Legal News
14 April 2026
IP & Technology

Privacy vs. Transparency: As the DPDP Act Hits a Constitution Bench, Corporate Lawyers Must Race Against the May 2027 Clock

The honeymoon phase for the Digital Personal Data Protection (DPDP) Act, 2023, is officially over. As the Supreme Court grapples with the fundamental friction between privacy and transparency, India’s corporate law ecosystem is waking up to a harsh r...

The honeymoon phase for the Digital Personal Data Protection (DPDP) Act, 2023, is officially over. As the Supreme Court grapples with the fundamental friction between privacy and transparency, India’s corporate law ecosystem is waking up to a harsh reality: the compliance clock is ticking, and boilerplate data protection clauses are now a liability.

Recent developments have split the DPDP narrative into two distinct battlegrounds: the constitutional challenge playing out in the Supreme Court, and the operational scramble happening in boardrooms as the May 13, 2027 compliance deadline looms. For practicing lawyers, ignoring either front borders on professional negligence.

The Constitutional Showdown: Article 19(1)(a) vs. Article 21

The most consequential legal dispute right now is the clash between the Right to Information (RTI) Act, 2005, and the DPDP Act. The Supreme Court has rightly issued notices to the Centre on a PIL filed by the Mazdoor Kisan Shakti Sangathan. The crux of the challenge lies in Section 44(3) of the DPDP Act, which fundamentally alters the DNA of Section 8(1)(j) of the RTI Act.

Historically, Section 8(1)(j) exempted personal information from RTI disclosure unless a larger public interest justified it. It was a carefully calibrated balancing test. The DPDP Act, however, brings a sledgehammer to this balance, amending the RTI Act to create a blanket exemption for all personal information.

"By removing the public interest carve-out, the legislature has effectively weaponized privacy against accountability. Social audits, PDS beneficiary lists, and MGNREGA transparency are now at the mercy of a blunt privacy shield."

The Supreme Court has referred the batch of petitions challenging the DPDP Act and the newly notified DPDP Rules, 2025 to a 5-judge Constitution Bench. This is exactly where it belongs. The bench will have to reconcile the fundamental right to information under Article 19(1)(a) with the fundamental right to privacy recognized under Article 21 in the landmark Puttaswamy judgment. However, the Court’s explicit refusal to grant an interim stay sends a clear message to the industry: the law is in force, and parliamentary intent stands until proven unconstitutional.

Multi-Forum Enforcement: Enter the NHRC

While litigators watch the Supreme Court, a surprising new enforcement vector has emerged. The National Human Rights Commission (NHRC) recently issued notices over alleged DPDP violations by AI, social media, and edtech platforms.

Why does this matter? Because it shatters the assumption that the Data Protection Board (DPB) will be the sole arbiter of data privacy disputes. If AI algorithms or edtech surveillance mechanisms infringe on privacy, human rights bodies are now viewing this through the lens of constitutional violations. For technology lawyers, this means advising clients on multi-forum liability. A data breach or misuse might not just trigger a financial penalty under the DPDP Act; it could spark a human rights inquiry.

Drafting for 2026: The Death of Boilerplate Contracts

With the DPDP Rules triggering a shortened 12-month compliance window ending in May 2027, the grace period for corporate India is evaporating. The legal advisory practice must pivot from theoretical seminars to structural engineering.

If you are drafting commercial contracts for 2026, your standard "compliance with applicable laws" clause is obsolete. Here is what is changing on the ground:

  • Global Capability Centres (GCCs): With a 14-month clock ticking, GCCs are dangerously behind. Employment lawyers need to overhaul HR policies immediately. The DPDP Act does not exempt employee data. GCCs require India-specific privacy notices, rigorous vendor scrutiny, and comprehensive data inventories.
  • Healthcare & Insurance: This sector faces the highest burden. Medical records are sensitive data by nature. Lawyers must ensure clients are embedding privacy-by-design into legacy systems—a massive operational hurdle that requires bridging the gap between IT infrastructure and legal compliance.
  • The "Ongoing Consent" Paradigm: The biggest conceptual shift for in-house counsel is treating consent as a "continuing legal relationship." Rule 3 demands standalone privacy notices. You can no longer bury data processing consent in a 50-page Terms of Service clickwrap. Consent must be verifiable, granular, and easily withdrawable.

The Bottom Line for Practitioners

Firms are already flagging the exorbitant costs of data verification and compliance under the new regime. As a legal advisor, your role is no longer just mitigating risk—it is project management.

Do not let your clients use the pending 5-judge bench reference as an excuse to delay their compliance roadmaps. Constitutional litigation moves at its own pace, but statutory deadlines do not. The DPDP Act is forcing a hard reset on how commercial, technology, and constitutional law intersect in India. Lawyers who master the operational nuances of the DPDP Rules while understanding the constitutional vulnerabilities of Section 44(3) will dominate the advisory space for the next decade.

Published by AnrakLegal AI