Rethinking Corporate Governance Under The DPDP Framework: Data Breach Liability And Board Oversight Of Artificial Intelligence Deployment In Private Companies
Adv. Thushara Menon, LL.M (Commercial Law), Bharata Mata School of Legal Studies, Ernakulam, Kerala
ABSTRACT
The rapid adoption of Artificial Intelligence (AI) by private companies has transformed the manner in which personal data is connected, processed, analysed and utilised for commercial purposes. While AI systems can improve efficiency and decision-making, their increasing reliance on personal data also creates significant concerns relating to data security, accountability and corporate risk management. The Digital Personal Data Protection Act, 2023 (DPDP Act) provides an important statutory framework for regulating the processing of digital personal data in India and places significant responsibilities upon Data Fiduciaries, including obligations relating to security safeguards and personal data breaches. These obligations assume greater importance where companies deploy AI systems or rely on external AI service providers for processing personal data.
This paper examines data breach liability and board oversight in private companies through the emerging intersection of corporate governance, data protection and AI deployment. It analyses the responsibilities imposed upon Data Fiduciaries under the DPDP framework and considers their relationship with existing duties of directors under the Companies Act, 2013. Particular attention is given to the distinction between the technical responsibility of management and processors and the broader governance responsibility of boards to identify and oversee material data-related risks. The paper argues that although the DPDP Act does not establish a universal statutory requirement for boards to supervise every AI system or conduct algorithmic audits, companies should integrate significant data-protection and AI-related risks into their existing corporate governance and risk-management structures. Such an approach can strengthen accountability while avoiding an unwarranted expansion of statutory obligations beyond what the law presently provides.
Keywords: Digital Personal Data Protection Act, 2023; Corporate Governance; Artificial Intelligence; Data Breach; Board Oversight; Data Fiduciary.
