Legal News
2 July 2026
IP & Technology

The Transparency Black Hole: How the DPDP Act is Weaponizing Privacy Against IP Enforcement and the RTI Act

The Collision of Privacy, Transparency, and Property For months, technology lawyers and IP litigators have been whispering about the unintended—or perhaps entirely intended—consequences of the Digital Personal Data Protection (DPDP) Act, 2023. Now, i...

The Collision of Privacy, Transparency, and Property

For months, technology lawyers and IP litigators have been whispering about the unintended—or perhaps entirely intended—consequences of the Digital Personal Data Protection (DPDP) Act, 2023. Now, in mid-2026, those whispers have culminated in high-stakes constitutional battles. The Supreme Court has finally issued notice on a plea challenging the constitutional validity of the DPDP Act, transferring it to a larger bench. Simultaneously, the Delhi High Court is hearing a sweeping Public Interest Litigation (PIL) against multiple provisions of the Act.

Why should the practicing advocate care? Because the DPDP Act is rapidly evolving from a shield for consumer privacy into a sword used by state and corporate actors to kill transparency, obfuscate intellectual property (IP) theft, and dodge accountability.

The RTI Act's Death Knell: Section 44(3) Under the Scanner

The most dangerous legal sleight-of-hand in the DPDP Act is Section 44(3), which stealthily amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Prior to this amendment, personal information could be exempted from RTI disclosure unless the Public Information Officer (PIO) was satisfied that the larger public interest justified its disclosure.

The DPDP Act surgically removed that public interest caveat. Today, if information qualifies as "personal," it is subject to a blanket ban on disclosure.

"The amendment to Section 8(1)(j) effectively subordinates the fundamental right to information under Article 19(1)(a) to a statutory right of privacy, devoid of any proportionality test."

For IP lawyers, this is a procedural nightmare. Historically, RTI applications have been a vital pre-litigation tool to uncover patent infringements in government procurement, software piracy by state departments, or unauthorized use of proprietary databases. By blurring the lines between "public data" and "personal data," state entities are now predictably rejecting RTI requests by citing the DPDP Act. The Supreme Court's decision to scrutinize this amendment is not just a win for activists; it is crucial for maintaining the evidentiary avenues necessary for enforcing IP rights against the state.

IP Theft and the Corporate Privacy Shield

While the Supreme Court tackles the RTI intersection, the Delhi High Court PIL filed by advocate Chandresh Jain targets the corporate implications of the Act—specifically Sections 17 through 21, and 33. The core argument here is highly relevant to commercial litigators: the DPDP Act's strict consent architecture is actively hindering the investigation of corporate espionage and IP theft.

Imagine a scenario where a rogue employee exfiltrates proprietary code or trade secrets to a competitor. Under the 2025 DPDP Rules, which enforce a strict "governance-centric" approach to data collection and processing, employers (Data Fiduciaries) face massive compliance hurdles when processing employee data (Data Principals) to investigate the breach.

If a company attempts to analyze email logs, access trails, or personal device usage to trace stolen IP, the accused employee can weaponize the DPDP Act, claiming unauthorized processing of their personal data. While Section 17 provides certain exemptions for enforcing legal rights, the procedural friction is immense. We are seeing a rising trend where defense counsel in IP infringement suits are filing counter-claims under the DPDP Act to paralyze legitimate internal investigations.

The AI Regulatory Cop-Out

Adding fuel to the fire is the Ministry of Electronics and IT's (MeitY) recent declaration that India does not need a bespoke Artificial Intelligence law. MeitY Secretary S. Krishnan's stance that the DPDP Act and existing Intellectual Property laws are sufficient to govern AI is, frankly, a regulatory cop-out.

The DPDP Act regulates personal data. It does absolutely nothing to address the scraping of copyrighted, non-personal data by Large Language Models (LLMs). Telling an artist, author, or software developer that the DPDP Act protects their IP from being ingested by generative AI is legally incoherent.

For practitioners advising tech startups, this government stance means you are operating in a regulatory gray area. You must aggressively use the Copyright Act, 1957 and contract law to protect AI-related IP, because the government has mistakenly equated data privacy compliance with algorithmic and intellectual property governance.

Section 12 Erasure vs. Evidentiary Preservation

Finally, we must address the Right to Digital Erasure under Section 12. As the 2025 Rules take full effect, Data Principals are increasingly exercising their right to be forgotten. But what happens when an IP holder or a cloud service provider receives an erasure request for data that is crucial evidence for an impending copyright or trademark infringement suit?

Lawyers must proactively advise corporate clients to update their Data Processing Agreements (DPAs). You must clearly document the retention of specific user data under the "legal obligation" and "establishment of legal claims" exemptions. Failure to meticulously document why data wasn't erased will result in crippling penalties from the Data Protection Board, even if you retained the data to save your client's IP.

The DPDP Act was meant to usher in an era of digital trust. Instead, mid-2026 has proven that it is a labyrinth of conflicting rights. Until the Supreme Court lays down the law on the RTI amendment, and the High Courts clarify the bounds of internal investigations, lawyers must draft their pleadings and privacy policies with extreme defensive precision.

Published by AnrakLegal AI