AI model. The Act's "voluntarily made public" exemption sets a higher bar than most training pipelines can clear.

  • Purpose limitation. Data collected to deliver a service cannot simply be repurposed to train a model on that service. That requires fresh, specific consent, which is a genuine audit problem for any organisation sitting on years of accumulated records.

  • The erasure problem. A Data Principal can withdraw consent and request deletion. Deleting the database row is straightforward. Removing that person's contribution from an already-trained model generally is not, short of retraining it entirely.


MeitY's India AI Governance Guidelines, published days before the DPDP Rules, chose deliberately not to create a separate AI statute, relying instead on the DPDP Act and existing frameworks. The Guidelines acknowledge that consent and purpose limitation need greater clarity as applied to AI. That clarity has not yet arrived.



What Valid Consent Actually Looks Like


Consent under the Act is not a formality. It must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and it must be preceded by a notice that is genuinely readable. NABH's healthcare guidance spells out what that means in operational terms, and the requirements translate well beyond hospitals:


  • Consent must not be bundled with other paperwork such as admission, billing or treatment forms. A signature on an intake form is not consent to secondary processing.

  • The notice must be standalone and itemised, specifying the types of data collected, the purposes, storage location and retention period, who it will be shared with, and how to withdraw or complain.

  • Withdrawal must be as easy as granting, available through both digital and physical routes.

  • For minors and persons with disabilities requiring assisted decision-making, consent must come from a verifiable parent or guardian.

  • Systems must actually support this: granular consent capture, withdrawal mechanisms and proxy consent are software requirements, not policy statements.


One line in the NABH guidance deserves particular attention, because it speaks directly to the AI question. On third-party and vendor management, it states that there must be no replication, monetisation or secondary use without independent consent. Feeding patient records into a vendor's model to improve that model is secondary use. It needs its own consent, separately obtained.


And the honest answer on data already absorbed into a model: nobody has fully solved it. Withdrawal stops future processing and should trigger deletion of the underlying records, but the trained model retains whatever it learned. Machine unlearning is an active research field, not a compliance product you can buy. This is the single largest unresolved gap between what the Act promises and what technology currently delivers.



Four People Whose Data You Hold


India's enforcement record is necessarily thin: the Act is new and the Data Protection Board only became functional in 2026. The examples below therefore come from jurisdictions where comparable law has been in force for years. They are useful precisely because they show what regulators actually do once enforcement matures, and each maps onto a category of Data Principal that Indian organisations already hold data about.


Minors


The Act treats children as a special category. Processing a child's data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. There is no graduated age scale: under 18 is a child, full stop, which is stricter than the GDPR's 13-to-16 range.


Italy's data protection authority, the Garante, has tested this ground twice. In December 2024 it fined OpenAI €15 million, citing training on personal data without an adequate legal basis and the absence of any real age verification, leaving under-13s exposed. In July 2026 it fined Character Technologies €158,000 over the Character.AI platform, again flagging weak safeguards for minors, ineffective age verification and a late data protection impact assessment.


The OpenAI story has a twist that matters: the Court of Rome annulled that €15 million decision on 18 March 2026. The lesson is not that enforcement is toothless, but that the law here is genuinely unsettled, and regulators and courts are still working out where the lines sit.


Patients


A clinician reviewing patient records and scans at a hospital workstation
Illustrative artwork

Health data is the most sensitive category most organisations handle, and India now has two overlapping layers of guidance on it.


NABH has issued a Guidance on the Digital Personal Data Protection Act, 2023 applying to accredited hospitals, HIS/EMR/CMS providers and any third-party system touching health data. It is unusually concrete. Retention is tied to record type: roughly three to five years for outpatient records, five to seven for inpatient, seven or more for paediatric and medico-legal cases. Where there has been no patient interaction for three consecutive years, data must be deleted after 48 hours' notice unless law, medical council guidelines, litigation or insurance require retention. Breaches must be notified within 72 hours to both affected individuals and the Data Protection Board. Health data should not leave India unless expressly permitted. Hospitals must maintain a data processing register, run impact assessments, undergo independent audits and appoint a Data Protection Officer where they qualify as Significant Data Fiduciaries.


Separately, on 21 July 2026 the CDSCO issued its final Guidance Document on Medical Device Software (Doc No. CDSCO/MD/GD/MDSW/01/2026), following an October 2025 draft. It brings AI-enabled medical software squarely within the Medical Devices Rules, 2017, using a function-based test rather than a rigid label. For AI systems it requires manufacturers to disclose the composition of the datasets used for training, validation and testing, including demographic distribution, geographic origin and clinical diversity, alongside bias assessment, cybersecurity documentation and post-market surveillance. In effect, an AI diagnostic tool must now account for whose data taught it.


The cautionary example comes from the United Kingdom. In 2015 the Royal Free NHS Foundation Trust transferred around 1.6 million patient records to Google DeepMind to test Streams, an app for detecting acute kidney injury. The clinical intent was sound. The legal basis was not. In 2017 the Information Commissioner's Office found the Trust had failed to comply with data protection law: patients were not adequately informed, and the argument that "direct care" supplied implied consent did not hold, because a patient who had visited A&E years earlier would not expect their record to reach a third party for app testing. The Trust also completed its privacy impact assessment only after handing over the data. No fine was imposed, but a binding undertaking was. As the Commissioner put it, the price of innovation did not have to be the erosion of privacy rights.


Clients


Professional and commercial relationships carry confidentiality obligations that exist independently of the DPDP Act, and the two now interact. A law firm, accountancy practice, agency or consultancy holds client data under both contractual duties and statutory ones.


The instructive incident here involves no regulator at all. In early 2023 Samsung permitted engineers in one division to use ChatGPT. Within roughly three weeks the company had identified multiple incidents of confidential material being pasted in, including internal source code and a recorded meeting transcript. The tools were banned on company devices by May 2023.


What makes it relevant is the reason Samsung could not simply undo it. Under the terms then applying to most public AI tools, submitted content could be used to improve the underlying model. Once entered, the material sat on infrastructure Samsung did not control, under terms it had not negotiated, and could not be recalled. Any professional pasting client information into a general-purpose AI tool is running the same experiment.


Employees


An office worker at a desk with a supervisor visible in the background
Illustrative artwork

Employee data is the category organisations most often overlook, on the assumption that the employment relationship itself supplies consent. It does not. Employees are Data Principals with the same rights as anyone else, and the power imbalance in the relationship makes consent harder to treat as freely given, not easier.


Germany's Hamburg data protection authority fined H&M €35.3 million in October 2020 over practices at its Nuremberg service centre. Since at least 2014, team leaders had conducted "welcome back talks" with employees returning from leave or illness, and recorded what they learned: symptoms, diagnoses, family circumstances, religious beliefs, details of holidays. Combined with performance records, this produced detailed profiles that fed into employment decisions. It surfaced only because a configuration error briefly made the notes readable across the company.


The regulator's language is worth noting. It described the combination of private-life detail and activity monitoring as a particularly intensive encroachment on employees' civil rights. H&M apologised, compensated affected staff and overhauled its practices, which the authority credited. The fine still stood.



What Fiduciaries and Processors Actually Have to Do


Stripped of legalese, the obligations fall into a manageable set. The detail below draws on the Act, the DPDP Rules and NABH's healthcare guidance, which offers the clearest operational reading currently available.


Know what you hold, and why

Maintain a record of what personal data you process, for what purpose, where it is stored and how long you keep it. Collect only what the stated purpose requires. Most compliance failures begin as inventory failures: organisations cannot protect data they have forgotten they hold.

Standalone itemised notice before consent, never bundled into other paperwork. Granular where purposes differ. Withdrawal must be as easy as granting it, and must actually propagate through your systems rather than merely setting a flag nobody reads.

Vendors, cloud providers, labs, analytics tools and AI services processing data on your behalf need binding data processing agreements with purpose-restricted, time-bounded access. Critically, no replication, monetisation or secondary use without independent consent. Accountability stays with you regardless of who does the processing.

Encryption in transit and at rest, role-based access, audit logs, and a documented incident response plan. Breach notification runs to both affected individuals and the Data Protection Board on prescribed timelines, with 72 hours as the working standard in the healthcare guidance.

Access in readable form, correction, erasure where legally permissible, grievance redressal, and nomination so someone can exercise these rights after death or incapacity. Each needs a working process behind it, not a paragraph in a policy.

Organisations classified as Significant Data Fiduciaries carry extra duties: a Data Protection Officer based in India, independent audits, and data protection impact assessments before high-risk processing, including new AI deployments.



The Hard Parts


None of this is straightforward, and it is worth naming the genuine difficulties rather than pretending compliance is a checklist.


  • Legacy data. Consent obtained years ago, for purposes described vaguely, probably does not cover what you want to do with that data now. Re-consenting a large historical database is expensive and produces low response rates. Many organisations will find deletion cheaper than justification.

  • Consent fatigue. If every interaction triggers another dialogue box, people stop reading and click through. Consent that is technically valid but practically meaningless serves nobody, and regulators have begun saying so.

  • Vendor opacity. You remain accountable for processors you cannot fully inspect. Where an AI vendor will not disclose what happens to submitted data, that is itself a finding, and increasingly a reason to choose differently.

  • The unlearning gap. Until machine unlearning becomes practical, the right to erasure and the reality of trained models will not fully reconcile. The honest position is to minimise what enters training in the first place.

  • Overlapping regulators. A hospital deploying an AI diagnostic tool answers to the Data Protection Board, NABH accreditation standards and CDSCO device regulation simultaneously. These frameworks are broadly aligned in intent but were not drafted together.



Where This Leaves Us


The Consent Manager framework is due in November 2026. The substantive obligations most organisations must meet arrive in May 2027. Between now and then, the practical work is unglamorous: find out what data you hold, work out why, fix how you ask for it, and be honest about what you cannot yet undo.


The four groups in this piece are not edge cases. Most organisations hold data on all four simultaneously, often in the same system, frequently without having thought about the distinction. That is the gap the next eighteen months will need to close.


A law written for records that sit still is now governing systems that learn. Getting consent right at the front end is the only part of that problem anyone currently knows how to solve.


BRB Legal's Technology & Privacy desk tracks developments like these as they unfold.


This article is for general information only and does not constitute legal advice. For advice on a specific situation, please consult a qualified professional.

Comments


  • LinkedIn
  • Instagram
  • X

+91 11 4058 2711

Z29, Block Z, Hauz Khas, New Delhi, Delhi 110016, India

©2026 BRB Legal.

 

Disclaimer: The information on this website is for general information purposes only. Nothing on this site should be taken as legal advice for any individual case or situation. This information is not intended to create, and receipt or viewing does not constitute, an attorney-client relationship.

bottom of page