Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

India's Domain Privacy Crisis: How a Delhi High Court Ruling Pits the DPDP Act Against Itself

A December 2025 Delhi High Court order could strip domain privacy from millions of Indian website owners. GoDaddy's July 16 appeal reveals a direct conflict with the DPDP Act.

D
DPDPBot Research Team
🕐 10 min read
A web globe icon beside a courthouse pillar losing glowing contact data strands
A web globe icon beside a courthouse pillar losing glowing contact data strands

#India's Domain Privacy Crisis: How a Delhi High Court Ruling Pits the DPDP Act Against Itself

A Delhi High Court order designed to crush phishing sites may end up exposing the home addresses of millions of ordinary Indian website owners — and it directly contradicts India's own landmark privacy law. On July 16, GoDaddy appeared before a larger bench of the Delhi High Court in a case that could determine whether the DPDP Act's privacy protections apply to the 80 million domains hosted in India, or whether a single trademark-enforcement ruling rewrites the rules of the global internet.

The stakes are not abstract. If the December 2025 order stands, any person — not just law enforcement — who claims a "legitimate interest" can demand the name, home address, phone number, and email address of any domain owner in India within 72 hours.


#What the December 2025 Ruling Actually Said

The case, Dabur India Ltd. v. Ashok Kumar (decided December 24, 2025), started as a straightforward trademark-infringement complaint. Over twenty companies — including Amazon, Microsoft, McDonald's, Colgate-Palmolive, Tata Sky, Amul, Bajaj Finance, and Meesho — complained that more than 1,100 fraudulent websites were impersonating their brands to run phishing and counterfeit-goods scams. Justice Prathiba M. Singh of the Delhi High Court agreed the problem was systemic and ordered the domains blocked under Section 69A of the IT Act.

So far, unremarkable. But the court went further, issuing 14 structural directives binding every domain registrar operating in India. The most consequential ones:

  1. End free WHOIS privacy. Registrars must stop offering domain privacy protection as a complimentary default feature. Owners who want their personal data masked must pay extra — or go without.
  2. 72-hour disclosure. Any party claiming a "legitimate interest" — a term the order does not define — can demand a registrant's full contact details. Registrars must comply within 72 hours.
  3. Mandatory e-KYC at registration. All new domain buyers must submit government-issued identity documents (Aadhaar, PAN, Passport) before a domain goes live.
  4. Proactive trademark blocking. Registrars must refuse domains that closely resemble protected trademarks — automatically, before registration is finalised.
  5. SERVERHOLD for unverified domains. Domains whose owners haven't completed KYC are placed on SERVERHOLD, rendering them unreachable.

India recorded 2.4 million cybercrime complaints in 2024, totalling roughly $2.4 billion in losses. The court's frustration with the scale of the fraud is understandable. Its chosen remedy, however, sweeps far beyond the 1,100 fraudulent domains it was trying to stop.


#GoDaddy's 5,121-Page Challenge — and Why the Number Matters

GoDaddy filed a 5,121-page appeal with a larger Delhi High Court bench. That document length is not an accident of lawyerly verbosity; it reflects how many registrants and scenarios the directives affect when applied globally.

GoDaddy manages 80 million domains across India and serves more than 20 million customers. Its core legal argument is structural: domain names resolve identically worldwide. GoDaddy cannot implement a split WHOIS regime — Indian registrants exposed, everyone else masked — because the technical architecture of the Domain Name System does not work that way. Complying with the order in India means changing WHOIS policy for every customer on every registrar platform it operates globally.

The company called the directives "commercially destabilising" and said they could force registrars to exit India entirely. Namecheap and Hosting Concepts (Registrar.eu) filed parallel appeals. The consolidated hearing before the larger bench was scheduled for July 16, 2026.

GoDaddy's privacy-specific argument deserves attention independent of the business concern: "Stopping privacy-by-default features will result in public disclosure of name, address, telephone and email of legitimate website owners, exposing them to foreseeable privacy and security risks such as stalking and harassment."

This is not a hypothetical. WHOIS databases are routinely scraped. Before ICANN instituted privacy-by-default norms in 2018, it was common for domain owners to receive unsolicited marketing calls, targeted phishing emails addressed to them by name, and in documented cases, in-person visits from individuals who had harvested their address from the public record.


#The DPDP Act Conflict No One Is Talking About Loudly Enough

Here is where the story becomes legally uncomfortable for the Indian government: the Delhi High Court order and the Digital Personal Data Protection Act 2023 are pulling in opposite directions, and both are simultaneously in force.

The DPDP Act's Section 6 requires that consent for personal data collection be "free, specific, informed, unconditional, and unambiguous." The court's order creates a system where a domain owner's personal data is disclosed on demand without their consent, to any entity that asserts — not proves — a legitimate interest. The disclosing party is the registrar, not the data principal. The data principal has no say, no notice, and no 72-hour window of their own.

The DPDP Act also embodies the principle of data minimisation: collect only what you need, retain only as long as required, share only on lawful grounds. Mandatory public disclosure of name, address, and phone number for every domain owner inverts that principle entirely. The Act's consent framework would class forced WHOIS disclosure as processing without consent and without a recognised alternative legal basis — the DPDP Rules 2025 do not include "a court order directing disclosure to private parties with unverified interests" as a standalone basis for data sharing.

The conflict with Europe's GDPR is equally sharp. Article 25 of the GDPR mandates privacy-by-default. EU-based registrars operating in India who comply with the Delhi High Court order would simultaneously violate a binding regulation in their home jurisdiction. Non-compliance in India risks Section 69A blocking. Compliance in India risks GDPR enforcement action. There is no clean path.


#Who Actually Gets Hurt If the Order Stands

The 1,100 phishing sites the order originally targeted are run by operators who have no reason to use accurate registration details in the first place. Fraudsters routinely use fake names, stolen identities, and offshore addresses. The e-KYC requirement and the 72-hour disclosure window will catch exactly zero of them while they are still useful; by the time a registrar receives a disclosure request, the phishing campaign has already run.

The people the order would expose are everyone else:

  • Independent journalists covering sensitive beats who register personal domains
  • Small business owners — India has more than 63 million MSMEs — who register .in or .com addresses for their shops or portfolios
  • Civil society workers and activists whose home addresses become one Google search away from anyone with a plausible grievance
  • Individual professionals — doctors, lawyers, freelancers — running personal practice websites
  • Anyone using a domain for a newsletter, a hobby project, or a family website

The court's trademark-variation blocking rule compounds the harm in a different direction. The order requires registrars to block domain names that "closely resemble" protected trademarks. GoDaddy's appeal cites the practical impossibility: common English words and syllables overlap with hundreds of registered trademarks. A person named McDonald cannot register a personal website under their own name. Blocking three-letter trademark variations would, by the registrar's own count, conflict with over 118 common English words containing those letter combinations.


#The Global Governance Dimension

Tech governance experts quoted in Reuters described the order as having "rewritten rules of internet governance" through a national court rather than through consensus bodies like ICANN. That description captures the deeper structural problem.

The Domain Name System has been governed since the late 1990s through a multi-stakeholder model — ICANN convenes governments, registrars, registries, civil society, and technical experts to set standards that apply globally. The UDRP (Uniform Domain-Name Dispute-Resolution Policy) gives trademark holders a credentialed, relatively swift mechanism to challenge infringing domains without requiring mass disclosure of registrant data.

India's court has bypassed that architecture entirely. A national tribunal has imposed obligations on global infrastructure through a bilateral ruling that affects every internet user who registers a domain with an India-operating registrar, regardless of where that user lives. If the larger bench upholds the directives, other national courts will notice. A ruling that "worked" for India becomes a template for courts in jurisdictions with far less concern for privacy to demand the same access to global registrant databases.


#What the DPDP Act Should Mean for This Ruling

The DPDP Act is not irrelevant to this case — it is potentially decisive. Counsel for GoDaddy and Namecheap have argued that the proportionality requirements of the Act were not correctly applied in the original judgment, and that a more recent reading of Section 6 and the data-minimisation obligations makes the 72-hour disclosure directive legally untenable.

The larger bench will need to answer whether the Act's right to informational self-determination — which the Supreme Court's 2017 Puttaswamy judgment recognised as a fundamental constitutional right — can be overridden by a trademark court's structural directions. That is not a narrow procedural question. It is a constitutional one.

The Data Protection Board of India, currently being constituted (MeitY invited applications for its Chairperson and four Members in May 2026), has not yet weighed in. When it does become operational, it will face a live question: does a court order requiring private-party data disclosure without data principal consent fall within the scope of DPDP Act enforcement? If the Board decides it does, it would create a direct institutional conflict between judicial and regulatory authority over personal data.


#What Businesses and Website Owners Should Watch

Until the July 16 hearing produces a written order — which typically takes several weeks — the December 2025 directions remain formally in force, even as registrars have effectively delayed compliance pending appeal. If you own or manage a domain registered through an India-operating registrar, here is what matters:

  • The KYC requirement is real. Registrars may begin requesting government ID verification before renewal cycles. Check whether your registrar has issued guidance.
  • Paid privacy protection is not currently available on most Indian-origin registrar platforms. If the order stands, it becomes a paid add-on — not a default protection.
  • Businesses with Indian users should verify that their consent management flows comply with both the DPDP Act's November 2026 Consent Manager deadline and the separate obligations created by any registrar compliance changes. Our consent manager resources cover the practical steps.
  • Legal teams at companies with India-facing web properties should review whether their domain registration vendor has filed a compliance plan or an appeal, and what that means for their own exposure under the 72-hour disclosure window.

The broader lesson from Dabur India v. Ashok Kumar is that India's data protection framework is not yet settled. The DPDP Act 2023 sets strong principles on paper. But those principles encounter a real world where courts handling cybercrime, trademark enforcement, and fraud may reach for blunt structural instruments that undercut the very privacy norms the Act is designed to protect. The July 16 hearing — and the written order that follows — will be one of the first serious tests of whether the DPDP Act's privacy-by-design logic can hold ground against a judiciary that is, with the best intentions, trying to clean up the internet one sweeping directive at a time.


#Conclusion

India is simultaneously building one of the world's most comprehensive data protection regimes and watching one of its courts potentially dismantle domain privacy for the global internet. The Delhi High Court's Dabur India ruling is not a rogue judgment — it responded to a genuine fraud epidemic. But its structural fix conflicts with the DPDP Act, the GDPR, ICANN norms, and basic principles of data minimisation that India's own lawmakers endorsed in 2023.

GoDaddy warning it may exit India's 80-million-domain market is not hyperbole. It is a registrar explaining, in the plainest possible commercial language, that it cannot operate when compliance in one jurisdiction means violating binding law in every other.

The July 16 hearing outcome will take weeks to reach a written order. When it does, it will tell us whether India's courts read the DPDP Act as a floor that cannot be cut through — or as background noise in a room where trademark rights currently speak louder than privacy.

To understand your own DPDP Act obligations as these rulings develop, explore the resources section or test your current consent setup with our DPDP consent manager.


Sources: GoDaddy appeal filings reported by Business Standard, Gizmodo, webhosting.today, KanoonPlus legal analysis, and GadgetReview. DPDP Act analysis based on the Digital Personal Data Protection Act, 2023, and the DPDP Rules 2025.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial