The Death of the Passive Intermediary: Delhi HC Mandates Proactive Domain Blocking as DPDP and IT Rules Tighten the Noose
The Era of "Safe Harbor" is Effectively Over For years, Indian IP litigators have banged their heads against the same digital wall: a client’s trademark is hijacked by a fraudulent domain, you file a routine Ashok Kumar (John Doe) suit, and the Domai...
The Era of "Safe Harbor" is Effectively Over
For years, Indian IP litigators have banged their heads against the same digital wall: a client’s trademark is hijacked by a fraudulent domain, you file a routine Ashok Kumar (John Doe) suit, and the Domain Name Registrar (DNR) hides behind privacy shields and the Section 79 safe harbor of the Information Technology Act, 2000. By the time you get a court order, the cyber-squatter has vanished, and three new domains have sprouted in their place.
Make no mistake—the Delhi High Court’s latest ruling in Dabur India Ltd. v. Ashok Kumar (decided December 2025, reported March 2026) has fundamentally altered this landscape. When read alongside the accelerated rollout of the Digital Personal Data Protection (DPDP) Act and the draconian new 3-hour takedown windows under the amended IT Rules, a clear, unified judicial and legislative trend emerges for 2026: Intermediaries are no longer mere pipelines; they are now mandatory gatekeepers.
Dabur India: Proactive Blocking and the CGPDTM Masterlist
In Dabur, the Delhi High Court tackled the menace of fraudulent domains used for phishing, impersonation, and selling counterfeit goods. But rather than just issuing another reactive dynamic injunction, the Court did something unprecedented. It directed DNRs to proactively protect well-known marks.
How? By forcing registrars to check new domain applications against the Controller General of Patents, Designs and Trade Marks (CGPDTM) list of well-known trademarks. DNRs are now expected to place these marks on blocked or reserved lists, stopping fraudulent registrations before they go live.
"This is a seismic shift in trademark enforcement practice. The burden of policing has historically rested entirely on the brand owner. By mandating DNRs to cross-reference the CGPDTM registry, the Delhi High Court is effectively forcing private tech infrastructure to integrate with state IP databases."
Practice Note for IP Lawyers: If your client’s mark is not on the CGPDTM well-known list, get it there immediately. The value of achieving "well-known" status under Section 11(6) of the Trade Marks Act, 1999 has just skyrocketed. It is no longer just a defensive shield in litigation; it is an automated, court-mandated block list across all compliant domain registrars.
Piercing the Privacy Veil: DPDP Act vs. IP Rights
The second, arguably more critical development in Dabur addresses the collision between IP enforcement and data privacy. For years, DNRs have used privacy proxy services or cited international data protection laws to refuse disclosure of registrant details. With India's DPDP Act coming into operational force, there was a legitimate fear among litigators that the Act would become the ultimate shield for cyber-squatters.
The Delhi High Court nipped this in the bud. The Court held that DNRs and registry operators have a mandatory obligation to disclose registrant details when a party demonstrates a "legitimate interest." The Court expressly noted that such disclosures are governed by the DPDP Act—meaning that the enforcement of legal rights (and the prevention of fraud) constitutes a valid ground for processing and disclosing personal data without the data principal's consent.
This is a massive relief for civil practitioners. It clarifies that the DPDP Act is not a blanket veto against civil discovery or IP enforcement. When you draft your next cease-and-desist or interim injunction application, you must explicitly plead "legitimate interest" and cite the Dabur precedent to bypass the DNR's inevitable DPDP objections.
The 3-Hour Synthetic Content Takedown Nightmare
While IP lawyers are celebrating Dabur, technology and compliance lawyers are facing an operational nightmare. According to the latest 2026 analyses of the amended IT Rules, India has drastically lowered the takedown threshold for synthetically generated information (deepfakes and AI-generated misinformation).
Intermediaries are now required to respond to notices regarding such content within a staggering 3 hours. This is a massive departure from the traditional 36-hour or 72-hour windows.
This timeline is, quite frankly, absurd for any platform lacking enterprise-grade, automated content moderation AI. The legal friction is palpable. Industry bodies like the Broadband India Forum (BIF) and ICEA are already pushing back against the government's refusal to stagger the DPDP compliance timelines. When you combine a compressed DPDP rollout—where "consent" is now treated as a strict governance mechanism requiring provable notice and lawful tracking—with a 3-hour AI takedown rule, you are looking at a recipe for massive, uneven compliance across the digital ecosystem.
The Bottom Line for Your Practice
The legal scaffolding of the Indian internet is being rewired in real-time. What should practitioners do this week?
- For IP Litigators: Update your standard John Doe domain-squatting pleadings. Stop asking for just dynamic injunctions; demand proactive blocking based on the CGPDTM list. Cite Dabur to force DNRs to unmask proxy registrants under the "legitimate interest" exception of the DPDP Act.
- For Tech/Corporate Lawyers: Advise your intermediary and data-fiduciary clients that privacy and content moderation can no longer be handled by a side-desk. If your client relies on AI-generated content or hosts user-generated media, their incident-response protocol must be capable of processing takedowns in 3 hours. Furthermore, audit their DPDP consent mechanisms—if they treat consent as a mere "checkbox" rather than a strict, auditable governance flow, they are walking into a regulatory buzzsaw.
The courts and the Ministry of Electronics and Information Technology (MeitY) have spoken: the days of "we are just a platform" are over. Govern your clients accordingly.
Tags
Published by AnrakLegal AI