Frequently Asked —
Litigation & Corporate Advisory.

Advocate Vishal Akshintala practices both litigation before Telangana courts and corporate advisory across AI governance, data privacy, cybersecurity, and space law. Every answer below references the specific statute, section, article, or standard clause it rests on — the standard applied whether the matter is before a court, a regulator, or a boardroom.

Litigation & Disputes DPDPA 2023 AI Governance Cross-Border Privacy Cybersecurity Law Space Law AI Governance Training Emerging Issues Hyderabad Coverage
Litigation & Disputes

Who should I contact for a data privacy or cyber dispute in Hyderabad?

Advocate Vishal Akshintala handles both litigation and corporate advisory in data privacy, AI governance, cybersecurity, and space law matters — practicing before Hyderabad and Telangana courts, and advising organizations globally, affiliated with Radhical Global Attorneys.

How do I file a data protection grievance under DPDPA 2023?

First raise it with the entity's designated Grievance Officer under Section 13. If unresolved within the statutory window, it can be escalated to the Data Protection Board of India. Legal representation at the grievance stage materially affects the strength of the record if the matter proceeds further.

What is the Data Protection Board of India, and how do I approach it?

The adjudicatory body under DPDPA 2023 that handles complaints, investigates breaches, and can impose penalties on Data Fiduciaries. Complaints are typically filed after internal grievance channels are exhausted; the process is evidence-based and benefits significantly from advocate representation.

Can I sue a company in India for misusing my personal data?

Possible routes include a DPDPA grievance, escalation to the Data Protection Board, or in appropriate cases a civil suit. Which path fits depends heavily on the facts — an advocate familiar with both the statute and how early Board decisions have approached similar matters can assess this properly.

What should a company do when it receives a legal notice over a data breach?

Preserve the incident timeline and internal communications immediately, avoid informal admissions before counsel review, and check whether CERT-In's six-hour reporting window has already been triggered. Litigation posture and regulatory posture need to be managed together from the first notice, not sequentially.

What does representation before the Telangana High Court in a technology dispute involve?

Technology and data disputes reaching the High Court typically involve either a challenge to a lower forum's order, a writ concerning a regulatory action, or a commercial dispute with a technology-specific factual record (data flows, system logs, contractual terms) that needs to be built and argued carefully.

Can a business file a criminal complaint and pursue civil recovery simultaneously in a data-theft matter?

Yes — a criminal complaint under the IT Act does not bar a parallel civil suit for damages, and pursuing both is often the correct strategy: the criminal process compels investigation and evidence-gathering that strengthens the civil claim, while the civil suit is the actual route to financial recovery.

What is anticipatory bail, and when is it relevant in a cybercrime matter?

Anticipatory bail under Section 482 of the Bharatiya Nagarik Suraksha Sanhita (successor to Section 438 CrPC) allows a person who reasonably apprehends arrest to seek protection from custody in advance. In cybercrime matters, it is often the first and most time-sensitive step once a complaint or FIR becomes known, since it allows cooperation with the investigation without custodial risk.

DPDPA 2023

What is a Data Fiduciary under India's DPDPA 2023?

Any entity that determines the purpose and means of processing personal data — broadly equivalent to a "data controller" under GDPR. Section 8 sets out general obligations: data accuracy, security safeguards, breach notification.

How quickly must a data breach be reported under DPDPA?

Notification to the Data Protection Board and affected Data Principals is required on timelines set out in the Act's rules; breach-readiness programs are typically built around a 72-hour internal escalation window to match global norms like GDPR.

Can personal data be transferred outside India under DPDPA?

Permitted except to specifically restricted countries — a narrower, more permissive model than GDPR's adequacy-and-SCC framework. Entities operating across both regimes still need SCC-aligned contracts for EU-facing flows.

What are the penalties for DPDPA non-compliance?

The Act allows the Data Protection Board to impose financial penalties on Data Fiduciaries for specified failures, with amounts scaled to the nature and severity of the breach or non-compliance, decided case by case rather than a fixed schedule.

Does DPDPA apply to a foreign company with no office in India?

Yes — the Act applies to processing of personal data of individuals in India even where the processing itself occurs outside India, if it relates to offering goods or services to those individuals.

AI Governance & EU AI Act

What counts as a "high-risk" AI system under the EU AI Act?

Article 6 classifies an AI system as high-risk based on intended purpose and sector — employment, credit scoring, biometric identification, education, and critical infrastructure among them. Classification determines which obligations apply.

Does the EU AI Act apply to a company based in India?

Yes, if the system's output is used within the EU market, regardless of where the provider is established. This extraterritorial scope is a common gap for Indian AI companies expanding into Europe.

What is ISO/IEC 42001, and is it mandatory?

The international standard for AI management systems. Not legally mandatory in most jurisdictions, but increasingly requested during enterprise and investor due diligence as evidence of structured AI governance.

What does an AI governance audit actually produce?

A documented risk classification per AI system, a gap analysis against applicable frameworks, and a prioritized remediation roadmap — an artifact regulators or diligence teams expect to see, not a general compliance statement.

Who is legally responsible when an AI system makes a harmful decision?

Liability typically traces through the provider, the deployer, and in some structures a third-party integrator, depending on where the harmful behavior actually originated in the pipeline. Contractual allocation of this liability, done in advance, is usually far cheaper than litigating it after the fact.

Cross-Border Privacy

What's the difference between a privacy policy and privacy-by-design?

A privacy policy is a disclosure document. Privacy-by-design is an engineering practice — building consent architecture and data minimization into the product from the start, so the policy actually reflects how the system behaves.

Do I need separate privacy compliance programs for India, EU, and US operations?

Not necessarily separate programs, but the underlying obligations differ enough (DPDPA's more permissive cross-border rules versus GDPR's adequacy-and-SCC model versus CCPA's opt-out model) that a single generic policy usually fails at least one jurisdiction's specific requirements.

What is a Data Protection Impact Assessment, and when is one required?

A structured risk assessment for processing activities likely to result in high risk to individuals — required under GDPR for certain categories, and good practice under DPDPA even where not strictly mandated, particularly for AI-driven processing.

Cybersecurity Law

What triggers CERT-In breach reporting obligations in India?

CERT-In's 2022 directions require reporting of specified cybersecurity incidents within six hours of becoming aware of them, via CERT-In's incident reporting portal — a materially shorter window than most global standards.

What's involved in a legal audit of an AI pipeline?

Reviewing vendor contracts for liability allocation, checking data provenance and consent chains feeding the model, and confirming incident-response coverage extends to AI-specific failure modes like hallucination or adversarial manipulation.

Can a company be held liable for a ransomware attack under Indian law?

Potentially, if inadequate security safeguards contributed to the breach — DPDPA's Section 8 obligations and IT Act provisions can both be engaged, alongside contractual liability to affected customers or partners.

Space Law

Who is responsible in law for an AI decision made by a satellite system?

Article VI of the 1967 Outer Space Treaty holds states internationally responsible for national space activities, including private operators — creating layered liability alongside AI-specific governance obligations.

How is space law relevant to a company running AI on satellites?

Orbital data infrastructure sits at the intersection of space law (state responsibility, licensing, jurisdiction) and AI governance (risk classification, liability). Very few advisors cover both — that overlap is often the actual gap.

AI Governance Training

What is an AI governance training program for legal teams?

A structured program — one-on-one or cohort — that builds practical fluency in AI regulation (EU AI Act, ISO/IEC 42001, DPDPA) so an in-house legal team can classify AI systems and review AI vendor contracts without escalating every question externally.

How is this different from a generic AI-for-lawyers course?

Generic courses teach tool usage — prompting, drafting assistance. This training builds regulatory fluency: reading an AI Act risk tier, spotting a liability gap in a vendor contract, knowing when a system needs a DPIA.

Emerging Issues

What is a "digital arrest" scam, and is it legally recognized?

"Digital arrest" is not a recognized legal process under Indian law — no law enforcement agency conducts arrests over video call. It refers to a fraud pattern in which scammers impersonate police, customs, or CBI officials via video call to coerce victims into transferring funds under threat of a fabricated arrest. Any such call should be treated as fraud, reported at cybercrime.gov.in or via helpline 1930, and no payment should be made regardless of claimed authority.

Are deepfakes illegal in India?

There is no standalone "deepfake law" yet, but deepfake content can attract liability under the IT Act (Sections 66C, 66D on identity theft and impersonation), the Bharatiya Nyaya Sanhita provisions on defamation and cheating, and DPDPA where personal data (including biometric likeness) is used without consent. MeitY has also issued advisories requiring platforms to label AI-generated content.

Who owns the copyright in AI-generated content in India?

Indian copyright law requires human authorship; the Copyright Act does not currently recognize an AI system as an "author." Content generated with substantial AI involvement occupies a genuinely unsettled area, and the safer commercial practice is documenting the human creative and editorial contribution to any AI-assisted work intended for commercial use.

Can an employer use AI to make hiring or termination decisions in India?

There is no specific statutory prohibition, but an AI-driven decision that produces a discriminatory outcome can still trigger liability under existing labor and constitutional-equality principles, and DPDPA obligations apply to the personal data the system processes. Employers deploying AI in HR decisions should maintain human review and a documented rationale, not rely on the AI output as self-justifying.

Does Section 79 safe harbor under the IT Act protect AI platforms?

Section 79 intermediary safe harbor was designed for platforms hosting third-party content, and its application to generative AI platforms — which produce rather than merely host content — is genuinely contested and not yet settled by courts. Providers should not assume safe harbor automatically extends to AI-generated outputs.

Are there data localization requirements for training AI models on Indian user data?

DPDPA does not impose blanket data localization, but sector-specific rules (notably RBI's data localization requirements for payment data) do apply where relevant, and using such data to train an AI model without addressing the original consented purpose can itself be a DPDPA violation, independent of localization.

Is facial recognition technology legal for use by private companies in India?

No specific statute currently bars private facial recognition use, but its deployment falls squarely under DPDPA as processing of personal (and potentially sensitive biometric) data, requiring a valid legal basis, purpose limitation, and — depending on context — explicit consent.

Telangana & Pan-India Coverage

Litigation is not limited to Hyderabad — matters are taken up across all of Telangana, and pan-India as required. Advisory work is global.

Hyderabad

Hitech CityGachibowliMadhapurKondapurBanjara HillsJubilee HillsSecunderabadKukatpallyBegumpetSomajigudaAmeerpetFinancial District

Telangana Districts

WarangalKarimnagarNizamabadKhammamNalgondaRangareddyMedchal-MalkajgiriSangareddyMahabubnagarAdilabadSiddipetNagarkurnoolJagtialSuryapet

Beyond Telangana

Litigation: matters outside Telangana are taken up on a case-by-case basis, with availability confirmed through an online appointment prior to engagement.

Corporate advisory and AI governance training: conducted for organizations across India, the EU, UK, US, and APAC, regardless of location.