AI Vendor Uses Customer Data for Model Training: DPDP Purpose, Contract and Opt-Out Review
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
2-minute summary
- Do not describe broad DPDP processing duties as already fully operative on 5 October 2026.
- The 13 November 2025 commencement notification staggered the Act: most substantive processing obligations begin 18 months after publication, while a smaller set started immediately and another tranche starts after one year.
- AI-training contracts should still be redesigned now because purpose boundaries, security, deletion, processor controls and withdrawal mechanics require implementation lead time.
Current position
Control and evidence map
| # | Control / evidence requirement | |
|---|---|---|
| 1 | Inventory exactly which customer fields the AI vendor receives and whether prompts, files, logs or embeddings are retained. | |
| 2 | Define the permitted service purpose separately from vendor model-training or product-improvement use. | |
| 3 | Contract for security safeguards, sub-processors, incident cooperation, deletion/return and evidence of instruction. | |
| 4 | Design a route to honour withdrawal or changed instructions once the relevant DPDP provisions commence. | |
| 5 | Disable vendor training by default where the business cannot support the purpose, notice and governance case. | |
Worked example
A CRM vendor offers a generative-AI assistant and proposes using uploaded support tickets to improve its global model. The business should not treat a generic SaaS clause as enough. It should separate service processing from model training, identify personal data in tickets, decide whether training is actually necessary, and preserve a contractual opt-out/deletion path before the substantive DPDP obligations commence.
Common mistakes
- Writing that all DPDP obligations are already live in October 2026.
- Treating a processor contract as permission for unrestricted secondary model training.
- Ignoring embeddings, telemetry and prompt logs when mapping data.
- Using “anonymised” as a label without testing whether individuals can realistically be identified.
Frequently asked questions
Are all DPDP duties in force on 5 October 2026?
No. Commencement is staggered.
When do most core duties begin?
Eighteen months after the 13 November 2025 Gazette publication, subject to the exact notification wording.
Should contracts wait until then?
No. Implementation and vendor renegotiation need lead time.
Is model training automatically the same purpose as providing the SaaS service?
No; the purposes should be analysed separately.
Official sources
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Act, 2023 (Act 22 of 2023; 2023-08-11)
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E); 2025-11-13)
- Ministry of Electronics and Information Technology - DPDP Act commencement notification (G.S.R. 843(E); 2025-11-13)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.