Legal News
16 June 2026
IP & Technology

No Stay, No Delay: The Supreme Court’s DPDP Referral Traps Tech Lawyers in a Compliance Purgatory

The Schrödinger’s Privacy Law The Supreme Court has officially punted the constitutional validity of the Digital Personal Data Protection (DPDP) Act, 2023, and the newly minted DPDP Rules, 2025, to a five-judge Constitution Bench. But the real headli...

The Schrödinger’s Privacy Law

The Supreme Court has officially punted the constitutional validity of the Digital Personal Data Protection (DPDP) Act, 2023, and the newly minted DPDP Rules, 2025, to a five-judge Constitution Bench. But the real headline for practicing lawyers is what the Court didn't do: it outright declined to grant an interim stay.

For TMT (Technology, Media, and Telecommunications) partners and in-house counsel, we are now operating in a paradoxical reality. We must advise clients to spend millions of rupees overhauling their digital architecture for a compliance regime that is simultaneously enforceable and existentially threatened. The fact that the Delhi High Court is hearing parallel PILs challenging multiple sections of the Act and Rules only adds to the jurisdictional chaos.

The Constitutional Crosshairs: Why the Law is Vulnerable

To understand the risk, we have to look at why the Supreme Court felt compelled to refer this to a larger bench. The primary challenge rests on fundamental rights—specifically Articles 14 (Equality), 19(1)(a) (Free Speech), and 21 (Right to Life and Personal Liberty).

The DPDP Act severely tests the limits of the proportionality doctrine laid down in the landmark nine-judge bench decision in Justice K.S. Puttaswamy (Retd.) v. Union of India. The most glaring vulnerability is Section 17(2)(a), which grants the Central Government unchecked power to exempt its own instrumentalities from the Act’s obligations in the name of sovereignty, state security, and public order.

"By insulating the State—the largest data fiduciary in the country—from the very privacy safeguards it imposes on private enterprises, the Act risks failing the Puttaswamy test of necessity and proportionality. A privacy law that exempts the government is a surveillance law by omission."

Furthermore, the broad scope of "Certain Legitimate Uses" under Section 7, which allows for the processing of personal data without explicit consent under vaguely defined government and employment contexts, is facing heavy fire. The delegated legislation in the DPDP Rules, 2025, notified in November, only expands on these administrative ambiguities rather than curing them.

The MeitY Squeeze: Compressing the Timeline

If the Supreme Court’s refusal to stay the law wasn't enough to induce panic, the Ministry of Electronics and Information Technology (MeitY) is turning the screws. Initially, the industry was promised a generous 18-month phased transition period. Now, sources confirm MeitY is actively considering compressing this timeline into aggressive immediate, 3-month, and 12-month staggered obligations.

The government's rationale is that Indian companies are already adhering to global norms like the GDPR, so they should be ready. Any tech lawyer worth their salt knows this is a fallacy. An Indian fintech startup or a domestic AI platform does not have the compliance machinery of a multinational corporation. The DPDP Rules dictate highly specific, localized mandates for consent managers, vernacular notice requirements (under Section 5), and stringent verifiable parental consent for processing children's data (under Section 9).

What You Should Be Advising Your Clients Right Now

When the CEO of a data-heavy digital platform asks you, "Should we spend ₹50 lakhs on gap assessments and consent tooling for a law that might be struck down?" your answer, unfortunately, must be an unequivocal yes.

Here is why, and how you should structure your counsel:

1. The Sword of Damocles (Section 33): The absence of a stay means the Data Protection Board (DPB) will become operational and can levy penalties. Under the Schedule to the Act, failure to take reasonable security safeguards can result in penalties up to ₹250 crores. You cannot risk your client facing a multi-crore penalty on the mere hope that a Constitution Bench will eventually read down the law.

2. Triage Your Compliance Rollout: Do not try to boil the ocean. If MeitY compresses the timeline, focus your clients on the highest-risk areas first: Consent Architecture: Immediately audit user journeys to ensure consent is free, specific, informed, unconditional, and unambiguous with a clear affirmative action (Section 6). Ensure the notice is available in the 22 languages listed in the Eighth Schedule. Data Breaches: Establish a rapid-response protocol for reporting personal data breaches to the DPB and the affected Data Principals (Section 8(6)). This is the most likely trigger for immediate regulatory action.

3. Audit "Legitimate Use" Claims: Many companies are overly relying on Section 7 to bypass consent. Advise your clients to strictly limit their reliance on "certain legitimate uses." Given that this section is a prime target for the Constitution Bench, over-leveraging it now could lead to massive historical non-compliance if the Court strikes it down or reads it down strictly.

The Verdict for Practitioners

The Supreme Court’s referral guarantees that India’s privacy jurisprudence will remain in a state of flux well into 2026. For lawyers, the task is no longer just interpreting the law; it is risk management in the face of immense regulatory uncertainty. We must prepare our clients for the letter of the DPDP Act today, while architecting their systems flexibly enough to adapt when the Constitution Bench inevitably redraws the boundaries of Indian privacy law tomorrow.

Published by AnrakLegal AI