Legal News
18 July 2026
IP & Technology

The DPDP Act Paradox: Killing the RTI While Moonlighting as India’s Default AI Law

For Indian technology and public law practitioners, the landscape of digital governance has fundamentally shifted as of July 2026. The Digital Personal Data Protection (DPDP) Act, 2023 is no longer just a looming compliance hurdle—it is fully operati...

For Indian technology and public law practitioners, the landscape of digital governance has fundamentally shifted as of July 2026. The Digital Personal Data Protection (DPDP) Act, 2023 is no longer just a looming compliance hurdle—it is fully operational, administratively weaponized, and currently at the center of a massive constitutional showdown at the Supreme Court. But more surprisingly, the government has decided to force-fit this privacy legislation into a completely different role: India’s de facto Artificial Intelligence law.

If you are advising tech platforms, media houses, or digital enterprises, you are currently navigating a schizophrenic regulatory regime. Here is an analytical breakdown of why the government’s reliance on the DPDP Act changes your daily practice, and why the Supreme Court’s recent intervention could rewrite public transparency.

The Constitutional Collision: DPDP vs. RTI

In February 2026, the Supreme Court referred petitions challenging the DPDP Act’s amendment to the Right to Information (RTI) Act, 2005 to a larger bench. The petitioners, including the NCPRI and The Reporters’ Collective, have hit the nail on the head regarding a legislative sleight of hand that fundamentally alters Indian administrative law.

Prior to the DPDP Act, Section 8(1)(j) of the RTI Act provided a nuanced exemption for personal information. It stated that personal information would not be disclosed unless the Public Information Officer (PIO) was satisfied that the larger public interest justified the disclosure. It was a statutory embodiment of the proportionality test laid down in Justice K.S. Puttaswamy v. Union of India.

Enter Section 44(3) of the DPDP Act. This provision amends Section 8(1)(j) to create a blanket exemption. It completely removes the "public interest" carve-out. Now, if information qualifies as "personal," it is absolutely exempt from RTI disclosure—no balancing test, no proportionality, no public interest exception.

"By removing the public interest caveat from the RTI Act, the DPDP Act effectively shields corrupt public officials from scrutiny by simply categorizing their asset declarations, administrative decisions, or disciplinary records as 'personal data'."

Practice Implication: Because the Supreme Court did not stay the operation of the DPDP Act pending the larger bench’s decision, this blanket exemption is currently the law of the land. For lawyers handling writ petitions under Article 226 or RTI appeals, your traditional strategy of arguing "larger public interest" before the Central Information Commission (CIC) is temporarily dead. You must now pivot to arguing that the requested information does not meet the strict definitional threshold of "personal data" under Section 2(t) of the DPDP Act in the first place.

The Lazy Regulatory Patchwork: AI Governance via DPDP

While the DPDP Act is busy dismantling the RTI Act, MeitY Secretary S. Krishnan recently confirmed that the government prefers to use the DPDP Act and existing Intellectual Property (IP) laws to govern Artificial Intelligence, actively avoiding a bespoke AI regulation.

This is bureaucratic convenience masquerading as regulatory innovation. Squeezing AI governance into the DPDP Act is like trying to fit a square peg into a round hole.

The DPDP Act governs personal data. However, the foundational models of Generative AI (like LLMs) are trained on vast oceans of non-personal, proprietary data, copyrighted code, and artistic works. When an AI scrapes a photographer's portfolio or a coder's GitHub repository, it is an IP infringement issue under Section 51 of the Copyright Act, 1957, not a privacy breach under the DPDP Act.

Practice Implication: For IP practitioners, you cannot rely on the DPDP Act to protect your clients' commercial data libraries from AI scraping. You must aggressively enforce copyright protections, utilizing the "fair dealing" exceptions tightly under Section 52 of the Copyright Act, and perhaps exploring the tort of passing off for AI-generated deepfakes of public personalities.

The IT Rules 2026 Amendment: The End of AI Safe Harbour

To patch the gaping holes left by relying solely on the DPDP Act for tech regulation, the government amended the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 in February 2026. The target? AI-generated content and deepfakes.

The amendment mandates that platforms shall verify and prominently label AI-generated content. Notice the use of the mandatory "shall" instead of "may." This drastically shifts the intermediary liability landscape under Section 79 of the Information Technology Act, 2000.

Previously, platforms could claim safe harbor immunity by acting as mere conduits and taking down content upon receiving actual knowledge (via a court order or government notification, as per Shreya Singhal v. Union of India). The 2026 amendment imposes a proactive duty on intermediaries to label synthetic information. Failure to do so strips them of their Section 79 safe harbor, exposing executives to direct criminal liability.

What You Need to Do Tomorrow

With the final DPDP Rules, 2025 now fully notified and operational, the era of regulatory transition is over. Here is what should be on your desk:

  • Consent Audits: The new administrative rules require consent notices to be brutally simple. If your client's Privacy Policy is a 40-page legalese labyrinth, they are in violation of the "clear and understandable" mandate of the new rules. Withdrawal of consent must literally be a one-click process.
  • AI Labeling Compliance: Advise all intermediary clients (social media, aggregators, forums) to immediately integrate AI-detection and labeling UI/UX to preserve their Section 79 safe harbor under the new IT Rules amendment.
  • RTI Strategy Shift: Warn your litigation clients that RTI applications seeking information on public servants or third parties will be summarily rejected under the amended Section 8(1)(j) until the Supreme Court larger bench rules otherwise.

The government has chosen its weapons for the next decade of digital regulation: a fiercely protective DPDP Act and heavily amended IT Rules. Make no mistake—the compliance burden has just shifted entirely onto the shoulders of the private sector, while the state has successfully shielded its own data from public view.

Published by AnrakLegal AI