Indian Journal for Research in Law and Management

Advancing Law and Management

ISSN No. : 2583-9896

CHATGPT AND DATA BREACHES: LEGAL LIABILITY FOR LLM -INDUCED THIRD-PARTY PRIVACY VIOLATIONS UNDER THE DPDP ACT, 2023

Cite this Article

Ms. Aashi Lalchand Khanchandani (2026). CHATGPT AND DATA BREACHES: LEGAL LIABILITY FOR LLM -INDUCED THIRD-PARTY PRIVACY VIOLATIONS UNDER THE DPDP ACT, 2023. The Indian Journal for Research in Law and Management, Volume III(Issue 10). Retrieved from https://ijrlm.com/journal/chatgpt-and-data-breaches-legal-liability-for-llm-induced-third-party-privacy-violations-under-the-dpdp-act-2023/

Abstract

Generative large language models, such as ChatGPT, are trained and continue to generate substantial amounts of personal information about individuals who have not consented to the model’s developer. This structural feature exposes a gap in India’s Digital Personal Data Protection Act, 2023 which relies on a fiduciary processor framework that presumes a bilateral relationship between a data principal and a data fiduciary. This article examines whether the DPDP Act can effectively assign liability when a Large Language Model discloses memorised personal data or fabricates false information about a named third party who has never interacted with the system. Drawing on global enforcement experience, including Italy’s since-annulled fine against OpenAI, multiple complaints filed by the privacy group noyb under the General Data Protection Regulation, the Samsung trade-secret disclosure, and the Georgia defamation suit Walters v. OpenAI, this article argues that the DPDP Act’s consent-centric design, ambiguous breach-notification requirements, and absence of data accuracy provisions leave third-party victims of LLM-induced disclosure largely unprotected. The analysis compares the DPDP Act with the GDPR and the EU Artificial Intelligence Act’s data-governance provisions, and proposes targeted statutory and regulatory reforms, such as activating the Significant Data Fiduciary mechanism for foundation-model providers and introducing a limited third-party accuracy right. Keywords: Digital Personal Data Protection Act, 2023, Large Language Models, Data Fiduciary, AI Hallucination, Third-Party Privacy.

Journal Information

The Indian Journal for Research in Law and Management
ISSN No.
2583-9896
Submit Manuscript
Licensing
All research articles published in The Indian Journal for Research in Law and Management are fully open-access. i.e. immediately freely available to read, download, and share. Articles are published under the terms of a Creative Commons license, which permits use, distribution, and reproduction in any medium, provided the original work is properly cited.
Disclaimer
The opinions expressed in this publication are those of the authors. They do not purport to reflect the opinions or views of the IJRLM or its members. The designations employed in this publication and the presentation of material therein do not imply the expression of any opinion whatsoever on the part of the IJRLM.

Article Analytics

20
Page Views
0
Downloads