Privacy as a Shield, Transparency as a Casualty: The SC’s DPDP-RTI Conundrum and What the 2025 Rules Mean for Tech Lawyers
The Supreme Court Draws the Battle Lines The honeymoon period for data scraping, bundled consent, and unchecked digital harvesting is officially over. In a monumental development for technology, IP, and constitutional lawyers alike, the Supreme Court...
The Supreme Court Draws the Battle Lines
The honeymoon period for data scraping, bundled consent, and unchecked digital harvesting is officially over. In a monumental development for technology, IP, and constitutional lawyers alike, the Supreme Court in February 2026 issued notice on a clutch of petitions challenging the Digital Personal Data Protection (DPDP) Act, 2023 and the newly operational DPDP Rules, 2025. Crucially, while the Apex Court referred the highly contentious amendment to the Right to Information (RTI) Act to a larger bench, it flatly refused to stay the operation of the DPDP Act.
For practicing lawyers, the message from the bench is unequivocal: compliance is not a future-state aspiration. It is a present-day mandate. With the DPDP Rules having been notified by MeitY on November 13, 2025, and phased implementation rolling out through 2026 and 2027, corporate data architectures must be overhauled immediately. But beyond corporate compliance, a massive constitutional friction point has emerged: the weaponization of privacy against public transparency.
Section 44(3): The Death Knell for the Public Interest Exemption?
The most alarming facet of the DPDP Act for media houses, investigative journalists, and transparency activists is Section 44(3). This provision quietly but lethally amends Section 8(1)(j) of the RTI Act, 2005.
Before this amendment, public information officers (PIOs) could refuse to disclose personal information only if it had no relationship to any public activity or interest, or if it caused unwarranted invasion of privacy. More importantly, the RTI Act contained a golden proviso: information which cannot be denied to the Parliament or a State Legislature shall not be denied to any person. Furthermore, PIOs could override privacy if a larger public interest justified the disclosure.
Section 44(3) of the DPDP Act obliterates this balancing act. It replaces the nuanced Section 8(1)(j) with a blanket exemption for any information that relates to "personal data."
"By removing the public interest override, the DPDP Act effectively creates an impenetrable fortress for public officials. Privacy, a fundamental right birthed in Puttaswamy to protect the citizen from the State, is now being inverted to protect the State from the citizen."
The Supreme Court’s decision to refer this to a larger bench is legally sound, given the clash between two fundamental rights—the Right to Privacy (Article 21) and the Right to Know (Article 19(1)(a)). However, by refusing an interim stay, the Court has allowed a regime of severe opacity to take root. Lawyers representing media entities or filing public interest litigations (PILs) must now brace for a wave of RTI rejections citing the DPDP Act.
The 2025 Rules: The Tech and IP Practitioner’s Nightmare
While the constitutional litigators battle over the RTI Act, tech and IP lawyers have their own fires to put out. The notification of the DPDP Rules, 2025 in November has operationalized the compliance heavy-lifting. Reuters appropriately dubbed this the most critical operational step since the Act's inception, and the 2026 legal landscape reflects this panic.
Under the new regime, the standard of consent has been drastically elevated. It must be free, specific, informed, unconditional, and unambiguous. What does this mean for your clients?
- The End of "Take It or Leave It": You can no longer gatekeep a service by forcing users to consent to unnecessary data collection. If an e-commerce app demands access to a user's contact list to sell them a pair of shoes, that consent is not "unconditional." It violates the principle of data minimization.
- The AI Scraping Dilemma: For IP lawyers advising AI startups, the DPDP Act represents a severe bottleneck. Training large language models (LLMs) requires massive datasets, often scraped from the web. If that data contains personally identifiable information (PII), the lack of "specific and informed" consent creates massive liability. Publicly available personal data is exempted under the Act, but only if the data principal themselves made it public. Proving the provenance of scraped data will be a nightmare for AI developers.
- Breach Notification: The Rules mandate strict protocols for notifying the Data Protection Board (DPB) and the affected users in the event of a breach. There is no materiality threshold—if personal data is breached, you report it.
The Action Plan for 2026
The refusal of the Supreme Court to grant a stay is a clarion call. If you are advising Data Fiduciaries (tech platforms, AI companies, hospitals, or even traditional brick-and-mortar businesses with digital loyalty programs), your immediate deliverables are clear.
First, audit the consent architecture. The UI/UX of your client's platforms must be redesigned to ensure withdrawal of consent is as seamless as granting it. Dark patterns that manipulate users into clicking "I Agree" are now direct violations of the DPDP framework.
Second, draft specific data processing agreements (DPAs) with any third-party vendors. The liability under the DPDP Act rests squarely on the Data Fiduciary, not the Data Processor. If your client's cloud provider leaks data, your client pays the penalty—which can run up to ₹250 crores.
Finally, for those on the litigation side, watch the larger bench reference closely. If the Supreme Court ultimately strikes down Section 44(3) as unconstitutional, it will reaffirm the supremacy of the RTI Act in matters of public interest. Until then, practitioners must navigate a schizophrenic legal landscape where corporate data hoarding is strictly policed, while the State enjoys unprecedented, legally-sanctioned opacity.
Tags
Published by AnrakLegal AI