Privacy Shield or Transparency Gag? The DPDP Act Finally Bites as SC Scrutinizes the RTI Amendment
The DPDP Act is Finally Operational, But at What Constitutional Cost? After nearly three years of legislative limbo and intense lobbying, the Central Government has finally notified the administrative rules for the Digital Personal Data Protection (D...
The DPDP Act is Finally Operational, But at What Constitutional Cost?
After nearly three years of legislative limbo and intense lobbying, the Central Government has finally notified the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023 this June 2026. For corporate lawyers, the implementation clock has struck midnight. Data fiduciaries can no longer hide behind the excuse of "awaiting operational guidelines."
However, while the boardrooms scramble to map data flows, the real battleground has shifted to the Supreme Court. The highest court's recent decision to refer the DPDP Act’s controversial amendment of the Right to Information (RTI) Act, 2005 to a larger bench proves what privacy advocates have argued since day one: the Act is suffering from a fundamental Jekyll-and-Hyde complex. It heavily regulates private data while simultaneously drawing an opaque curtain over the State.
The Death of the Public Interest Exemption: Section 44(3) under Scrutiny
For litigators dealing with writ petitions and administrative law, the most alarming aspect of the DPDP Act is Section 44(3), which amended Section 8(1)(j) of the RTI Act. Before this amendment, Public Information Officers (PIOs) had to apply a proportionality test: personal information could be disclosed if the larger public interest justified it. This was the bedrock for uncovering massive state-corporate nexuses and electoral anomalies.
The DPDP Act surgically removed this public interest exemption, replacing it with a blanket ban on the disclosure of any personal information. Petitioners, including The Reporters’ Collective and the National Campaign for Peoples’ Right to Information (NCPRI), have rightly challenged this as ultra vires Articles 14, 19(1)(a) (Right to Know), and 21 of the Constitution.
"The Supreme Court’s acknowledgment that 'some creases need to be ironed out' is a judicial understatement. By weaponizing the fundamental right to privacy established in Puttaswamy to slaughter the fundamental right to information, the legislature has created an unsustainable paradox."
Crucially for practitioners, the Supreme Court did not stay the operation of the Act pending the larger bench's review. This means PIOs currently possess a statutory shield to reject almost any RTI request tangentially involving an individual. Lawyers representing journalists, activists, or even commercial clients seeking tender-related disclosures must now prepare for prolonged appellate battles before Information Commissions, arguing constitutional overreach until the larger bench rules.
Tech-Law Convergence: Machine Unlearning and Section 12 Erasure
If you are advising tech, fintech, or healthcare clients, the June 2026 administrative rules demand a radical shift from policy drafting to hard-coded technical compliance. The most pressing challenge is the Right to Erasure under Section 12(3) of the DPDP Act.
It is no longer sufficient to merely "delete" a user's database entry. As legal-tech analysts highlighted this month, when a Data Principal requests erasure, their data must also be excised from the Artificial Intelligence and Machine Learning models trained on it. This brings “Machine Unlearning” from the realm of academic computer science squarely into the legal compliance matrix.
How do you prove to the Data Protection Board that a client's data was removed from a neural network? The emerging standard relies on Merkle tree structures and zero-knowledge proofs, allowing Data Fiduciaries to verify digital erasure without exposing the proprietary dataset.
Practice Note: If your client's Data Processing Agreement (DPA) does not explicitly mandate their third-party Data Processors to implement machine unlearning protocols, your client (the Data Fiduciary) is sitting on a severe liability. Remember, under the DPDP Act, the fiduciary bears the ultimate burden, with penalties stretching up to ₹250 crores for failure to implement reasonable security safeguards.
Data Sovereignty vs. The US CLOUD Act
Another immediate headache for commercial lawyers structuring cross-border transactions is the glaring conflict surrounding extraterritorial data access. Section 16 of the DPDP Act adopts a "negative list" approach, technically liberalizing cross-border data transfers to most jurisdictions.
However, recent analyses flag a massive blind spot: the DPDP Act lacks a statutory mechanism to resist involuntary extraterritorial access by foreign governments. If an Indian banking fiduciary uses a US-headquartered cloud provider (the processor), that processor is subject to the US CLOUD Act. If US law enforcement subpoenas Indian citizen data residing on those servers, the processor is caught in a dual-sovereignty trap.
Without a "blocking statute" or clear guidance in the new administrative rules, Indian tech lawyers must draft highly aggressive indemnification clauses and localized data-hosting mandates in vendor contracts to shield Indian fiduciaries from foreign subpoenas.
The Road Ahead for Practitioners
The DPDP Act in 2026 is no longer a theoretical debate; it is an enforceable reality with teeth. While we wait for the Supreme Court's constitutional bench to decide whether the State can use privacy to dodge transparency, the private sector has no such reprieve.
Lawyers must pivot from conducting basic "privacy audits" to engaging in deep architectural reviews of their clients' data ecosystems. The era of generic privacy policies is dead. The era of zero-knowledge proofs, algorithmic erasure, and ₹250 crore liabilities has arrived.
Tags
Published by AnrakLegal AI