Legal News
25 April 2026
IP & Technology

Constitution Bench to Test DPDP Act: The RTI Collision and the 14-Month Scramble for Corporate Counsel

The Ultimate Stress Test for India’s Privacy Regime The honeymoon period for the Digital Personal Data Protection (DPDP) Act, 2023, is officially over. In a move that every constitutional and technology lawyer should be tracking closely, a Supreme Co...

The Ultimate Stress Test for India’s Privacy Regime

The honeymoon period for the Digital Personal Data Protection (DPDP) Act, 2023, is officially over. In a move that every constitutional and technology lawyer should be tracking closely, a Supreme Court bench led by Justice Surya Kant has referred multiple challenges against the DPDP Act and its newly minted 2025 Rules to a five-judge Constitution Bench. Deeming the issues "complex but interesting," the Court has set the stage for the most significant data jurisprudence battle since Justice K.S. Puttaswamy v. Union of India.

But here is the catch for practicing lawyers: the Supreme Court explicitly refused to stay the operationalization of the DPDP Act or the 2025 Rules. For corporate counsel, this means the ticking compliance clock—now drastically shortened to a 12-14 month window ending around May 2027—cannot be ignored while waiting for constitutional clarity. We are now operating on dual tracks: high-stakes constitutional litigation on one end, and a frantic corporate compliance scramble on the other.

Weaponizing Privacy? The RTI Act Dilution

The most consequential aspect of the Constitution Bench referral is the PIL filed by the Mazdoor Kisan Shakti Sangathan, which strikes at the heart of Section 44(3) of the DPDP Act. To understand why this matters, one must look at how the DPDP Act surreptitiously rewrites the Right to Information (RTI) Act, 2005.

Prior to this amendment, Section 8(1)(j) of the RTI Act provided a nuanced balancing act. It exempted personal information from disclosure unless the Public Information Officer (PIO) was satisfied that a "larger public interest justifies the disclosure of such information." Section 44(3) of the DPDP Act obliterates this public interest test entirely, replacing it with a blanket exemption for any "personal information."

This is not a mere statutory tweak; it is a fundamental re-engineering of state accountability. By removing the public interest caveat, the state has effectively weaponized the shield of data privacy to mandate government opacity.

For lawyers practicing in administrative and constitutional law, this is a glaring regression. Proactive disclosures of beneficiary data, electoral rolls, and public servant assets—the bedrock of grassroots transparency—are now legally vulnerable. The Supreme Court's issuance of notices to the Centre and the Ministry of Personnel indicates that the Court recognizes the friction between Article 19(1)(a) (Right to Information) and Article 21 (Right to Privacy). If the Constitution Bench does not read down Section 44(3), the RTI Act stands functionally castrated.

The Corporate Reality: A 14-Month Sprint

While constitutional lawyers debate the RTI Act, transactional and in-house lawyers face a brutal operational reality. The notification of the DPDP Rules in November 2025 has shortened the grace period. Organizations now have barely 14 months (until May 13, 2027) to overhaul their data architectures.

If you are advising Global Capability Centres (GCCs), healthcare providers, or tech aggregators, the era of boilerplate privacy policies is dead. Here is how your practice needs to pivot immediately:

  • Data Processing Agreements (DPAs): Commercial contracts for 2026 must be aggressively renegotiated. Under the DPDP Act, the Data Fiduciary bears the ultimate liability for breaches by a Data Processor. Vendor indemnities, strict breach notification timelines (often moving from 72 hours to immediate reporting), and audit rights must be hardcoded into every tech and IP licensing agreement.
  • Consent Architecture Redesign: The Rules reimagine consent not as a static checkbox, but as a dynamic, ongoing relationship. Notice mechanisms must be multilingual, granular, and verifiable. If your client is relying on pre-2025 "clickwrap" agreements, they are staring down the barrel of massive penalties.
  • SDF Classification and AI Due Diligence: The intersection of DPDP and Artificial Intelligence is critical. Significant Data Fiduciaries (SDFs)—a category that will likely sweep up major AI and EdTech platforms—are mandated to conduct Data Protection Impact Assessments (DPIAs). The National Human Rights Commission (NHRC) has already issued notices over alleged DPDP violations by AI platforms. If your client’s algorithmic tools process personal data to train models, that data pipeline must be audited for "purpose limitation" immediately.

The Interplay with IP and Tech Transfers

Technology lawyers must also brace for the IP-DPDP overlap. When negotiating cross-border tech transfers or software-as-a-service (SaaS) agreements, data localization and cross-border transfer restrictions under the new government notifications will dictate the flow of intellectual property. Pseudonymisation and privacy-by-design are no longer just IT buzzwords; they are legal standards that must be embedded into the engineering architecture to claim safe harbor.

The Verdict for Practitioners

The Supreme Court’s decision to refer the DPDP Act to a Constitution Bench is a welcome intervention against the government's attempt to dilute transparency under the guise of privacy. However, a judicial stay is absent, and the regulatory guillotine is set for May 2027.

For the Indian legal fraternity, the mandate is clear: Litigate the constitutional overreach, but bill the hours to ensure your clients are compliant. The DPDP Act is no longer a looming legislative threat—it is an active, litigious, and commercially disruptive reality.

Published by AnrakLegal AI