DPDP 3.5.1: DPDP and Data Analytics

INTRODUCTION

Data analytics and DPDP compliance may appear to be an unlikely pairing. One is a business tool. The other is a legal framework. Yet they collide precisely because analytics, at its most powerful, is built on personal data — and the DPDP Act, 2023 governs every piece of it.

IS Audit 3.0 study material by ICAI defines data analytics as the science of examining raw and unprocessed data with the intention of drawing conclusions from the information thus derived. At its simplest level, descriptive analytics tells us what happened. Diagnostic analytics explains why it happened. Predictive analytics forecasts what may happen next. Prescriptive analytics recommends what should be done. Cognitive analytics — the highest tier — uses Big Data and artificial intelligence to recognise patterns and take proactive action.

Each tier of this evolution processes more personal data, draws more intimate inferences, and creates more consequential outputs for the individuals at the centre of that data. By the time an organisation is running predictive or cognitive analytics at scale, it is not merely analysing data. It is constructing detailed models of human behaviour — including patterns the individual herself may not be aware of. The Puttaswamy judgment (2018) confronted precisely this reality when it held that data mining and knowledge discovery processes can create new knowledge about individuals, including facts that even those individuals did not possess about themselves.

The DPDP Act does not prohibit analytics. However, it requires that every stage of the analytics pipeline — from data collection to model output to decision-making — be governed by a lawful basis, a specific purpose, and a respect for Data Principal rights. Three stories show exactly where that governance breaks down in practice, and what responsible Data analytics and DPDP compliance looks like.

Story 1 — Devika’s Loan Application and the Score That Came From Nowhere

The Scenario

Devika is a 33-year-old chartered accountant in practice who applied for a personal loan from a digital lending platform. Her credit profile was clean. Her income was verifiable and above the threshold. Nevertheless, the platform’s system rejected her application within seconds, flagging her as a high-risk borrower.

Devika asked for a reason. The lender’s customer service team explained that an internal risk model had assessed her application and that a detailed explanation could not be provided. She then invoked her right to know what personal data the platform held about her and how it was being processed. The platform sent her a generic response listing basic data categories — name, income, PAN — but made no mention of the behavioural and transactional data from third-party sources that the model had actually used.

Devika had been profiled based on data she had not provided and had never been informed about.

The DPDP Act Position

Three distinct compliance failures arise from Devika’s situation.

First — Absence of notice for third-party data under Section 5. Section 5(1) of the DPDP Act requires that every request for consent be accompanied or preceded by a notice informing the Data Principal of the personal data to be processed and the purpose for which it will be processed. Rule 3 of the DPDP Rules reinforces this: the notice must give an itemised description of the personal data, including its source. When the lender ingested Devika’s behavioural data from third-party platforms without disclosing this as a data source in its notice, it failed this obligation entirely.

Data analytics pipelines routinely pull data from multiple external sources — credit bureaux, social media signals, transaction aggregators, app usage patterns, telecom data partners. Every one of these data categories must be disclosed, itemised, and tied to a specific processing purpose in the notice. A generic privacy policy that refers to “data from third parties” does not satisfy this standard.

Second — Processing beyond the stated purpose under Section 6(1). Devika’s consent, to the extent it was obtained, covered the processing of her application data for a lending decision. Behavioural profiling using third-party data analytics is a materially different processing activity. Section 6(1) limits consent to the personal data that is necessary for the specified purpose. Conducting wide-scope predictive profiling on data not covered by the stated purpose, and not disclosed in the notice, has no lawful consent basis.

Third — Right to access information violated under Section 11(1). Section 11(1) of the DPDP Act gives every Data Principal the right to obtain from the Data Fiduciary a summary of personal data being processed, a description of processing activities, and the identities of all Data Fiduciaries and Data Processors with whom her personal data has been shared. The platform’s generic response — listing only basic data categories — is an inadequate discharge of this obligation. Devika had a statutory right to know that third-party data was feeding the model that rejected her. She was denied that right.

The IS Audit 3.0 and Puttaswamy Perspective

IS Audit 3.0 material by ICAI explicitly identifies data privacy and confidentiality as a primary risk of deploying data analytics, noting that the copying and storage of client data risks breach of confidentiality and data protection laws. In an analytics context, this risk is not limited to the data that is explicitly collected — it extends to every data source the analytics model ingests, however indirectly.

The Puttaswamy judgment (2018) is even more direct. Justice Kaul’s concurring opinion described profiling — the use of personal data to evaluate a person’s performance, economic situation, health, personal preferences, reliability, behaviour, or movements — as a fundamental privacy concern, and warned that proprietary algorithms used to make consequential decisions about individuals can, if biased or unaccountable, produce discrimination based on religion, ethnicity, caste, or gender. This concern is not hypothetical in India’s digital lending sector. It is a live compliance and human rights risk.

The Compliance Fix

Digital lenders and any organisation using predictive analytics for individual decisions must:

→ Issue a Rule 3-compliant notice that itemises every data source used in the analytics model — including third-party data providers, their categories, and the specific purpose for which each is used.

→ Limit data ingestion to what is necessary for the stated lending purpose. Section 6(1) applies to every data point in the analytics pipeline, not just the primary application form.

→ Maintain a Data Processor register of every analytics partner or data provider, with contracts under Section 8(2) that specify permitted data uses.

→ Build a meaningful Section 11 response mechanism — one that can accurately answer a Data Principal’s question about what data sources contributed to a decision about her.

→ Where predictive analytics is used for credit, insurance, or employment decisions, conduct a DPIA under Section 10 to assess algorithmic risk to Data Principal rights before deployment.

Devika’s loan was rejected by a model she could not question, fed by data she did not know existed. Under the DPDP Act, that outcome has a name. It is a compliance failure.

Four things digital lenders using predictive analytics must do now:

→ Issue Rule 3-compliant notices that itemise every third-party data source feeding the lending model.

→ Build a meaningful Section 11 response capability — one that can accurately identify which data sources contributed to a specific decision.

→ Limit data ingestion to what is necessary for the stated lending purpose under Section 6(1).

→ Conduct a DPIA under Rule 13 of the DPDP Rules before deploying or updating predictive models used for credit decisions.

The DPDP Act does not permit algorithmic opacity when personal data drives consequential decisions.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors: This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.5.1: DPDP and Data Analytics