Author: Mahima Mittal
College: Asian Law College, CCSU
To the Point
Indian data protection law regulates the processing of personal data but does not expressly establish a standalone framework governing the accuracy, contestability or consequences of algorithmically generated inferences. A person’s transaction history may be accurate, yet a credit system may wrongly infer that she is a poor repayment. Similarly, accurate employment or behavioural information may produce an incorrect assessment of suitability for a job.
The Digital Personal Data Protection Act, 2023 provides a right to correct personal data that is inaccurate or misleading, but it does not expressly address an inference that is inaccurate while the underlying data remains accurate. This article identifies that gap and proposes a limited, risk-based Right to Contest an Inference where an algorithmic inference materially affects an individual’s life.
Abstract
Indian data protection law has developed significantly since Justice K.S. Puttaswamy (Retd.) v. Union of India recognised privacy as a constitutionally protected right connected with dignity, autonomy and personal liberty under Article 21. Parliament subsequently enacted the Digital Personal Data Protection Act, 2023, which provides rights relating to consent, access, correction, erasure and grievance redressal.
However, the legal framework remains primarily concerned with personal data rather than the conclusions generated from that data. Algorithmic systems increasingly produce scores, classifications and predictions that may influence credit, insurance, employment, education, healthcare and access to services.
This article distinguishes between the accuracy of personal data and the accuracy of an inference generated from that data. It examines the Indian constitutional and statutory framework and considers Puttaswamy and three decisions of the Court of Justice of the European Union as comparative jurisprudence. It proposes a limited, risk-based Right to Contest an Inference for high impact automated or algorithmically assisted decisions.
The proposal does not create a general right not to be profiled and does not seek to import Article 22 of the GDPR into Indian law. Instead, it argues that where accurate personal data produces a materially inaccurate or harmful inference with significant consequences, the affected individual should have a meaningful opportunity to understand and contest that inference.
“The data may be accurate. The inference may nevertheless be wrong.”
Indian Legal Framework
Article 21 and the Puttaswamy Foundation
Article 21 provides the constitutional foundation for privacy protection in India. In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court recognised privacy as a fundamental right connected with dignity, autonomy and personal liberty. The Court also established that State interference with privacy must satisfy requirements of legality, legitimate purpose, necessity and proportionality.
The relevance of Puttaswamy to algorithmic inference lies in its recognition of informational autonomy. Privacy is not limited to secrecy of information. It also concerns how personal information is collected, combined, processed and used. Algorithmic systems can transform ordinary information into conclusions about a person’s financial capacity, behaviour, preferences or employability.
However, Puttaswamy did not decide the legality of algorithmic profiling or automated decision making. It therefore does not itself establish a right to challenge algorithmic inferences. Its importance is constitutional because it provides the foundation for considering whether individuals should have greater control over consequential uses of their personal information.
Article 14 and Arbitrariness
Article 14 provides protection against arbitrary State action. Where a State authority uses an automated assessment to deny a public benefit or impose an adverse classification, the decision may be examined for arbitrariness, discrimination and procedural fairness.
The absence of transparency may become relevant where an individual is unable to understand or contest the basis of an adverse decision. However, Article 14 primarily operates against State action. Much consequential profiling is undertaken by private entities such as banks, insurers, employers and technology companies. Article 14 therefore does not provide a comprehensive remedy for harmful algorithmic inferences in the private sector.
The Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 is India’s principal statutory framework for digital personal data. It provides rights concerning access, correction, completion, updating, erasure and grievance redressal.
Section 12 permits a Data Principal to seek correction and completion of personal data that is inaccurate or misleading. This is important where the underlying information itself is wrong. However, it does not expressly provide a separate mechanism for challenging an inference generated from accurate information.
This distinction is central to the issue. A person’s financial records may be completely accurate while an algorithm wrongly classifies that person as a high credit risk. Likewise, an individual’s employment history may be accurate while an automated system incorrectly concludes that the person is unsuitable for a particular role. Correcting the underlying information would not necessarily address the resulting harm.
Section 8 also requires a Data Fiduciary to ensure that personal data is complete, accurate and consistent where it is likely to be used to make a decision affecting the Data Principal. This strengthens the quality of data used in decision making but does not expressly require the resulting inference to be accurate, reasonable or contestable.
The Act also provides access and grievance redressal rights. Nevertheless, it does not expressly recognise a standalone right to challenge an algorithmic score, classification or prediction.
The Digital Personal Data Protection Rules, 2025
The Digital Personal Data Protection Rules, 2025 provide the procedural framework for implementing the Act. They address matters including notices, consent, security safeguards, breach-related obligations and grievance redressal.
The Rules add operational detail to the Act but do not expressly introduce a substantive right to challenge an algorithmically generated inference or profiling outcome. The framework therefore remains focused principally on personal data rather than the conclusions generated from it.
The Information Technology Act, 2000
The Information Technology Act, 2000 remains relevant to India’s broader digital regulatory framework. Section 43A and the Information Technology Rules, 2011 address liability concerning negligent handling of certain personal information.
Its relevance to algorithmic inference is indirect. The framework concerns information security and negligent handling rather than whether an algorithmic conclusion drawn from accurate information is fair, reliable or valid. It therefore does not fill the specific gap identified in this article.
The Emerging Legal Gap
The existing framework creates a distinction between regulation of personal data and regulation of conclusions generated from personal data.
Article 21 protects privacy, dignity and informational autonomy. Article 14 may address arbitrary State action. The DPDP Act provides rights concerning personal data, while the DPDP Rules provide procedural safeguards. The Information Technology Act addresses certain aspects of data security.
What remains comparatively underdeveloped is the inferential stage. At this stage, accurate information is transformed into a score, classification, prediction or other conclusion that may materially affect an individual’s opportunities.
The problem can therefore be expressed simply:
The data may be accurate. The inference may nevertheless be wrong. The resulting decision may cause serious harm.
Indian law does not presently provide an express, standalone and comprehensive statutory mechanism specifically directed towards challenging such an inference, particularly where the decision is made by a private entity.
This does not mean that individuals have no legal remedies. Constitutional principles, data protection rights and sector-specific laws may provide protection in particular situations. The narrower point is that these mechanisms do not specifically address the problem of a materially inaccurate or harmful inference generated from otherwise accurate personal data.
Case Laws
1. Justice K.S. Puttaswamy (Retd.) v. Union of India
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, is the constitutional starting point for informational privacy in India. The nine-judge Bench recognised privacy as a fundamental right connected with liberty, dignity and autonomy under Article 21 and held that interference with privacy must satisfy constitutional requirements including legality and proportionality.
Its relevance to algorithmic inference lies in the protection of informational autonomy. Modern systems can combine personal information and generate conclusions about individuals. However, Puttaswamy did not consider algorithmic profiling or automated decision making and therefore does not establish an existing general right against algorithmic prediction.
2. OQ v. Land Hessen (SCHUFA Holding AG)
In OQ v. Land Hessen (SCHUFA Holding AG), Case C-634/21, the CJEU considered an automated creditworthiness score generated by SCHUFA. The issue was whether such a probability value could fall within Article 22 GDPR where it was relied upon by a third party in making a significant decision.
The decision is significant because it demonstrates that an algorithmically generated score may itself become legally relevant when it decisively influences a consequential decision. SCHUFA is not binding in India, but provides useful comparative support for regulating the inferential stage rather than only the final decision.
3. Maximilian Schrems v. Meta Platforms Ireland Ltd.
In Maximilian Schrems v. Meta Platforms Ireland Ltd., Case C-446/21, the CJEU considered the processing of personal data in the context of personalised advertising, including information concerning sexual orientation. The Court examined principles including purpose limitation, data minimisation and protection of sensitive personal data.
The case illustrates the risks of combining information from different sources to construct profiles or infer sensitive characteristics. It supports stronger safeguards around sensitive profiling, but does not establish a general right to challenge every algorithmic inference.
4. Meta Platforms Inc. v. Bundeskartellamt
In Meta Platforms Inc. v. Bundeskartellamt, Case C-252/21, the CJEU considered the combination of data for personalised advertising and the interaction between data protection and competition law.
The decision demonstrates that large-scale data aggregation and profiling can have regulatory consequences beyond traditional data protection. Its principal contribution, however, concerns the interaction between competition law and data protection rather than an individual’s direct right to challenge an algorithmic prediction.
Comparative Significance
Taken together, these decisions illustrate different dimensions of the problem. Puttaswamy provides the constitutional foundation of privacy and informational autonomy; SCHUFA demonstrates the legal significance of automated scoring; Schrems highlights risks associated with inferred sensitive characteristics; and Meta Platforms demonstrates the wider regulatory significance of profiling.
None establishes a general right not to be predicted. Their value for this article is comparative: they demonstrate that legal regulation may need to address not only personal data itself, but also consequential conclusions generated from it.
Possible Legal Solution
India should consider introducing a limited, risk-based Right to Contest an Inference for high-impact algorithmic decision making. It should apply where an automated or algorithmically assisted inference materially affects areas such as credit, employment, insurance, healthcare or education.
The framework should provide three core protections. First, individuals should be informed when a consequential decision materially relies on an automated inference. Second, they should receive meaningful information about the principal factors behind that inference without requiring disclosure of proprietary source code. Third, they should have an opportunity to contest a materially inaccurate inference and obtain meaningful human review.
Additional safeguards may apply where an inference concerns sensitive characteristics or creates a serious risk of discrimination. Low-risk personalisation, such as ordinary shopping recommendations or content ranking, should ordinarily remain outside the framework.
This proposal is a legal reform, not an existing statutory right. Its purpose is not to prohibit algorithmic prediction, but to ensure accountability where automated conclusions materially affect individual rights or opportunities.
Conclusion
Indian privacy law has established important foundations through Puttaswamy and the DPDP Act, but its principal focus remains the collection, processing, protection and correction of personal data rather than the conclusions generated from that data.
Algorithmic systems increasingly classify and evaluate individuals. A person’s data may be accurate while the resulting inference is materially wrong. Where that inference affects employment, credit, insurance, healthcare or education, correcting the underlying data may not provide a meaningful remedy.
The comparative experience of the CJEU, particularly SCHUFA on automated credit scoring, together with Schremson sensitive-data profiling and Meta Platforms on large-scale data aggregation, demonstrates that algorithmic scoring and profiling can raise legal concerns beyond the accuracy of the underlying data.
India need not adopt the European framework wholesale. Instead, it should consider a narrowly tailored Right to Contest an Inference for high-impact situations. The future of Indian data protection law should therefore address not only what is collected and stored, but also what is inferred from it.
FAQ
Q1. Does the DPDP Act, 2023 already give Indians a right to challenge algorithmic decisions?
Not expressly. The Act provides rights relating to personal data, including access, correction, erasure and grievance redressal. It does not establish a standalone right to challenge an algorithmic inference where the underlying data is accurate.
Q2. Does Puttaswamy create a right against algorithmic profiling?
No. Puttaswamy recognises privacy, dignity and informational autonomy as constitutional values, but did not specifically decide the legality of algorithmic profiling or establish a right to contest automated inferences.
Q3. Do the CJEU decisions apply directly in India?
No. They are comparative jurisprudence and are not binding on Indian courts. They are relevant because they demonstrate possible approaches to automated scoring, profiling and data aggregation.
Q4. Would the proposed Right to Contest an Inference apply to all automated recommendations?
No. The proposal is risk-based and is intended mainly for high-impact decisions involving areas such as credit, employment, insurance, healthcare and education. Low-stakes personalisation would generally remain outside its scope.
Q5. Is the proposed Right to Contest an Inference already available under Indian law?
No. It is proposed as a legal reform and is not presented as an existing statutory right.
References
1. Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1.
2. Digital Personal Data Protection Act, 2023, Act No. 22 of 2023, Government of India.
3. Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, Government of India.
4. Information Technology Act, 2000, particularly Section 43A, and the Information Technology Rules, 2011.
5. OQ v. Land Hessen (SCHUFA Holding AG), Case C-634/21, Court of Justice of the European Union, judgment dated 7 December 2023.
6. Maximilian Schrems v. Meta Platforms Ireland Ltd., Case C-446/21, Court of Justice of the European Union, judgment dated 4 October 2024.
7. Meta Platforms Inc. and Others v. Bundeskartellamt, Case C-252/21, Court of Justice of the European Union, judgment dated 4 July 2023.
8. Regulation (EU) 2016/679, General Data Protection Regulation, particularly Articles 5, 9 and 22.
