The End of Easy WHOIS: Delhi High Court Forces IP Litigators to Navigate the DPDP Maze to Unmask Cyber-Squatters
The Intersecting Collision of IP Enforcement and Data Privacy For the better part of a decade, the playbook for Indian IP litigators dealing with rogue websites, counterfeiters, and phishing scams has been comfortably predictable. You draft a suit fo...
The Intersecting Collision of IP Enforcement and Data Privacy
For the better part of a decade, the playbook for Indian IP litigators dealing with rogue websites, counterfeiters, and phishing scams has been comfortably predictable. You draft a suit for trademark infringement under Section 29 of the Trade Marks Act, 1999, file an application for an ex parte ad interim injunction, and secure an Ashok Kumar (John Doe) order. Crucially, you get a direction compelling the Domain Name Registrar (DNR) to rip off the mask of the anonymous registrant by handing over their WHOIS data.
That era of frictionless unmasking is officially over.
In a watershed development, the Delhi High Court has fundamentally altered intermediary liability and data disclosure norms. While tightening compliance expectations for DNRs handling trademark misuse and counterfeit sales, the Court explicitly held that the disclosure of registrant data—even in legitimate IP enforcement actions—will now be governed by India’s Digital Personal Data Protection (DPDP) Act, 2023. The DPDP Act has officially crashed the IP litigation party, and the traditional IP bar is going to have to learn a new language.
Why This Decision Changes Your Practice Tomorrow
Until now, DNRs like GoDaddy, Namecheap, or BigRock operated under the safe harbor of Section 79 of the Information Technology Act, 2000. When slapped with a court order, they routinely functioned as passive conduits, handing over the personal data of the infringing domain owner to the plaintiff's counsel without a second thought. It was a mechanical process.
The Delhi High Court’s integration of the DPDP Act into this process flips the script. Under the DPDP framework, a DNR is a Data Fiduciary. The domain registrant—even if they are a cyber-squatter or a scammer—is a Data Principal. Section 8 of the DPDP Act mandates that fiduciaries protect personal data, and Section 4 requires valid consent or a "certain legitimate use" for processing (which includes sharing) that data.
"We are witnessing the friction point where the absolute right to brand protection collides with the fundamental right to privacy. The Court is signaling that an allegation of trademark infringement does not automatically strip a citizen of their data protection rights."
What does this mean for the practicing advocate? Your plaints must evolve immediately.
You can no longer file a standard boilerplate application demanding registrant details. Litigators must now proactively plead the exemption under Section 17(1)(c) of the DPDP Act, which allows the processing of personal data when it is necessary for "enforcing any legal right or claim." If you fail to demonstrate to the judge that the unmasking of the registrant is strictly necessary and proportionate to enforce your client's IP rights under the Trade Marks Act or Copyright Act, the Court—and the DNR's legal counsel—will use the DPDP Act as a shield to deny your request.
Intermediaries Caught in the Crossfire: The 2026 IT Rules Amendment
This data privacy hurdle is materializing at the exact moment the government is demanding faster action from tech platforms. Alongside the DPDP integration, recent analyses of the impending 2026 IT Rules amendments reveal a broader regulatory squeeze. The Ministry of Electronics and Information Technology (MeitY) has sharply reduced takedown timelines for synthetically generated content (deepfakes) and is pushing for mandatory platform verification measures.
This creates a schizophrenic regulatory environment for tech lawyers advising intermediaries. On one hand, the amended IT Rules demand hyper-fast takedowns of AI-generated IP infringement, stripping away the leisurely 36-hour window. On the other hand, the DPDP Act and the new administrative rules (which are currently being rolled out for a phased enforcement by May 2027) threaten massive financial penalties if platforms recklessly share user data with private plaintiffs without watertight legal justification.
As industry bodies like the Broadband India Forum warn against fast-tracking DPDP enforcement, intermediaries are going to become inherently defensive. They will scrutinize every court order. If a Delhi High Court order directs data disclosure but lacks a specific DPDP exemption finding, expect DNRs and platforms to file modification applications rather than risk a data breach violation.
The Burden of Proof Has Shifted
The convergence of IP law, AI regulation, and data protection is no longer an academic discussion for panel seminars; it is the reality of the daily cause list. Recent commentary correctly points out that under the DPDP Act, consent is governance. Data fiduciaries bear the burden of proving valid notice and lawful processing. To avoid carrying that burden, intermediaries will force IP owners to do the heavy lifting in court.
For law students and junior litigators, the takeaway is stark: pure IP lawyers are a dying breed. To successfully land an injunction against a digital counterfeiter in 2026, you will need to argue Section 29 of the Trade Marks Act alongside Section 17 of the DPDP Act and the intermediary guidelines of the IT Rules. The Delhi High Court has drawn the line in the sand. You either master the privacy-IP matrix, or your John Doe suits are going to be dismissed at the admission stage.
Tags
Published by AnrakLegal AI