Legal News
12 August 2026
IP & Technology

The DPDP Act is Swallowing Indian Tech Law: Why IP and Privacy Are Now the Same Practice Area

The Illusion of a Dedicated AI Law is Dead For the last three years, Indian tech lawyers and policy wonks have been holding their breath, waiting for a bespoke Artificial Intelligence Act to drop from the legislative heavens. It is time to exhale and...

The Illusion of a Dedicated AI Law is Dead

For the last three years, Indian tech lawyers and policy wonks have been holding their breath, waiting for a bespoke Artificial Intelligence Act to drop from the legislative heavens. It is time to exhale and face reality. The Union Government has made its 2026 playbook abundantly clear: there will be no standalone AI statute unless absolutely necessary. Instead, the Ministry of Electronics and Information Technology (MeitY) is weaponizing existing frameworks. If you are advising tech clients, creators, or platforms today, the Digital Personal Data Protection (DPDP) Act, 2023, and the amended Information Technology (Intermediary Guidelines) Rules are your de facto AI laws.

What we are witnessing is a massive jurisprudential convergence. The DPDP Act is no longer operating as a siloed privacy statute. As recent developments in the Supreme Court and Delhi High Court demonstrate, it has mutated into the apex predator of Indian tech regulation—eating into copyright disputes, algorithmic governance, and even the Right to Information (RTI) regime.

The Supreme Court Flexes the DPDP Act: APAAR and RTI

If you thought the DPDP Act would be a paper tiger pending the full operationalization of the Data Protection Board, the Supreme Court's August 2026 directive on the APAAR (Automated Permanent Academic Account Registry) scheme should serve as a wake-up call. Dealing with the mass collection of student data, the Court mandated that APAAR consent forms must include a clear opt-out option, expressly subjecting the state's data collection and retention practices to DPDP scrutiny.

This is a critical shift for practitioners. The Court is strictly interpreting the consent architecture under Section 6 of the DPDP Act, demanding that consent be free, specific, informed, unconditional, and unambiguous. For law firms advising EdTech or health-tech data fiduciaries, the era of bundled, "take-it-or-leave-it" terms of service is effectively over. If withdrawal of consent is not as frictionless as granting it, your client is staring at massive penal liabilities.

"The judicial message in 2026 is clear: the state and private actors alike cannot use public utility as a shield against DPDP compliance. Proportionality and informed consent are now non-negotiable prerequisites for data processing."

Equally consequential is the Supreme Court's February 2026 decision regarding the DPDP Act's controversial amendment to the Right to Information Act, 2005. By virtue of Section 44(3) of the DPDP Act, Section 8(1)(j) of the RTI Act was amended to exempt all personal information from disclosure, deleting the public interest caveat. While the Supreme Court referred the constitutional challenge to a larger bench, it crucially refused to stay the operation of the Act. For litigators, this means the RTI route for investigative discovery involving public servants or state beneficiaries remains severely bottlenecked for the foreseeable future.

Copyright v. AI: The DPDP Overlap

Perhaps the most fascinating evolution for intellectual property lawyers is how AI training disputes are being forced into the data protection matrix. Take the ongoing Delhi High Court litigation in ANI v. OpenAI. While historically this would be pleaded purely under Section 14 (exclusive rights) and Section 52 (fair dealing) of the Copyright Act, 1957, the strategy is evolving.

When an LLM scrapes the Indian internet for training data, it isn't just ingesting copyrighted text; it is ingesting vast quantities of personal data. Under the DPDP Act, scraping personal data without explicit notice (Section 5) and consent (Section 6) is a direct violation, regardless of whether the text was publicly available. IP lawyers can no longer litigate AI infringement in a vacuum. To successfully injunct AI platforms, practitioners must now plead copyright infringement concurrently with DPDP violations and IT Rule breaches.

Furthermore, the recent amendments to the IT Intermediary Rules have introduced a draconian regime for synthetically generated information (deepfakes and AI hallucinations). Intermediaries are now subject to aggressively compressed takedown timelines. If your client is a platform hosting generative AI outputs, the safe harbour protection under Section 79 of the IT Act is hanging by a thread. The burden has shifted from reactive takedowns to proactive algorithmic hygiene.

What This Means for Legal Practice in 2026

The siloing of legal departments is obsolete. You cannot have an "IP team" handling copyright and a separate "Privacy team" handling DPDP compliance when advising an AI startup. The regulatory cluster is now unified. Here is what practicing lawyers need to change today:

1. Redrafting Consent Architectures: Audit your clients' UI/UX. Dark patterns that obscure the opt-out mechanism are now direct violations of the DPDP Act, as affirmed by recent Supreme Court observations on the APAAR scheme.

2. Rethinking Data Scraping: If you are advising AI developers, relying on "fair dealing" under the Copyright Act will not save them from the Data Protection Board if their training datasets contain non-consensual personal data.

3. Intermediary Compliance: Platforms must update their grievance redressal mechanisms to specifically address synthetically generated content, or risk losing their safe harbour immunity entirely.

We are in a new era of tech jurisprudence. The government has decided that instead of passing an AI Act, it will stretch the DPDP Act and the IT Rules to govern the algorithmic future. Lawyers who fail to connect these dots will find themselves, and their clients, swiftly outmaneuvered.

Published by AnrakLegal AI