A Ghost Regulator and Activist Courts: Why the DPDP Act is Bleeding Before it Breathes
For corporate counsel and technology lawyers in India, the current trajectory of the Digital Personal Data Protection (DPDP) Act, 2023 is resembling a slow-motion car crash. As we approach the tail-end of 2026, the legislative framework that promised...
For corporate counsel and technology lawyers in India, the current trajectory of the Digital Personal Data Protection (DPDP) Act, 2023 is resembling a slow-motion car crash. As we approach the tail-end of 2026, the legislative framework that promised to drag Indian data privacy into the 21st century is suffering from a severe case of regulatory negligence.
The Data Protection Board of India (DPBI)—the beating heart of the DPDP enforcement mechanism under Section 18 of the Act—exists on paper but remains embarrassingly unstaffed. Yet, the clock is ticking. With the Consent Manager framework slated for November 2026 and substantive compliance obligations going live by May 2027, companies are being forced to build compliance architectures in the dark.
But nature, and the Indian legal system, abhors a vacuum. In the absence of a functional Board, the Constitutional Courts have seized the reins, actively reshaping the boundaries of consent, digital identity, and AI data usage. For practicing lawyers, relying solely on the bare act is no longer an option; the real DPDP jurisprudence is being written right now through writ petitions.
The APAAR Pushback: A Death Blow to "Forced Consent"
The Supreme Court’s recent intervention in the APAAR (Automated Permanent Academic Account Registry) matter is a massive wake-up call for EdTech companies and data fiduciaries dealing with children's data. The Centre and the CBSE were pushing a digital student registry, essentially strong-arming participation.
The Supreme Court didn't just frown upon this; it explicitly directed the Centre to revise the consent forms to include an unequivocal right for parents or guardians to refuse or opt out, whilst heavily restricting third-party data sharing.
"The right to informational privacy, birthed in Puttaswamy, is not a right you can condition upon the receipt of basic educational services."
Why this matters for your practice: If you are drafting privacy policies or consent architectures under Section 6 (Consent) and Section 9 (Processing of personal data of children), the APAAR directive is your new baseline. The state’s attempt to bypass explicit, freely given consent failed. If the government cannot rely on implied or coerced consent for a public registry, your private sector client absolutely cannot make service delivery contingent on blanket data-sharing. Review your clients' "Deemed Consent" (Section 7) classifications immediately—if it involves minors, it is legally radioactive.
The Section 44(3) Collision: Privacy vs. Transparency
Perhaps the most intellectually fascinating—and practically disruptive—litigation currently before the Supreme Court is the challenge to Section 44(3) of the DPDP Act. This provision notoriously amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005, creating a blanket exemption for the disclosure of all personal data, stripping away the public interest override that existed previously.
The Supreme Court has recognized the gravity of this statutory collision, referring the RTI amendment challenges to a larger bench. Furthermore, a separate writ has sought interim relief against the masking or deletion of currently available public data under the guise of DPDP compliance, and the Court has issued notice.
The litigation strategy: For lawyers handling RTI appeals against public authorities, do not accept the DPDP Act as an absolute shield just yet. Public Information Officers (PIOs) are currently using Section 44(3) as a lazy excuse to deny every information request. Until the larger bench rules, you must argue that the DPDP Act cannot retrospectively obliterate transparency mandates, and cite the pending interim relief applications to stay any mass data-deletion exercises by state authorities.
Digi Yatra and the Aadhaar Fallacy
Down South, the Kerala High Court has taken up the mantle against stealth data-harvesting in the aviation sector. Taking a prima facie view on the Digi Yatra privacy concerns, the Court reiterated a foundational, yet frequently ignored, legal principle: Aadhaar is not mandatory if another valid ID proof is available.
This is a direct application of the proportionality test and a strict reading of the Aadhaar Act, 2016. Fiduciaries cannot force biometric authentication when less intrusive means (like a PAN or Voter ID) suffice. If your client is building physical access control systems or digital onboarding flows, forcing Aadhaar-based e-KYC without an alternative is an invitation to a writ of mandamus.
The AI Blindspot: Inferences as Personal Data
While the courts tackle state surveillance, the private sector is sleepwalking into an intellectual property and privacy minefield: Generative AI. Recent legal commentary highlights a massive DPDP blind spot regarding employee AI use.
When an employee uploads a client dataset or a photograph into an enterprise LLM, who is liable for the inferences drawn? If an AI system infers a user’s medical condition or sexual orientation from a seemingly benign photograph, does that constitute processing of personal data without consent?
The answer is increasingly yes. Under the DPDP Act, "processing" includes any operation performed on digital personal data. If an AI infers personal attributes, the Data Fiduciary is strictly liable under Section 8 for failing to implement reasonable security safeguards.
Immediate action required: Technology lawyers must immediately draft and enforce "Shadow IT and AI Acceptable Use Policies" for their corporate clients. Your employment contracts need indemnification clauses specifically targeting unauthorized data inputs into public LLMs. The IP leakage is bad enough; the impending DPDP fines for unauthorized automated processing could be fatal.
The Bottom Line
We are staring down a May 2027 compliance deadline with an unstaffed Data Protection Board and a statute that is actively being rewritten by the Supreme Court. The advice to clients cannot be "wait for the Board's rules." By the time the DPBI is functional, the judicial precedents will have already cemented the compliance standards. Draft defensively, prioritize explicit opt-outs, and treat generative AI as a primary vector for data breaches.
Tags
Published by AnrakLegal AI