Algorithmic Accountability By The Back Door: The Significant Data Fiduciary Due Diligence Mandate As India's De Facto AI Governance Instrument
- IJLLR Journal
- Jul 20
- 1 min read
Mr. Aryan Verma, University of Allahabad
ABSTRACT
India has currently decided not to establish a specific law for artificial intelligence. The India AI Governance Guidelines, released by the Ministry of Electronics and Information Technology on November 5, 2025, indicate this choice for a lighter, voluntary framework based on existing laws instead of a comprehensive statute like the one adopted by the European Union. Yet just nine days later, the same government announced the Digital Personal Data Protection Rules, 2025, whose Rule 13(3) imposes a binding duty on Significant Data Fiduciaries to ensure the algorithmic software they deploy does not pose a likely risk to the rights of Data Principals. This article argues that Rule 13(3), though framed as an incidental data protection obligation, functions in practice as India's first binding algorithmic accountability provision. It traces the provision's scope and enforcement design, places it alongside the voluntary AI Guidelines and the risk-tiered EU AI Act, and identifies four gaps in the current framework: the absence of risk classification, a narrow trigger confined to notified fiduciaries and personal data, a due diligence standard that speaks to the regulator rather than the individual, and the lack of any right for an affected person to know that a decision was automated. It closes with suggestions that could be implemented through delegated rule-making, without the need for fresh legislation.
Keywords: Digital Personal Data Protection Rules, 2025; Significant Data Fiduciary; algorithmic accountability; artificial intelligence governance; automated decision-making.
