DPDP Act 2026: Supreme Court Refuses Stay, Forcing Corporate India into a Compliance Crucible While RTI Hangs in the Balance
The Ticking Clock: No Stay on the DPDP Act The Supreme Court has made its stance unequivocally clear: the Digital Personal Data Protection (DPDP) Act, 2023, and its much-debated 2025 Rules are here to stay, at least for now. By explicitly refusing to...
The Ticking Clock: No Stay on the DPDP Act
The Supreme Court has made its stance unequivocally clear: the Digital Personal Data Protection (DPDP) Act, 2023, and its much-debated 2025 Rules are here to stay, at least for now. By explicitly refusing to stay the operation of the Act while referring constitutional challenges to a larger bench, the Apex Court has sent a chilling, yet necessary, message to corporate India. If your clients are still relying on boilerplate privacy policies and pre-ticked consent boxes, they are walking blindfolded into a regulatory minefield.
For practicing Technology, Media, and Telecom (TMT) lawyers, the academic debates over the DPDP Act must now take a backseat to hard, operational reality. With the Data Protection Board of India (DPBI) already operational and Consent Manager registrations slated to open in November 2026, the runway for compliance has officially run out. Full enforcement in 2027 is no longer a distant threat; it is an imminent reality.
The Constitutional Clash: Privacy vs. Transparency
While corporate lawyers scramble to audit data flows, constitutional practitioners are watching a fascinating, high-stakes battle unfold. Petitions led by The Reporters’ Collective and journalist Nitin Sethi have zeroed in on the most insidious provision of the DPDP Act: Section 44(3), which amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005.
Before this amendment, Section 8(1)(j) allowed Public Information Officers (PIOs) to withhold personal information unless there was a larger public interest justifying its disclosure. It was a delicate balancing act birthed from the jurisprudence of both the RTI Act and the landmark K.S. Puttaswamy privacy judgment. The DPDP Act obliterates this balance. It replaces the public interest test with a blanket exemption: any personal information is now exempt from RTI disclosure.
"By removing the public interest override, the DPDP Act has effectively handed a golden shield to corrupt public officials. The right to privacy is being weaponized to kill the right to know."
The Supreme Court’s decision to refer this to a larger bench is legally sound, as it requires harmonizing two fundamental rights (Article 19(1)(a) and Article 21). But for journalists and transparency activists, justice delayed is transparency denied. Expect a severe chilling effect on investigative journalism relying on government data over the next year.
The AI Conundrum: What Exactly is "Public Data"?
During the hearings, the Supreme Court astutely flagged a massive gray area that every IP and tech lawyer is currently wrestling with: the demarcation between public data and personal data.
Under Section 3(c)(ii) of the DPDP Act, the law does not apply to personal data made publicly available by the Data Principal themselves or by any other person under a legal obligation. But what happens when a third party scrapes publicly available data (like a Twitter feed or a LinkedIn profile) to train a Generative AI model?
If an individual posts their phone number on a public forum, they have waived their DPDP protection for that specific data point. But if a data broker aggregates millions of such public data points to create a shadow profile, does it remain "public data"? The Act is dangerously silent here, and the 2025 Rules offer little comfort. Until the Supreme Court or the DPBI clarifies this, lawyers advising AI startups and ad-tech firms must adopt a conservative approach: treat scraped personal data as regulated personal data.
The Death of the Checkbox: Overhauling Consent Governance
The most immediate upheaval for practitioners advising Data Fiduciaries is the operationalization of Consent (Section 6) and Notice (Section 5). The 2025 Reuters report on India's new privacy rules confirms what we feared: the DPDP regime is fundamentally incompatible with the current architecture of the Indian internet.
Historically, Indian digital businesses have relied on "browsewrap" agreements or a single "I agree to the Terms and Privacy Policy" checkbox. Under the DPDP Act, this is legally defunct. Consent must now be free, specific, informed, unconditional, and unambiguous.
Here is what changes in practice for you and your clients:
- Unbundling Consent: You can no longer make access to a service conditional on consenting to non-essential data processing. If your client runs an e-commerce app, they can demand the user's address to ship a shirt. They cannot demand access to the user's contact list to sell them the shirt.
- Granular Notice: The Section 5 Notice must be an itemized, easily digestible breakdown of what data is collected and why. Legalese is out; plain-English (and vernacular) UI/UX is in.
- The Withdrawal Squeeze: The Act mandates that withdrawing consent must be as easy as giving it. If it takes one click to opt-in to promotional emails, it cannot take an email to customer support and a five-day waiting period to opt-out.
The Rise of Consent Managers
With the DPBI opening registrations for Consent Managers (Section 9) in November 2026, we are witnessing the birth of a new legal-tech sector in India. These entities will act on behalf of Data Principals to provide, manage, review, and withdraw consent through accessible platforms. Corporate lawyers must start drafting interoperability agreements and API terms of service to ensure their clients' platforms can "talk" to these Consent Managers seamlessly.
The Verdict for Practitioners
The Supreme Court's refusal to grant a stay is a wake-up call. The DPDP Act is not a piece of legislation you can comply with by merely updating a PDF on your client's website. It requires a fundamental re-architecting of data flows, marketing stacks, and UI/UX design.
If you are in-house counsel or an external TMT advisor, your immediate mandate is clear: stop treating privacy as a legal compliance checkbox and start treating it as an engineering problem. Map the data, rewrite the notices, and kill the dark patterns. The DPBI is awake, and the era of data impunity in India is officially over.
Tags
Published by AnrakLegal AI