10.11 Responsible AI and Indian data law
You can ship a system that survives a compliance review.
India's DPDP Act 2023, with GDPR as contrast, defines the compliance floor for any system touching personal data: consent, purpose limitation, minimisation — with bias audits and model cards documenting what the system does and where it fails. It closes the production module because responsibility ships with the system. The retrofit trap is structural: consent and retention are architecture, and adding them to a built system costs many times what designing them in did.
Work through these
DPDP Act 2023 obligations; GDPR contrasts
India's data protection law and how its obligations compare with the European regime. Anyone handling personal data in a system deployed here is subject to the first.
Consent, purpose limitation, data minimization
Collecting only with agreement, using only for the stated purpose, and collecting no more than needed. These three principles decide most design questions before they become legal ones.
Bias auditing and fairness metrics
Measuring whether a model performs differently across groups, using metrics chosen deliberately because they cannot all be satisfied at once. Choosing which fairness definition applies is a decision, not a calculation.
Model cards, datasheets and documented limitations
Written documentation of what a model is for, what data trained it, and where it should not be used. This is what a review asks for and what protects you when something goes wrong.
Sign in to keep your progress.
Free resources
We haven't checked most of these for screen reader use yet.
Links last checked 29 Aug 2026.
Stuck here?
Ask a mentor. A real person answers, and they can see exactly which topic you're on. Usually within a couple of working days.
Checking your session…
Topics shown in module order.