DPDP Act & AI: Consent Gap in Automated Decisions
By Technology Desk
India’s DPDP Act 2023 faces AI governance challenges. Consent for data processing is insufficient for complex, potentially biased AI automated decisions.
India’s Digital Personal Data Protection (DPDP) Act, 2023, while emphasizing consent-based data processing, faces limitations in governing Artificial Intelligence (AI) systems making consequential decisions. This challenge arises because consent for data collection does not inherently address how AI interprets data, draws inferences, or influences outcomes.
Authors Harsh Walia and Vanshika Lal argue that AI systems can generate inaccurate, biased, or difficult-to-explain results, even with lawful data consent. The core issue lies in the AI system’s operation rather than solely in the initial data usage.
Understanding AI’s Decision-Making Complexities
AI systems operate by processing data to produce various outcomes. These operational aspects present distinct challenges:
- AI systems can generate outcomes that are inaccurate.
- They may produce results that are inherently biased.
- Decisions derived from AI are often difficult to explain.
These issues highlight a critical gap where data protection principles, centered on consent, do not fully extend to the intricate processes of AI-driven decision-making.
Global and Indian Regulatory Responses
Recognizing these complexities, other jurisdictions and Indian initiatives have developed frameworks for AI governance. These emphasize broader control mechanisms beyond mere data consent.
Key frameworks include:
- The EU’s GDPR.
- NITI Aayog’s Principles for Responsible AI.
- The Supreme Court’s Draft Regulations for Use of AI in Courts, 2026.
These frameworks collectively underscore the necessity for specific governance measures, especially when AI systems impact fundamental rights or opportunities. The Supreme Court’s draft regulations notably prohibit judicial outcomes based solely on algorithmic decision-making.
DPDP Act’s Specific Limitations in AI Context
Despite its foundational role in data protection, the DPDP Act does not explicitly regulate automated decision-making. This creates several operational and legal challenges for both data principals and organizations utilizing AI.
The Act’s specific shortcomings include:
- It lacks provisions for a right to explanation.
- It does not mandate mechanisms for human review, unlike other jurisdictions.
- The principle of processing data for specified purposes may conflict with AI development’s need for large datasets for future use cases.
- Operationalizing data principals’ rights, such as correction and redress, becomes challenging when organizations cannot explain AI-driven outcomes.
Effective AI governance, therefore, demands measures beyond the DPDP Act’s current provisions. This includes establishing robust human review mechanisms and ensuring clear explanations to foster transparency and trust in AI systems. Businesses are increasingly expected to demonstrate accountability for automated decisions, aligning with India’s evolving AI policy framework.