Course Content
AI Safety & Guardrails
5 sections · 50 lessons
What are the main privacy regulations affecting AI systems?
What you need to know
| Law | Key points for AI builders |
|---|---|
| GDPR (EU, and UK GDPR) | Lawful basis per purpose; minimisation and purpose limitation; access, correction and erasure rights; breach notification to the regulator within 72 hours; transfer rules outside the EEA; rights around solely automated decisions with legal or similarly significant effects (Article 22). |
| DPDP Act 2023 (India) | Consent or a listed "legitimate use" for processing; clear notice; duties on the Data Fiduciary; stronger duties for Significant Data Fiduciaries; children's data rules; breach reporting; a Data Protection Board with large financial penalties. |
| CCPA / CPRA (California) | Right to know, delete, correct, and opt out of sale or sharing; rules on automated decision-making technology being phased in. |
| HIPAA (US health) | Protected health information needs a business associate agreement with any vendor that touches it. |
| PCI DSS (card data) | Card numbers must not sit in logs or prompts outside the controlled environment. |
| EU AI Act | Not a privacy law, but adds risk-tiered duties: transparency, logging, data governance and human oversight for high-risk systems. |
India's DPDP Act 2023 in more detail
- Consent must be free, specific, informed and unambiguous, given by a clear action, and as easy to withdraw as to give. A Consent Manager is a registered entity that lets people manage consents across companies.
- Notice must say what data is collected and why, in clear language, with an option to read it in English or languages listed in the Constitution's Eighth Schedule.
- Rights: access a summary of processing, correction and erasure, grievance redressal, and nominating someone to act for you.
- Children (under 18): verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising aimed at them.
- Significant Data Fiduciaries (notified by the government based on volume and risk) must appoint a Data Protection Officer based in India, run periodic data protection impact assessments and use an independent data auditor.
- Cross-border transfer is allowed except to countries the government restricts by notification.
- Breaches must be reported to the Board and to affected people.
- Timeline: the DPDP Rules were notified in November 2025 with a phased rollout; most fiduciary duties apply after a transition period of roughly 18 months. Check the current dates before quoting them.
What changes in your build
- A data inventory: what personal data each system holds, why, and where it came from.
- Region pinning where transfers are restricted.
- A DPA with every model vendor, with training on your data switched off.
- Consent state that the retrieval layer actually reads — withdrawn consent means those documents are no longer retrieved.
- Retention and erasure jobs that cover every derived store.
A real-life example
A healthcare symptom-checker serves users in India and Germany. For Indian users, it collects consent with a notice available in Hindi and English, keeps symptom history only for 90 days, and treats users under 18 as needing parental consent. For German users it runs on an EU-region deployment of the model under GDPR, with health data handled as a special category that needs explicit consent.
When a user asks for deletion, the job deletes the account row, the conversation history, the embeddings of their past chats in the vector store, the cached summaries, and the traces — five systems. The first test of the job found that the trace store had no delete API at all; the team switched to a tracing setup with per-user deletion before launch.
Follow-up questions to expect
- "Does DPDP have 'sensitive personal data' like the old IT Rules?" — No separate category in the Act; all digital personal data is treated the same way, with extra rules for children.
- "Can you train a model on user data under DPDP?" — Only for a purpose the user consented to or a listed legitimate use. Training is a separate purpose from answering their question, so it needs its own basis.
- "How do you honour erasure for a fine-tuned model?" — Removing one person from trained weights is hard. Keep personal data out of fine-tuning sets, or retrain on a schedule from a dataset with deletions applied.