Privacy as a Sword? The Supreme Court’s DPDP-RTI Conundrum and Delhi HC’s AI Copyright Pivot
The Erosion of Transparency: DPDP Act vs. RTI Act For technology and constitutional lawyers alike, 2026 is shaping up to be the year the Digital Personal Data Protection (DPDP) Act, 2023 finally bares its teeth—not just as a privacy shield, but poten...
The Erosion of Transparency: DPDP Act vs. RTI Act
For technology and constitutional lawyers alike, 2026 is shaping up to be the year the Digital Personal Data Protection (DPDP) Act, 2023 finally bares its teeth—not just as a privacy shield, but potentially as a weapon against public transparency. On February 16, 2026, the Supreme Court of India took up a batch of petitions, including a lead challenge by The Reporters’ Collective, targeting the DPDP Act and the newly notified DPDP Rules, 2025. While the Court rightly referred the matter to a larger bench acknowledging the gravity of the constitutional questions, it made a critical tactical choice: it refused to stay the operation of the law.
For practicing advocates, the immediate fallout of this "no-stay" order is profound, specifically regarding Section 44(3) of the DPDP Act. This provision quietly but lethally amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Historically, Section 8(1)(j) provided a nuanced balancing test: a Public Information Officer (PIO) could deny personal information unless they were satisfied that the larger public interest justified its disclosure. Section 44(3) of the DPDP Act obliterates this test, converting the exemption into an absolute embargo on disclosing "personal information."
The removal of the public interest override is not a mere statutory tweak; it is a fundamental re-engineering of Indian administrative law. By weaponizing 'privacy' to create a blanket ban on personal data disclosure, the state effectively shields public officials from scrutiny regarding their assets, appointments, and administrative footprint.
The Supreme Court has indicated it will examine the jurisprudential distinction between public data and private data. Until the larger bench rules, lawyers utilizing the RTI Act for pre-litigation fact-finding or PIL research will find their applications routinely stonewalled. PIOs now have statutory cover to reject any request tangentially involving an individual's data. If you are advising journalists, whistleblowers, or civil rights activists, your litigation strategy must now pivot from statutory appeals under the RTI Act to challenging the constitutional validity of the denial under Article 19(1)(a).
The Regulatory Vacuum: A Ghost Board and Looming Deadlines
While the Supreme Court debates the constitutional text, corporate lawyers are wrestling with a bizarre administrative reality. The Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025, triggering the institutional setup of the Data Protection Board of India (DPBI) under Section 18 of the Act. Yet, as of mid-2026, the Board exists purely as a legal fiction. Government communications from May and June 2026 indicate the nomination processes are "underway," but the Board currently lacks a Chairperson and Members.
This bureaucratic inertia is a trap for data fiduciaries. Substantive commencement of the framework is slated for May 13, 2027, with Consent Manager registrations opening on November 13, 2026. Corporate counsel cannot afford to wait for the DPBI to become functional before initiating compliance audits. The new privacy rules demand stringent limits on data collection and hyper-clear notice mechanisms. Lawyers must immediately begin drafting upgraded privacy notices and auditing data flows, treating the May 2027 deadline as a hard stop, regardless of the regulator's current headless state.
The AI Intersection: Fair Dealing and Section 8(5) DPDP Liabilities
Beyond pure privacy, 2026 has delivered massive tremors at the intersection of IP, technology, and data protection. A critical blindspot is emerging for employers regarding employee use of Generative AI (GenAI). Under Section 8(5) of the DPDP Act, a data fiduciary must protect personal data in its possession or control by taking reasonable security safeguards. If your client's employees are feeding unredacted customer data into public Large Language Models (LLMs) to draft emails or summarize documents, that is a textbook data breach waiting to attract severe DPBI penalties. Advising clients to implement strict, written "Shadow AI" policies is no longer optional; it is a baseline fiduciary duty.
Simultaneously, the IP landscape is shifting. In a landmark preliminary ruling on July 29, 2026, the Delhi High Court noted that OpenAI’s scraping and storage of ANI’s copyrighted works for training its LLMs could prima facie fall within the ambit of "fair dealing" under Section 52 of the Copyright Act, 1957.
This is a bombshell for IP practitioners. Indian courts have traditionally applied a strict, narrow interpretation of fair dealing. If ingesting massive datasets of copyrighted journalism to train commercial AI is deemed "fair dealing," the economic foundation of copyright law is upended. For IP litigators representing content creators, publishers, and media houses, the immediate strategy must shift towards aggressive technological gating (like strict robots.txt enforcement) and exploring licensing consortiums, as the traditional infringement lawsuit may face a steep uphill battle against the "transformative use" defense that Indian courts seem increasingly willing to entertain.
The Takeaway: We are witnessing a historic realignment. The state is using privacy to limit transparency, while courts are stretching traditional IP doctrines to accommodate AI innovation. For the Indian practitioner, relying on old precedents regarding Section 8(1)(j) of the RTI Act or Section 14 of the Copyright Act is a guaranteed path to failure. The law has moved; it is time our practice moves with it.
Tags
Published by AnrakLegal AI