Legal News
27 July 2026
IP & Technology

No Stay on DPDP Act: Supreme Court Sets the Stage for a Privacy vs. Transparency Showdown While Corporate India Scrambles

The Compliance Clock is Ticking: SC Refuses to Stay the DPDP Act For the Indian technology and corporate lawyer, the waiting game is officially over. On February 16, 2026, the Supreme Court of India fundamentally altered the immediate trajectory of t...

The Compliance Clock is Ticking: SC Refuses to Stay the DPDP Act

For the Indian technology and corporate lawyer, the waiting game is officially over. On February 16, 2026, the Supreme Court of India fundamentally altered the immediate trajectory of tech-law practice. While the apex court agreed to refer the constitutional challenges against the Digital Personal Data Protection Act, 2023 (DPDP Act) and its newly minted 2025/2026 Rules to a larger bench, it explicitly refused to stay the operation of the Act.

What does this mean for the practicing lawyer? It means you can no longer advise your clients to "wait and see what the Supreme Court does." The law is live, the final rules are operational, and the regulatory grace period is effectively dead. With the government confirming it will not introduce legislative amendments and will only rely on FAQs to smooth over administrative friction, the burden of navigating this poorly drafted legislation falls entirely on the shoulders of the legal fraternity.

The Heart of the Dispute: Section 44(3) and the Muzzling of the RTI Act

The core of the present Supreme Court litigation—spearheaded by the Reporters' Collective and journalist Nitin Sethi, followed by a fresh PIL in April 2026—strikes at the most insidious provision of the DPDP Act: Section 44(3).

To understand why this matters, we have to look at how Section 44(3) of the DPDP Act quietly butchered Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Previously, Section 8(1)(j) exempted personal information from disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified its release. It established a delicate proportionality test: a balancing act between the fundamental right to privacy (post-Puttaswamy) and the fundamental right to information.

Section 44(3) of the DPDP Act obliterates this balance. It amends the RTI Act to create a blanket exemption for any "information which relates to personal information."

"By removing the public interest caveat, the DPDP Act effectively weaponizes the right to privacy against democratic accountability. It hands government departments a statutory shield to reject virtually any RTI request that contains a name, an employee ID, or a designation."

For litigation lawyers, this is a watershed moment. The referral to a larger bench indicates the Supreme Court recognizes the severe constitutional friction between two competing fundamental rights under Article 19(1)(a) and Article 21. However, because there is no interim stay against the masking or deletion of available data, public authorities will immediately begin retroactively scrubbing government portals of "personal data" (like beneficiary lists or electoral affidavits) to claim DPDP compliance.

The "Dual-Reporting" Nightmare for Regulated Entities

While constitutional lawyers battle over Section 44(3), corporate and in-house counsel are facing an immediate operational crisis. As reported by the Economic Times, the notification of the final administrative rules in January 2026 has triggered panic across regulated sectors, particularly banking, insurance, and fintech.

The most pressing issue for practice is the emergence of a dual-reporting regime for data breaches. Until now, a cybersecurity incident required reporting to CERT-In within the draconian 6-hour window under the April 2022 Cyber Security Directions, and potentially to sectoral regulators like the RBI.

Now, Section 8(6) of the DPDP Act and the new rules mandate parallel reporting to the newly constituted Data Protection Board (DPB) and the affected Data Principals. For lawyers drafting Incident Response (IR) plans, this is a minefield.

Consider the practical implications:

  • Conflicting Timelines: Aligning the DPB breach notification timelines with CERT-In’s 6-hour rule without premature admission of liability.
  • Notice Fatigue vs. Liability: The new rules strictly require companies to explain why data is collected, allow users to refuse, and notify them of breaches. Over-notifying risks reputational damage; under-notifying invites DPB penalties that can scale up to ₹250 crores.
  • Sectoral Overlap: Banks are already undertaking massive gap assessments to reconcile RBI's Master Directions on IT Governance with the DPDP Act's data minimization mandates.

The Takeaway for Practitioners

The Supreme Court's refusal to grant a stay is a signal to the market: compliance is not contingent on constitutional clarity.

Lawyers must pivot from theoretical privacy debates to aggressive compliance enforcement. You must audit your clients' data collection touchpoints, revise every single consent artifact to ensure it meets the "freely given, specific, informed, unconditional, and unambiguous" threshold of Section 6, and prepare for immediate RTI rejections if your practice involves extracting data from state agencies.

The DPDP Act is no longer a looming threat. It is the reality of the Indian digital economy in 2026, and the cost of non-compliance will be measured not just in regulatory fines, but in the existential disruption of business operations.

Published by AnrakLegal AI