Compliance
GDPR obligations when buying Indian AI training data
What EU and UK buyers need in place when speech data is collected in India: lawful basis, transfer mechanism, special-category risk and documentation.

- Regime
- GDPR / UK GDPR
- Basis
- Consent, documented
- Transfer
- SCCs where required
- DPIA
- Supported with artefacts
The short version
- Consent is the practical lawful basis for voluntary speech contribution, captured in writing and specific to AI training
- Standard contractual clauses cover transfer where the buyer requires them, alongside a documented transfer impact assessment
- Biometric-identification risk is avoided by contract: voice data is licensed for training speech and language models, not for voiceprint identification, unless separately consented
- Transcripts are screened for direct identifiers, with redaction or pseudonymisation applied where the specification requires it
- Records of processing, consent templates and retention schedules are provided as DPIA evidence
Why it matters in practice
The recurring GDPR question in speech procurement is not whether data can be collected in India — it can — but whether the buyer can evidence the chain: what the speaker was told, what they agreed to, how the data moved, and how long anyone keeps it.
Every artefact in that chain ships as part of the delivery rather than being reconstructed under audit pressure.

How it is operated
| Requirement | Evidence provided |
|---|---|
| Lawful basis | Signed consent form per speaker, translated, with a countersigned English version |
| Transparency | Participant information sheet naming the purpose and the buyer category |
| International transfer | SCC module 2 or 3 as appropriate, plus transfer impact assessment |
| Special category | Contractual prohibition on biometric identification use unless separately consented |
| Data minimisation | Metadata limited to fields the specification actually requires |
| Retention | Deletion certificate after the contractual window |
What you receive
- The relevant policy or template as a document, not a claim on a web page
- Programme-specific artefacts delivered with the corpus manifest
- Named contact for audit questions during and after the programme
- Written confirmation at close-out
If your legal or procurement team has a questionnaire, send it with the specification. It is faster to answer it once, up front, than to unblock a signed programme later.
Frequently asked
Is voice data special-category data under GDPR?
Only when processed for the purpose of uniquely identifying a person. Training an ASR or TTS model is not that purpose, and our licence terms exclude biometric identification unless it is separately and explicitly consented.
Do we need SCCs?
Where personal data moves from the EEA or UK to India, yes in most structures. We sign the appropriate module and supply a transfer impact assessment.
Can speakers be pseudonymised?
Yes. Speaker IDs replace names throughout the delivery, and the mapping is held only where the contract requires it.
Will this pass a DPIA?
The artefacts a DPIA asks for — lawful basis, categories, transfer mechanism, retention, security measures — are all delivered as documents rather than assertions.
Related pages
Send your compliance questionnaire with the spec
We answer procurement, legal and security questionnaires alongside the technical scope, in the same working day where we can.