Legal News
6 July 2026
IP & Technology

The Honeymoon is Over: DPDP Rules 2025 Notified Amidst an RTI Collision Course and Glaring AI Blindspots

The End of "Suspended Animation" For the past two years, corporate lawyers and privacy professionals have been floating in a state of speculative limbo. With the government’s recent notification of the Digital Personal Data Protection (DPDP) Rules, 2...

The End of "Suspended Animation"

For the past two years, corporate lawyers and privacy professionals have been floating in a state of speculative limbo. With the government’s recent notification of the Digital Personal Data Protection (DPDP) Rules, 2025, that suspended animation has officially ended. The DPDP Act finally has its teeth, and the newly minted Data Protection Board of India is gearing up for enforcement.

But while compliance teams scramble to update consent notices, the real battlelines are being drawn in our constitutional courts. The implementation of the DPDP Act has triggered a massive collision between fundamental privacy rights, the transparency mandate of the Right to Information (RTI) Act, and the rapidly evolving landscape of Artificial Intelligence (AI) and Intellectual Property (IP).

The Death of the "Public Interest" Exception in RTI

The most critical development for litigators and investigative journalists isn't the compliance burden—it is the existential threat to the RTI Act. The Supreme Court has rightly issued notice on a plea challenging the vires of Section 44(3) of the DPDP Act. For the uninitiated, this seemingly innocuous provision acts as a backdoor amendment to Section 8(1)(j) of the RTI Act, 2005.

Previously, Section 8(1)(j) allowed the disclosure of personal information if a Public Information Officer (PIO) determined that the larger public interest justified it. The DPDP Act has brutally severed this caveat, creating a near-total blackout on personal data disclosure under the RTI regime. The petitioners rightfully argue that this blanket ban violates Articles 14, 19(1)(a), and 21 of the Constitution.

"We are witnessing the weaponization of privacy to shield bureaucratic opacity. Without the public interest exception, due diligence, exposing corporate fraud, or uncovering administrative malfeasance becomes exponentially harder for practitioners."

The Kerala High Court’s recent ruling—that there is no "unrestricted right" under the RTI Act to invade personal privacy—echoes this statutory shift. However, if the Supreme Court does not read down Section 44(3), lawyers will lose one of their most potent tools for pre-litigation fact-finding. We are effectively staring at a regime where "personal data" becomes a convenient impenetrable shield for public servants and state instrumentalities.

The Government’s Cop-Out on AI Regulation

While the Supreme Court tackles the privacy-transparency intersection, the Ministry of Electronics and IT (MeitY) has made a baffling policy declaration. The government has stated it prefers to rely on "existing legal frameworks"—namely the DPDP Act and the Copyright Act, 1957—to govern AI, avoiding new regulatory frameworks unless "absolutely necessary."

From a practitioner's standpoint, this "wait and watch" approach is deeply flawed and dangerously naive. Existing IP and privacy laws are woefully ill-equipped to handle Generative AI, creating massive legal blindspots.

Take Section 8(5) of the DPDP Act, which mandates Data Fiduciaries to protect personal data in their possession. What happens when an employee, looking to optimize their workflow, feeds proprietary company data or client personal data into a public Large Language Model (LLM) like ChatGPT? Not only is this a blatant data breach under the DPDP Rules, triggering severe penalty schedules, but it also creates an IP nightmare.

Who owns the output? If an employee generates code or marketing copy using an AI tool trained on third-party copyrighted material, who holds the liability? The current Indian Copyright Act requires a human author. The Delhi High Court is already grappling with the Stephen Thaler plea regarding AI copyrightability, but relying on piecemeal jurisprudence while the government drags its feet on a dedicated AI framework leaves corporate legal departments in the dark.

What This Means for Practice Today

The notification of the DPDP Rules and the government's stance on AI require immediate, aggressive shifts in how we advise clients:

1. Overhaul Employment Contracts & IT Policies: You can no longer rely on standard confidentiality clauses. Employment agreements must explicitly define and restrict the use of Generative AI. A breach of Section 8(5) via employee AI usage must be classified as gross misconduct to shield the Data Fiduciary from vicarious liability.

2. Rethink Information Gathering: With the RTI Act knee-capped by Section 44(3) of the DPDP Act, lawyers conducting due diligence or background checks must pivot. Relying on RTI applications for service records, disciplinary proceedings (as seen in the Kerala HC matter), or property details linked to individuals will result in immediate rejections. Strategy must shift toward court-ordered discoveries and subpoenas.

3. IP Due Diligence in M&A: When evaluating tech companies, IP due diligence must now include an "AI Audit." If a target company's core IP was generated using AI tools, its copyright protection under Indian law is highly questionable, directly impacting the valuation.

The Road Ahead

The year 2026 will be defined by how the Supreme Court balances the DPDP Act against the RTI Act. But for commercial and IP lawyers, the immediate threat is the government's reluctance to legislate on AI. Until the much-delayed Digital India Bill arrives, practitioners must use contractual duct tape to bridge the massive gaps left by outdated IP laws and a privacy statute that is currently biting off more than it can chew.

Published by AnrakLegal AI