The "No New AI Law" Paradigm: How the Delhi HC and DPDP Act are Rewriting Indian IP Litigation
For the better part of two years, Indian technology and intellectual property lawyers have been holding their breath, waiting for a bespoke "Artificial Intelligence Act" to solve the complex web of AI data scraping, deepfakes, and algorithmic account...
For the better part of two years, Indian technology and intellectual property lawyers have been holding their breath, waiting for a bespoke "Artificial Intelligence Act" to solve the complex web of AI data scraping, deepfakes, and algorithmic accountability. It is time to exhale—and get to work with the tools we already have.
At the Assocham AI Leadership Meet in April 2026, MeitY Secretary S. Krishnan delivered a definitive policy stance: India will not enact new AI regulations unless "absolutely necessary." Instead, the government is deliberately leaning on the intersection of the Digital Personal Data Protection (DPDP) Act, 2023, and existing Intellectual Property laws to govern emerging tech. The message to the bar is clear: stop lobbying for a new statute and start mastering statutory interpretation.
This isn't just a policy quirk; it is a fundamental shift in how tech-IP litigation and advisory practice will operate in India through 2026 and beyond. Here is why this matters for your practice today.
Piercing the Privacy Shield: The Dabur Precedent on Domain Fraud
If you are an IP litigator chasing counterfeiters or phishing operations, you’ve likely hit the "privacy wall." Over the past year, Domain Name Registries (DNRs) have increasingly weaponized privacy laws, refusing to disclose registrant details of infringing domains by citing DPDP compliance.
Enter the Delhi High Court’s critical April 10, 2026, ruling by Justice Prathiba M. Singh in Dabur India v. Unknown Entities. The court confronted the direct clash between a trademark owner's right to enforce its IP and a DNR’s obligation to protect personal data under the DPDP Act.
"Privacy cannot be construed as a sanctuary for cybersquatters and trademark infringers."
Justice Singh, drawing heavily on the proportionality test from K.S. Puttaswamy v. Union of India ((2017) 10 SCC 1), clarified that the DPDP Act’s privacy framework accommodates lawful data disclosure when mandated by a court order. The court didn't just order disclosure; it issued dynamic injunctions involving MeitY, the RBI, and ICANN to systemically curb tech-enabled IP abuse.
The Practice Shift: For IP litigators filing Ashok Kumar (John Doe) suits, the DPDP Act is no longer a valid defense for intermediaries withholding infringer identities. Draft your interim applications to explicitly preempt DPDP objections by citing the lawful disclosure exceptions, demanding dynamic injunctions that compel DNRs to unmask fraudulent registrants immediately.
Consent as Governance: The Death of the Clickwrap Defense
With MeitY notifying the DPDP Rules in November 2025, the grace period for data fiduciaries is rapidly closing. For corporate lawyers advising AI startups or tech platforms, the most dangerous misread of the DPDP Act is treating "consent" as a static, one-time checkbox.
Recent legal analysis of the DPDP rollout emphasizes that consent is now a continuing legal relationship. If your client is scraping user-generated content or biometric data to train AI avatars, a standard Terms of Service (ToS) agreement will no longer shield them from liability under the IT Act, 2000, or the DPDP Act.
The Practice Shift: Tech advisory must evolve. When drafting data processing agreements for AI firms, you must reconcile IP assignment with DPDP consent withdrawal mechanisms. If a user revokes consent for their data, does your client's AI model have to "unlearn" that data? Structuring these agreements requires siloing training data and integrating the newly operationalized "Consent Managers" (effective Nov 2026) to track the lifecycle of personal data within IP-generating algorithms.
The Great Compliance Collision: Right to Erasure vs. Statutory Retention
As banks, fintechs, and tech startups prepare for the phased enforcement of the DPDP Act by May 2027, a massive compliance headache is emerging: the conflict between the DPDP's "Right to Erasure" and statutory retention mandates.
Consider a semiconductor startup operating under the DLI 2.0 scheme, or a fintech app. Under the DPDP Act, a user can demand the erasure of their personal data. However, the Prevention of Money Laundering Act (PMLA), tax laws, and even IP residency tracking require data retention. Furthermore, we are seeing the integration of UIDAI’s new Aadhaar app, which allows for DPDP-compliant age verification (via the amended Aadhaar Authentication Rules 2020) without oversharing data—a vital tool for age-gating IP-sensitive content like gaming and streaming.
The Practice Shift: In-house counsel and corporate advisors can no longer provide siloed advice. You must build "hierarchy of compliance" matrices for your clients. When a user requests erasure, your client needs a legally bulletproof automated protocol that deletes marketing and profiling data (DPDP compliance) while quarantining transaction histories and age-verification logs required by the PMLA or IT Rules.
The Bottom Line
The government has called the legal fraternity's bluff. There is no magic AI legislation coming to neatly package these issues. The future of Indian tech law relies on the gritty, complex overlap of the DPDP Act, the Trade Marks Act, the Copyright Act, and the IT Act.
Lawyers who continue to view IP enforcement and data privacy as two separate practice areas will be left behind in 2026. The practitioners who will dominate the next decade are those who know how to use a DPDP exemption to win a trademark injunction, and how to draft an IP assignment that survives a DPDP consent withdrawal.
Tags
Published by AnrakLegal AI