Privacy vs. Transparency: SC Defers DPDP-RTI Clash to Larger Bench, But the Era of Data Compliance is Now Live
The Constitutional Collision We've Been Waiting For The honeymoon phase for India’s data protection regime is officially over. In a defining moment for tech and privacy jurisprudence this year, the Supreme Court has issued notice on petitions challen...
The Constitutional Collision We've Been Waiting For
The honeymoon phase for India’s data protection regime is officially over. In a defining moment for tech and privacy jurisprudence this year, the Supreme Court has issued notice on petitions challenging the constitutional validity of Section 44(3) of the Digital Personal Data Protection (DPDP) Act, 2023, referring the matter to a larger bench. But here is the critical takeaway for every practicing lawyer: the Apex Court categorically declined to stay the operation of the DPDP Act.
For litigators, this sets the stage for the most consequential constitutional showdown since K.S. Puttaswamy v. Union of India. For corporate and technology lawyers, the refusal to grant interim relief means the compliance clock hasn't just started ticking—it has struck midnight. The DPDP Act, along with the 2025 Rules, is active law.
The Death of the "Public Interest" Caveat in RTI
To understand why this larger bench referral is monumental, we must look at the surgical strike the DPDP Act performed on the Right to Information (RTI) Act, 2005. Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act.
Prior to this amendment, personal information could be exempted from RTI disclosure unless the Central Public Information Officer (CPIO) was satisfied that a "larger public interest justifies the disclosure of such information." Furthermore, information that could not be denied to Parliament or a State Legislature could not be denied to an ordinary citizen.
The DPDP Act obliterates this nuance. It replaces Section 8(1)(j) with a blanket exemption for any information that relates to "personal information."
"By removing the 'larger public interest' test, the DPDP Act effectively weaponizes the fundamental right to privacy to shield bureaucratic and state machinery from the fundamental right to know. It is a statutory cloak for opacity."
The petitioners rightly argue that this amendment curtails transparency. The Supreme Court's referral to a larger bench acknowledges that balancing Article 19(1)(a) (freedom of speech and right to know) with Article 21 (right to privacy) requires a nuanced constitutional harmonisation that a two-judge bench cannot resolve. But until that larger bench decides, public authorities will routinely reject RTI applications citing the DPDP Act.
What the "No Stay" Order Means for Corporate Practice
If you are an in-house counsel or a transactional lawyer, the Supreme Court’s refusal to halt the DPDP Act’s operation is your immediate headache. You can no longer rely on boilerplate "data protection" clauses in commercial contracts. The 2026 landscape demands hyper-specific drafting.
Here is what is actively changing in commercial practice right now:
- Role Allocation Risk: Contracts must explicitly demarcate the Data Fiduciary (who determines the purpose of processing) from the Data Processor. Under the DPDP Act, the fiduciary bears the brunt of the liability for breaches, even if the processor is at fault. Your indemnity clauses need a complete overhaul to reflect this statutory risk allocation.
- Consent Governance: Commentary making the rounds this quarter emphasizes that consent under the DPDP Rules must be free, specific, informed, unconditional, and unambiguous. If your client’s app uses pre-ticked boxes or bundles terms of service with data processing consent, they are sitting ducks for regulatory penalties. The withdrawal mechanism must be as frictionless as the consent mechanism.
- Breach Notification Timelines: With the Data Protection Board (DPB) coming into its own, contracts must stipulate immediate notification protocols between processors and fiduciaries to facilitate mandatory breach reporting to the Board and the Data Principal.
Enforcement is Multi-Front: From Digi Yatra to EdTech
If anyone thought enforcement would be sluggish, 2026 is proving them wrong. The DPDP framework is bleeding into everyday technology implementation disputes.
The Kerala High Court is currently examining data-protection concerns surrounding Digi Yatra. This is a classic test case of state-backed technological convenience clashing with verifiable, unconditional consent. Can consent truly be "free" if opting out means facing unreasonable delays at airport checkpoints?
Simultaneously, the National Human Rights Commission (NHRC) has taken suo motu cognisance of alleged DPDP violations by AI, social media, and EdTech platforms. Their focus? Children's data. Under the DPDP Act, verifiable parental consent is mandatory, and behavioral monitoring or targeted advertising directed at children is strictly prohibited. EdTech platforms that track student engagement metrics for algorithmic upselling are now in the crosshairs of both the DPB and human rights watchdogs.
The Verdict for the Bar
The DPDP Act is no longer a theoretical compliance exercise; it is an active, litigated, and enforced regime. While constitutional scholars and litigators prepare for the larger bench battle over the RTI amendment, the corporate bar must operate under the assumption that the Act is here to stay in its current form.
Stop waiting for the Supreme Court to clarify the constitutional edges. Audit your clients' consent flows, renegotiate those processor agreements, and prepare for a year where data privacy becomes the most heavily contested ground in Indian commercial and public law.
Tags
Published by AnrakLegal AI