Data Privacy in the Age of Artificial Intelligence: A Global Legal Reckoning
Examining how the world's major legal systems are responding to the intersection of artificial intelligence and personal data — and where the law is still catching up.
Every second, billions of data points are generated, harvested, processed, and monetised, often without the meaningful knowledge or consent of the individuals they describe. In 2024 alone, global regulators issued fines totalling more than €4 billion for data protection violations. And yet, the intersection of artificial intelligence and personal data remains one of the most under-regulated, legally ambiguous, and consequential frontiers of our time. This article examines how the world's major legal systems are responding and where the law is still catching up.
I. The Regulatory Landscape: A Patchwork in Motion
The General Data Protection Regulation (GDPR) of the European Union remains the gold standard of data privacy law globally. Since its enforcement began in May 2018, it has fundamentally shifted the relationship between data subjects and data controllers, enshrining rights to access, erasure, portability, and objection. Its extraterritorial reach, applying to any entity that processes data of EU residents, regardless of where that entity is based, has made it a de facto global benchmark.
India entered this regulatory conversation decisively with the Digital Personal Data Protection Act, 2023 (DPDPA). The Act marks a significant departure from India's earlier piecemeal approach under the Information Technology Act, 2000. It introduces the concept of a 'Data Fiduciary' and 'Data Principal', imposes consent obligations, mandates data localisation for certain categories of sensitive data, and establishes the Data Protection Board of India as the adjudicatory body. While the statute draws inspiration from the GDPR, it is importantly calibrated to India's developmental priorities, permitting broader governmental exemptions and adopting a principles-based rather than prescriptive framework.
Meanwhile, the United States continues to operate without a comprehensive federal privacy law, relying instead on a sectoral patchwork of HIPAA for health data, COPPA for children's data, and GLBA for financial information supplemented by state-level legislation such as the California Consumer Privacy Act. This fragmentation increasingly strains businesses operating across state lines and creates regulatory arbitrage opportunities that undermine consumer protection.
II. The AI Problem: When Personal Data Becomes Training Data
The advent of large language models and generative AI has created an entirely new category of data privacy challenge. Unlike traditional data processing, where a company collects specific information for a defined purpose, AI systems consume vast, often indiscriminate datasets during training, embedding personal information into model weights in ways that may be irreversible and difficult to audit.
The Court of Justice of the European Union's landmark ruling in Schrems II had already exposed the fragility of transatlantic data transfer frameworks. The concern is now compounded: when personal data used to train an AI model is transferred across borders, which jurisdiction's law governs? If a model trained on EU citizens' data is hosted on servers in the United States and accessed from India, the question of applicable law becomes genuinely intractable under current frameworks.
The GDPR offers some guidance. Article 22 restricts purely automated decision-making with significant effects on individuals, requiring human oversight and the ability to contest such decisions. The European Data Protection Board has taken a robust position on facial recognition technology in particular, recommending a general prohibition in law enforcement contexts pending stronger safeguards. But the law was not written with generative AI in mind, and regulators are visibly struggling to apply eighteenth-century legal concepts, consent, purpose limitation, and data minimisation to twenty-first-century technology.
III. Consent: A Fiction We Maintain
Perhaps no principle in data privacy law is more widely invoked and more routinely violated in spirit than consent. The notice-and-consent model under which individuals are presented with lengthy, opaque privacy policies and asked to click 'I agree' has long been identified by scholars as functionally meaningless. Studies consistently show that the average consumer would need over 200 hours per year to read the privacy policies of every service they use.
The DPDPA attempts to address this through the concept of 'free, specific, informed, unconditional, and unambiguous' consent, communicated in plain language and accompanied by an itemised notice. India's Supreme Court, in the landmark Puttaswamy judgment, had already elevated privacy to the status of a fundamental right under Article 21 of the Constitution, a constitutional anchor that gives statutory data protection laws considerably greater force.
The deeper problem, however, is structural. In an ecosystem where dominant platforms exercise enormous market power, consent is rarely truly voluntary. Competition regulators are beginning to recognise this: the Competition Commission of India, in proceedings against WhatsApp, found that the 2021 privacy policy update constituted an abuse of dominant position, effectively conditioning service access on data sharing that exceeded what users could meaningfully refuse.
IV. Cross-Border Data Flows: Sovereignty vs. Connectivity
Data localisation, the requirement that certain data be stored and processed within national borders, has emerged as one of the most contentious issues in international data governance. China's Personal Information Protection Law (PIPL) mandates security assessments before sensitive personal information can cross its borders. India's DPDPA empowers the Central Government to restrict cross-border transfers to notified countries, with criteria yet to be fully defined by subordinate legislation. While such measures are defensible on national security grounds, they risk Balkanising the global internet and imposing disproportionate compliance costs on smaller enterprises.
The OECD's Privacy Framework, now over four decades old, articulated the principle that personal data flows between member countries should not be restricted except for legitimate reasons, a principle that remains technically operative but increasingly under political pressure as data becomes synonymous with geopolitical power.
The challenge for international lawyers is significant: how do we construct a workable multilateral framework for data governance when the very states involved have fundamentally different visions of privacy, sovereignty, and the legitimate role of government in digital life?
V. The Road Ahead: Principles for a Coherent Framework
Several principles, drawn from comparative law and international human rights frameworks, offer a path forward.
First, the right to privacy must be understood not merely as an individual right but as a collective social infrastructure. The United Nations General Assembly's 2013 resolution on the right to privacy in the digital age recognised that mass surveillance, whether by states or corporations, undermines democratic governance and chills the exercise of other fundamental rights. Privacy law must be designed to protect this collective dimension, not merely to empower individual opt-outs.
Second, purpose limitation and data minimisation must be given genuine teeth in the AI context. Regulators must develop workable standards for what constitutes 'compatible' secondary use of personal data in AI training standards that go beyond vague proportionality assessments and provide actionable guidance to developers and deployers.
Third, algorithmic accountability must become a first-order legal obligation. The right to an explanation, the right to contest automated decisions, and requirements for ex ante impact assessments should not be treated as administrative add-ons but as core elements of the duty of care that AI operators owe to those whose data and lives their systems affect.
Finally, international cooperation must be reinvigorated. A world of fragmented, competing data sovereignty regimes is in no one's long-term interest. The legal profession has a central role to play not just in advising clients on compliance but in shaping the treaty frameworks, regulatory standards, and judicial interpretations that will define digital life for the next generation.
Conclusion
Data privacy law is no longer a niche compliance function. It sits at the intersection of constitutional rights, market regulation, national security, and the ethics of technology. The individuals whose data flows through global networks deserve legal frameworks that are coherent, enforceable, and genuinely protective, not systems that generate the appearance of consent while perpetuating opacity.
The law is catching up. But in technology, catching up is rarely enough.