Legal News
31 August 2026
IP & Technology

The 2026 Tech Law Paradox: SC Greenlights DPDP Compliance Without a Regulator, While Delhi HC Blesses AI Scraping

The DPDP Compliance Clock is Ticking—Even if the Regulator is a Ghost Corporate India’s data compliance clock is officially ticking, and the Supreme Court has made it clear that constitutional challenges will not buy your clients any extra time. In a...

The DPDP Compliance Clock is Ticking—Even if the Regulator is a Ghost

Corporate India’s data compliance clock is officially ticking, and the Supreme Court has made it clear that constitutional challenges will not buy your clients any extra time. In a defining moment for Indian technology law this February 2026, the Supreme Court issued notice on writ petitions challenging key provisions of the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025. Crucially, while referring the matter to a larger bench, the Court was categorical: there will be no stay on the legislation.

For practicing corporate lawyers and in-house counsel, the takeaway is absolute. You can no longer advise clients to "wait and watch" the litigation. The monumental penalties—reaching up to ₹250 crore for data breaches and non-compliance—are now a live operational risk.

Yet, we are operating in a bizarre statutory vacuum. As of mid-2026, the Data Protection Board of India (DPBI) exists primarily on paper. It remains inadequately staffed, functioning without a permanent Chairperson and core Members. We have a draconian penalty mechanism hanging over the heads of Data Fiduciaries, but the very adjudicatory body meant to enforce it is a ghost. Advising clients in this environment requires extreme caution: build your consent architectures and data mapping protocols now, because when the Board is finally constituted, they will be looking for early scalps to establish authority.

Section 44(3) and the Death of RTI Transparency

The core of the Supreme Court challenge, spearheaded by The Reporters’ Collective and journalist Nitin Sethi, strikes at the heart of democratic accountability: Section 44(3) of the DPDP Act.

This provision fundamentally alters the Right to Information (RTI) Act, 2005. Historically, under Section 8(1)(j) of the RTI Act, Public Information Officers (PIOs) had a statutory duty to weigh privacy against the public interest. If the disclosure of personal data served a larger public interest (such as exposing corruption or administrative overreach), the PIO could mandate disclosure. Section 44(3) of the DPDP Act bulldozes this nuanced balancing act, amending the RTI Act to create a blanket exemption for all personal information.

"By removing the public interest override, the DPDP Act has effectively weaponized data privacy to shield bureaucratic accountability. Privacy is a fundamental right, but it cannot be an impenetrable cloak for the State."

The Supreme Court has rightly noted that this requires examining the global jurisprudence on the distinction between public data and private data. For litigators handling RTI appeals or writ petitions against state agencies, expect severe stonewalling from PIOs citing the DPDP Act. Your counter-strategy must now pivot to challenging the definition of "personal data" itself in the context of official public duties.

The APAAR Ruling: A Glimmer of Purpose Limitation

While the broader DPDP challenge plays out, the Supreme Court has already begun enforcing the Act’s core tenets. In a significant 2026 ruling regarding the APAAR Scheme (the government's student ID initiative), the Court explicitly held that student data collection and processing are squarely subject to the DPDP Act. The Court barred the sharing of student information with private entities and third parties without explicit legal backing and verifiable consent.

This is purpose limitation and data minimization in action. Education-tech companies and private institutions that previously treated student databases as monetizable assets must immediately restructure their data-sharing agreements. Relying on vague, bundled consent forms will no longer survive judicial scrutiny.

Delhi HC on AI and Copyright: Stretching "Fair Dealing" Too Far?

While privacy lawyers grapple with the DPDP Act, intellectual property practitioners have been handed a bombshell by the Delhi High Court. In a prima facie view concerning OpenAI’s unauthorized ingestion of ANI’s literary works to train its Large Language Models (LLMs), the Court suggested this storage and processing might fall under the "fair dealing" exception of Section 52(1)(a) of the Copyright Act, 1957.

This is a dangerous, albeit preliminary, precedent. Section 52(1)(a) protects fair dealing for the purpose of "private or personal use, including research."

Can the ingestion of terabytes of copyrighted news media by a multi-billion-dollar commercial entity to build a for-profit AI product genuinely be classified as "research"? This interpretation violently stretches the boundaries established in landmark cases like the DU Photocopy case (Chancellor, Masters & Scholars of the University of Oxford v. Rameshwari Photocopy Services). It conflates computational data mining with traditional academic research.

What this means for IP practice: You can no longer rely solely on Section 14 infringement claims to protect your clients' content from AI scraping. IP lawyers must aggressively pivot to contract law and cyber law. You need to draft airtight "No-Scraping" clauses in website Terms of Use, implement robust Technological Protection Measures (TPMs), and explore actions under the IT Act for unauthorized access. Until the legislature amends the Copyright Act to specifically address text and data mining (TDM), the courts are going to struggle to fit generative AI into a 1957 statutory framework.

2026 is proving to be a watershed year. The courts are actively rewriting the rules of data and content ownership. As practitioners, relying on the old playbooks will be professional malpractice. Adapt, or be left behind.

Published by AnrakLegal AI