Legal News
1 September 2026
IP & Technology

Privacy as a Shield Against Transparency: SC Refuses to Stay DPDP Act while a 'Phantom' Data Board Leaves India Inc. in Limbo

For practicing lawyers navigating India's technology and privacy landscape, advising clients right now feels like building a house on quicksand. On February 16, 2026, the Supreme Court took up a batch of highly anticipated petitions challenging the c...

For practicing lawyers navigating India's technology and privacy landscape, advising clients right now feels like building a house on quicksand. On February 16, 2026, the Supreme Court took up a batch of highly anticipated petitions challenging the constitutional validity of the Digital Personal Data Protection (DPDP) Act, 2023 and the newly minted DPDP Rules, 2025. While the Court rightly acknowledged the gravity of the issues by referring the matter to a larger bench, it dropped a hammer on immediate hopes for regulatory relief: there will be “no question of stay” on the legislation.

The refusal to grant interim relief, coupled with the glaring administrative vacuum at the newly established Data Protection Board of India (DPBI), creates a massive compliance paradox. We are now operating under a fully enforceable data protection regime overseen by a phantom regulator, while simultaneously witnessing the systematic dismantling of India’s transparency laws.

The Evisceration of the RTI Act: Section 44(3) Under Fire

At the heart of the Supreme Court challenge is Section 44(3) of the DPDP Act, a Trojan horse provision that quietly amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005.

Historically, Section 8(1)(j) protected personal information from RTI disclosure unless the Public Information Officer (PIO) was satisfied that the larger public interest justified the disclosure. It was a delicate, judicially tested balancing act between privacy and transparency. Section 44(3) of the DPDP Act took a sledgehammer to this balance, deleting the "public interest" override entirely. Now, if information qualifies as "personal data," it is absolutely exempt from RTI disclosure—full stop.

"By removing the public interest caveat, the State has effectively weaponized the fundamental right to privacy to shield itself from accountability. The distinction between public data and private data has been deliberately blurred."

The Supreme Court has indicated it will examine this exact distinction between public and private data. A separate plea has rightfully sought interim relief against the masking or deletion of data already available in public records. But without a stay, what does this mean for practitioners?

Practice Pointer: If you are advising government departments or entities qualifying as "State" under Article 12, the immediate directive is defensive compliance. PIOs are already weaponizing the amended Section 8(1)(j) to reject RTI applications en masse. Litigators representing journalists, activists, or corporate intelligence firms must now pivot to arguing that the requested information does not meet the threshold of "personal data" under Section 2(t) of the DPDP Act, rather than arguing public interest.

A Phantom Regulator: The Headless DPBI

If the RTI amendment is the legal fire, the administrative rollout of the DPDP Act is the structural failure. The DPDP Rules, 2025 were notified on November 13, 2025, bringing into immediate effect provisions establishing the Data Protection Board of India.

Yet, as of mid-2026, the DPBI exists only on paper. It has no appointed Chairperson and no Members, despite nomination communications circulating in May and June.

This leaves Data Fiduciaries in a perilous regulatory limbo. Section 8(6) of the DPDP Act mandates that fiduciaries must intimate the Board in the event of a personal data breach. But how do you report a breach to a non-existent Board? Furthermore, the much-touted Consent Manager framework—which promises to revolutionize how Data Principals manage their digital footprints—is slated for a November 2026 registration window. A Board is required to register and regulate these entities.

For in-house counsel, this means operating in the dark. You must build expensive compliance architectures, revise privacy notices, and establish breach-reporting protocols to satisfy a law whose chief enforcement mechanism is currently a ghost town. The risk of retrospective penalization once the Board is finally staffed is not a risk India Inc. can afford to ignore.

The EdTech Ripple Effect: Real Consent is Non-Negotiable

While the broader constitutional challenge brews, the Supreme Court has already signaled its strict approach to the DPDP Act’s consent requirements in specific sectors. In a recent order concerning the government's APAAR Scheme (the "One Nation, One Student ID" registry), the Court held that student data collection, processing, and sharing remains strictly subject to the DPDP Act.

Crucially, the Court mandated that consent forms must give parents or guardians a real and practical option to withhold consent. This strikes at the heart of "take-it-or-leave-it" privacy policies.

For lawyers advising EdTech platforms, schools, or any entity dealing with children's data (Section 9 of the DPDP Act), this is a massive red flag. The days of burying consent in 50-page Terms of Service are over. If your client's user interface does not allow a user to explicitly opt-out of data sharing without losing core functionality, it is ex facie non-compliant.

The Verdict

The Supreme Court’s refusal to stay the DPDP Act forces the legal fraternity into a state of hyper-vigilance. The law is live, the transparency exemptions are biting hard, and the regulatory infrastructure is lagging dangerously behind. Until the larger bench decides on the constitutional validity of Section 44(3), practitioners must advise clients to strictly adhere to the DPDP Act's data minimization and consent mandates, while bracing for a chaotic transition when the Data Protection Board finally wakes up.

Published by AnrakLegal AI