IPR

Topic 105 IP Privacy DPDP

Topic 105 — IP and Data Privacy / DPDP Act 2023

IP enforcement and data privacy increasingly intersect. IP enforcement requires identification of infringers (often through personal data); data privacy frameworks restrict data processing. The Digital Personal Data Protection Act 2023 (DPDP Act) — enacted 11 August 2023, effective in stages from 2024-25 — fundamentally reshapes this intersection. The DPDP Act creates comprehensive framework: data fiduciaries (data controllers), data principals (data subjects), Significant Data Fiduciaries (SDFs), Data Protection Board of India, lawful bases for processing (consent + legitimate uses), rights of data principals (access, correction, erasure), penalties up to ₹250 crore. The intersection with IP is multifold: IP enforcement requires identification of infringers; user data is processed in IP enforcement; intermediaries must balance IP takedown with user privacy; trade secrets often involve personal data; AI training raises copyright + privacy issues simultaneously. Foundational case: Justice K.S. Puttaswamy v. UoI (2017) — Supreme Court declared right to privacy fundamental under Article 21. The IT Rules 2021 + DPDP Act 2023 create overlapping frameworks. Recent ANI Media v. OpenAI (CS(COMM) 1028/2024) raises both copyright (training data) and privacy (training data containing personal data) issues — judgment reserved 2025. This topic walks through every aspect of IP-Privacy intersection — DPDP framework, IP enforcement implications, intermediary obligations, AI training issues, and strategic considerations.

1. The Privacy Constitutional Foundation

A. Justice K.S. Puttaswamy (Privacy) v. UoI

📖 Justice K.S. Puttaswamy v. UoI, AIR 2017 SC 4161; (2017) 10 SCC 1

Background — 9-judge Constitution Bench. Question of whether right to privacy is a fundamental right.

Holding — Supreme Court (24 August 2017): Right to privacy is FUNDAMENTAL RIGHT under Article 21.

Foundational pronouncement — Privacy is "intrinsic to liberty and dignity"; "right to be let alone" recognized as part of Constitution.

Significance — Foundational privacy decision: · Right to privacy elevated to fundamental status. · Article 21 broader interpretation. · State must respect privacy. · Foundation for DPDP Act 2023. · Affects IP enforcement involving personal data.

B. Constitutional Framework for Privacy

  • Article 21 — right to life and personal liberty includes privacy.
  • Article 14 — non-arbitrary processing of personal data.
  • Article 19(1)(a) — freedom of speech includes informational privacy.
  • Article 19(2) — reasonable restrictions framework.
  • Test for restrictions: legality + necessity + proportionality (Puttaswamy).

2. Digital Personal Data Protection Act 2023

A. Statutory Framework

  • Enacted: 11 August 2023.
  • Effective: in stages from 2024-25.
  • Replaces: section 43A IT Act 2000 + IT (Reasonable Security Practices) Rules 2011.
  • Inspired by: GDPR (EU) + global frameworks.
  • Indian-specific: data localization considerations, exceptions for legal proceedings.

B. Key Concepts

Term

Definition

Data Fiduciary

Person determining purpose and means of processing personal data (similar to GDPR controller).

Data Processor

Person processing data on behalf of data fiduciary (similar to GDPR processor).

Data Principal

Individual whose personal data is processed (similar to GDPR data subject).

Personal Data

Any data about identifiable individual.

Sensitive Personal Data

Reserved category (subset).

Significant Data Fiduciary (SDF)

Designated by Government based on volume, sensitivity, processing risks.

Data Protection Board of India

Statutory regulator under DPDP Act.

Consent

Specific, informed, unambiguous indication of agreement.

Legitimate Use

Specified non-consent based legal grounds.

C. Lawful Bases for Processing

DPDP Act — Lawful Bases

1. CONSENT — Specific, informed, unambiguous; can be withdrawn. 2. LEGITIMATE USE without consent (limited categories): · Specified purpose (e.g., legal compliance). · Court orders. · Government function. · Compliance with judgment. · Public health emergency. · Performance of state function. · Notified circumstances. For IP enforcement: · Generally requires consent OR legitimate use. · Court orders provide clearest legal basis. · Voluntary compliance with takedown notice may require consent. · Litigation discovery may rely on court process. Intermediaries balance: · IP rights holder demand (under Section 79 IT Act). · DPDP Act consent requirements. · Specific user data minimization.

3. Rights of Data Principals

A. Statutory Rights

Right

Description

Access

Right to know what data fiduciary processes.

Correction

Right to correct inaccurate data.

Erasure

Right to delete data when no longer necessary.

Grievance Redressal

Right to grievance officer + escalation to Data Protection Board.

Nominate

Right to nominate person to act on behalf in case of incapacity/death.

Portability (limited)

Right to receive data in structured format.

Withdrawal of Consent

Right to withdraw consent.

B. Exemptions for Legal Proceedings

  • Court orders.
  • Compliance with judgment.
  • Statutory obligations.
  • Investigation of offences.
  • Related to legal proceedings.

4. IP Enforcement and Personal Data

A. The Identification Challenge

IP enforcement requires identification — privacy implications

IP rights holders must identify infringers: · For e-commerce counterfeiters — identify sellers. · For online piracy — identify uploaders/distributors. · For software piracy — identify users. · For trademark infringement — identify infringers. · For trade secret theft — identify malicious actors. · For employee mobility — identify ex-employees. DPDP Act framework: · Identification often involves personal data processing. · Lawful basis required (consent or legitimate use). · Court orders provide clearest authorization. · Voluntary compliance requires consent. · Anonymized data acceptable for some purposes. Key points: · Section 79 IT Act + Shreya Singhal — court order required for actual knowledge. · DPDP exemptions for legal proceedings provide pathway. · Intermediary obligations balance privacy with IP enforcement.

B. Specific IP Enforcement Scenarios

Scenario

Privacy Implications

Counterfeiter identification through e-commerce platform

Platform must process seller data; DPDP exempt for legal proceedings.

Trademark infringement identification on social media

Platform follows IT Rules + DPDP framework.

Software piracy identification

User data minimization required.

Online piracy mirror site identification

IP address tracking; coordination with ISPs.

Trade secret theft investigation

Forensic analysis with DPDP compliance.

Employee mobility cases

Employee data restrictions.

AI training data - subject identification

Personal data within training corpus.

5. Intermediary Obligations

A. The Multi-Statutory Framework

  • IT Act 2000 + IT Rules 2021 — intermediary obligations.
  • DPDP Act 2023 — data fiduciary/processor obligations.
  • Section 79 IT Act — safe harbour requirements.
  • Cross-cutting requirements.

B. Specific Intermediary Obligations

Intermediaries balancing IP enforcement and privacy

IT Rules 2021 obligations: · Privacy policy and user agreement displaying. · Grievance officer designation. · Resident Grievance Officer for SSMI. · Chief Compliance Officer for SSMI. · Monthly compliance reports for SSMI. · Take-down procedures. DPDP Act 2023 obligations: · Notice and consent. · Lawful basis identification. · Data minimization. · Purpose limitation. · Security safeguards. · Data Protection Officer (for SDFs). Coordination requirements: · IP take-down with privacy compliance. · User data sharing only with proper authorization. · Court orders for sensitive data. · DPDP exemptions for legal proceedings. · Data breach notification frameworks.

6. Trade Secrets and Personal Data

A. The Overlap

  • Trade secrets often contain personal data: - Customer information. - Employee personal data. - Supplier data. - Personally identifiable financial data.
  • Privacy of personal data within trade secrets.
  • Cross-cutting compliance obligations.
  • Sensitive personal data special protections.

B. Trade Secret + Privacy Cases

  • Arjan Dugal v. Shubham Gandhi (Del HC 2025) — customer database (~6,000 clients) misappropriation.
  • Combination of trade secret + privacy violation considerations.
  • DPDP Act compliance for stolen customer data handling.
  • Cross-jurisdictional considerations for international cases.

7. AI Training and Privacy + Copyright

A. The Multi-Statutory Conflict

AI training data — IP and privacy intersection

AI training data raises BOTH copyright AND privacy issues: Copyright issues: · Training data may include copyrighted works. · Section 14 reproduction rights. · Section 52 fair dealing analysis. · ANI v. OpenAI pending. Privacy issues: · Training data may include personal data. · DPDP Act lawful basis required. · Web-scraped data complicates consent. · Right to erasure complications. · Cross-border data transfer rules. Both intersect in: · News articles (copyrighted + personal data of subjects). · Social media (UGC copyrighted + user personal data). · Public records (potentially copyrighted + personal data). Landmark case: ANI Media v. OpenAI (CS(COMM) 1028/2024) — judgment reserved 2025. Will define both intersections.

B. ANI Media v. OpenAI Implications

  • Copyright: AI training on news content.
  • Privacy: Training data contains personal data of news subjects.
  • Cross-border: US-based servers, Indian rights.
  • Section 52 fair dealing analysis.
  • DPDP Act application to training data.

8. Penalties and Enforcement

A. DPDP Act Penalties

500

₹ Cr

breach of children data

500

₹ Cr

breach SDF obligations

250

₹ Cr

breach security

200

₹ Cr

breach data principal rights

50

₹ Cr

breach voluntary undertaking

X

OTHER

specified

B. Enforcement Authority

  • Data Protection Board of India.
  • Investigation powers.
  • Penalty imposition.
  • Compliance directions.
  • Appeals to designated authority + High Court.

9. Strategic Considerations

For data fiduciaries (companies) — eight points

For IP enforcement involving personal data, document lawful basis.

For court orders, treat as primary authorization.

For consent-based processing, document clearly.

For data minimization, process only necessary IP enforcement data.

For security safeguards, implement DPDP Act standards.

For SDF designation, prepare comprehensive compliance program.

For breach notification, establish protocols.

For employee data, navigate combined IP + privacy framework.

For data principals (individuals) — six points

For consent withdrawal, exercise statutory right.

For access requests, leverage DPDP rights.

For correction/erasure, navigate process.

For grievances, escalate through proper channels.

For IP-related processing, understand legitimate use exemptions.

For court orders, recognize as authorization.

🎯 EXAM POINTERS — TOPIC 105

  • Justice K.S. Puttaswamy v. UoI (AIR 2017 SC 4161; (2017) 10 SCC 1) — right to privacy fundamental under Article 21.
  • Nine-judge Bench Constitution decision (24 August 2017).
  • DPDP Act 2023 — enacted 11 August 2023; effective stages from 2024-25.
  • DPDP replaces Section 43A IT Act + IT (Reasonable Security Practices) Rules 2011.
  • Data Fiduciary (controller); Data Processor; Data Principal (data subject).
  • Significant Data Fiduciary (SDF) — designated by Government.
  • Data Protection Board of India — statutory regulator.
  • Lawful bases: consent + legitimate use (legal proceedings exempt).
  • Rights of data principals: access, correction, erasure, grievance, nominate, withdrawal.
  • IT Rules 2021 + DPDP Act 2023 — overlapping intermediary frameworks.
  • Section 79 IT Act + Shreya Singhal — court order required for actual knowledge.
  • Penalties up to ₹250 crore (security); ₹500 crore (children data, SDF breaches).
  • Trade secrets + personal data — combined compliance obligations.
  • AI training raises both copyright + privacy issues.
  • ANI Media v. OpenAI (CS(COMM) 1028/2024) — copyright + privacy implications; judgment reserved 2025.
  • Right to be Forgotten — DPDP erasure right + Article 21 privacy framework.