Legal News
12 July 2026
IP & Technology

The DPDP Era Begins: RTI in the Crosshairs and the Government’s Risky "Shoehorn" Approach to AI Governance

For Indian technology and IP practitioners, July 2026 will be remembered as the month the theoretical finally gave way to the operational—and the litigious. Over two years after receiving presidential assent, the Centre has finally notified the admin...

For Indian technology and IP practitioners, July 2026 will be remembered as the month the theoretical finally gave way to the operational—and the litigious. Over two years after receiving presidential assent, the Centre has finally notified the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023. But while corporate counsels scramble to overhaul their clients' consent architectures, a far more profound constitutional battle is brewing at the Supreme Court: the existential collision between data privacy and the Right to Information.

The DPDP Act vs. The RTI Act: Transparency on Trial

In April 2026, the Supreme Court issued notice to the Union Government on pleas challenging Section 44(3) of the DPDP Act. For litigators and activists who rely on the RTI Act to unearth public corruption, this provision is nothing short of disastrous.

Before the DPDP Act, Section 8(1)(j) of the RTI Act, 2005 exempted personal information from disclosure unless the Public Information Officer (PIO) was satisfied that the larger public interest justified the disclosure. Section 44(3) of the DPDP Act surgically removes this public interest caveat, replacing it with an almost absolute embargo on disclosing personal information.

"We are witnessing the weaponization of privacy to shield bureaucratic opacity. By refusing to stay the operation of the DPDP Act while referring the matter to a larger bench, the Supreme Court has effectively handed government departments a statutory shield to reject virtually any RTI request that tangentially involves an individual."

Practice Note: For lawyers advising clients on administrative law or filing writ petitions for mandamus to compel disclosure, expect immediate, blanket rejections from PIOs citing the amended Section 8(1)(j). Until the larger bench rules, you will need to creatively argue that the requested data does not qualify as "personal data" under Section 2(t) of the DPDP Act, rather than relying on the traditional public interest exception.

Consent Governance: The End of "Clickwrap" Complacency

The newly notified Digital Personal Data Protection Rules, 2025/2026 leave no room for ambiguity: the era of burying broad data-harvesting permissions in 50-page Terms of Service is over. The rules dictate that consent must be free, specific, informed, unconditional, and unambiguous.

More critically for Data Fiduciaries, the rules mandate that the withdrawal of consent must be as frictionless as providing it. Upon withdrawal, Data Fiduciaries must erase the data unless retention is explicitly mandated by another law (such as PMLA or taxation statutes).

Practice Note: Corporate and tech lawyers must immediately audit their clients' UI/UX flows. If your client requires a user to navigate through five sub-menus or send an email to a grievance officer to withdraw consent, they are in direct violation of the DPDP Rules. Data minimization is now a strict liability issue.

The "Jugaad" Approach to AI: Retrofitting IT and IP Laws

The most revealing policy posture of 2026 came from MeitY Secretary S. Krishnan, who confirmed the government will not introduce a bespoke Artificial Intelligence Act. Instead, India will govern AI by retrofitting the existing DPDP Act and Intellectual Property frameworks. This "shoehorn" approach is a massive gamble, but it opens lucrative avenues for IP litigators.

We are already seeing this play out in two areas:

1. The IT Rules (Amendment) 2026: In February, the Centre amended the IT (Intermediary Guidelines) Rules, 2021. Social media platforms must now incorporate technical verification measures and label AI-generated content (like deepfakes). Crucially, the language shifted from a directory “endeavour to deploy” to a mandatory “shall.” For law firms representing intermediaries, this is a red alert. Failing to deploy these technical measures will likely strip platforms of their safe harbor protection under Section 79 of the Information Technology Act, 2000, opening them up to primary liability for user-generated deepfakes.

2. DPIIT’s Overhaul of the Designs Act, 2000: To accommodate the AI and digital reality, the DPIIT’s January 2026 proposed amendments are a game-changer. The amendments finally extend statutory protection to virtual designs (GUIs, AR/VR interfaces, icons, and animations)—a long-standing demand of software companies.

From a litigation standpoint, the proposal to introduce statutory damages of up to ₹50 lakh for wilful infringement is monumental. Previously, proving actual damages in design infringement suits was a grueling evidentiary exercise that often resulted in paltry payouts. Statutory damages will force swift settlements. Furthermore, the shift to a "5+5+5" renewable term structure and the introduction of a 12-month grace period for novelty aligns India with global standards and forgives inventors who prematurely disclose their designs.

The Verdict for Practitioners

The regulatory ambiguity of the early 2020s has crystallized into hard law. The government's reliance on existing frameworks to regulate AI means tech lawyers can no longer operate in silos. A deepfake issue is now simultaneously an IT Act safe harbor issue, a DPDP Act personal data issue, and potentially a Copyright/Designs Act issue. As the Supreme Court weighs the balance between the DPDP and RTI Acts, practitioners must brace for a volatile year of compliance audits and high-stakes constitutional litigation.

Published by AnrakLegal AI