Schrödinger’s Privacy Law: DPDP Rules Drop Amid Constitutional Challenges and India’s ‘Patchwork’ AI Strategy
The End of the Waiting Game, The Beginning of the Compliance Nightmare After years of legislative limbo, the Centre has finally notified the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023. For technology and IP lawyers...
The End of the Waiting Game, The Beginning of the Compliance Nightmare
After years of legislative limbo, the Centre has finally notified the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023. For technology and IP lawyers, the theoretical debates are over; the era of enforcement has arrived. But the rollout is chaotic. While the government has indicated a phased transition—spanning 12 to 18 months, with full operationalisation tied to May 2027—recent reports suggest the Centre is actively considering compressing this timeline for large tech companies.
Here is the brutal reality for legal practitioners: you must now advise corporate clients to overhaul their entire data architecture—costing millions in compliance—under the looming shadow of a Supreme Court Constitution Bench that could still strike down key provisions of the statute.
AI Governance: The "Patchwork" Regulatory Strategy
Perhaps the most significant policy signal accompanying the DPDP Rules is the government’s stance on Artificial Intelligence. Officials have made it clear: India will not be getting a standalone Artificial Intelligence Act anytime soon. Instead, the Centre intends to govern AI through an interconnected web of the DPDP Act, the Information Technology Act, 2000, and existing Intellectual Property frameworks.
For the Bar, this means the days of siloed legal practice are officially dead. You can no longer draft a Terms of Service or a Privacy Policy for an AI startup in a vacuum.
To properly advise an AI-driven business today, a lawyer must simultaneously mitigate copyright infringement risks under the Copyright Act, 1957 (specifically regarding the use of training data and the limits of Section 52 fair dealing) while ensuring strict compliance with the newly notified DPDP rules on data collection, purpose limitation, and algorithmic processing.
The DPDP rules drastically raise the compliance bar for AI firms. Training Large Language Models (LLMs) requires scraping massive datasets, which invariably include personally identifiable information (PII). Under the new rules, AI companies must establish clear notice and consent mechanisms (Section 5 and 6 of the DPDP Act) before processing this data. The legal friction is obvious: how does a foundational model obtain granular consent for data scraped from the open web? The government's answer seems to be that it is the tech industry's legal headache to solve.
The Constitutional Cloud: RTI Act vs. DPDP Act
While compliance teams scramble, the Supreme Court has thrown a massive wrench into the works. Petitions challenging the DPDP Act and the 2025 Rules have been referred to a larger 5-judge bench. Though the Court declined to stay the operation of the law—creating a "Schrödinger’s Compliance" scenario where the law is both active and constitutionally suspect—it is zeroing in on the most controversial aspect of the DPDP Act: its intersection with the Right to Information (RTI) Act, 2005.
Section 44(3) of the DPDP Act introduces a devastating amendment to Section 8(1)(j) of the RTI Act. Previously, the RTI Act exempted personal information from disclosure unless a larger public interest justified it. The DPDP Act wipes out this public interest caveat, creating a blanket exemption for all "personal data."
This is where privacy is weaponized against transparency. As a legal practitioner, if you represent a government contractor, a public servant, or a corporation involved in a public-private partnership, the amended Section 8(1)(j) is a powerful shield against journalistic and civil society scrutiny. However, civil society argues this violates the fundamental right to information under Article 19(1)(a) of the Constitution. The Supreme Court is now tasked with defining the boundary between K.S. Puttaswamy v. Union of India (the right to privacy) and the democratic necessity of public data.
What This Means for Your Practice Today
Despite the constitutional challenge, general counsel and external advisors cannot afford to wait for the Supreme Court's final verdict. The lack of an interim stay means the DPDP rules are live. Here is how practice must pivot immediately:
1. Data Mapping is Non-Negotiable: You must force your clients to conduct immediate, comprehensive data mapping. If the government compresses the compliance timeline for Significant Data Fiduciaries (SDFs), large clients will have months, not years, to appoint Data Protection Officers (DPOs) and establish algorithmic impact assessments.
2. Redrafting AI Vendor Contracts: Standard boilerplate privacy indemnities will no longer suffice. Contracts with third-party AI vendors must now explicitly allocate liability for DPDP breach-reporting obligations and copyright infringement claims arising from AI training datasets.
3. Preparing for Consent Fatigue: The rules mandate verifiable consent mechanisms. Lawyers must work with UI/UX teams to ensure that "notice" is legally robust but practically executable, avoiding the trap of dark patterns which could attract regulatory penalties.
India’s technology law landscape has never been more volatile. The DPDP Act’s transition from a theoretical bill to an enforceable—albeit legally contested—regime marks a paradigm shift. For lawyers, the mandate is clear: prepare your clients for aggressive enforcement today, but keep a very close eye on the Supreme Court tomorrow.
Tags
Published by AnrakLegal AI