DPDP Bill 2023 A Comparative Analysis
Introduction
THE DIGITAL PERSONAL DATA PROTECTION BILL, 2022 Released for Public Consultation on November 18, 2022THE DIGITAL PERSONAL DATA PROTECTION BILL, 2023Tabled at LokSabha on August 03. 2023Personal data may be processed only for a lawful purpose for which an individual has given consent. Consent may be deemed in certain cases.The 2023 bill imposes reasonable obligations on data fiduciaries and data processors to safeguard digital personal data.There is a Data Protection Board under the 2022 bill to deal with the non-compliance of the Act.Under the 2023 bill, there is the Establishment of a new Data Protection Board which will ensure compliance, remedies and penalties.
Under the new bill, the Board has been entrusted with the power of a civil court, such as the power to take cognisance in response to personal data breaches, investigate complaints, imposing penalties. Additionally, the Board can issue directions to ensure compliance with the act.The 2022 Bill grants certain rights to individuals, such as the right to obtain information, seek correction and erasure, and grievance redressal.The 2023 bill also grants More Rights to Individuals and establishes a balance between user protection and growing innovations. The bill creates a transparent and accountable data governance framework by giving more rights to individuals. In the 2023 bill, there is an Incorporation of Business-friendly provisions by removing criminal penalties for non-compliance and facilitating international data transfers.
The new 2023 bill balances out fundamental privacy rights and puts reasonable limitations on those rights.Under the 2022 bill, Personal data can be processed for a lawful purpose for which an individual has given his consent. And there was a concept of deemed consent.The new data protection board will carefully examine the instance of non-compliance by imposing penalties on non-compiler.The bill does not provide any express clarity in regards to compensation to be granted to the Data Principal in case of a Data Breach.Under 2023 Deemed consent is there in its new form as ‘Legitimate Users’.The 2022 bill allowed the transfer of personal data to locations notified by the government.There is an introduction of the negative list, which restricts cross-data transfer.
Related Blogs

Executive Summary:
This report deals with a recent cyberthreat that took the form of a fake message carrying a title of India Post which is one of the country’s top postal services. The scam alerts recipients to the failure of a delivery due to incomplete address information and requests that they click on a link (http://iydc[.]in/u/5c0c5939f) to confirm their address. Privacy of the victims is compromised as they are led through a deceitful process, thereby putting their data at risk and compromising their security. It is highly recommended that users exercise caution and should not click on suspicious hyperlinks or messages.
False Claim:
The fraudsters send an SMS stating the status of delivery of an India Mail package which could not be delivered due to incomplete address information. They provide a deadline of 12 hours for recipients to confirm their address by clicking on the given link (http://iydc[.]in/u/5c0c5939f). This misleading message seeks to fool people into disclosing personal information or compromising the security of their device.

The Deceptive Journey:
- First Contact: The SMS is sent and is claimed to be from India Post, informs users that due to incomplete address information the package could not be delivered.
- Recipients are then expected to take action by clicking on the given link (http://iydc[.]in/u/5c0c5939f) to update the address. The message creates a panic within the recipient as they have only 12 hours to confirm their address on the suspicious link.
- Click the Link: Inquiring or worried recipients click on the link.
- User Data: When the link is clicked, it is suspected to launch possible remote scripts in the background and collect personal information from users.
- Device Compromise: Occasionally, the website might also try to infect the device with malware or take advantage of security flaws.
The Analysis:
- Phishing Technique: The scam allures its victims with a phishing technique and poses itself as the India Post Team, telling the recipients to click on a suspicious link to confirm the address as the delivery package can’t be delivered due to incomplete address.
- Fake Website Creation: Victims are redirected to a fraudulent website when they click on the link (http://iydc[.]in/u/5c0c5939f) to update their address.
- Background Scripts: Scripts performing malicious operations such as stealing the visitor information, distributing viruses are suspected to be running in the background. This script can make use of any vulnerability in the device/browser of the user to extract more info or harm the system security.
- Risk of Data Theft: This type of fraud has the potential to steal the data involved because it lures the victims into giving their personal details by creating fake urgency. The threat actors can use it for various illegal purposes such as financial fraud, identity theft and other criminal purposes in future.
- Domain Analysis: The iydc.in domain was registered on the 5th of April, 2024, just a short time ago. Most of the fraud domains that are put up quickly and utilized in criminal activities are usually registered in a short time.
- Registrar: GoDaddy.com, LLC, a reputable registrar, through which the domain is registered.
- DNS: Chase.ns.cloudflare.com and delilah.ns.cloudflare.com are the name servers used by Cloudflare to manage domain name resolution.
- Registrant: Apart from the fact that it is in Thailand, not much is known about the registrant probably because of using the privacy reduction plugins.

- Domain Name: iydc.in
- Registry Domain ID: DB3669B210FB24236BF5CF33E4FEA57E9-IN
- Registrar URL: www.godaddy.com
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Updated Date: 2024-04-10T02:37:06Z
- Creation Date: 2024-04-05T02:37:05Z (Registered in very recent time)
- Registry Expiry Date: 2025-04-05T02:37:05Z
- Registrant State/Province: errww
- Registrant Country: TH (Thailand)
- Name Server: delilah.ns.cloudflare.com
- Name Server: chase.ns.cloudflare.com
Note: Cybercriminals used Cloudflare technology to mask the actual IP address of the fraudulent website.
CyberPeace Advisory:
- Do not open the messages received from social platforms in which you think that such messages are suspicious or unsolicited. In the beginning, your own discretion can become your best weapon.
- Falling prey to such scams could compromise your entire system, potentially granting unauthorized access to your microphone, camera, text messages, contacts, pictures, videos, banking applications, and more. Keep your cyber world safe against any attacks.
- Never reveal sensitive data such as your login credentials and banking details to entities where you haven't validated as reliable ones.
- Before sharing any content or clicking on links within messages, always verify the legitimacy of the source. Protect not only yourself but also those in your digital circle.
- Verify the authenticity of alluring offers before taking any action.
Conclusion:
The India Post delivery scam is an example of fraudulent activity that uses the name of trusted postal services to trick people. The campaign is initiated by using deceptive texts and fake websites that will trick the recipients into giving out their personal information which can later be used for identity theft, financial losses or device security compromise. Technical analysis shows the sophisticated tactics used by fraudsters through various techniques such as phishing, data harvesting scripts and the creation of fraudulent domains with less registration history etc. While encountering such messages, it's important to verify their authenticity from official sources and take proactive measures to protect both your personal information and devices from cyber threats. People can reduce the risk of falling for online scams by staying informed and following cybersecurity best practices.

Introduction
According to a new McAfee survey, 88% of American customers believe that cybercriminals will utilize artificial intelligence to "create compelling online scams" over the festive period. In the meanwhile, 31% believe it will be more difficult to determine whether messages from merchants or delivery services are genuine, while 57% believe phishing emails and texts will be more credible. The study, which was conducted in September 2023 in the United States, Australia, India, the United Kingdom, France, Germany, and Japan, yielded 7,100 responses. Some people may decide to cut back on their online shopping as a result of their worries about AI; among those surveyed, 19% stated they would do so this year.
In 2024, McAfee predicts a rise in AI-driven scams on social media, with cybercriminals using advanced tools to create convincing fake content, exploiting celebrity and influencer identities. Deepfake technology may worsen cyberbullying, enabling the creation of realistic fake content. Charity fraud is expected to rise, leveraging AI to set up fake charity sites. AI's use by cybercriminals will accelerate the development of advanced malware, phishing, and voice/visual cloning scams targeting mobile devices. The 2024 Olympic Games are seen as a breeding ground for scams, with cybercriminals targeting fans for tickets, travel, and exclusive content.
AI Scams' Increase on Social Media
Cybercriminals plan to use strong artificial intelligence capabilities to control social media by 2024. These applications become networking goldmines because they make it possible to create realistic images, videos, and audio. Anticipate the exploitation of influencers and popular identities by cybercriminals.
AI-powered Deepfakes and the Rise in Cyberbullying
The negative turn that cyberbullying might take in 2024 with the use of counterfeit technology is one trend to be concerned about. This cutting-edge technique is freely accessible to youngsters, who can use it to produce eerily convincing synthetic content that compromises victims' privacy, identities, and wellness.
In addition to sharing false information, cyberbullies have the ability to alter public photographs and re-share edited, detailed versions, which exacerbates the suffering done to children and their families. The study issues a warning, stating that deepfake technology would probably cause online harassment to take a negative turn. With this sophisticated tool, young adults may now generate frighteningly accurate synthetic content in addition to using it for fun. The increasing severity of these deceptive pictures and phrases can cause serious, long-lasting harm to children and their families, impairing their identity, privacy, and overall happiness.
Evolvement of GenAI Fraud in 2023
We simply cannot get enough of these persistent frauds and fake emails. People in general are now rather adept at [recognizing] those that are used extensively. But if they become more precise, such as by utilizing AI-generated audio to seem like a loved one's distress call or information that is highly personal to the person, users should be much more cautious about them. The rise in popularity of generative AIs brings with it a new wrinkle, as hackers can utilize these systems to refine their attacks:
- Writing communications more skillfully in order to deceive consumers into sending sensitive information, clicking on a link, or uploading a file.
- Recreate emails and business websites as realistically as possible to prevent arousing concern in the minds of the perpetrators.
- People's faces and voices can be cloned, and deepfakes of sounds or images can be created that are undetectable to the target audience. a problem that has the potential to greatly influence schemes like CEO fraud.
- Because generative AIs can now hold conversations, and respond to victims efficiently.
- Conduct psychological manipulation initiatives more quickly, with less money spent, and with greater complexity and difficulty in detecting them. AI generative already in use in the market can write texts, clone voices, or generate images and program websites.
AI Hastens the Development of Malware and Scams
Even while artificial intelligence (AI) has many uses, cybercriminals are becoming more and more dangerous with it. Artificial intelligence facilitates the rapid creation of sophisticated malware, illicit web pages, and plausible phishing and smishing emails. As these risks become more accessible, mobile devices will be attacked more frequently, with a particular emphasis on audio and visual impersonation schemes.
Olympic Games: A Haven for Scammers
The 2024 Olympic Games are seen as a breeding ground for scams, with cybercriminals targeting fans for tickets, travel, and exclusive content. Cybercriminals are skilled at profiting from big occasions, and the buzz that will surround the 2024 Olympic Games around the world will make it an ideal time for scams. Con artists will take advantage of customers' excitement by focusing on followers who are ready to purchase tickets, arrange travel, obtain special content, and take part in giveaways. During this prominent event, vigilance is essential to avoid an invasion of one's personal records and financial data.
Development of McAfee’s own bot to assist users in screening potential scammers and authenticators for messages they receive
Precisely such kind of technology is under the process of development by McAfee. It's critical to emphasize that solving the issue is a continuous process. AI is being manipulated by bad actors and thus, one of the tricksters can pull off is to exploit the fact that consumers fall for various ruses as parameters to train advanced algorithms. Thus, the con artists may make use of the gadgets, test them on big user bases, and improve with time.
Conclusion
According to the McAfee report, 88% of American customers are consistently concerned about AI-driven internet frauds that target them around the holidays. Social networking poses a growing threat to users' privacy. By 2024, hackers hope to take advantage of AI skills and use deepfake technology to exacerbate harassment. By mimicking voices and faces for intricate schemes, generative AI advances complex fraud. The surge in charitable fraud affects both social and financial aspects, and the 2024 Olympic Games could serve as a haven for scammers. The creation of McAfee's screening bot highlights the ongoing struggle against developing AI threats and highlights the need for continuous modification and increased user comprehension in order to combat increasingly complex cyber deception.
References
- https://www.fonearena.com/blog/412579/deepfake-surge-ai-scams-2024.html
- https://cxotoday.com/press-release/mcafee-reveals-2024-cybersecurity-predictions-advancement-of-ai-shapes-the-future-of-online-scams/#:~:text=McAfee%20Corp.%2C%20a%20global%20leader,and%20increasingly%20sophisticated%20cyber%20scams.
- https://timesofindia.indiatimes.com/gadgets-news/deep-fakes-ai-scams-and-other-tools-cybercriminals-could-use-to-steal-your-money-and-personal-details-in-2024/articleshow/106126288.cms
- https://digiday.com/media-buying/mcafees-cto-on-ai-and-the-cat-and-mouse-game-with-holiday-scams/
.webp)
Introduction
The rise of artificial intelligence has transformed how individuals search for information, buy and compare products online. Unlike the traditional search engines like Google that presents the user with a set of links and directs users to websites, AI-powered systems provide synthesised answers and recommendations which means we don't have to click through every link to find what we are looking for, we simply have to ask an LLM and it provides recommendations based on our needs expressed through prompt. This development has raised important legal and commercial questions, one such question was addressed in the judgement of Indiamart Inter Mesh Limited v. Open AI Inc. and Others (2026 SCC OnLine Cal 5738) decided by HMJ Ravi Krishan Kapur of Calcutta High court on 20 May 2026. If an AI platform becomes a primary source of information, can a business demand inclusion in its responses? Is it a legal injury if the LLM omits a business? More fundamentally, how do the existing laws classify technologies that not only process information, but also generate new content? These were the questions that came before Calcutta High Court. Although the dispute arose from Indiamart’s complaint regarding visibility on ChatGPT search, the judgement explored beyond the disagreement between two private entities.
The Dispute
IndiaMart is one of India’s largest electronic business-to-business marketplaces since 1996, serving millions of buyers and sellers across India. They also have registered trademarks and their entire business depends on visibility on the internet considering the digitalisation of the market. Open AI launched ChatGPT search in October 2024, which is a feature that supplements AI responses with links to relevant web sources. Indiamart alleged that ChatGPT was not displaying links to their online platform in the same way that it displayed links to other competing services or individual sellers. A major grievance raised by Indiamart was that ChatGPT allegedly bypassed IndiaMart market listings by directing users to sellers’ individual websites while continuing to provide platform level links for other competing platforms. Hence, they contended that this practice diverted users away from their platform and negatively affected their business interests. The company argued that such exclusion amounted to discriminatory treatment and resulted in economic harm, diluted its trademarks and amounted to disparagement. They alleged that it violated their rights under article 14, 19, 21 under the constitution and rights under IT Act and IT Rules also. When IndiaMart sought an explanation from OpenAI, the company stated that its decision was influenced by the inclusion of IndiaMart in the United States Trade Representative (USTR) Review of Notorious Markets for Counterfeiting and Piracy 2024, a U.S. government report that identifies online and physical marketplaces alleged to facilitate intellectual property infringements. IndiaMart challenged this justification, arguing that the USTR report has no statutory or binding force in India. It further alleged selective discrimination, pointing out that several other platforms featured on the same USTR list including DHGate, Pinduoduo, Shopee, and Taobao continued to remain accessible through ChatGPT-generated responses. Consequently, IndiaMart approached the Calcutta High Court seeking interim relief directing ChatGPT to display and provide access to IndiaMart links in its responses.
ARGUMENTS BEFORE THE COURT
IndiaMart's contentions: They argued that ChatGPT, because its search feature, performs the role of an "intermediary" within the meaning of Section 2(1)(w) of the IT Act and is therefore required to comply with the obligations imposed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Relying on Rule 3(1)(n), IndiaMart argued that an intermediary cannot engage in discriminatory treatment of platforms or selectively restrict access to information. IndiaMart further maintained that users have a right to access information relating to its platform and that the omission of IndiaMart links from ChatGPT's responses violated this interest. They alleged violation of Articles 14, 19, and 21 of the Constitution, along with the broader principle of a user's "right to know", to argue that OpenAI owed an obligation to display IndiaMart listings in response to relevant queries. In addition, IndiaMart alleged that the exclusion of its links caused commercial harm, diluted its trademarks, amounted to disparagement, and constituted an unfair trade practice that adversely affected its business and reputation.
OpenAI's contentions: OpenAI asserted that IndiaMart had no legally enforceable ‘Right to visibility’ on ChatGPT. They argued that neither contract, statute, nor constitutional law imposed any obligation on OpenAI to display, prioritise, or recommend IndiaMart links in response to user queries. In the absence of any recognised legal right, there could be no actionable injury and therefore no valid cause of action. OpenAI also challenged the classification of ChatGPT as an "intermediary" under the Information Technology Act, 2000. According to OpenAI, ChatGPT does not merely host, transmit, or facilitate access to third-party content but also generates responses through its large language model (LLM) and therefore functions more closely as an "originator" than an intermediary. Consequently, the obligations applicable to intermediaries under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, including those relied upon by IndiaMart, were inapplicable. With respect to the USTR Notorious Markets List, OpenAI submitted that its reliance on the report formed part of its internal risk-management and business policies. Such decisions, it argued, were matters of private commercial judgment and not ordinarily subject to judicial review. OpenAI further pointed out that IndiaMart had also previously blocked ChatGPT from accessing and crawling its website that weakened the company's demand for greater visibility within ChatGPT-generated responses.
Court’s decision: The court rejected Indiamart's claim that they were entitled to be displayed in ChatGPT searches. The court emphasised the autonomy of private businesses, the court held that the right to carry on trade and business is "inviolable" and that no law can compel one private entity to operate their platform for the benefit of another, which is based on foundational economic philosophy of laissez faire. Unless there is a contractual, statutory or constitutional obligation, a platform has no duty to the other platform to promote or advance their economic interest. Applying this principle, the court found no such duty or “vested legal right” that entitled IndiaMart’s visibility on ChatGPT. The court reasoned that even if users possess the ‘right to know’, Indiamart could not convert that interest into an enforceable claim under article 19(1)(g) or other legal provision. The court looked at the dispute as one arising from commercial disadvantage rather than violation of any legally protected right. Although the reduced visibility may have had economic consequences, economic harm does not by itself create a cause of action.
The court also took into consideration whether ChatGPT should be classified as an intermediary under Section 2(1)(w) of the Information Technology Act, 2000 or as an originator under Section 2(1)(za). This was an important distinction, because the intermediaries can claim safe harbour protection under section 79 of the IT act, but the originators cannot. The court expressed a preliminary view that ChatGPT is generative capabilities, place it closer to an originator than an intermediary because, unlike conventional search engines, which identify and rank existing information, Generative AI systems, analyse the data and produce new output based on algorithms, which is in response to the user’s prompt. The Court also referenced the NITI Aayog National Strategy for Artificial Intelligence (pages 7 to 12) to support its observations that ChatGPT does not merely store, host or transmit information, it can produce essays, research material, code, creative writing, and other forms of content that did not previously exist in that exact form, hence extending beyond the conventional understanding of an intermediary. The court also recognised that it is a vexed issue and remains unsettled because AI systems operate in response to users instructions and do not function independently, which is why the court refrained from providing a definitive classification and acknowledged that the question may ultimately require legislative clarification as well.
In addition to this, the Court took the view that the IndiaMart’s grievances did not amount to an Intellectual property dispute, as they found no trademark infringement or dilution because any reference to the "IndiaMart" mark was merely descriptive and did not constitute commercial use "in the course of trade" under Section 29(4) of the Trade Marks Act. IndiaMart also hadn’t demonstrated any false or misleading use of its trademark.
Similarly, the Court found that claims of disparagement, trade libel, and injurious falsehood were unsustainable because such claims require the publication of a false statement that harms reputation and since ChatGPT had not published any derogatory statement about IndiaMart, the mere omission of links could not amount to disparagement or libel. The Court relied on Tech Plus Media v. Jyoti Janda, that allegations of unfairness or copyright infringement must be supported by specific pleadings and evidence.
Beyond the immediate dispute, the judgment shed light on the growing difficulty of applying legal categories created for an earlier internet era to generative AI systems. The Information Technology Act was enacted at a time when internet regulation focused primarily on websites, service providers, and electronic communications and therefore existing classifications may not adequately address the hybrid nature of contemporary AI technologies. The Court acknowledged OpenAI's concern that granting IndiaMart's request could trigger floodgates of litigation on similar claims from businesses dissatisfied with AI-generated visibility, however, it clarified that such concerns cannot outweigh genuine legal claims or fundamental rights. The Court suggested that legislative intervention may eventually be necessary.
Conclusion
This judgement not only addressed the visibility issue in AI generated responses, but also whether visibility itself can become a legally protected interest in AI-driven searches? As more and more users rely on AI generated output for their preference rather than traditional search engine output, the power to decide what information is displayed and what is not will eventually become economically significant. The Calcutta High Court through this judgement declined to create any such right through judicial interventions and also highlighted that the existing legal framework is not adequately equipped to address the novel challenges posed by generative AI.
(This blog is based on the judgment in Indiamart Inter Mesh Limited v. Open AI Inc. and Others, 2026 SCC OnLine Cal 5738, decided on May 20, 2026 by the Calcutta High Court, and related reporting by LiveLaw and SCC Times.)
References
- https://www.livelaw.in/high-court/calcutta-high-court/no-right-to-visibility-exists-on-private-ai-platforms-calcutta-high-court-refuses-to-direct-chatgpt-to-display-indiamart-links-536891
- https://www.scconline.com/blog/post/2026/06/03/chatgpt-intermediary-originator-it-act-calcutta-high-court/
- https://indiankanoon.org/doc/198449710/