Introduction The European Commission issued preliminary findings indicating that TikTok may have breached the Digital Services Act (“DSA”) in relation to the protection of minors. The Commission’s concerns include the accessibility of public account content, the ease with which younger users can change their account settings, and the recommendation of minors’ content through the platform’s…
€403M Fine on Google: What Global Enforcement Means for India’s DPDPA Landscape? When a legacy UX decision costs €403 million, “industry standard” is no longer a defense. India is sitting on a time bomb of legacy data only. Ireland’s Data Protection Commission (DPC) has penalized Google €403 million over historical location-tracking practices across Web &…
Introduction The Department of Consumer Affairs, Ministry of Consumer Affairs, Food and Public Distribution, notified the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 on 9 September 2026, amending the Consumer Protection (E-Commerce) Rules, 2020 framed under the Consumer Protection Act, 2019. The amendment, which comes into force on 1 January 2027, is the most significant recalibration…
Introduction Modern businesses increasingly rely on third-party infrastructure to operate: cloud storage providers, artificial intelligence platforms, payment processors and HR systems now hold, transmit or process significant volumes of personal and business data on behalf of the organisations that engage them. This arrangement is efficient, but it does not change where legal responsibility for that…
Introduction As India’s data protection regime moves from legislation to enforcement, businesses are increasingly treating cyber insurance as a ready answer to their compliance worries. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) became operational once the DPDP Rules were notified in November 2025, with phased implementation expected through 2027, and insurers are already…
Introduction The internet has made Child Sexual Abuse Material (hereinafter referred to as “CSAM”) a profoundly transnational crime. A child may be located in India, the offender may operate from another jurisdiction, the platform may be incorporated in the United States, and the relevant electronic evidence may be stored across multiple servers. Yet, investigations continue…
Introduction The Digital Personal Data Protection Act, 2023 (“DPDP Act”) borrows some of the European Union (“EU”)’s General Data Protection Regulation (“GDPR”)’s vocabulary a Data Fiduciary echoes a “controller,” a Data Principal echoes a “data subject” and the legal architecture behind those words is roughly the same. In several places the DPDP Act gives a…
Meta, MEITY And The DPDP Act: Does India’s Data Protection Framework Match Global Scrutiny?
- 2026-08-19
Introduction In August, Meta’s technical team and the Ministry of Electronics and Information Technology (MeitY) lead to the government clarifying that Meta’s platforms in India must be governed by Indian law, not merely by the company’s global policies. The discussion focused on content moderation, deepfakes, child sexual abuse material (CSAM), and the opacity of Meta’s…
Introduction France’s decision to prohibit unsolicited telemarketing calls from August 2026 onwards marks a significant shift in the philosophy of consumer protection. Rather than requiring consumers to register their objection to marketing calls, the French approach reverses the presumption itself, businesses must obtain consent before making the call. The distinction is important because it determines…
WhatsApp’s Age Check and the DPDP Act : What Section 9 Means for Children’s Data Compliance
- 2026-08-05
Introduction WhatsApp has started asking some users in India to confirm they are over eighteen before they can keep using the app. On its face, it looks like nothing more than another screen to tap through, the kind of prompt people barely register before moving on. But the timing tells a different story. This age…
Introduction The hospitality sector presents a distinctive compliance problem under the Digital Personal Data Protection Act, 2023 (“DPDP Act, 2023”), read with the Digital Personal Data Protection Rules, 2025 (“DPDP Rules, 2025”). The personal data a hotel processes rarely originates from a single, controlled channel. It flows in through Online Travel Aggregators, walk-in bookings, corporate…
Medical Devices and Privacy by Design: A Way to DPDPA Compliance in the Healthcare Sector
- 2026-07-22
Introduction The healthcare sector in India is witnessing a change with the advancement of technology. The use of medical devices is not limited to wards and laboratories anymore. Smart insulin pumps, fitness trackers, heart rate monitors, intelligent diagnostic applications, image processing systems, and patient monitoring applications are some of the many innovations that form part…
EDPB’s New Anonymization Guidelines: What They Mean for Indian Businesses under the DPDP Act
- 2026-07-15
Introduction The European Data Protection Board (“EDPB”) has issued detailed guidelines on anonymisation and web scraping in the context of generative AI. These guidelines clarify when data can be considered truly “anonymous” and therefore outside the scope of the EU General Data Protection Regulation (“GDPR”). Although the guidelines are not binding in India, they are…
Introduction While facial recognition technology has emerged as a critical tool for policing and infrastructural purposes in India, the technology’s use does not have a legal mechanism that is specifically designed to regulate it. While the Digital Personal Data Protection Act, 2023 (“DPDP Act”) provides for a legal framework on how personal data should be…
Introduction Cloud regulation is no longer limited to questions of data protection and cybersecurity. Increasingly, governments are also examining who controls the infrastructure on which data is stored, processed, and accessed. Reflecting this shift, the European Commission proposed the Cloud and AI Development Act on 3 June 2026, a legislative initiative aimed at strengthening the…
Introduction ‘Facial Recognition Technology’ has become more and more predominant in Society as technology has developed over time. We have transitioned from a period where we required a high-quality and expensive camera with an experienced photographer to take a single photo to a point where any layperson can take a photo, such was the development…
From Privacy Policies to System Architecture: The Supreme Court’s New Compliance Standard
- 2026-06-02
Your Privacy Policy is now Irrelevant! A strategic breakdown of the Supreme Court’s shift in “No Privacy by Design”!! On May 22, 2026, the Supreme Court quieted a massive structural debate in Pune Bar Association v. UOI. They ruled that data integrity is a matter of necessity, not convenience, making cryptographic hashing the absolute floor…
The Government of India wants to turn law into code. This is bigger than automation!! MeitY is reportedly exploring “law-to-code” translating DPDPA provisions into machine executable rules so systems enforce compliance by design. The logic is sound. When AI moves at machine speed, governance cannot run at the speed of a legal opinion. A system…
Introduction The introduction of generative Artificial Intelligence (“AI”) into the mainstream digital communication platforms is rapidly changing the way we interact online. One of the latest developments in this space is Meta’s reported exploration of privacy-focused AI chat functionality using “Private Processing” technology, which may eventually be introduced across WhatsApp and the Meta AI ecosystem….
GDPR turns Eight this May!! Day One, 25 May 2018, 4 Complaints were filed within hours!!! Eight years later, GDPR fines have crossed €7.1 billion!!! Now look at India 1.4 billion people. 900 million internet users. The largest digital footprint any privacy regulator has ever been asked to supervise. UPI clears more transactions in a…
Introduction The European Parliament and the Council of the European Union have reached a provisional political agreement to amend the EU Artificial Intelligence Act (“AI Act”) as part of the broader “Digital Omnibus on AI” legislative initiative. One of the key developments under the proposed amendments is the prohibition of AI systems designed or used…
Introduction The blood banking sector plays a critical but underappreciated role within the healthcare system. It handles thousands of blood samples every day, all of which are associated with particular donors and receivers. Therefore, the institutions act as custodians of highly personal and confidential information, including health-related data. In today’s technological age, they have gone…
Introduction AI systems are gradually moving beyond generating responses and are now beginning to take actions across systems with limited human involvement. They plan tasks, interact with external systems, retrieve and process data, and carry out multi-step actions with limited human involvement. These systems, commonly referred to as ‘AI agents’, are already being used across…
Introduction Most organisations today can point to a compliant looking privacy setup, cookie banners, preference centres, and neatly maintained consent logs. However, the real issue is whether that choice actually changes anything. Increasingly, the answer appears to be no. Users click “Reject All”, withdraw consent, or opt out of tracking, yet data continues to flow…
On 2 March in CIO and 5 March in Computerworld, I outlined how the Anthropic & OpenAI–DoD clash would unfold. Anthropic’s latest filing in the Northern District of California follows exactly the framework I predicted, confirming that analysis. Further, this is no longer a policy debate rather it is a constitutional test of whether the…
Introduction The ongoing massive use of personal data drives the present-day digital economy. Every online transaction, whether using a mobile application, registering for a service, or making a digital payment, generates data that businesses analyse and process for a variety of uses. Although people typically give their information to a specific platform, the information rarely…
You clicked “I Agree” on a quick commerce app. That was 5 months ago. Since then, the AI has figured out you are likely pregnant. Probably diabetic. Financially stretched every third week of the month. You never consented to any of that. You consented to delivery. This is what I call “Agentic Consent Collapse” It…
Introduction In the evolving corporate environment, the transition from static software to dynamic AI agents is basically reshaping how business is conducted. No more confined to simple “if-then” logic, AI-driven automation is now powering sophisticated operations across several sectors. In customer service, intelligent agents handle complex inquiries and process refunds in real time, they conduct…
Introduction Social platforms designed for interaction between autonomous Artificial Intelligence (“AI”) agents present a new category of legal and technical risk. Unlike conventional platforms where user conduct is the primary source of exposure, AI-agent environments involve automated generation, storage, and exchange of data without continuous human oversight. This increases the likelihood that technical misconfigurations may…
Introduction The challenge before SC centres on Section 44(3) of the DPDP Act, which amends Section 8(1)(j) of the Right to Information Act. While Section 8(1)(j) previously permitted disclosure of personal information in cases of larger public interest, the amendment under the DPDP Act now effectively bars such disclosure. We are moving away from “discretionary…
