The DPDP Act lets data handlers process personal data on consent or a short list of "legitimate uses" — and a 2025 industry ask wants to add "publicly available" to the menu.
India's 2023 privacy law, the Digital Personal Data Protection (DPDP) Act, gives data handlers — the entities the Act calls "data fiduciaries" — two legal grounds to process personal data: the person's consent, or one of a short list of "legitimate uses" written into the statute. AI training at scale depends on data that was never collected with AI in mind. The gap between those two facts is the regulatory test case the Act is now being asked to settle.
The flashpoint is an August 2025 ask from IAMAI, the country's main internet industry body, which asked the Indian government to amend the DPDP Act so that "publicly available" personal data could be used to train or fine-tune AI models without further consent. The body also asked, separately, for an interim exemption under the government's existing powers under the Act (MediaNama coverage of the IAMAI ask). The carve-out would add a third ground to a regime that today has only two.
The ask exposes a structural mismatch the Act was not drafted to absorb. Three Web-era privacy principles — consent regimes, basis-for-processing rules, and purpose limitation — were built around a data controller asking a user a question and using the answer for a defined service. A model that trains on a corpus of public posts is doing something different: it is inferring patterns from data the person never gave it for that purpose, and it is producing a system whose downstream uses were not specified at collection. None of the DPDP's two grounds cleanly covers that case. Consent is impractical at corpus scale; legitimate uses, as currently enumerated, are tied to specified functions like employment or medical emergencies, not to "training a general-purpose model."
Purpose limitation is the principle the personal-AI case makes hardest to defend. A user's chat history, photo library, and search log are useful precisely because they are broad and historical; that is also exactly the profile of data that a consent regime asks the user to authorise one use at a time. When AI vendors begin offering memory-augmented assistants — the same product class MediaNama has been tracking on the AI memory and data-portability beat — the question is no longer whether one corpus can train one model. It is whether a single user can effectively license years of personal history to a system that will keep using it, and on what terms.
That is the practical problem IAMAI named. Its filing argued that establishing whether an individual "voluntarily" made their data public is not feasible at the scale AI training requires. The request is therefore not for a marginal clarification. It is to make publicly available data a third statutory ground for processing, with consent removed from the picture for that category.
The closed-door MediaNama discussion in 2026 surfaced a sharper split under that ask: whether people "own" their public data, in a sense strong enough that they could license it, or only "control access" to it (the writeup of the discussion). The two answers lead to different legal designs. Ownership implies a property-style regime, with default control sitting with the individual and a payment or licence mechanism for use. Access-control implies the data is treated as already in the public domain once posted, with whatever constraint the data handler chooses to add. An "interim exemption" under existing DPDP powers slides toward the second; a statutory amendment with consent removed for public data slides further.
The EU's General Data Protection Regulation (GDPR) is the cross-jurisdictional signal in the room. It recognises six lawful bases for processing — consent is one, but legitimate interest, contract necessity, legal obligation, vital interest, and public task are also available. The Indian framework, with two grounds, leaves narrower room for the same use case. The GDPR has not solved AI training either. The difference is that its broader menu of bases makes a carve-out a question of which basis applies, not a question of whether the law's structure fits at all.
The DPDP Act is still months away from being actively enforced, so the carve-out is being designed in the window before the law has enforcement teeth. That window is also when the rules in the Act get shaped, and the rules shape what an eventual enforcement action can reach. The industry's August 2025 ask, in that sense, is not just about training today's models. It is about what counts as lawful processing when enforcement does start.
The sharper question the carve-out would settle is whether the consent regime that worked for websites should also be the consent regime that governs the data those websites generated, once a model is the consumer.