Legal News
19 June 2026
IP & Technology

The DPDP Rules Are Finally Here, But India’s ‘De Facto’ AI Law Faces a Constitutional Trial by Fire

For nearly three years, Indian tech and privacy lawyers have been playing a dangerous game of regulatory limbo. We had the Digital Personal Data Protection (DPDP) Act, 2023 , but without the operational rules, advising clients on data governance was ...

For nearly three years, Indian tech and privacy lawyers have been playing a dangerous game of regulatory limbo. We had the Digital Personal Data Protection (DPDP) Act, 2023, but without the operational rules, advising clients on data governance was largely an exercise in speculative fiction. That era ended this week in 2026.

The Centre has finally notified the long-awaited administrative rules, setting the compliance clock ticking with a graded 12 to 18-month transition period. But while corporate law firms are busy billing hours to draft new consent managers and data-mapping policies, the real battleground has shifted to the Supreme Court. The top court has just referred a clutch of petitions challenging the DPDP Act to a five-judge Constitution Bench, critically refusing to stay the law’s operation in the interim.

The RTI Blackout: Section 44(3) Under the Microscope

For litigation and public interest lawyers, the most alarming aspect of the DPDP Act isn't what it does to tech companies—it’s what it does to the Right to Information (RTI) Act, 2005.

Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act. Previously, a Public Information Officer (PIO) could deny personal information *unless* they were satisfied that the larger public interest justified its disclosure. The DPDP Act has taken a sledgehammer to this nuanced balancing act, replacing it with a blanket exemption. If it is personal information, it cannot be disclosed. Period.

"By removing the public interest caveat, the DPDP Act weaponizes privacy to shield bureaucratic opacity. It effectively overrides the transparency mandate that has driven Indian administrative law for two decades."

This is a constitutional tightrope. The Supreme Court is now tasked with reconciling the fundamental right to privacy (Justice K.S. Puttaswamy v. Union of India) with the fundamental right to information derived from Article 19(1)(a). Because the Court declined an interim stay, practitioners advising journalists, civil rights groups, and corporate investigators must immediately brace for PIOs routinely rejecting RTI applications under the guise of "data protection." Your writ petitions challenging these rejections must now pivot from statutory interpretation to constitutional fundamental rights arguments.

The Backdoor AI Regulation

Perhaps the most fascinating takeaway for IP and technology lawyers is how the government is positioning the DPDP Act. The Ministry of Electronics and Information Technology (MeitY) has made it explicitly clear: India will not see a dedicated, standalone Artificial Intelligence statute anytime soon. Instead, the government is treating existing frameworks—primarily the DPDP Act and the Copyright Act, 1957—as the baseline for AI governance.

This fundamentally alters how practitioners must advise AI startups and enterprises. You can no longer silo your privacy and IP teams.

Consider the training of Large Language Models (LLMs). When an indigenous AI model scrapes the Indian web, it inevitably ingests Personal Identifiable Information (PII). Under Section 5 (Notice) and Section 6 (Consent) of the DPDP Act, processing this data without explicit, affirmative consent is illegal. There is no broad "legitimate interest" exception for web scraping in the Indian law, unlike in the GDPR.

Furthermore, we are seeing a massive blind spot regarding Section 8(5) of the DPDP Act, which mandates reasonable security safeguards. When employees feed proprietary client data or personal customer information into public generative AI tools (shadow AI), it is not just an IP leak—it is a statutory data breach under the DPDP Act.

What Must Change in Practice?

The 12 to 18-month phased compliance window is a deceptive comfort. Here is what lawyers need to start executing immediately:

  • Audit AI Training Pipelines: If your client is building or fine-tuning AI models, you must audit their datasets. If the data contains Indian PII, they need a legally sound justification for processing it, which in most cases now requires verifiable consent.
  • Overhaul Employment Contracts: Standard confidentiality clauses are no longer enough. Employment agreements and IT policies must explicitly forbid the input of personal data into unsanctioned AI models to prevent Section 8(5) breach liabilities.
  • Prepare for Fiduciary Liability: Under the new rules, the obligations of a Data Fiduciary are non-delegable. If you advise businesses heavily reliant on third-party data processors (SaaS vendors, cloud hosts), their indemnification clauses under the Indian Contract Act, 1872 need to be ironclad, as the DPDP Act holds the primary fiduciary liable for the processor's failures.

The notification of the DPDP Rules marks the maturation of India's digital legal ecosystem. But with the Supreme Court actively scrutinizing its constitutional validity and the government stretching the Act to cover the sprawling complexities of AI, the law is far from settled. For practitioners, the "wait and watch" era is over. The era of aggressive compliance and constitutional litigation has begun.

Published by AnrakLegal AI