The DPDP Act is Finally Operational: A Shrinking Compliance Window, a Stealth AI Law, and a Constitutional Showdown over RTI
The Wait is Over, But the Chaos Has Just Begun For the past two years, Indian technology and corporate lawyers have been advising clients on the Digital Personal Data Protection (DPDP) Act, 2023, based on theoreticals. That era ended this week. With ...
The Wait is Over, But the Chaos Has Just Begun
For the past two years, Indian technology and corporate lawyers have been advising clients on the Digital Personal Data Protection (DPDP) Act, 2023, based on theoreticals. That era ended this week. With the Centre finally notifying the much-anticipated administrative rules, the DPDP Act has officially transitioned from the statute books to operational reality.
But if corporate boardrooms were hoping for a quiet, predictable rollout, they are in for a rude awakening. Between the Centre’s aggressive compliance posturing, a looming constitutional challenge at the Supreme Court over the Right to Information (RTI) Act, and the government’s backdoor strategy to use the DPDP Act to regulate Artificial Intelligence, practicing lawyers need to completely recalibrate their tech-law advisory.
The Compliance Crunch: Time is Shorter Than You Think
The notified rules outline a phased compliance timeline, reportedly stretching over 12 to 18 months, with a final hard stop around May 2027. However, the most critical takeaway for in-house counsels and tech advisors is the Centre’s recent signaling: the government is actively considering compressing this 18-month transition period for large companies.
The rationale? The Ministry of Electronics and Information Technology (MeitY) believes that large tech companies and Significant Data Fiduciaries (SDFs) are already complying with global standards like the GDPR, making a lengthy Indian runway unnecessary. This is a dangerous assumption by the government, but a reality lawyers must prepare for.
"Advising clients to wait out the 18-month window is now borderline malpractice. Data mapping, overhauling consent architectures, and establishing verifiable parental consent mechanisms for users under 18 must begin immediately."
For practitioners, the immediate mandate is clear. You must audit your clients' data collection touchpoints now. If your client qualifies as an SDF—based on data volume, sensitivity, or risk to electoral democracy—they will be the first targets of the Data Protection Board's enforcement sweep.
The Constitutional Showdown: Privacy vs. Transparency
While corporate lawyers scramble for compliance, litigators are watching the Supreme Court. In a massive development, the apex court has referred petitions challenging the DPDP Act’s amendments to the RTI Act to a larger bench, likely a Constitution Bench, citing serious constitutional questions.
At the heart of the dispute is Section 44(3) of the DPDP Act, which amends Section 8(1)(j) of the RTI Act, 2005. Previously, personal information could be exempted from RTI disclosure unless a Public Information Officer (PIO) determined that the larger public interest justified its release. Furthermore, the old RTI Act held a powerful proviso: information that cannot be denied to Parliament or a State Legislature cannot be denied to a citizen.
The DPDP Act obliterates this nuance. It introduces a blanket prohibition on disclosing personal information under the RTI Act, erasing the "public interest" exception entirely.
As a legal journalist, I must call a spade a spade: this is a dangerous overcorrection. While protecting personal data is a mandate under Article 21 (Right to Privacy) post-Puttaswamy, the RTI Act is anchored in Article 19(1)(a) (Freedom of Speech and Expression, which includes the right to know). By creating an absolute bar on the disclosure of personal data—which could include the assets of public servants or beneficiaries of state schemes—the DPDP Act severely defangs the transparency regime.
The Supreme Court correctly refused to stay the operation of the DPDP Act while hearing the matter—a stay would have thrown the entire digital economy into regulatory limbo. However, this impending Constitution Bench hearing will be the most significant privacy jurisprudence since Puttaswamy. Litigators representing civil society or media should prepare for a protracted battle over the doctrine of proportionality.
The De Facto AI Law: Regulating by Proxy
Perhaps the most fascinating strategic signal from the government this week is its stance on Artificial Intelligence. MeitY has stated it prefers utilizing existing legal frameworks rather than drafting a new, standalone AI statute. For tech lawyers, this means the DPDP Act and the Copyright Act, 1957, are now India’s de facto AI regulations.
What does this mean for practice?
If you are advising generative AI startups or foundation model builders, their web-scraping practices are now directly in the crosshairs of the DPDP Act. Training Large Language Models (LLMs) on datasets scraped from the Indian internet inevitably involves processing personal data. Under the new rules, unless the data principal has explicitly consented, or the data was voluntarily made public by the user themselves (a very narrow exception), scraping that data for AI training is a breach of the DPDP Act.
Coupled with potential infringement under Section 14 of the Copyright Act, the government is building an AI governance cage using the bars of existing IP and privacy laws. Lawyers must stop looking for a mythical "AI Act" and start applying the DPDP principles of purpose limitation and data minimization to algorithmic training.
The Bottom Line
The notification of the DPDP rules marks the end of the advisory honeymoon. The law is live, the compliance windows are shrinking, and the constitutional friction points are heading straight to the Supreme Court. For Indian lawyers, the transition from theoretical risk to hard litigation and aggressive regulatory enforcement begins today.
Tags
Published by AnrakLegal AI