Home About Services Jurisdictions Insights FAQs Contact Us Client Login Terms & Conditions Privacy Policy Get a Quote →
Home › Insights › Patent Strategy for Privacy-Enhancing Computation: Framing Technical Effect under Indian Patent Law
09/25/2026 4:01 PM

Patent Strategy for Privacy-Enhancing Computation: Framing Technical Effect under Indian Patent Law

Introduction : For a founder building a fraud-detection or underwriting system on banking or health data, model accuracy is only part of the problem. How the data is handled during computation, and whether that process can withstand regulatory scrutiny, matters just as much. India's Digital Personal Data Protection Act, 2023 has sharpened this tension: businesses increasingly need to extract value from data while paying closer attention to how that data is processed.

Secure multiparty computation (SMPC) allows multiple parties to work together on computations without disclosing their individual data. Homomorphic encryption (HE) enables calculation on data that has been encrypted. Trusted execution environments (TEEs) keep sensitive operations isolated in secure hardware settings.

However, these technologies face challenges under Indian patent law. Because they rely heavily on mathematics, algorithms, and software, they often bring Section 3(k) of the Patents Act, 1970 into consideration. If these technologies are applied in sectors like lending, insurance, or healthcare, Section 3(m) could pose additional hurdles. Each claim likely involves an algorithm at its core, raising the essential question of whether the proposed technical arrangement offers a significant technical effect beyond just that algorithm.

The Legal Framework

Section 3(k) specifies that "a mathematical or business method or a computer program per se or algorithms" cannot be patented. The phrase "per se" is crucial here because it implies that the presence of software alone doesn’t automatically disqualify an invention from being patentable if it demonstrates a technical effect.

Section 3(m) addresses another concern by excluding "a mere scheme or rule or method of performing a mental act or method of playing a game." This section becomes pertinent when the commercial activity involved, such as credit scoring or underwriting, is central to the patent claim.

For years, IPO practice ran on the 2017 CRI Guidelines, which asked examiners to look for a "technical effect" without ever quite defining the term.

The examination process has also been updated recently. The 2017 guidelines on computer-related inventions were replaced with the Revised Guidelines for Examination of Computer Related Inventions in 2025, which were put into effect on July 29, 2025. These new guidelines aim to provide a more structured way to handle exclusions related to computer programs, algorithms, and business methods. It’s essential for intellectual property applications to align with this updated framework.

Patent Law

When Does a PEC Invention Become Technical?

The challenge with obtaining patents for privacy-enhancing computational (PEC) inventions lies in their inherently mathematical nature. For instance, federated learning gathers local data inputs, SMPC breaks input data into confidential parts, HE conducts calculations on encrypted information, and TEEs use secure hardware isolation to operate. An examiner will often find an algorithmic component in nearly all PEC inventions, which doesn’t automatically determine patentability. What truly matters is what the specific technical arrangement accomplishes.

For PEC inventions, technical effect may appear through:

  • reduced transmission of raw or sensitive data through local computation, encryption or aggregation;
  • a secret-sharing architecture that achieves a defined security property through system operation;
  • ciphertext-domain computation combined with a specific mechanism for controlling noise growth or managing cryptographic parameters;
  • hardware-backed attestation that verifies code integrity before access to protected memory;
  • improvements in efficiency, convergence, fault tolerance or communication overhead attributable to a particular technical arrangement.

A useful approach for drafting claims is to remove the business goal from the claim. If a functional technical mechanism still exists, it's easier to establish its technical character. Conversely, if the claim centers around a business decision, like determining if someone should receive a loan, there's a risk of objections under Sections 3(k) and 3(m).

What the Courts Have Said

Ferid Allani v. Union of India, 2019 SCC OnLine Del 11867, remains central to India's approach to computer-implemented inventions. The Delhi High Court held that Section 3(k) targets computer programmes claimed "per se" and recognised the relevance of technical effect.

In Microsoft Technology Licensing, LLC v. Assistant Controller of Patents and Designs, 2023 SCC OnLine Del 3465, the Delhi High Court emphasised that the claims and specification must be read together and rejected the proposition that patentability necessarily requires novel hardware. An improvement in the functioning of existing hardware can itself constitute a technical contribution.

Raytheon Company v. Controller General of Patents, Designs and Trade Marks also rejected a novel-hardware requirement, focusing instead on technical effect over the prior art.

The business-method exclusion remains distinct. In OpenTV Inc. v. The Controller of Patents and Designs, 2023:DHC:3305, the Delhi High Court treated Section 3(k)'s business-method exclusion as independently applicable. Technical sophistication cannot rescue a claim whose substance remains a method of doing business.

Priya Randolph v. Deputy Controller of Patents and Designs, 2023:MHC:5450, provides a useful counterpoint. The Madras High Court held that the presence of a business context does not by itself defeat patentability where a hardware-software-firmware combination makes a genuine technical contribution.

The Blackberry Limited matters, C.A. (COMM-IPD-PAT) 229/2022 and 318/2022, show the same thing from another angle: how the specification treats the alleged technical contribution.

The US Supreme Court's Alice Corp. v. CLS Bank International, 573 U.S. 208 (2014), offers a comparative perspective through its abstract-idea framework.¹⁷ Foreign patentability tests should not, however, be imported mechanically into Indian prosecution.

The pattern across these cases points to one practical proposition: build the patent around the technical arrangement that produces the privacy, security or computational improvement, not around the underlying mathematical idea.

Drafting Claims That Survive the Objection

A claim stating "a method of performing privacy-preserving analytics" focuses on the outcome rather than the technical process, leaving it vulnerable to Section 3(k) objections. A stronger claim should detail the technical architecture. For instance, it may describe how data is divided into secret shares at a client device, sent to uncolluding nodes, evaluated using a defined arithmetic process, and then reconstructed when certain conditions are met.

The same principle applies to TEE-related inventions. If the innovation relies on a secure enclave or hardware-backed attestation process, the pertinent hardware-software interaction must be clear in the claims. For claims related to HE, it’s vital to identify technical features that carry out the tasks effectively, like noise management or managing ciphertext parameters, rather than simply mentioning "performing calculations on encrypted data."

When creating claims for industries that are heavily regulated, such as finance or healthcare, it can be beneficial to draft layered claims. This means starting with broader claims related to the PEC mechanism and then specifying narrower dependent claims that focus on particular applications in banking, health, or insurance.

For regulated industries, layered claims can be useful: broader claims directed to the PEC mechanism, followed by narrower dependent claims incorporating the particular banking, healthcare or insurance application.

Enablement and Prior Art

When it comes to cryptographic inventions, clarity is key. Vague terms like "encrypted" or "secret-shared" aren’t sufficient for someone skilled in the field to reproduce the claimed effects. A patent application should provide meaningful technical specifics, including the relevant techniques and processes involved, such as the encryption method or the MPC protocol. Providing pseudocode or practical examples can enhance the application’s strength.

It’s also important to differentiate between claiming a known cryptographic method and its application in a new context. Just placing a known encryption technique inside a new commercial product won’t make it novel. Often, the innovation may rest in how that method is adapted for a specific technical challenge.

Consequently, prior art searches should go beyond traditional patent databases. Research involving PEC is often published quickly in academic publications, standards documents, and technical repositories, and even open-source projects can be pivotal for determining prior art relevance. Relying only on patent databases like InPASS or Espacenet may miss critical information impacting the novelty of a claim.

Strategic Choices for Startups

For startups focused on privacy-enhancing technologies, their patent strategy should reinforce their approach to data protection rather than replace it. The technical documentation needed to submit a robust patent application can also help outline data flows, processing methods, and security measures necessary for compliance and due diligence.

Not every technical feature requires patent protection. Features that are difficult to reverse-engineer from a product—like certain key-management approaches—might be better safeguarded through trade secrets, whereas patents are valuable for mechanisms that can be observed or reconstructed by competitors.

Filing in India can also pave the way for future PCT proceedings and national phase applications, which makes it prudent to consider international options early in the drafting process. Startups recognized by the DPIIT may also qualify for expedited examination under the Indian Patents Rules.

Conclusion

PEC inventions navigate complex waters within Indian patent law, where cryptography and mathematics intersect with commercial activities. Sections 3(k) and 3(m) certainly present challenges for drafting, but they do not make PEC inventions automatically unpatentable. The best approach is to clarify the technical arrangement that delivers the desired privacy, security, or computational benefits and ensure that this arrangement is clear throughout the entire patent specification and claims.

For PEC startups, that comes down to technical precision in the drafting itself, and to deciding early which parts of the technology are worth patenting and which are better kept as trade secrets. More technology-specific guidance on cryptographic inventions would make this area easier to navigate as Indian patent practice develops.

Author :- Samvidha Rastogi, in case of any query, contact us at Global Patent Filing or write back us via email at support@globalpatentfiling.com.

  1. Digital Personal Data Protection Act, 2023 (India).
  2. Peter Kairouz et al., Advances and Open Problems in Federated Learning, 14 Foundations & Trends in Machine Learning 1 (2021).
  3. Patents Act, 1970, § 3(k) (India).
  4. Patents Act, 1970, § 3(m) (India).
  5. Patents Act, 1970, §§ 10(4)–(5), 25, 64 (India).
  6. Guidelines for Examination of Computer Related Inventions (CRIs), 2017 (superseded).
  7. CGPDTM, Revised Guidelines for Examination of Computer Related Inventions (CRIs), 2025 (29 July 2025).
  8. Yehuda Lindell & Benny Pinkas, Secure Multiparty Computation for Privacy-Preserving Data Mining, 1 J. Privacy & Confidentiality 59 (2009).
  9. Alexander Wood, Kayvan Najarian & Delaram Kahrobaei, Homomorphic Encryption for Machine Learning in Medicine and Bioinformatics, 53(4) ACM Computing Surveys 1 (2020).
  10. NIST, Privacy-Enhancing Cryptography Project, Computer Security Resource Center.
  11. Ferid Allani v. Union of India, 2019 SCC OnLine Del 11867.
  12. Microsoft Technology Licensing, LLC v. Assistant Controller of Patents and Designs, 2023 SCC OnLine Del 3465.
  13. Raytheon Company v. Controller General of Patents, Designs and Trade Marks, 2023 SCC OnLine Del 2029.
  14. OpenTV Inc. v. The Controller of Patents and Designs, 2023:DHC:3305.
  15. Priya Randolph v. Deputy Controller of Patents and Designs, 2023:MHC:5450.
  16. Blackberry Limited v. Controller of Patents and Designs, C.A. (COMM-IPD-PAT) 229/2022 & 318/2022 (Del. H.C., 2024).
  17. Alice Corp. Pty. Ltd. v. CLS Bank International, 573 U.S. 208 (2014).
  18. Patent Cooperation Treaty, Washington, 19 June 1970 (as amended).
  19. Patents Rules, 2003, r. 24C (India).
  20. Press Information Bureau, Government of India, Patent Office Releases Revised Guidelines for Examination of Computer Related Inventions (CRIs), 2025 (29 July 2025).
  21. S. Chatterjee, Intellectual Property Rights for Software, Artificial Intelligence and Computer Related Inventions: A Comparative Analysis, 29(1) J. Intell. Prop. Rts. (2024).
  22. S. Balasubramanian, Exploring the Landscape of Software Patents in India, 13(1) Int'l J. Intell. Prop. Rts. 1 (2023).
  23. Cyril Amarchand Mangaldas, Scope of Business Method Inventions under Section 3(k), India Corporate Law (Mar. 2024).
← Back to All Insights