The DPDP Rules Are Finally Here: Why the Supreme Court’s Refusal to Stay the RTI Amendment and MeitY’s AI Stance Will Redefine Tech Law Practice
The End of Theoretical Privacy: DPDP Rules Go Live For the past two years, Indian tech lawyers and consultants have been billing clients for "readiness assessments" based on a ghost. The Digital Personal Data Protection (DPDP) Act, 2023, while ambiti...
The End of Theoretical Privacy: DPDP Rules Go Live
For the past two years, Indian tech lawyers and consultants have been billing clients for "readiness assessments" based on a ghost. The Digital Personal Data Protection (DPDP) Act, 2023, while ambitious, was essentially a skeletal framework waiting for its administrative muscle. That wait is officially over. The Centre has notified the long-awaited administrative rules, shifting India’s data protection regime from a theoretical debate into a live compliance mandate.
The rollout is staggered, with full operationalization expected by May 13, 2027. However, practitioners advising Data Fiduciaries must act now. The phased compliance timeline means that backend engineering to facilitate Section 5 (Notice) and Section 6 (Consent) obligations must begin immediately. The era of loose "opt-out" privacy policies is dead; granular, affirmative, and verifiable consent is now the regulatory baseline. If your clients are still relying on pre-ticked boxes, they are staring down the barrel of massive penalties.
The Constitutional Collision: Privacy vs. Transparency
While the corporate sector scrambles to comply, a massive constitutional battle has just been escalated at the Supreme Court. The apex court has referred petitions challenging specific provisions of the DPDP Act and the 2025 Rules to a larger Constitution Bench.
The core of this dispute lies in Section 44(3) of the DPDP Act, which surgically alters Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Under the original RTI framework, personal information could be disclosed if the Public Information Officer (PIO) determined that a larger public interest justified the disclosure. The DPDP Act entirely strips away this "public interest" carve-out, creating a blanket exemption against the disclosure of any personal data under the RTI Act.
"By deleting the public interest exception, the DPDP Act effectively weaponizes the right to privacy against the right to information, shielding public servants from legitimate scrutiny."
Civil society is understandably up in arms, demanding a rollback. The tension here is a classic clash of fundamental rights: the Right to Privacy (K.S. Puttaswamy v. Union of India) versus the Right to Know (State of U.P. v. Raj Narain).
The Practice Takeaway: Crucially, the Supreme Court refused to stay the operation of the DPDP Act or the RTI amendment while the Constitution Bench deliberates. For litigators and in-house counsel handling RTI appeals, the amendment is the law of the land right now. Expect public authorities to aggressively use the amended Section 8(1)(j) to reject RTI queries involving any semblance of personal data. Lawyers challenging these rejections will have to get creative, perhaps arguing that the data sought does not meet the strict definitional threshold of "personal data" under Section 2(t) of the DPDP Act.
The AI Regulatory Void: Shoehorning New Tech into Old Law
Perhaps the most strategically significant news for IP and tech lawyers is the Ministry of Electronics and IT’s (MeitY) latest signaling on Artificial Intelligence. Rather than rushing a bespoke AI statute—as Europe did with the AI Act—the government’s current stance is to govern AI through existing frameworks, specifically the DPDP Act and the Copyright Act, 1957.
This "wait and watch" approach is a double-edged sword. On one hand, it avoids stifling innovation with premature regulation. On the other hand, it creates a massive regulatory void that practicing lawyers will have to bridge through creative interpretation.
Consider the scraping of data to train Large Language Models (LLMs). If the training dataset contains personal data, the DPDP Act is instantly triggered. Did the AI developer obtain Section 6 consent to process that personal data for machine learning? Almost certainly not. Furthermore, relying on the Copyright Act, 1957 to police AI-generated content and training data is going to stretch the doctrine of "fair dealing" (Section 52) to its absolute breaking point. Can ingesting copyrighted literary works to train a neural network be considered a transformative fair use, or is it wholesale infringement?
My take: Shoehorning 21st-century generative AI into a 1957 copyright framework and a nascent privacy law is a recipe for judicial chaos. The government is essentially outsourcing AI regulation to the courts. Until a dedicated AI law is passed, tech litigators are going to have a field day arguing whether prompt-engineering qualifies as "original literary work" under Section 2(o) of the Copyright Act.
The Road Ahead
The notification of the DPDP Rules, the looming Supreme Court showdown over the RTI Act, and the government's reliance on existing IP/Privacy laws for AI governance all point to one reality: India's technology law landscape has never been more volatile or more critical to corporate strategy.
Lawyers can no longer afford to operate in silos. Advising a tech client today requires a fluid understanding of how data privacy, constitutional rights, and intellectual property intersect. As the 2027 DPDP compliance deadline ticks closer, the firms that can operationalize these overlapping, and sometimes conflicting, mandates will dominate the market.
Tags
Published by AnrakLegal AI