IPR
Topic 105 IP Privacy DPDP
Topic 105 — IP and Data Privacy / DPDP Act 2023
IP enforcement and data privacy increasingly intersect. IP enforcement requires identification of infringers (often through personal data); data privacy frameworks restrict data processing. The Digital Personal Data Protection Act 2023 (DPDP Act) — enacted 11 August 2023, effective in stages from 2024-25 — fundamentally reshapes this intersection. The DPDP Act creates comprehensive framework: data fiduciaries (data controllers), data principals (data subjects), Significant Data Fiduciaries (SDFs), Data Protection Board of India, lawful bases for processing (consent + legitimate uses), rights of data principals (access, correction, erasure), penalties up to ₹250 crore. The intersection with IP is multifold: IP enforcement requires identification of infringers; user data is processed in IP enforcement; intermediaries must balance IP takedown with user privacy; trade secrets often involve personal data; AI training raises copyright + privacy issues simultaneously. Foundational case: Justice K.S. Puttaswamy v. UoI (2017) — Supreme Court declared right to privacy fundamental under Article 21. The IT Rules 2021 + DPDP Act 2023 create overlapping frameworks. Recent ANI Media v. OpenAI (CS(COMM) 1028/2024) raises both copyright (training data) and privacy (training data containing personal data) issues — judgment reserved 2025. This topic walks through every aspect of IP-Privacy intersection — DPDP framework, IP enforcement implications, intermediary obligations, AI training issues, and strategic considerations.
1. The Privacy Constitutional Foundation
A. Justice K.S. Puttaswamy (Privacy) v. UoI
📖 Justice K.S. Puttaswamy v. UoI, AIR 2017 SC 4161; (2017) 10 SCC 1 Background — 9-judge Constitution Bench. Question of whether right to privacy is a fundamental right. Holding — Supreme Court (24 August 2017): Right to privacy is FUNDAMENTAL RIGHT under Article 21. Foundational pronouncement — Privacy is "intrinsic to liberty and dignity"; "right to be let alone" recognized as part of Constitution. Significance — Foundational privacy decision: · Right to privacy elevated to fundamental status. · Article 21 broader interpretation. · State must respect privacy. · Foundation for DPDP Act 2023. · Affects IP enforcement involving personal data. |
B. Constitutional Framework for Privacy
- Article 21 — right to life and personal liberty includes privacy.
- Article 14 — non-arbitrary processing of personal data.
- Article 19(1)(a) — freedom of speech includes informational privacy.
- Article 19(2) — reasonable restrictions framework.
- Test for restrictions: legality + necessity + proportionality (Puttaswamy).
2. Digital Personal Data Protection Act 2023
A. Statutory Framework
- Enacted: 11 August 2023.
- Effective: in stages from 2024-25.
- Replaces: section 43A IT Act 2000 + IT (Reasonable Security Practices) Rules 2011.
- Inspired by: GDPR (EU) + global frameworks.
- Indian-specific: data localization considerations, exceptions for legal proceedings.
B. Key Concepts
Term | Definition |
|---|---|
Data Fiduciary | Person determining purpose and means of processing personal data (similar to GDPR controller). |
Data Processor | Person processing data on behalf of data fiduciary (similar to GDPR processor). |
Data Principal | Individual whose personal data is processed (similar to GDPR data subject). |
Personal Data | Any data about identifiable individual. |
Sensitive Personal Data | Reserved category (subset). |
Significant Data Fiduciary (SDF) | Designated by Government based on volume, sensitivity, processing risks. |
Data Protection Board of India | Statutory regulator under DPDP Act. |
Consent | Specific, informed, unambiguous indication of agreement. |
Legitimate Use | Specified non-consent based legal grounds. |
C. Lawful Bases for Processing
✅ DPDP Act — Lawful Bases 1. CONSENT — Specific, informed, unambiguous; can be withdrawn. 2. LEGITIMATE USE without consent (limited categories): · Specified purpose (e.g., legal compliance). · Court orders. · Government function. · Compliance with judgment. · Public health emergency. · Performance of state function. · Notified circumstances. For IP enforcement: · Generally requires consent OR legitimate use. · Court orders provide clearest legal basis. · Voluntary compliance with takedown notice may require consent. · Litigation discovery may rely on court process. Intermediaries balance: · IP rights holder demand (under Section 79 IT Act). · DPDP Act consent requirements. · Specific user data minimization. |
3. Rights of Data Principals
A. Statutory Rights
Right | Description |
|---|---|
Access | Right to know what data fiduciary processes. |
Correction | Right to correct inaccurate data. |
Erasure | Right to delete data when no longer necessary. |
Grievance Redressal | Right to grievance officer + escalation to Data Protection Board. |
Nominate | Right to nominate person to act on behalf in case of incapacity/death. |
Portability (limited) | Right to receive data in structured format. |
Withdrawal of Consent | Right to withdraw consent. |
B. Exemptions for Legal Proceedings
- Court orders.
- Compliance with judgment.
- Statutory obligations.
- Investigation of offences.
- Related to legal proceedings.
4. IP Enforcement and Personal Data
A. The Identification Challenge
✅ IP enforcement requires identification — privacy implications IP rights holders must identify infringers: · For e-commerce counterfeiters — identify sellers. · For online piracy — identify uploaders/distributors. · For software piracy — identify users. · For trademark infringement — identify infringers. · For trade secret theft — identify malicious actors. · For employee mobility — identify ex-employees. DPDP Act framework: · Identification often involves personal data processing. · Lawful basis required (consent or legitimate use). · Court orders provide clearest authorization. · Voluntary compliance requires consent. · Anonymized data acceptable for some purposes. Key points: · Section 79 IT Act + Shreya Singhal — court order required for actual knowledge. · DPDP exemptions for legal proceedings provide pathway. · Intermediary obligations balance privacy with IP enforcement. |
B. Specific IP Enforcement Scenarios
Scenario | Privacy Implications |
|---|---|
Counterfeiter identification through e-commerce platform | Platform must process seller data; DPDP exempt for legal proceedings. |
Trademark infringement identification on social media | Platform follows IT Rules + DPDP framework. |
Software piracy identification | User data minimization required. |
Online piracy mirror site identification | IP address tracking; coordination with ISPs. |
Trade secret theft investigation | Forensic analysis with DPDP compliance. |
Employee mobility cases | Employee data restrictions. |
AI training data - subject identification | Personal data within training corpus. |
5. Intermediary Obligations
A. The Multi-Statutory Framework
- IT Act 2000 + IT Rules 2021 — intermediary obligations.
- DPDP Act 2023 — data fiduciary/processor obligations.
- Section 79 IT Act — safe harbour requirements.
- Cross-cutting requirements.
B. Specific Intermediary Obligations
✅ Intermediaries balancing IP enforcement and privacy IT Rules 2021 obligations: · Privacy policy and user agreement displaying. · Grievance officer designation. · Resident Grievance Officer for SSMI. · Chief Compliance Officer for SSMI. · Monthly compliance reports for SSMI. · Take-down procedures. DPDP Act 2023 obligations: · Notice and consent. · Lawful basis identification. · Data minimization. · Purpose limitation. · Security safeguards. · Data Protection Officer (for SDFs). Coordination requirements: · IP take-down with privacy compliance. · User data sharing only with proper authorization. · Court orders for sensitive data. · DPDP exemptions for legal proceedings. · Data breach notification frameworks. |
6. Trade Secrets and Personal Data
A. The Overlap
- Trade secrets often contain personal data: - Customer information. - Employee personal data. - Supplier data. - Personally identifiable financial data.
- Privacy of personal data within trade secrets.
- Cross-cutting compliance obligations.
- Sensitive personal data special protections.
B. Trade Secret + Privacy Cases
- Arjan Dugal v. Shubham Gandhi (Del HC 2025) — customer database (~6,000 clients) misappropriation.
- Combination of trade secret + privacy violation considerations.
- DPDP Act compliance for stolen customer data handling.
- Cross-jurisdictional considerations for international cases.
7. AI Training and Privacy + Copyright
A. The Multi-Statutory Conflict
✅ AI training data — IP and privacy intersection AI training data raises BOTH copyright AND privacy issues: Copyright issues: · Training data may include copyrighted works. · Section 14 reproduction rights. · Section 52 fair dealing analysis. · ANI v. OpenAI pending. Privacy issues: · Training data may include personal data. · DPDP Act lawful basis required. · Web-scraped data complicates consent. · Right to erasure complications. · Cross-border data transfer rules. Both intersect in: · News articles (copyrighted + personal data of subjects). · Social media (UGC copyrighted + user personal data). · Public records (potentially copyrighted + personal data). Landmark case: ANI Media v. OpenAI (CS(COMM) 1028/2024) — judgment reserved 2025. Will define both intersections. |
B. ANI Media v. OpenAI Implications
- Copyright: AI training on news content.
- Privacy: Training data contains personal data of news subjects.
- Cross-border: US-based servers, Indian rights.
- Section 52 fair dealing analysis.
- DPDP Act application to training data.
8. Penalties and Enforcement
A. DPDP Act Penalties
500 ₹ Cr breach of children data | 500 ₹ Cr breach SDF obligations | 250 ₹ Cr breach security |
200 ₹ Cr breach data principal rights | 50 ₹ Cr breach voluntary undertaking | X OTHER specified |
B. Enforcement Authority
- Data Protection Board of India.
- Investigation powers.
- Penalty imposition.
- Compliance directions.
- Appeals to designated authority + High Court.
9. Strategic Considerations
✅ For data fiduciaries (companies) — eight points For IP enforcement involving personal data, document lawful basis. For court orders, treat as primary authorization. For consent-based processing, document clearly. For data minimization, process only necessary IP enforcement data. For security safeguards, implement DPDP Act standards. For SDF designation, prepare comprehensive compliance program. For breach notification, establish protocols. For employee data, navigate combined IP + privacy framework. |
✅ For data principals (individuals) — six points For consent withdrawal, exercise statutory right. For access requests, leverage DPDP rights. For correction/erasure, navigate process. For grievances, escalate through proper channels. For IP-related processing, understand legitimate use exemptions. For court orders, recognize as authorization. |
🎯 EXAM POINTERS — TOPIC 105
|