Legal News
27 June 2026
IP & Technology

Privacy as a Shield or a Sword? Supreme Court Constitution Bench to Test the DPDP Act as Corporate India Braces for Impact

For technology and privacy lawyers in India, June 2026 has delivered a tectonic shift. The Digital Personal Data Protection (DPDP) Act, 2023, is no longer a looming legislative ghost; it is fully operational, armed with the newly notified DPDP Rules,...

For technology and privacy lawyers in India, June 2026 has delivered a tectonic shift. The Digital Personal Data Protection (DPDP) Act, 2023, is no longer a looming legislative ghost; it is fully operational, armed with the newly notified DPDP Rules, 2025. But just as corporate compliance teams begin their 18-month scramble toward the May 2027 enforcement deadline, the Supreme Court has thrown a constitutional wrench into the works.

By referring challenges against the DPDP Act to a 5-judge Constitution Bench, the apex court has acknowledged what civil society and sharp legal practitioners have argued for two years: the current privacy framework is on a collision course with constitutional transparency.

The Section 44 Dilemma: Weaponizing Privacy Against the RTI Act

The most consequential battleground at the Supreme Court revolves around Section 44 of the DPDP Act, which amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005. For decades, the RTI Act operated on a delicate balancing test: personal information could be withheld unless the Public Information Officer (PIO) determined that a larger public interest justified its disclosure. It was a statutory embodiment of the friction between the Right to Privacy (Article 21) and the Right to Know (Article 19(1)(a)).

The DPDP Act obliviates this balance. It replaces the conditional exemption with a blanket prohibition on disclosing any "personal information."

"There is no question of stay," the Supreme Court remarked while refusing interim relief, but the referral under Article 145(3) signifies that the Court recognizes the gravity of the constitutional question at hand.

Why this matters for your practice: If you represent media houses, investigative journalists, or NGOs, your litigation strategy must pivot immediately. The state is now statutorily empowered to use privacy as an impenetrable shield against accountability. Until the Constitution Bench rules on whether this blanket exemption violates the basic structure of transparency or the doctrine of proportionality laid down in K.S. Puttaswamy, writ petitions challenging PIO rejections will need to directly attack the vires of the amendment rather than just the merits of the RTI application.

The Compliance Squeeze: Dual Reporting and Compressed Timelines

While the constitutional litigators prepare for a showdown, transactional and corporate lawyers face an immediate operational nightmare. The government has signaled an 18-month phased compliance runway, culminating on May 13, 2027. However, murmurs from the Centre suggest this timeline may be aggressively compressed for "Significant Data Fiduciaries" (SDFs) and large tech platforms already adhering to GDPR or other global norms.

The immediate headache for practitioners advising fintechs, banks, and SaaS companies is the dual-reporting regime for data breaches. Under the new rules, a breach doesn't just trigger a mandatory notice to the Data Protection Board (DPB); it often still requires reporting to CERT-In under Section 70B of the Information Technology Act, 2000.

Practice pointer: Lawyers must draft unified incident response protocols for clients immediately. Discrepancies in the factual timeline or severity assessment between a CERT-In filing (required within 6 hours) and a DPB notification will inevitably be weaponized by regulators to levy the draconian penalties (up to ₹250 crores) prescribed under the DPDP Act.

AI Regulation by Proxy: The Lazy Legislative Approach

Perhaps the most strategically vital development this month came not from the courts, but from the Ministry of Electronics and IT. MeitY Secretary S. Krishnan confirmed that India will not introduce bespoke Artificial Intelligence regulations. Instead, the government intends to shoehorn AI governance into the existing DPDP Act and the Intellectual Property (IP) framework.

This is a legally clumsy, albeit pragmatic, reality that IP and tech lawyers must now exploit. The government is essentially outsourcing AI regulation to data privacy and copyright litigators.

How does this play out in courts? When dealing with generative AI, Large Language Models (LLMs), and algorithmic bias, the battle lines are now drawn across two existing statutes:

  • The Copyright Act, 1957: Scraping copyrighted data to train LLMs will be fought under traditional infringement doctrines and the "fair dealing" exceptions under Section 52.
  • The DPDP Act, 2023: The unauthorized scraping of personal data for AI training is now a textbook DPDP violation. Furthermore, issues of algorithmic bias—where AI makes discriminatory decisions in lending or hiring based on personal data—will be challenged as violations of the data fiduciary's obligation to ensure the completeness, accuracy, and consistency of data under Section 8(5).

By refusing to enact an AI-specific law, the government has ensured that the DPDP Act will be the primary weapon to rein in AI platforms. If you are advising AI startups, relying merely on IP indemnities is no longer sufficient; they need a robust, DPDP-compliant data-sourcing architecture.

The Road Ahead

We are witnessing the messy, real-time birth of India's unified digital jurisprudence. The DPDP Act is being stretched in three directions simultaneously: as a corporate compliance behemoth, as a proxy regulator for Artificial Intelligence, and as a constitutional battering ram against the RTI Act.

For the Indian legal fraternity, the mandate is clear. The era of siloed practices is over. You can no longer be just an "IP lawyer" or a "Constitutional litigator." Advising a tech client today requires harmonizing the Copyright Act, the DPDP Rules, and Article 19(1)(a). The Supreme Court's upcoming Constitution Bench hearings will not just decide the fate of the RTI Act—they will define the boundaries of digital authoritarianism and corporate data governance for the next decade.

Published by AnrakLegal AI