Legal News
23 April 2026
IP & Technology

Constitutional Collision: SC Sends DPDP Act to a 5-Judge Bench, But Refuses to Stop the Compliance Clock

The Article 19 vs. Article 21 Showdown: A Legislative Sleight of Hand? In a move that forces a reckoning between India’s transparency framework and its nascent privacy regime, the Supreme Court has referred the constitutional challenges against the D...

The Article 19 vs. Article 21 Showdown: A Legislative Sleight of Hand?

In a move that forces a reckoning between India’s transparency framework and its nascent privacy regime, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023, to a five-judge Constitution Bench. But for practicing lawyers and in-house counsel, the real headline isn't the referral—it’s the Court’s point-blank refusal to grant an interim stay on the Act’s operation.

At the heart of this PIL—spearheaded by the Mazdoor Kisan Shakti Sangathan—is Section 44(3) of the DPDP Act. This provision quietly but aggressively amputates Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Previously, the RTI Act allowed public information officers to disclose personal information if the larger public interest justified it (e.g., exposing corruption, verifying the assets of babus and politicians, or scrutinizing public resource allocation). Section 44(3) of the DPDP Act obliterates this public interest test. Now, any personal information is categorically exempt from RTI disclosure.

This is a textbook constitutional collision. The petitioners rightly argue that this blanket exemption violates Article 19(1)(a) (the right to know, as a facet of free speech) and Article 14 (manifest arbitrariness). The State is effectively weaponizing Article 21 (the right to privacy, cemented in Puttaswamy) to shield public officials from accountability. As legal professionals, we must recognize this for what it is: the DPDP Act is not just regulating Big Tech; it is actively restructuring the citizen-state relationship. A Constitution Bench will now have to determine if this amendment survives the proportionality test.

"By removing the public interest override in the RTI Act, the legislature has created an ironclad privacy shield for public servants. Privacy was meant to protect the citizen from the State, not the State from the citizen."

No Interim Stay: The Compliance Sunk-Cost Dilemma

While the constitutional purists debate Articles 19 and 21, corporate lawyers are facing a more immediate, expensive reality. By declining to stay the DPDP Rules (notified in late 2025), the Supreme Court has effectively told India Inc. to keep the compliance engines running. With the initial 18-month rollout compressed and full enforcement looming by May 13, 2027, the grace period is over.

If you are advising clients in data-heavy sectors—healthcare, fintech, banking, or edtech—you cannot afford to hit snooze and wait for the Constitution Bench’s verdict. If the Supreme Court ultimately upholds the Act, or merely reads down the RTI amendment while leaving the corporate obligations intact, non-compliant entities will face crippling penalties. Millions of rupees are currently being poured into data mapping, re-architecting consent flows, and drafting standalone privacy notices under Rule 3.

For practitioners, the shift from the old Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 to the DPDP regime is seismic. Under the IT Rules, consent was often a one-time, click-wrap fiction. Under the DPDP Act, consent is an ongoing, verifiable relationship. Rule 3 mandates itemized, granular notices. If your client's UI/UX doesn't allow a user to withdraw consent as easily as they gave it, they are in breach.

Commercial Contracts in 2026: Beyond Boilerplate

The immediate practical fallout of the DPDP Act’s phased rollout is sitting on the desks of transactional lawyers. The days of slapping a standard boilerplate "compliance with applicable data laws" clause into Master Service Agreements (MSAs) are dead.

As we navigate 2026, commercial contracts must be forensically embedded with DPDP-specific clauses. Here is what needs to change in your drafting practice immediately:

1. The Data Fiduciary vs. Data Processor Divide: You must explicitly define who holds the liability. If your client is the fiduciary, your vendor agreements need aggressive audit rights and strict data destruction timelines.

2. Dual Breach Reporting: Currently, under the directions of the Computer Emergency Response Team (CERT-In), cyber incidents must be reported within 6 hours. The DPDP Act introduces a parallel obligation to notify the Data Protection Board (DPB) and the affected data principals. Indemnity clauses must now specifically cover the costs of this dual-regulatory reporting and the subsequent PR fallout.

3. Vendor Oversight: Privacy experts are already flagging severe gaps in third-party vendor compliance. Your contracts must mandate that downstream sub-processors adhere to the exact same DPDP standards as the primary processor.

Jurisdictional Creep: Enter the NHRC

Adding a fascinating wrinkle to the regulatory landscape is the recent intervention by the National Human Rights Commission (NHRC). With notices issued to AI platforms, social media giants, and edtech companies over alleged DPDP violations, the NHRC is flexing its jurisdictional muscles.

Why does this matter? Because the Data Protection Board (DPB) is still finding its operational footing. In this regulatory vacuum, other statutory bodies are treating data privacy as a fundamental human right violation under their own mandates. This means corporate litigators must now be prepared to defend data practices not just before the DPB or appellate tribunals, but potentially against human rights commissions wielding suo motu powers.

The Bottom Line: The Supreme Court’s 5-judge bench will eventually decide if the DPDP Act goes too far in gutting the RTI Act. But for the private sector, the law is already alive, biting, and demanding structural change. Advise your clients to draft, map, and comply as if the Act is written in stone. In the realm of data protection, waiting for judicial clarity is a luxury no business can afford.

Published by AnrakLegal AI