Artificial Intelligence And Personal Data: Reassessing The Digital Personal Data Protection Framework In India
- IJLLR Journal
- 3 minutes ago
- 2 min read
Preeti, LLM, Amity University, Gurugram
ABSTRACT
However, Artificial Intelligence (AI) is changing the way personal data is collected, inferred, aggregated and reused, which is threatening fundamental data protection and privacy principles and calls for a re-thinking of the Indian Digital Personal Data Protection (DPDP) regime. The objective of this study was to understand the correlation between AI and personal data processing in India, delineate privacy risks and challenges of data protection with respect to AI, analyze the effectiveness of the DPDP Act, 2023 and DPDP Rules, 2025, and investigate the transparency, accountability, and governance measures with respect to processing and using personal data in India through AI technologies, and to draft qualitative metrics for assessment of compliance and adequacy with respect to data protection laws and regulations in India. Employing a qualitative, theoretical method based on secondary sources, the study analyzed the possibility of a largely consent- based regime to cope with the lifecycle-based processing of AI through privacy-as-control, contextual integrity, privacy-as-dignity and autonomy (including the constitutional framing in Justice K.S. Puttaswamy v. Union of India), surveillance-capitalism, critical privacy, and algorithmic accountability theories. The results show that there is a mismatch between the discrete, purpose-specific processing logic of the DPDP Act and the continuous processing logic, inferences, and repurposing of AI systems throughout the model lifecycle, confirming concerns raised in the context of the DPDP Act for improper information flow after secondary use. The three salient risks were identified as re-identification, function creep and algorithmic bias, with UNESCO's point of viewpoint driven by a lifecycle approach being more analytically appropriate than the Act's point of collection approach under Section 6. In the Rules' substantive section, there was a relatively small number of AI-specific obligations, such as no algorithmic fairness principles, no protections against automated decision- making, and operationalising the right to erasure proved challenging for generative AI due to the lack of machine unlearning at scale. The study also noted that the framework is about disclosure-based transparency, and not relational accountability that is enough to ensure meaningful algorithmic answerability. While the DPDP framework is an important piece of general-purpose legislation, its failure to adequately protect informational autonomy from profiling and inference by AI does have implications for dignity, equality, public trust, the necessity of AI-specific subordinate legislation and sectoral codes for certain high-risk sectors and fields, and the fact that there is a lack of specific qualitative indicators.
Keywords: Artificial Intelligence, Digital Personal Data Protection, privacy- as-control, contextual integrity, informational privacy, surveillance- capitalism, automated decision-making.
