The Compliance Clock is Ticking: Supreme Court Refuses to Stay DPDP Act While Govt 'Frankensteins' AI Regulation
The End of the Waiting Game for Tech Lawyers For the better part of two years, a dangerous complacency had settled over India’s corporate legal departments. The prevailing wisdom was that the Digital Personal Data Protection (DPDP) Act, 2023, bogged ...
The End of the Waiting Game for Tech Lawyers
For the better part of two years, a dangerous complacency had settled over India’s corporate legal departments. The prevailing wisdom was that the Digital Personal Data Protection (DPDP) Act, 2023, bogged down by constitutional challenges and delayed rules, would be stayed by the Supreme Court. On February 16, 2026, the apex court shattered that illusion.
While the Supreme Court referred the constitutional challenges against the DPDP Act—specifically its controversial dilution of the Right to Information (RTI) Act—to a larger bench, it explicitly refused to stay the operation of the law. With the Centre recently notifying the administrative rules and the Data Protection Board (DPB) now fully operational as of August 2026, the message to practicing tech lawyers and in-house counsel is unambiguous: compliance is no longer sub judice; it is mandatory.
The Generative AI Loophole: Public vs. Private Data
Perhaps the most intellectually stimulating—and practically terrifying—development came on March 12, 2026, when the Supreme Court issued notice to examine the dividing line between public and private data under the new regime. This is not mere academic hair-splitting; it is the battleground upon which the future of artificial intelligence in India will be fought.
Under Section 3(c)(ii) of the DPDP Act, the law does not apply to personal data made publicly available by the Data Principal themselves. For AI developers, this provision has been treated as a golden ticket for web-scraping. If a user posts their resume on LinkedIn or a photo on Instagram, AI companies argue it is "public data" ripe for algorithmic harvesting to train Large Language Models (LLMs).
"The Supreme Court’s willingness to scrutinize the 'public data' exemption threatens to upend the foundational data-harvesting practices of generative AI companies operating in India."
As lawyers, you must advise clients that relying blindly on the Section 3(c) exemption is a high-risk strategy. If the Supreme Court interprets "publicly available" narrowly—for instance, ruling that data shared for social networking does not imply consent for commercial AI training—every AI model trained indiscriminately on Indian internet data could instantly become non-compliant. We are already seeing this intersection of IP and privacy play out, as copyright infringement (Section 14 of the Copyright Act) and data privacy violations bleed into a single cause of action against AI developers.
Legal Jugaad: Regulating AI through the IT Rules
If you were holding out for a bespoke, European-style AI Act in India, it is time to pivot. Recent statements from MeitY clearly indicate the government prefers using existing legal frameworks to govern AI, prioritizing innovation over stringent ex-ante regulation. Instead of a new statute, the government is relying on legal jugaad—patching the Information Technology Act, 2000.
The February 2026 amendments to the IT Rules specifically target synthetically generated information and deepfakes. What does this mean for intermediary practice? The Section 79 "safe harbour" is shrinking rapidly. Social media platforms and AI hosting services are now subject to highly aggressive, accelerated takedown timelines for deepfakes and AI-generated misinformation. If your firm represents intermediaries, your standard operating procedures for grievance officers need an immediate overhaul. The defense of "we are just a dumb pipe" is legally dead when it comes to AI content.
Consent as Governance: The APAAR Directive
Finally, we must look at the Supreme Court's August 2026 directive regarding the APAAR (Automated Permanent Academic Account Registry) scheme. The Court mandated that consent forms for student data collection must include an explicit opt-out option, strictly tying the scheme's data-sharing mechanisms to DPDP Act compliance.
This is a masterclass in how Section 6 of the DPDP Act will be interpreted by the judiciary. Consent must be free, specific, informed, unconditional, and unambiguous. The APAAR ruling signals the death knell for "dark patterns" and bundled consent. If your client’s privacy policy still forces users to accept data harvesting to access a primary service, it is a ticking regulatory time bomb. The DPB will undoubtedly rely on the APAAR precedent to strike down conditional consent architectures.
The Takeaway for Practitioners
The silos of Intellectual Property, Data Privacy, and Intermediary Liability have officially collapsed. You can no longer draft a Terms of Service agreement without simultaneously considering the DPDP Act's consent requirements, the IT Rules' deepfake takedown timelines, and the Copyright Act's fair dealing exemptions for AI training data.
The Data Protection Board is open for business. The Supreme Court has denied a stay. The grace period is over. It is time to audit your clients' data pipelines before the regulator does it for them.
Tags
Published by AnrakLegal AI