15 August 2026

What India is witnessing right now is nothing less than a privacy paradox. There is an increasing stratum of society getting conscious regarding their browsing history & how they are being tracked by targeted advertisements , yet the same set of people lack actual digital privacy knowledge & understanding of synthetic media.
Today people primarily associate privacy with passwords and financial details, however mobile numbers, health information, children details, daily life personal details are being publicly shared. They complain about surveillance and tracking by public CCTV cameras however share geotagging , locational updates on social media in real time, freely submitting their personal photos in Ai chatbots for image enhancements. The new modern trend we are witnessing is consumption of news not from TV news channels & newspapers but from social media handles of influencers chasing likes & follows.
Is our privacy regulation DPDPA robust enough to protect its citizens and society from the harms orchestrated by these algorithms and widespread adoption of automated tools and deepfakes ? Short answer is No. DPDPA provides a foundational data protection framework but is insufficient to comprehensively regulate Ai’s societal impact.
It’s technology neutral approach means it applies to any processing of digital personal data including Ai systems, however several critical gaps are there when we take a closer look.
DPDPA requires a detailed consent & privacy notice before the systems obtain the data from its users detailing processing purposes (training, inference, personalization, model improvement etc) and opt in choices. It exempts publicly available data from its scope allowing unrestricted use for Ai training models including data scraping. This creates a potential for “invisible processing” where individuals are unaware their data is being used.
There is no special category or differentiation between sensitive personal data. Hence the ai systems processing highly sensitive personal data face the same requirements as those processing basic contact information. Several technical challenges arise in dpdpa applicability to these machine learning models, operationalizing data principal rights such as right to erasure and data privacy principal of purpose limitation. Without requirements for bias testing, algorithmic audits, or transparency in Ai systems, DPDPA cannot address concerns about discriminatory outcomes.
DPDPA implementation and readiness remain minimal in India with now 9months until full enforcement of the Act. With a lot of organizations wanting to follow quick fixes in privacy policy updates rather than adopt a comprehensive personal data governance structure, in depth knowledge & understanding of the regulation remains low with various interpretations around applicability to businesses, classification of personal data and documentary approach to its use. Many organizations lack adoption of privacy technologies due to cost involved.
Though the approach of DPDPA towards simplifying privacy policies & notices, granting rights to citizens on data privacy are well in place, there are operational challenges in adoption by the organizations. Legal protections mean little when citizens don’t know they exist or how to exercise them. Although the Constitution recognizes right to privacy, it remains interpretive by the citizens. Public understanding is critical; privacy culture is underdeveloped. There is a massive requirement to promote understanding of and implications of use of synthetic data, hold the organizations accountable and bring transparency in working of ai technologies.


