Abstract
Generative large language models, such as ChatGPT, are trained and continue to generate substantial amounts of personal information about individuals who have not consented to the model’s developer. This structural feature exposes a gap in India’s Digital Personal Data Protection Act, 2023 which relies on a fiduciary processor framework that presumes a bilateral relationship between a data principal and a data fiduciary. This article examines whether the DPDP Act can effectively assign liability when a Large Language Model discloses memorised personal data or fabricates false information about a named third party who has never interacted with the system. Drawing on global enforcement experience, including Italy’s since-annulled fine against OpenAI, multiple complaints filed by the privacy group noyb under the General Data Protection Regulation, the Samsung trade-secret disclosure, and the Georgia defamation suit Walters v. OpenAI, this article argues that the DPDP Act’s consent-centric design, ambiguous breach-notification requirements, and absence of data accuracy provisions leave third-party victims of LLM-induced disclosure largely unprotected. The analysis compares the DPDP Act with the GDPR and the EU Artificial Intelligence Act’s data-governance provisions, and proposes targeted statutory and regulatory reforms, such as activating the Significant Data Fiduciary mechanism for foundation-model providers and introducing a limited third-party accuracy right.
Keywords: Digital Personal Data Protection Act, 2023, Large Language Models, Data Fiduciary, AI Hallucination, Third-Party Privacy.