Compliance
DPDP Act compliance for speech and AI training data
How India's Digital Personal Data Protection Act 2023 applies to voice and speech collected for AI training, and the practical controls we operate against it.

- Regime
- DPDP Act 2023 (India)
- Role
- Data processor for clients
- Consent
- Written, purpose-specific
- Retention
- Defined per contract
The short version
- Voice recordings are personal data: a speaker is identifiable from their voice, so every recording is treated as personal data from capture onwards
- Consent is purpose-specific and written in a language the speaker reads, covering AI model training, derivative models and commercial deployment
- Consent artefacts are mapped to speaker IDs and file IDs so provenance survives an external audit
- Withdrawal is operationally supported: a withdrawn speaker's material is removed from undelivered batches and flagged in delivered manifests
- Access to raw recordings is role-limited and logged; transfer is over access-controlled channels only
- Retention and deletion windows are set in the statement of work, not left open-ended
Why it matters in practice
The DPDP Act frames obligations around notice, purpose limitation and the ability of a data principal to withdraw consent. For AI training data that translates into three practical requirements: prove what the speaker agreed to, prove which files came from that speaker, and be able to act on a withdrawal without re-processing the whole corpus.
We structure deliveries so that each of those is answerable from the manifest rather than from a search through project email.

How it is operated
| Obligation | How it is operated |
|---|---|
| Notice | Plain-language notice read and signed before recording, in the speaker's language |
| Purpose limitation | Consent names AI training and commercial model deployment explicitly |
| Data principal rights | Speaker ID index allows withdrawal, correction and erasure requests to be executed |
| Security safeguards | Role-based access, encrypted transfer, logged downloads |
| Breach reporting | Contractual notification window to the client as processor |
| Retention | Deletion of working copies after the contractual window, certified in writing |
What you receive
- The relevant policy or template as a document, not a claim on a web page
- Programme-specific artefacts delivered with the corpus manifest
- Named contact for audit questions during and after the programme
- Written confirmation at close-out
If your legal or procurement team has a questionnaire, send it with the specification. It is faster to answer it once, up front, than to unblock a signed programme later.
Frequently asked
Is speech data personal data under the DPDP Act?
Treat it as such. A voice recording can identify an individual, and transcripts frequently contain names and other identifiers, so the safe operating assumption is that the whole corpus is personal data.
Who is the data fiduciary?
For client programmes the buyer is normally the fiduciary and we act as processor under contract. Where we recruit and hold consent directly, we act as fiduciary until delivery transfers rights.
Can a speaker withdraw consent after delivery?
Yes, and the manifest makes it actionable: the speaker ID identifies every affected file so the buyer can remove them and document it.
Does this affect model commercialisation?
Only positively. Consent that explicitly covers commercial deployment removes the most common blocker enterprise legal teams raise before a model ships.
Related pages
Send your compliance questionnaire with the spec
We answer procurement, legal and security questionnaires alongside the technical scope, in the same working day where we can.