The DPDP Rules Drop at Last: Why the RTI Amendment and AI's Regulatory Vacuum Spell Chaos for Tech Lawyers
The Long Wait is Over, But the Legal Quagmire Has Just Begun Two years after Parliament passed the Digital Personal Data Protection (DPDP) Act, 2023, the Centre has finally notified the administrative rules to make India’s maiden comprehensive data p...
The Long Wait is Over, But the Legal Quagmire Has Just Begun
Two years after Parliament passed the Digital Personal Data Protection (DPDP) Act, 2023, the Centre has finally notified the administrative rules to make India’s maiden comprehensive data privacy framework operational. For corporate lawyers, in-house counsel, and tech litigators, the notification is less of a finish line and more of a starting pistol.
While the Ministry of Electronics and Information Technology (MeitY) has promised a "phased rollout" over the next 12 to 18 months, there are already whispers of the government compressing this transition timeline for large tech players. But the real story isn't just about compliance deadlines. It is about how this Act is simultaneously colliding with the Right to Information (RTI) Act, 2005, and being haphazardly duct-taped to the Copyright Act, 1957 to govern Artificial Intelligence.
If you are advising data fiduciaries today, you are walking into a minefield of pending constitutional challenges and patchwork jurisprudence. Here is why the latest developments matter for your practice.
The RTI vs. Privacy Tug-of-War: A Constitutional Showdown
The most explosive litigation currently brewing in the Supreme Court centers on Section 44(3) of the DPDP Act, which amends Section 8(1)(j) of the RTI Act. Previously, the RTI Act allowed the disclosure of personal information if the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified it. The DPDP Act obliterates this public interest carve-out, creating an absolute blanket ban on the disclosure of any personal information under the RTI Act.
Civil society and transparency activists have rightfully challenged this as a draconian dilution of public accountability, arguing it violates Article 19(1)(a) of the Constitution. The Supreme Court has issued notice and referred the challenge to a 5-judge Constitution Bench. However, here is the critical takeaway for litigators:
The Supreme Court explicitly refused to stay the operation of the impugned provisions pending the larger bench hearing.
What does this mean for practice? It means the masking and deletion of public data by government portals is legally valid right now. If you are a writ practitioner relying on RTI responses to unearth corporate frauds, electoral discrepancies, or public tender anomalies, your primary investigative tool has been severely blunted. Until the Constitution Bench decides where the boundary between the fundamental right to privacy (Puttaswamy) and the right to information lies, government departments will use the DPDP Act as an impenetrable shield against transparency.
Simultaneously, the Delhi High Court has sought the Centre’s response on a parallel PIL challenging key provisions of the DPDP Rules. We are entering an era of overlapping jurisdiction and fragmented interim orders. Advising clients on whether public data scraped from government websites is "publicly available personal data" (and thus exempt under the DPDP Act) is going to require immense caution.
AI Governance: A Dangerous Reliance on Existing IP Laws
Perhaps the most myopic policy stance revealed in the recent developments is the Centre’s indication that it will not enact a bespoke Artificial Intelligence statute. Instead, the government intends to use the existing DPDP framework alongside intellectual property laws to regulate AI deployments.
For IP and tech lawyers, this is a recipe for disaster. Generative AI fundamentally breaks the traditional paradigms of the Copyright Act, 1957. When an LLM (Large Language Model) scrapes the internet, it ingests both copyrighted literary works (Section 2(o)) and personal data.
Relying on "existing laws" means we are forcing square pegs into round holes. Can the training of an AI model be defended under the "fair dealing" exceptions of Section 52 of the Copyright Act? The law is entirely silent on text and data mining (TDM). Furthermore, if an employee feeds confidential client databases into an enterprise AI tool, it is no longer just an IP breach—it is a massive data breach under Section 8(5) of the DPDP Act, attracting penalties that can run into hundreds of crores.
You cannot properly govern algorithmic bias and automated decision-making using a statute designed to protect authors of books and a statute designed for standard digital data processing. By refusing to draft an AI-specific law, the government is outsourcing AI regulation to the judiciary. IP lawyers should brace for a surge in complex, high-stakes infringement suits where plaintiffs will creatively combine claims of copyright infringement with DPDP violations.
Actionable Takeaways for Corporate and Tech Counsel
With the government hinting at a compressed timeline for compliance, the "wait and watch" approach is officially dead. Here is what you need to execute immediately:
1. Overhaul Notice and Consent Architectures: Sections 5 and 6 of the DPDP Act are now operationalized by the new Rules. Your clients must provide itemized, clear, and multi-lingual notices before processing personal data. "Bundled consent" is legally void. If your client's UI/UX relies on dark patterns to secure consent, they are sitting ducks for the Data Protection Board.
2. Audit AI Supply Chains: Because the government is treating the DPDP Act as the de facto AI law, you must audit how your clients train their models. If they are scraping personal data without consent, assuming it is "publicly available," they might be misinterpreting the narrow exemptions provided in the Act.
3. Prepare for Data Breach Fire drills: The rules stringentize reporting timelines. A breach under the DPDP Act doesn't just mean a technical failure; under the new regime, it is a presumption of failure by the Data Fiduciary to implement reasonable security safeguards (Section 8(4)).
The notification of the DPDP Rules is a watershed moment for Indian technology law. But with the RTI Act heavily compromised, the Supreme Court circling the constitutional validity of the framework, and AI left to roam free in a regulatory vacuum, lawyers will be the ones writing the actual rules of the game in courtrooms over the next three years.
Tags
Published by AnrakLegal AI