Privacy Shield or Transparency Guillotine? The Supreme Court Takes Aim at Section 44(3) of the DPDP Act
The long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, have finally been notified, pulling India’s data protection regime out of its nine-month suspended animation. But while corporate India scrambles to update its consent architecture...
The long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, have finally been notified, pulling India’s data protection regime out of its nine-month suspended animation. But while corporate India scrambles to update its consent architectures, a far more consequential battle has erupted in the constitutional courts. In late June 2026, both the Supreme Court and the Delhi High Court issued notices challenging the constitutional validity of the DPDP Act, 2023.
For practicing lawyers, this isn't just academic constitutional debate. The current challenges strike at the heart of administrative transparency, corporate AI governance, and intermediary liability. Here is why the legal landscape is shifting and how it will impact your practice.
The Assassination of Section 8(1)(j) of the RTI Act
The most dangerous provision in the DPDP Act isn't about data localization or penalty caps; it is Section 44(3). This sneaky legislative maneuver amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005, fundamentally altering the balance of power between the citizen and the State.
Historically, Section 8(1)(j) of the RTI Act exempted personal information from disclosure unless the Central Public Information Officer (CPIO) or the appellate authority was satisfied that the "larger public interest justifies the disclosure." It was a delicate proportionality test, often relying on precedents like Girish Ramchandra Deshpande v. CIC to balance privacy with transparency.
Section 44(3) of the DPDP Act drops a sledgehammer on this balance. It completely removes the "public interest" caveat, creating a blanket ban on the disclosure of any personal information under the RTI Act.
"By eliminating the public interest test, Section 44(3) effectively cloaks India's right to know in secrecy. The State can now shield corrupt officials, hide beneficiary lists, and deny access to critical public records simply by slapping a 'personal data' label on them."
What this means for your practice: If your practice involves writ petitions, PILs, or administrative law, your primary fact-finding tool has just been neutralized. The Supreme Court has rightly recognized this as a "serious and debatable" issue, questioning the blurry line between "public" and "private" data. Until the larger bench decides, expect heavy resistance from CPIOs. Litigators must start framing RTI rejections not just as statutory violations, but as violations of Article 19(1)(a) of the Constitution.
The Corporate Blindspot: Section 8(5), AI, and IP Theft
While the courts grapple with transparency, corporate lawyers are facing a massive compliance headache fueled by the rapid integration of Artificial Intelligence. In June 2026, MEITY Secretary S. Krishnan confirmed that the government prefers using existing legal frameworks—namely the DPDP Act and foundational IP laws—to govern AI, rather than introducing a bespoke AI regulation.
This "make-do" approach is a disaster waiting to happen, primarily due to the blindspots in Section 8(5) of the DPDP Act. This section mandates Data Fiduciaries to protect personal data in their possession or under their control, including preventing data breaches.
However, what happens when an employee feeds a mix of proprietary company source code (IP) and client personal data into an unauthorized, open-source Generative AI tool to "work faster"?
The DPDP Act fails to adequately address this intersection of IP leakage and data breach. The Act hyper-focuses on the unauthorized external extraction of data, but is remarkably toothless when addressing internal, AI-driven data pollution.
What this means for your practice: In-house counsel and technology lawyers can no longer rely on standard Non-Disclosure Agreements (NDAs). You must immediately draft and enforce Acceptable AI-Use Policies. Furthermore, employment contracts must explicitly classify the feeding of confidential data into public AI models as gross misconduct. If you wait for the DPDP Board to issue clarifications, your client's IP will already be training the next generation of public LLMs.
The 3-Hour Deepfake Takedown: A Death Knell for "Safe Harbour"?
Following the India-AI Summit 2026, the government introduced the February 2026 Amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules. The amendment slashes the takedown window for "synthetically generated information" (deepfakes) from 72 hours to a staggering 3 hours, unless the intermediary can prove a "good faith" standard.
This 92% reduction in reaction time effectively obliterates the practical application of the Safe Harbour protection under Section 79 of the IT Act for platforms hosting user-generated content.
What this means for your practice: For lawyers representing intermediaries, social media platforms, or content aggregators, this is a compliance nightmare. A 3-hour window requires automated, AI-driven takedown mechanisms, which will inevitably lead to over-censorship and false positives. Litigators should prepare for a wave of lawsuits from creators whose legitimate, non-malicious AI-assisted content is taken down. The interpretation of "good faith" in this context will be the next major battleground in Indian cyber law.
The TDSAT Dilemma
Finally, as we gear up for enforcement, a jurisdictional debate is brewing. Is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) truly equipped to handle complex, AI-driven data privacy and IP disputes? Relying on a telecom tribunal for nuanced data protection jurisprudence is like asking a tax court to try a murder case. It lacks the specific technical bandwidth required.
The Bottom Line: The events of mid-2026 prove that India’s technology and privacy laws are colliding violently. The DPDP Act is being weaponized against transparency, while simultaneously failing to protect corporate IP from AI erosion. Lawyers must pivot from passive compliance advisory to aggressive, preemptive legal engineering. The rules of the game haven't just changed; the board has been flipped.
Tags
Published by AnrakLegal AI