Does synthetic data fall outside the DPDP Act? Synthetic data can fall outside the DPDP Act — but only if it is genuinely non-personal, meaning no individual can be identified from it directly or by re-linking it to other data. The catch is that poorly generated synthetic data often leaks real records or preserves rare, re-identifiable combinations, in which case it is still personal data and every DPDP obligation applies. This synthetic data governance pack gives AI and analytics teams a defensible framework: when synthetic data is permissible, how to validate that it is truly non-identifiable, the sign-off and documentation trail that proves it, and the guardrails for using it in model training and testing. Niti Bharat built it so mid-market teams can innovate with synthetic and anonymised data without accidentally creating new DPDP liability.
For AI, data science and analytics teams — decide when synthetic data is permissible, validate that it is truly non-identifiable, and document the sign-off that keeps it outside DPDP scope.
The DPDP Act 2023 applies to personal data — data about an identifiable individual. Data that is truly anonymous or synthetic, from which no individual can be identified directly or by re-linking to other available information, sits outside the Act's obligations. But 'synthetic' is not a magic label: the legal question is not how the data was made, it is whether a real person can still be picked out from it. Synthetic datasets frequently fail this test because generative models can memorise and reproduce real training records verbatim, and statistical methods often preserve rare outlier combinations (a single high-value transaction, an unusual age-location-diagnosis triple) that map back to one real person.
This framework therefore treats synthetic data as personal data by default until it has passed a documented validation, rather than assuming it is safe because it was labelled synthetic. The practical rule: if you cannot show, on paper, that no individual is re-identifiable from a synthetic dataset, you must treat that dataset as personal data and apply every DPDP obligation — consent basis, purpose limitation, security and breach handling — to it. Getting this default right is the single most important governance decision, because it determines whether your entire synthetic-data pipeline is a DPDP asset or a hidden DPDP liability.
Before any synthetic or anonymised dataset is treated as non-personal, it must pass a structured re-identification risk test. The framework walks through five checks: (1) Uniqueness — do any records represent a combination of attributes so rare that only one real person could match? (2) Linkage — could the dataset be joined with any other dataset you or a partner holds (or a public dataset) to re-identify individuals? (3) Memorisation — for model-generated data, does the output contain verbatim or near-verbatim copies of real training records? (4) Inference — can a sensitive attribute about a real person be reliably inferred even without a direct identifier? (5) Motivated-intruder — would a reasonably resourced, motivated party plausibly succeed at re-identification?
Each check produces a pass, fail, or mitigate outcome, and the dataset is only cleared as non-personal when all five pass or are mitigated to an acceptable, documented level. A fail on any check sends the dataset back for further synthesis, aggregation, or suppression of outliers — or, if it cannot be fixed, keeps it firmly inside DPDP scope. This test is the evidential core of the whole framework: it is what you show an auditor or the Data Protection Board to justify why a given dataset was treated as outside the Act.
Source-data categories that seed your synthetic datasets:
Synthetic data is often pitched as a clean way to escape data-protection obligations: generate artificial records that look real, and the privacy problem disappears. Under the DPDP Act 2023 that is only true if the synthetic data is genuinely non-personal — if no real individual can be identified from it directly or by re-linking. In practice, a great deal of synthetic and 'anonymised' data quietly fails that bar, because generative models can memorise real records and statistical methods preserve rare, re-identifiable outliers. A synthetic data governance pack matters precisely because the label 'synthetic' does not, by itself, put data outside the Act — a documented validation does.
This is a fast-moving area for AI and analytics teams under real pressure to move quickly with model training, testing and data sharing. Without a governance framework, teams tend to assume synthetic data is safe by default and discover the gap only during an incident or audit. A structured framework flips that assumption: synthetic data is treated as personal data until proven otherwise, with a repeatable test and a paper trail that makes the 'proven otherwise' decision defensible.
The goal of good synthetic-data governance is not to slow teams down — it is to let them use synthetic and anonymised data confidently for training, testing and sharing, knowing each dataset has cleared a defined bar. When the re-identification risk test, generation controls and sign-off record are in place, a data-science team can move fast on non-personal data and reserve heavier DPDP controls for the datasets that genuinely need them. That separation is what makes governance an enabler rather than a brake.
With DPDP enforcement expected around May 2027 and AI adoption accelerating across Indian mid-market companies, synthetic-data practices that were built informally now need a defensible framework behind them. Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) that embed synthetic-data governance into a company's wider data-protection programme — connecting it to DPIAs, security controls and vendor contracts so the whole pipeline holds together under scrutiny.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.