Legal News
13 June 2026
IP & Technology

DPDP Rules Go Live: The Death of the RTI Balancing Test, the Compliance Scramble, and India’s AI ‘Jugaad’

The long-awaited operationalisation of the Digital Personal Data Protection (DPDP) Act, 2023 is finally upon us. With the Centre notifying the administrative rules in mid-2026, the grace period for India Inc. is effectively over. But while corporate ...

The long-awaited operationalisation of the Digital Personal Data Protection (DPDP) Act, 2023 is finally upon us. With the Centre notifying the administrative rules in mid-2026, the grace period for India Inc. is effectively over. But while corporate law firms are busy billing hours to map data flows, a far more consequential constitutional battle is brewing in the Supreme Court—one that threatens to permanently alter the landscape of transparency and public accountability in India.

For practicing lawyers, the developments of the past few months signal a tectonic shift across three distinct practice areas: corporate compliance, constitutional litigation, and intellectual property. Here is why the latest DPDP notifications and MeitY’s recent policy declarations demand your immediate attention.

The Corporate Scramble: Compress the Timeline, Increase the Panic

The 2025 DPDP Rules initially teased a staggered 18-month transition window. However, recent reports indicate the government is aggressively considering compressing this timeline for large companies and Significant Data Fiduciaries (SDFs). The Centre’s rationale? Large tech players are already compliant with the GDPR and global norms, so they shouldn't need a year and a half to fall in line domestically.

This is a dangerous assumption that corporate counsel must immediately address with their clients. The DPDP Act is not a mere copy-paste of the GDPR. The obligations around verifiable parental consent for minors, the absolute right to erasure, and the rigid framing of "Notice" under Section 5 require bespoke Indian compliance architectures.

"Assuming GDPR compliance automatically translates to DPDP compliance is a fundamental misstep. The Indian framework strips away 'legitimate interest' as a ground for processing, forcing companies to rely almost entirely on explicit consent or narrowly defined 'certain legitimate uses' under Section 7."

Practice Point: Stop waiting for the clock to run out. If you are advising Data Fiduciaries, immediate audits of legacy data are non-negotiable. Data Processing Agreements (DPAs) with third-party processors must be renegotiated yesterday to include strict indemnity clauses, as the DPDP Act holds the Data Fiduciary solely liable for processor breaches.

The RTI Collision Course: Weaponizing Privacy Against Transparency

While tech lawyers deal with consent managers, litigators need to brace for a massive influx of Right to Information (RTI) denials. The Supreme Court has rightly referred the constitutional challenge against the DPDP Act’s amendment of the RTI Act to a larger Constitution Bench, though it frustratingly declined to stay the operation of the law in the interim.

The controversy strikes at the heart of Section 8(1)(j) of the RTI Act, 2005. Previously, personal information could be exempted from disclosure unless the Central Public Information Officer was satisfied that the larger public interest justified the disclosure. The DPDP Act brutally amputated this provision. The amendment replaces it with a blanket exemption for any information that "relates to personal data."

Let’s be direct: This is the weaponization of privacy to shield state machinery from accountability. By removing the public interest balancing test, the state has effectively created a legal black hole. Electoral rolls, beneficiary lists, bureaucratic accountability reports, and audit trail documents—all of which contain "personal data"—can now be summarily denied.

The Supreme Court will have to decide if this amendment violates Article 19(1)(a) (the right to know) under the guise of protecting Article 21 (the right to privacy). K.S. Puttaswamy v. Union of India established privacy as a fundamental right, but a nine-judge bench did not intend for it to be a cloak for state opacity. Until the Constitution Bench rules, writ courts across the country are going to be flooded with arbitrary RTI rejections. Litigators must prepare to argue proportionality and the doctrine of harmonious construction to pry information loose from reluctant Public Information Officers.

AI Governance: Regulating by Patchwork

Perhaps the most baffling development is the Ministry of Electronics and Information Technology (MeitY) officially declaring that India will not draft a bespoke Artificial Intelligence law. Instead, the Secretary noted that the government views the DPDP Act, coupled with existing Intellectual Property laws, as sufficient to govern the AI explosion.

This is regulatory jugaad at its finest, and it leaves IP and tech lawyers navigating a minefield blindfolded. Relying on the DPDP Act to govern AI only addresses the data-scraping privacy violations (i.e., using personal data to train Large Language Models). It does absolutely nothing to address the algorithmic bias, deepfakes, or the monumental copyright crisis triggered by Generative AI.

Under the Copyright Act, 1957, Section 2(d)(vi) defines the author of a computer-generated work as "the person who causes the work to be created." When this was drafted, "computer-generated" meant a human using software as a tool. Applying this to autonomous Gen-AI outputs where a user types a three-word prompt is legally incoherent. Furthermore, who owns the copyright when an AI hallucinates or infringes on an existing artist's style? The doctrine of fair dealing under Section 52 was never designed to cover mass, automated ingestion of copyrighted works for commercial LLM training.

The takeaway for IP practitioners: Because the legislature has abdicated its responsibility to draft an AI-specific statute, the burden will fall entirely on the judiciary. You must be prepared to litigate matters of first impression. Expect heavy reliance on interim injunctions and John Doe orders to protect creators, while tech clients will need aggressive defense strategies built around transformative use and the very narrow 'publicly available data' exemptions.

The operationalisation of the DPDP Act is not just a compliance milestone; it is the catalyst for a decade of intense constitutional and commercial litigation. Lawyers who treat this merely as a "privacy" issue will miss the forest for the trees.

Published by AnrakLegal AI