No Stay from the Supreme Court: Why the DPDP Act is Now India's De Facto 'AI Law'
The waiting game for India’s technology and privacy counsel is officially over. With the Centre finally notifying the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023, the theoretical debates of the past three years must...
The waiting game for India’s technology and privacy counsel is officially over. With the Centre finally notifying the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023, the theoretical debates of the past three years must now translate into urgent compliance mandates. More importantly, the Supreme Court has made it abundantly clear: while the constitutional validity of the DPDP regime will be scrutinized by a five-judge Constitution Bench, there will be no interim stay on the Act or its Rules.
For practicing lawyers, the message is unequivocal. If you have been advising your corporate clients to adopt a "wait-and-watch" approach pending the Supreme Court's decision, you need to change your counsel today. The compliance clock is ticking, and the Ministry of Electronics and Information Technology (MeitY) is already signaling a compressed 12-to-18-month transition period for large Data Fiduciaries.
The Constitutional Cloud: DPDP vs. The RTI Act
The Supreme Court’s referral of the DPDP challenges to a larger bench primarily hinges on the controversial backdoor amendments made to the Right to Information (RTI) Act, 2005. Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act, fundamentally altering India's transparency landscape.
Previously, Section 8(1)(j) allowed Public Information Officers (PIOs) to disclose personal information if the larger public interest justified it. The DPDP Act entirely strips away this public-interest exemption. Any personal information is now entirely exempt from RTI disclosure.
"By removing the public interest override, the DPDP Act treats the privacy of public officials as absolute, effectively weaponizing privacy against transparency. But until the Constitution Bench says otherwise, this is the law of the land."
For litigators and activists dealing with writ petitions for information, this creates a massive statutory roadblock. But for corporate lawyers, the refusal of the Supreme Court to stay the DPDP rules means your clients cannot use the pending constitutional challenge as an excuse for non-compliance. You must proceed as if the Act, in its entirety, will survive judicial scrutiny.
The "AI Law" Illusion: DPDP and IP as the New Regulatory Matrix
Perhaps the most significant development for IP and technology lawyers isn't just the notification of the DPDP Rules, but MeitY’s definitive policy signal regarding Artificial Intelligence. The government has confirmed it will not rush to enact a standalone AI statute. Instead, AI regulation in India will be governed by a patchwork of the DPDP Act, existing Intellectual Property laws (primarily the Copyright Act, 1957), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
This is a seismic shift for technology advisory practice. It means the DPDP Act is now India’s de facto AI regulation. Here is why this matters for your practice immediately:
1. Training Data is a Consent Nightmare: If your client is developing LLMs or AI tools using scraped data containing personal identifiers, they are now subject to Section 6 of the DPDP Act. The concept of "legitimate use" under Section 7 is notoriously narrow in the Indian iteration of the law. Unless the data principal voluntarily provided the data for that specific purpose, scraping personal data for AI training without explicit, itemized consent is illegal.
2. The IP-AI Overlay: MeitY is relying on the Copyright Act to handle the proprietary aspects of AI training. For IP lawyers, the defense of "fair dealing" under Section 52(1)(a) of the Copyright Act is about to be stretch-tested in Indian courts. Does ingesting copyrighted works to train an AI model constitute fair dealing for "research," or is it commercial infringement under Section 14? We are going to see massive litigation on this front, and lawyers need to start auditing their clients' algorithmic training datasets immediately.
3. Synthetic Media and Intermediary Liability: The IT Rules amendments concerning synthetic media (deepfakes) place the onus squarely on platforms. When combined with the DPDP’s strict grievance redressal mechanisms, intermediaries are looking at a dual-compliance nightmare where a single deepfake violates both the IT Rules (misinformation/impersonation) and the DPDP Act (unauthorized processing of personal data).
What Should Lawyers Do Tomorrow?
The transition period of 12 to 18 months might seem generous, but government sources are already mulling a compressed timeline for large tech entities, citing their existing adherence to GDPR norms. This is a flawed assumption—the DPDP Act is remarkably different from the GDPR, completely lacking the "legitimate interest" basis for processing data.
For in-house counsel and law firm partners, your immediate action items are clear:
- Rewrite Data Processor Agreements: Under Section 8(1), Data Fiduciaries are strictly liable for their Data Processors. You need to amend every vendor contract to include back-to-back indemnity clauses for DPDP compliance.
- Audit AI Due Diligence: In M&A or tech-transfer transactions, you must now demand the provenance of AI training data. If the target company trained its model on non-consensual personal data, the IP is toxic and creates massive DPDP liability.
- Revamp Notice Frameworks: Section 5 mandates clear, multi-lingual notices before consent is obtained. The era of buried, 50-page privacy policies is over.
The Supreme Court has drawn the line in the sand. The DPDP Act is active, AI is firmly within its crosshairs, and ignorance of delegated legislation is no longer a viable defense. It is time for the Indian legal fraternity to stop waiting for clarity and start building compliance.
Tags
Published by AnrakLegal AI