core Estimated learning time: 5 h

10.11 Responsible AI and Indian data law

You can ship a system that survives a compliance review.

Before:05. Classical Machine Learning

India's DPDP Act 2023, with GDPR as contrast, defines the compliance floor for any system touching personal data: consent, purpose limitation, minimisation — with bias audits and model cards documenting what the system does and where it fails. It closes the production module because responsibility ships with the system. The retrofit trap is structural: consent and retention are architecture, and adding them to a built system costs many times what designing them in did.

Work through these

  • DPDP Act 2023 obligations; GDPR contrasts

    India's data protection law and how its obligations compare with the European regime. Anyone handling personal data in a system deployed here is subject to the first.

  • Consent, purpose limitation, data minimization

    Collecting only with agreement, using only for the stated purpose, and collecting no more than needed. These three principles decide most design questions before they become legal ones.

  • Bias auditing and fairness metrics

    Measuring whether a model performs differently across groups, using metrics chosen deliberately because they cannot all be satisfied at once. Choosing which fairness definition applies is a decision, not a calculation.

  • Model cards, datasheets and documented limitations

    Written documentation of what a model is for, what data trained it, and where it should not be used. This is what a review asks for and what protects you when something goes wrong.

Sign in to keep your progress.

Free resources

Links last checked 29 Aug 2026.

Stuck here?

Ask a mentor. A real person answers, and they can see exactly which topic you're on. Usually within a couple of working days.

Checking your session…

Topics shown in module order.