Privacy as a Cloak? Supreme Court Escalates DPDP vs. RTI Showdown to a 5-Judge Bench as Compliance Clock Ticks
The Supreme Court of India has just fundamentally altered the trajectory of India’s data protection jurisprudence. In a massive development this week, a bench led by Chief Justice Surya Kant referred a clutch of petitions challenging the Digital Pers...
The Supreme Court of India has just fundamentally altered the trajectory of India’s data protection jurisprudence. In a massive development this week, a bench led by Chief Justice Surya Kant referred a clutch of petitions challenging the Digital Personal Data Protection (DPDP) Act, 2023, and its newly minted 2025 Rules to a five-judge Constitution Bench. But for practicing corporate lawyers and in-house counsel, the real headline isn’t the referral—it is the Court’s explicit refusal to stay the operation of the Act and its Rules.
We are now staring at a dual-track legal reality: a looming constitutional showdown over the limits of transparency, and a relentless, ticking compliance clock for India Inc. that will not wait for the Supreme Court’s final word.
The Collision of Article 19(1)(a) and Article 21
At the heart of this litigation is a legislative sleight of hand. The petitions—spearheaded by the National Campaign for People's Right to Information (NCPRI) and Mazdoor Kisan Shakti Sangathan (MKSS)—zero in on Section 44(3) of the DPDP Act. This provision quietly amputated a critical limb of the Right to Information (RTI) Act, 2005, by amending Section 8(1)(j).
Historically, Section 8(1)(j) of the RTI Act protected personal information from disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It was a statutory balancing act between the citizen's right to know under Article 19(1)(a) and the right to privacy under Article 21.
"The DPDP Act destroys this delicate balance. By deleting the public interest override, Section 44(3) creates a blanket exemption. It effectively weaponizes 'privacy' to shield public officials from accountability."
This is a chilling development for transparency. If an RTI applicant asks for the beneficiary list of a state welfare scheme (like those hosted on Rajasthan’s Jan Soochna Portal) or the asset declarations of public servants, the state can now simply cite the DPDP Act and slam the door. The petitioners are rightfully demanding a retrospective restoration of the original Section 8(1)(j). The Supreme Court has rightly flagged this as a "complex" issue requiring a Constitution Bench, as it directly tests the boundaries of the landmark K.S. Puttaswamy judgment.
No Stay: The Corporate Counsel’s Nightmare
While the constitutional scholars prepare for a protracted battle in the Supreme Court, corporate and technology lawyers must deal with the immediate fallout. By declining to stay the 2025 Rules, notified late last year, the Supreme Court has greenlit the Ministry of Electronics and Information Technology’s (MeitY) phased rollout.
Let us be entirely clear: You cannot advise your clients to "wait and watch." The compliance timeline has been aggressively accelerated from 18 to 12 months, with a hard enforcement deadline of May 13, 2027. If you are representing hospitals, insurers, fintechs, or any entity qualifying as a Significant Data Fiduciary (SDF), the grace period is effectively over.
Drafting for the New Regime: What Changes in Practice?
The operationalization of the DPDP Rules means the era of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011—the infamous SPDI Rules—is dead. Here is what needs to change on your desk immediately:
1. The End of Boilerplate Contracts:
Commercial contracts drafted in 2026 must look fundamentally different. You can no longer rely on standard IT Act Section 43A indemnities. Data Processing Agreements (DPAs) now require granular DPDP-specific clauses delineating the exact roles of the Data Fiduciary and the Data Processor. If your client is outsourcing data processing, the contract must mandate strict vendor oversight, breach notification timelines, and conditional data transfer protocols. The Act treats consent as an ongoing fiduciary-principal relationship, meaning your indemnification clauses must account for downstream vendor failures.
2. Standalone Privacy Notices (Rule 3):
Privacy experts have already flagged massive compliance gaps in how companies are approaching Rule 3 of the 2025 Rules. Burying consent in a 50-page Terms of Service document will now attract severe penalties. Notices must be standalone, itemized, and available in multiple languages. If you are drafting privacy policies this week, they need to be decoupled from general terms and conditions.
3. The SDF Burden:
For clients classified as Significant Data Fiduciaries, the regulatory burden is astronomical. They must appoint an India-based Data Protection Officer (DPO), conduct periodic Data Protection Impact Assessments (DPIAs), and institute algorithmic oversight—especially critical for platforms utilizing AI.
The NHRC Wildcard and Multi-Forum Litigation
Adding fuel to the fire, the National Human Rights Commission (NHRC) has suddenly entered the fray, issuing notices over alleged DPDP violations by AI, social media, and edtech platforms. This is a massive tactical shift. It signals that data protection in India is no longer just a regulatory issue before the Data Protection Board; it is being viewed through a strict human rights lens.
For litigators, this means defending tech clients across multiple forums. A single data breach or algorithmic bias incident could now trigger investigations by MeitY, sectoral regulators (like the RBI or IRDAI), consumer courts, and human rights commissions simultaneously.
The Bottom Line
The Supreme Court’s referral to a five-judge bench sets the stage for the most consequential privacy litigation since Puttaswamy. However, the refusal to grant a stay is the real immediate directive for the legal profession. Privacy cannot be a cloak for bureaucratic opacity, but until the Constitution Bench says otherwise, the DPDP Act is the law of the land.
For practitioners, the mandate is clear: audit your clients' data pipelines, rewrite those commercial contracts, and prepare for a regulatory onslaught. The cost of data verification and compliance is skyrocketing, and the penalty for ignorance is simply too high to risk.
Tags
Published by AnrakLegal AI