| Abstract: |
Artificial Intelligence has emerged as a transformative force in contemporary data-driven economies, fundamentally altering the scale, speed, and sophistication with which personal data is collected, processed, and monetised. This paper undertakes a doctrinal and comparative legal analysis of the adequacy of existing personal data protection frameworks principally India's Digital Personal Data Protection Act, 2023 and the European Union's General Data Protection Regulation, 2016 in governing AI-driven data processing. Through critical examination of the structural features of AI systems, including algorithmic opacity, automated decision-making, mass profiling, and cross-border data flows, the paper identifies systemic inadequacies in consent-based legal architectures that were substantially conceived in a pre-AI regulatory paradigm. Drawing upon landmark judicial pronouncements including Justice K.S. Puttaswamy v. Union of India, Google Spain v. AEPD, and Schrems II, as well as peer-reviewed scholarship and institutional reports, the paper demonstrates that current frameworks particularly India's DPDP Act lack enforceable protections against algorithmic discrimination, autonomous decision-making, and surveillance capitalism. The paper further undertakes a comparative evaluation of the India–EU regulatory divide, exposing gaps in India's legislative architecture including the absence of provisions equivalent to Article 22 of the GDPR. Based on this critical analysis, the paper advances concrete, non-generic reform proposals encompassing AI-specific regulatory legislation, algorithmic transparency mandates, an independent AI regulatory authority, and mandatory ethical compliance audits. The paper concludes that effective data protection in the AI era demands a fundamental reorientation from consent-centric models towards accountability-based governance frameworks that place individual fundamental rights at the normative centre of regulatory design. |