Skip to content

This website does not advertise or solicit work, consistent with the Bar Council of India's rules for advocates. Continued use confirms you are seeking this information at your own request and that it does not create a lawyer–client relationship. Read the full disclaimer.

Sagar & Sagar Law Offices

Legal Analysis & Regulatory Commentary · Technology & Data

Two Deadlines and a Judgment: Data Protection Compliance and AI in Indian Legal Practice

· Sagar & Sagar Law Offices · 11 min read

India's Digital Personal Data Protection Rules were notified in November 2025, converting the Digital Personal Data Protection Act, 2023 from a passed statute into an operative compliance regime with a phased timeline running to full compliance in May 2027. Obligations fall principally on data fiduciaries — the entities that determine the purpose and means of processing personal data — and include notice and consent, security safeguards, breach intimation, retention limits and grievance redressal, with penalties under the Act extending to substantial amounts per contravention. Separately, in July 2026 the Supreme Court of India held in Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd. that citing AI-generated precedents without verification constitutes misconduct on the part of an advocate, and that a decision resting even partly on fabricated material cannot stand.

The regime is no longer prospective

For roughly two years after the Digital Personal Data Protection Act received assent in August 2023, it was reasonable for a compliance officer to treat data protection as a watching brief. The Act delegated most of its operative detail to subordinate rules, and until those rules existed there was little that could be implemented with confidence.

That position ended in November 2025, when the Rules were notified and the Act was brought into force on a staggered basis. The framework now runs in phases: the Data Protection Board has been constituted and core provisions are operative; a further tranche of provisions, including the registration framework for consent managers, follows approximately twelve months on; and full compliance is required at the outer date in May 2027.

Eighteen months sounds generous. It is not, and the reason is that the obligations are not documentary. A privacy notice can be drafted in a week. A consent architecture that actually records what a customer agreed to, for which purpose, at which point in time, and permits that consent to be withdrawn as easily as it was given, is a systems project. So is a retention policy that is genuinely enforced rather than merely written, in an organisation that has spent two decades keeping everything. Surveys of Indian enterprise readiness through 2026 have consistently reported that a substantial majority of organisations have limited practical understanding of what the regime requires of them — which is itself the most useful indicator of how long the work takes.

The obligations that most often require system change rather than document change are these: notice and consent in the prescribed manner; the ability to give effect to data principal rights, including access, correction and erasure; reasonable security safeguards; intimation of personal data breaches to affected individuals and to the Board within the timelines the Rules specify; retention and logging obligations; and a grievance redressal mechanism operating within defined outer limits. Entities notified as Significant Data Fiduciaries carry additional obligations, including audit and assessment requirements.

Cross-border transfer, it is worth noting, was resolved more permissively than the draft Rules had led many to expect. The framework operates on a restriction model in respect of notified jurisdictions rather than a general localisation mandate — a materially different compliance posture, and one that spared a great deal of infrastructure expenditure.

What this means, sector by sector

The regime applies horizontally, but its practical weight varies considerably by the kind of organisation it lands on.

Banks and financial institutions are, in one sense, the best prepared. They already operate under a dense regulatory framework — KYC and anti-money-laundering obligations, cyber security directions, outsourcing norms, and reporting requirements to the Reserve Bank of India — and they are institutionally accustomed to supervised compliance. The difficulty is different: banks hold enormous volumes of legacy personal data, gathered over decades under consent language that predates the Act entirely, distributed across core banking systems, branch records, recovery files, and the systems of business correspondents, direct selling agents and recovery agencies. The exposure is rarely in the current customer journey. It sits in the archive, and in the third-party chain. The obligations of the data fiduciary do not transfer to a service provider by contract.

Non-banking financial companies and fintech lenders face the sharpest version of this. Their customer acquisition is digital by default, which means consent is captured at the moment of onboarding and is auditable — an advantage. But the digital lending framework already imposes its own requirements on data collection, storage and access through lending applications and lending service providers, and those obligations now sit alongside the DPDP requirements. Where an NBFC's origination runs through a platform partner, the allocation of fiduciary and processor roles between them requires explicit documentation. In our experience this is the single most frequently unaddressed point in NBFC-platform arrangements.

Micro, small and medium enterprises present the mirror image. The Act contemplates a lighter touch for certain classes of entity, and an MSME processing modest volumes of employee and customer data is not in the position of a listed bank. But "lighter" is not "exempt", and two exposures recur. The first is employee data, which every MSME holds and which is frequently governed by no policy at all. The second is contractual: an MSME supplying a large corporate or a bank will increasingly find data protection warranties, audit rights and indemnities appearing in its customer contracts, because its customer is passing its own compliance obligations down the chain. For many MSMEs the DPDP regime will arrive commercially, through a procurement questionnaire, well before it arrives regulatorily.

Listed companies carry an additional dimension. Data protection failure is not solely a regulatory matter for them; it is a disclosure matter and a governance matter. Boards are expected to have oversight of material compliance risk, and a significant breach engages disclosure obligations, sustainability reporting narratives and directors' responsibility considerations simultaneously. The relevant question at board level is not only whether the organisation is compliant, but whether it can demonstrate that it took reasonable steps — which is a documentation and governance question as much as a technical one.

Corporates generally should be attending to vendor and processor chains. Most organisations discover, when they map processing for the first time, that personal data has reached considerably more third parties than anyone had assumed — payroll processors, CRM platforms, marketing agencies, analytics providers, cloud infrastructure, and the sub-processors those parties use in turn. The processing agreement that governs each of those relationships is where a great deal of unmanaged exposure currently sits.

Our approach across these client categories is consistent: establish what personal data actually exists and where it goes before drafting anything; distinguish obligations that can be met by policy from those that require system change, because only the latter need long lead times; document the allocation of roles with every processor and platform partner; and prepare breach response before a breach, since the notification timelines do not accommodate a period of internal debate about who decides.

The judgment that changed the AI conversation

On 2 July 2026, the Supreme Court of India delivered judgment in Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd. & Anr. (Neutral Citation: 2026 INSC 668), a bench of Justices P. S. Narasimha and Alok Aradhe.

The matter reached the Court from insolvency proceedings. A bank had initiated an application under Section 7 of the Insolvency and Bankruptcy Code, 2016 in respect of a defaulted facility supported by a corporate guarantee. The National Company Law Tribunal admitted the application, relying in its reasoning on a series of purported precedents. Several of those authorities did not exist. Others were real citations to which fabricated paragraphs or incorrect titles had been attached. The National Company Law Appellate Tribunal affirmed the order without detecting the problem. The financial creditor's affidavit indicated that its counsel had not cited the offending authorities — the tribunal had sourced them through its own research.

The Court set aside both orders and stated its position in unusually direct terms. Citing AI-generated precedents without verification, it held, amounts to misconduct on the part of an advocate. A judicial decision resting even partly on fabricated material cannot be treated as a decision at all and must be set aside. And significantly, the Court did not reject the technology: it recorded a resolve to adopt AI in aid of adjudication while asserting complete control over the adjudicatory process, with human involvement retained at every stage. It also directed the Bar Council of India to examine the placing of fabricated material before courts.

Three features of this decision deserve attention from anyone practising in this space.

First, the standard applied is misconduct, not error. That is a different category with different consequences, and it forecloses the argument that an unverified citation is an honest mistake.

Second, the failure originated with the adjudicating authority rather than counsel, and the Court treated that as aggravating the damage rather than excusing it. Verification is not a burden that sits with one side of the bar table.

Third — and this is the part most likely to be overlooked — the decision creates a checking obligation in the other direction. If an order, a show cause notice or a tribunal ruling adverse to a client contains a fabricated citation, that is now a ground of challenge in itself. Reading the authorities relied upon in an adverse order has become part of competent practice, not diligence beyond the call.

The Indian position did not appear from nowhere. Over the preceding two years, a tax tribunal recalled a substantial order after non-existent citations were identified in it; a High Court quashed an assessment resting on invented precedents; courts have physically verified citations against library holdings and authorised databases. The trajectory was clear well before July.

How we use these tools, and where we stop

We think it is fair for clients to ask a firm what it actually does with this technology, so we will answer it plainly.

The firm's most substantial technology adoption is unglamorous: optical character recognition applied to scanned records. A large part of banking, recovery and insolvency practice arrives as scanned paper — loan files running to several hundred pages, statements of account, security documentation, court records of varying legibility. Converting these into searchable, indexed text materially reduces two specific failure modes: the figure transcribed incorrectly from a poor scan, and the document that exists in the file but is never located because nobody could search it.

We use assistive tools for extraction, indexing, chronology assembly from dated material, deduplication across large document sets, and first-pass identification of relevant passages in voluminous records. These are retrieval and organisation functions. They shorten the distance between a lawyer and the relevant material.

We do not use them to generate legal conclusions, and we do not permit anything derived from them to reach a client, a counterparty or a court without verification against an authoritative source by a qualified lawyer. Every citation is confirmed in an authorised database before it is filed. Where a scan is degraded — and in this practice degraded scans are routine — any figure or clause reconstructed from it is flagged for confirmation against the original instrument before it is relied upon.

The reasoning is not technological caution for its own sake. It is that professional responsibility is not delegable to a tool. The Supreme Court has now said so in terms, and it said so in a matter arising from a bank's insolvency application before the NCLT — which is to say, in precisely the kind of proceeding this firm conducts. The same verification discipline applies on the other side of the border: our companion post on legal process outsourcing to India sets out how supervision and confidentiality are assessed in an offshore legal engagement.

What to do in the meantime

For data protection, the sequence that works is: map processing before drafting policy; separate what requires system change from what requires documentation; fix the processor and platform contracts, because that is where unowned risk accumulates; and rehearse breach response, because the timelines assume a decision-making structure already exists.

For AI, the discipline is narrower and simpler: use it for retrieval and organisation, verify everything against an authoritative source, and never let it near a legal conclusion unsupervised.

Both deadlines in the title are real. The judgment, unlike the deadlines, has already arrived.

This post is general commentary on developments in law and regulation and does not constitute legal advice, nor does it create an advocate–client relationship. Statutory provisions, notified dates and regulatory guidance are subject to change and should be verified against the position in force. For enquiries, see Technology, AI, Data Privacy & Cybersecurity, the firm's wider practice areas, or the Contact page.

FAQ

When is the DPDP compliance deadline in India?
The Digital Personal Data Protection Rules were notified in November 2025 and the Act has been brought into force on a staggered basis. Core provisions and the Data Protection Board are already operative; a further tranche, including consent manager registration, follows approximately twelve months later; and full compliance is required at the outer date in May 2027. Organisations should verify the specific commencement dates applicable to each provision.
Who is a data fiduciary under the DPDP Act?
A data fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data. Data fiduciaries carry the principal obligations under the Act, including notice, consent, security safeguards, breach intimation, retention limits and grievance redressal. A data processor processes personal data on behalf of a fiduciary under contract, and the fiduciary's obligations are not discharged by that contract.
Does the DPDP Act apply to MSMEs?
The framework contemplates a lighter set of obligations for certain classes of entity, but it does not exempt small businesses generally. Employee personal data is held by essentially every MSME and is frequently ungoverned. In addition, MSMEs supplying larger corporates and financial institutions increasingly encounter data protection warranties, audit rights and indemnities in their customer contracts, which impose the requirements commercially regardless of regulatory threshold.
What must a bank or NBFC do differently under the DPDP regime?
The principal challenges for regulated lenders are legacy data collected under pre-Act consent language, and the third-party chain comprising business correspondents, direct selling agents, recovery agencies and platform partners. For NBFCs and fintech lenders, obligations under the digital lending framework operate alongside DPDP requirements, and the allocation of fiduciary and processor roles between the lender and any platform partner requires express documentation.
What are the penalties for non-compliance?
The Act provides for financial penalties in respect of contravention, with the highest exposure attaching to failures of reasonable security safeguards, and penalties are assessed per contravention. The specific amounts and the adjudication procedure are set out in the Act and the Rules, and should be confirmed against the provisions in force.
Can lawyers in India use AI tools?
Yes, subject to verification. In Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd. (2026 INSC 668), the Supreme Court permitted responsible, human-controlled use of AI in aid of adjudication while holding that citing AI-generated precedents without verification amounts to misconduct on the part of an advocate. The operative requirement is independent verification of any AI-derived material against an authoritative source before it is used.
What happens to a judgment based on AI-hallucinated citations?
The Supreme Court has held that a decision resting even partly on fabricated or hallucinated material cannot be treated as a decision in the eyes of the law and must be set aside. In practical terms this also means that an adverse order, ruling or notice containing a fabricated citation may be challengeable on that ground.
Is there a dedicated AI statute in India?
There is no single dedicated statute governing artificial intelligence in India. AI deployment is regulated through existing frameworks — data protection, information technology law, sectoral regulation, consumer protection and contract — together with judicial pronouncements and guidance issued from time to time. Regulatory instruments concerning the use of AI in courts, and guidance for advocates, have been under development following the Supreme Court's directions.