Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook β†’

AI in Indian Courts Meets the DPDP Act: The Judicial Data Gap Nobody Notified

The Supreme Court's draft AI-in-courts rules borrow DPDP language, but Section 17 exempts courts from the Act. Here's the gap that consultation exposed.

D
DPDPBot Research Team
πŸ• 10 min read

#AI in Indian Courts Meets the DPDP Act: The Judicial Data Gap Nobody Notified

The Supreme Court's draft rules for using artificial intelligence in courts quote the DPDP Act almost verbatim β€” purpose limitation, data minimisation, privacy by design, no training on personal data without approval. Yet the DPDP Act itself hands courts a broad exemption from exactly those obligations. That contradiction, largely ignored while the draft was being written, has become the central fault line now that the public consultation has closed. It is the most consequential unresolved question in Indian data protection this week, and it affects every litigant whose case file could one day be fed to a machine.

The DPDP Act and AI in Indian courts were drafted as if they lived in separate universes. The Digital Personal Data Protection Act, 2023 governs how organisations process personal data β€” but Section 17(1) carves out courts and tribunals almost entirely. The Supreme Court's Draft Regulations for Use of Artificial Intelligence in Courts, 2026, released for consultation on 3 June 2026, tries to import DPDP-style safeguards back into the judiciary by regulation. The result, as commentators writing this week have put it, is "regulatory dissonance": a statute that switches privacy protection off for courts, and a set of court rules trying to switch it back on without the force of law behind them.

#What just happened

On 3 June 2026, the Supreme Court's AI Committee published a preliminary draft titled "Regulations for Use of Artificial Intelligence in Courts, 2026" and opened it for public and stakeholder comment. After demand from the bar, technologists and civil-society groups, the Court extended the comment deadline to 15 July 2026. With that window now shut, the analysis phase has begun β€” and the sharpest submissions are all pointing at the same problem: the draft's relationship with the DPDP Act.

The draft is not a token gesture. It runs on real money β€” the government has allocated β‚Ή53.57 crore for technology, including AI, under e-Courts Project Phase III β€” and it lays down substantive rules. AI systems must be "trained and operated based on data that is accurate, representative, lawfully obtained" and free from discriminatory bias. AI may assist but never decide: the draft prohibits any system from determining case outcomes on its own, keeping the human judge as the "ultimate determinative authority." These are sensible principles. The trouble is where they collide with the statute they claim to respect.

#The Section 17 problem, in plain English

Here is the mechanism most coverage skips. The DPDP Act's Section 17(1) disapplies most of the Act β€” the notice-and-consent machinery, the data-principal rights, the core processing obligations β€” for "processing by any court or tribunal or any other body in India entrusted by law with judicial, quasi-judicial, regulatory or supervisory functions, where such processing is necessary" for those functions.

Read that carefully. When a court processes your personal data to adjudicate your dispute, the DPDP Act's protections largely do not apply. You cannot demand consent, you have no statutory right to erasure, and the Data Protection Board β€” which can levy penalties of up to β‚Ή250 crore on ordinary data fiduciaries β€” has no writ over the judicial processing itself. Section 17 exists for good reason: you cannot run a court on opt-in consent. But it was written for paper files and human clerks. It says nothing about what happens when that same exempt data is piped into a machine-learning system, indexed, embedded, and potentially used to train the next model.

That is the gap the draft AI rules fall into. They tell courts to apply DPDP principles. The DPDP Act tells courts they don't have to. A regulation cannot amend a statute, and the Board cannot enforce rules the Act exempts. So the safeguards in the draft β€” however well drafted β€” rest on the Supreme Court's own administrative authority, not on data-protection law. That is a materially weaker foundation than most litigants would assume when they hear "the AI rules comply with the DPDP Act."

#Where the draft borrows DPDP β€” and where it strains

The overlap is deliberate and, on paper, tight. According to a detailed analysis by M. G. Kodandaram on Naavi.org, the draft even adopts the DPDP Act's own vocabulary: Regulation 3(1)(s) imports the definition of "data" straight from Section 2(h) of the Act. Three provisions carry most of the weight:

  • Regulation 10 mandates purpose limitation, data minimisation and privacy by design β€” the DPDP Act's core hygiene principles.
  • Regulation 20 prohibits using personal data for AI training without prior approval and full DPDP compliance.
  • Regulation 48 restricts transfers of sensitive judicial data and requires encryption, access controls and annual cybersecurity audits.

The strain shows up the moment you ask who is responsible and on what legal basis. Two questions have no clean answer in the current draft:

Who is the data fiduciary? The DPDP Act defines a fiduciary as whoever "determines the purpose and means" of processing. In a courtroom running an AI tool, that could be the judge, the court's registry, the High Court's IT department, or the private vendor that built the system. A vendor might be a mere data processor following the court's instructions β€” or, if it decides how the model is trained and improved, an independent fiduciary in its own right. As the Naavi analysis notes, that distinction has "significant legal consequences" and demands "carefully structured contractual arrangements" that the draft does not yet mandate.

Can old consent stretch to new uses? Litigants hand over intimate details β€” medical records, financial statements, family disputes β€” because adjudication requires it, not because they agreed to feed a machine-learning pipeline. Whether the original disclosure can be read as consent to secondary AI training is, at best, doubtful. Under a consent-first regime like the DPDP Act, silence is not agreement. Under Section 17, the question may never even reach the Board.

#Why this matters beyond the courtroom

If you run a legal-tech company, this is your compliance map for the next 18 months. The vendors building court AI tools sit in a genuinely ambiguous zone: exempt-adjacent when acting for the judiciary, fully liable the moment they process the same data for their own product improvement. Getting the processor-versus-fiduciary line wrong is not a paperwork error β€” it is the difference between zero exposure and a Board inquiry that can reach β‚Ή250 crore. Any organisation deploying AI on litigation data should be mapping these roles now and building the consent and audit trails the Act demands where the exemption does not reach. Our /resources hub tracks the obligations that attach once you step outside Section 17's shelter, and a consent manager is the mechanism the DPDP framework expects for exactly the kind of downstream, secondary use that AI training represents.

For citizens and litigants, the stakes are more basic. Your case file is among the most sensitive dossiers the state holds about you. The draft rules are a real attempt to protect it β€” but because the DPDP Act exempts the courts, your protection depends on judicial self-regulation rather than an enforceable statutory right. That is a weaker guarantee than the one an ordinary consumer gets from a bank or an e-commerce app once the Act is fully in force.

#The courts have already been cautious β€” for good reason

India's judiciary has not been naΓ―ve about generative AI. The Punjab and Haryana High Court barred judicial officers from using ChatGPT, Gemini, Microsoft Copilot and Meta AI for writing judgments or conducting research, warning that violations "will be viewed seriously." The concern was twofold: hallucination β€” models producing confident, wrong answers β€” and privacy, since conversations with public AI tools are not confidential and providers like OpenAI have told courts they keep no servers in India, placing them beyond the reach of local confidentiality law. The Delhi High Court has separately held that ChatGPT output cannot form the basis for adjudicating legal or factual issues, and the Kerala High Court has issued its own AI guidelines.

Those precedents are the strongest argument for a national framework β€” and also the clearest illustration of why that framework needs statutory teeth. Ad-hoc High Court circulars are patchwork. A uniform regulation is better. But a regulation that depends on an exemption-riddled statute for its authority is still building on sand.

#How this compares abroad

The contrast with Europe is instructive. The EU's GDPR is a rights-based instrument with multiple lawful bases for processing and detailed, enforceable data-subject rights that follow the data wherever it goes β€” including, with carve-outs, into judicial contexts. India's DPDP Act, by design, is more growth-oriented and consent-centric, and it deliberately declines to recognise broad alternative bases like "legitimate interests." That streamlining is a feature for businesses that want clarity. But it also means that when a hard exemption like Section 17 switches the Act off, there is no residual "legitimate interests plus safeguards" layer to fall back on β€” the way GDPR often provides. The judicial-AI question exposes the cost of that simplicity: fewer moving parts, but also fewer backstops when a whole domain falls outside the frame.

#What should happen next

Commentators who filed submissions before the 15 July deadline are converging on a clear ask: don't paste DPDP language onto court rules and call it compliance β€” build a separate judicial data-protection architecture designed for the courtroom. Concretely, that means:

  • Mandatory AI-specific privacy impact assessments before any tool is deployed on litigation data.
  • Independent algorithmic audits for bias and fairness, not just the annual cybersecurity audit Regulation 48 already contemplates.
  • Prescribed retention timelines so case data does not sit indefinitely inside training corpora.
  • Clear liability allocation between courts and vendors, written into procurement contracts, so the fiduciary question is answered before deployment, not after a breach.
  • Litigant-facing procedural rights β€” at minimum, notice that AI was used and a route to challenge it.

None of this requires reopening the DPDP Act. It requires the Supreme Court's final regulations to stand on their own as a complete code, rather than borrowing authority they cannot actually inherit.

#The bottom line

India's data-protection machinery is finally live. The Data Protection Board has its chairperson and members, appointed in June 2026, and its grievance portal is running. Consent-manager registration opens on 13 November 2026, and full enforcement of most obligations is expected around 13 May 2027. Into that maturing framework, the judiciary is bringing AI β€” with real budgets, real draft rules, and real sensitivity. The one thing the framework does not yet do is reconcile the two. Section 17 turns the DPDP Act off for courts; the draft AI rules try to turn its principles back on by administrative fiat. Until that circle is squared β€” by a standalone judicial data-protection code with enforceable rights β€” every promise that court AI will "comply with the DPDP Act" carries an asterisk worth reading.

If your organisation touches litigation data, AI training pipelines, or court-facing legal tech, now is the moment to map your fiduciary status and lock down your consent and audit trails. Explore our compliance resources to see which obligations survive Section 17 β€” and which ones you cannot afford to assume away.


Sources: The Week β€” SC extends AI-rules consultation; Verdictum β€” Rethinking AI in Indian Courts; Naavi.org β€” DPDP implications for the draft AI regulations; DPDP Act Section 17 text; The Tribune β€” P&H High Court AI directive; PrivacyEngine β€” India–EU AI/privacy comparison.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready β€” all in one platform.

Start free trial