Legal News
1 June 2026
IP & Technology

Piercing the Privacy Shield: How the Delhi High Court Rescued IP Litigation from the DPDP Act

The Collision of IP Law and Data Privacy For the past year, Indian intellectual property litigators have been staring down the barrel of a data privacy nightmare. As the Digital Personal Data Protection (DPDP) Act framework gained momentum, Domain Na...

The Collision of IP Law and Data Privacy

For the past year, Indian intellectual property litigators have been staring down the barrel of a data privacy nightmare. As the Digital Personal Data Protection (DPDP) Act framework gained momentum, Domain Name Registrars (DNRs) and intermediaries began using "data privacy" as a convenient shield to block the disclosure of infringer identities. The traditional Ashok Kumar (John Doe) suit was suddenly at risk of being defanged by privacy compliance.

But in a watershed moment for Indian tech-law practice, the Delhi High Court’s March 2026 publication of its decision in Dabur India Ltd. v. Ashok Kumar has definitively resolved the tension between trade mark enforcement and data protection. If you are practicing in the IP or technology space today, this judgment fundamentally alters your litigation strategy.

Dabur v. Ashok Kumar: "Legitimate Interest" Trumps Cybersquatting

In Dabur, the Delhi High Court confronted an epidemic of domain-name fraud targeting well-known marks under Section 2(1)(zg) of the Trade Marks Act, 1999. Fraudsters were registering lookalike domains, running scams, and hiding behind the anonymity provided by registrars citing data-protection obligations.

The Court took a decisive, pro-enforcement stance. It ruled that requests by IP owners and law enforcement to unmask cyber-fraudsters constitute a legitimate interest under the DPDP framework. Crucially, the Court didn't just say DNRs may disclose this data—it stated they have a mandatory obligation to do so.

"Disclosure of registrant data in cases of intellectual property infringement and cyber-fraud is not a breach of data privacy, but a mandatory obligation born of legitimate interest."

Why this matters for your practice: When you are drafting an application under Order XXXIX Rules 1 and 2 of the CPC for an ex-parte ad interim injunction against an unknown cybersquatter, you no longer have to cross your fingers hoping the DNR will comply with a disclosure directive. You must actively cite Dabur and Section 7 (Certain legitimate uses) of the DPDP Act to pre-empt any privacy-based pushback from the registrar. Furthermore, the Court has directed DNRs to implement proactive technical measures to block fraudulent registrations of well-known marks. This shifts the burden—slightly, but significantly—from the rights holder to the intermediary.

The 3-Hour Squeeze: 2026 IT Rules Amendments

While the Delhi High Court is forcing platforms to hand over data, the executive branch is forcing them to act with breakneck speed. The newly notified 2026 amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules have drastically accelerated the takedown clock, specifically targeting AI-generated content and deepfakes.

The amendment reduces the intermediary takedown timeline from the standard 72 hours down to an aggressive 3 hours for specific categories of notices. It also elevates certain tech-based verification measures from being merely directory to mandatory.

This is a double-edged sword for practitioners. For lawyers representing brands or individuals targeted by AI-generated defamation or IP infringement, the 3-hour window is a massive tactical advantage. However, if you are advising intermediaries, hosting providers, or tech startups, this timeline is a logistical nightmare. The safe harbour protection under Section 79 of the IT Act is now hanging by a very thin, 180-minute thread.

The DPDP Compliance Reality Check

The aggressive posture of both the judiciary and MeitY is creating severe friction in the market. Industry bodies like the Broadband India Forum (BIF) and the India Cellular and Electronics Association (ICEA) have formally petitioned MeitY in April 2026 to halt the fast-tracked DPDP rollout, warning of uneven compliance across the digital ecosystem.

Their panic is justified when you look at the newly crystallized DPDP Rules, 2025. Legal commentary this month correctly identifies that consent has shifted from a mere checkbox to a heavy governance obligation. Consent must be free, specific, informed, unconditional, and unambiguous. More importantly, the DPDP Rules 2025 place the absolute burden of proof on the Data Fiduciary to demonstrate valid notice and lawful consent if disputed by a Data Principal.

For corporate lawyers, the days of copy-pasting standard privacy policies are over. If a client's withdrawal mechanism isn't as seamless as their onboarding mechanism, they are in breach. The integration of "Physical AI" (like domestic robots and smart home devices) is already triggering alarms about data spills, proving that India's privacy infrastructure is being tested at the bleeding edge of technology.

The Era of the "Siloed" Lawyer is Over

We are seeing top-tier law firms rapidly restructure their IP practices to absorb AI, technology, and data protection mandates. The reason is simple: you cannot advise a client on a trade mark infringement today without navigating intermediary liability under the IT Act and data disclosure obligations under the DPDP Act.

The Dabur ruling is a massive victory for rights holders, proving that the DPDP Act will not be allowed to become a haven for digital counterfeiters. But with 3-hour takedown windows and shifting burdens of proof on data consent, the margin for error in Indian tech law has never been narrower. Adapt your practice accordingly, or risk being left behind.

Published by AnrakLegal AI