Legal News
26 June 2026
IP & Technology

The DPDP Act Hits a Constitution Bench While Doubling as India's Defacto AI Law: What Tech Lawyers Need to Know Now

The Constitutional Showdown: Privacy vs. Transparency In a move that promises to define India’s digital jurisprudence for a generation, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) A...

The Constitutional Showdown: Privacy vs. Transparency

In a move that promises to define India’s digital jurisprudence for a generation, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023 to a 5-judge Constitution Bench. For tech and administrative lawyers, Monday's order by the bench comprising CJI Surya Kant and Justices Joymalya Bagchi and Vipul M. Pancholi is the clarion call we have been waiting for.

The core of the litigation, spearheaded by The Reporters' Collective and activist Nitin Sethi, zeroes in on how the DPDP Act quietly gutted the Right to Information (RTI) Act, 2005. By amending Section 8(1)(j) of the RTI Act, the DPDP framework effectively removed the "public interest" override. Previously, guided by precedents like Girish Ramchandra Deshpande v. CIC, Public Information Officers (PIOs) could disclose personal information if the larger public interest warranted it. Today, the DPDP Act provides a blanket exemption for anything containing "personal details."

"The State has weaponized privacy to shield itself from accountability. By removing the public interest safeguard, the DPDP Act transforms from a shield for the citizen into a fortress for the bureaucrat."

While the Court rightly acknowledged the vires of the Act as "serious and debatable," it crucially refused an interim stay. For practicing advocates and in-house counsel, the directive is clear: you cannot advise clients to pause their DPDP compliance while waiting for the Constitution Bench’s verdict. The law remains fully operational, and the regulatory clock is ticking.

The Government’s Stance: No Bespoke AI Law

While the Supreme Court scrutinizes the DPDP Act, the Ministry of Electronics and IT (MeitY) has dropped another bombshell for IP and tech practitioners. On Tuesday, IT Secretary S. Krishnan confirmed that India will not introduce a standalone Artificial Intelligence law. Instead, the government will rely on a patchwork of the DPDP Act, existing Intellectual Property (IP) laws (namely the Copyright Act, 1957 and Patents Act, 1970), and aggressively amended intermediary rules.

This "make-do" regulatory approach places an immense burden on technology lawyers. If you are advising an AI startup or a content platform, the legal landscape just became significantly more volatile. The government assumes that deepfakes, algorithmic bias, and data scraping can be neatly categorized under existing data breach and copyright infringement paradigms. But as any IP lawyer knows, applying the "fair dealing" exceptions of Section 52 of the Copyright Act to Large Language Model (LLM) training datasets is akin to fitting a square peg into a round hole.

The Draconian 3-Hour Takedown Window

The most immediate and aggressive shift in practice stems from the February 10, 2026 amendment to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules. Triggered by the proliferation of Synthetically Generated Information (SGI), the government has fundamentally altered the intermediary liability safe harbour under Section 79 of the IT Act.

Here is what changes for your clients immediately:

  • The 92% Time Compression: The response time for intermediaries to take down harmful AI-generated content has been slashed from 72 hours to a staggering 3 hours under Rule 3(b) and (d).
  • Mandatory Verification: The statutory language regarding user declarations has shifted from "endeavour to deploy" to an absolute "shall."

From a practical standpoint, a three-hour turnaround makes manual legal review impossible. Platforms will be forced to rely on automated, algorithmic takedowns to preserve their safe harbour status. Tech lawyers must immediately audit their clients' grievance redressal mechanisms. If your client is a social media intermediary, an ed-tech platform with user-generated content, or a digital publisher, failing to implement automated SGI flagging systems will result in immediate exposure to criminal liability.

Compliance Timelines: The Squeeze is On

With the DPDP Rules, 2025 officially notified this past November, the phased rollout is targeting full enforcement by May 13, 2027. Currently, an 18-month transition period is in place. However, MeitY is actively mulling the compression of this timeline for large data fiduciaries, arguing that multinational corporations already adhere to GDPR and similar global norms.

Corporate counsel cannot treat this as a standard compliance exercise. The era of drafting a generic privacy policy and calling it a day is entirely over. The industry—spanning fintechs, insurers, and chip startups preparing for the DLI 2.0 (Digital Literacy Initiative)—is being forced to "hardwire" privacy into their backend architecture.

The Takeaway for Practitioners:
We are witnessing a profound convergence of constitutional rights, intellectual property, and technology regulation. You must advise your corporate clients to accelerate their data mapping and consent-management systems immediately, ignoring the pending Supreme Court challenge. Simultaneously, tech counsel must overhaul intermediary compliance protocols to meet the brutal new 3-hour SGI takedown mandate. The legal framework may be a patchwork, but the penalties for failing to navigate it will be absolute.

Published by AnrakLegal AI