Balancing Data Privacy and Innovation: Legal Challenges in Regulating Artificial Intelligence Under India’s Digital Personal Data Protection Act, 2023

Author: Harsh Singh, Intern, Lex Lumen Research Journal. [Page: 420-440]

KEYWORDS: DPDP Act, European Union’s General Data Protection Regulation, small and medium enterprises, Risk-Based Regulation for AI Systems Risk-Based Regulation for AI Systems

ABSTRACT

India stands at a crucial moment. On one hand, it has made a powerful commitment to protecting personal privacy through the Digital Personal Data Protection Act (DPDP), 2023, which builds upon the Supreme Court’s landmark judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India declaring privacy a fundamental right. On the other hand, the country is racing ahead as a digital and AI powerhouse, with smart technologies being used in everything from healthcare and banking to education and governance. This rapid growth brings new opportunities but also serious questions. The DPDP Act tries to safeguard our personal data in this fast-changing digital world. It introduces clear rules around consent, gives individuals greater control over their data, and sets responsibilities for companies handling large volumes of personal information. But as promising as this sounds, the law also creates real challenges, especially for India’s growing artificial intelligence (AI) sector. AI needs large amounts of data to work well and improve over time, yet the DPDP’s strict consent rules, data retention limits, and localization mandates can slow down innovation, especially for small startups working with limited resources. This paper explores one key question: Can India protect personal privacy while still allowing AI to grow and thrive? It looks closely at the DPDP Act and how it affects real-world AI applications in areas like microlending, voice-based tutoring, and medical diagnosis. It also highlights how the Act’s exemptions for government use of data without strong oversight, raise serious concerns about surveillance and misuse, particularly for already vulnerable communities. By comparing India’s approach with global examples like the EU’s GDPR and AI Act, this research identifies what’s working and where changes are needed. It suggests practical steps forward: smarter consent mechanisms, more flexible rules for low-risk technologies, independent checks on government surveillance, and special support for small innovators. At its core, this paper argues that privacy and innovation don’t have to be at odds. With the right safeguards and a thoughtful, people-first approach, India can build a digital future that respects both our rights and our potential. The DPDP Act is a big step but to truly succeed, it must evolve to meet the realities of how technology shapes our lives today.

LexLumen – Open Access Box
LLRJ | Lex Lumen Research Journal Open Access Article
Open Access Licensed under CC BY-NC-SA 4.0

This is an Open Access article distributed under the terms of the Creative Commons Attribution–NonCommercial 4.0 International (CC BY-NC-SA 4.0) licence, which permits remixing, adapting, and building upon the work for non-commercial use, provided the original work is properly cited.

CC
BY
NC
SA
CC BY-NC-SA 4.0 · Free to read, share & adapt
Non-commercial use · Attribution required

Access Open Access
Copyright © LLRJ 2024–2026
Licence CC BY-NC-SA 4.0
Estd. 2024