Privacy vs. Transparency: Supreme Court Sends DPDP Act to Constitution Bench as Corporate India Scrambles for Compliance
The Collision of Article 19(1)(a) and Article 21 In what is shaping up to be the most consequential constitutional showdown since K.S. Puttaswamy v. Union of India , a Supreme Court bench led by Chief Justice Surya Kant has referred a batch of petiti...
The Collision of Article 19(1)(a) and Article 21
In what is shaping up to be the most consequential constitutional showdown since K.S. Puttaswamy v. Union of India, a Supreme Court bench led by Chief Justice Surya Kant has referred a batch of petitions challenging the Digital Personal Data Protection (DPDP) Act, 2023, and its 2025 Rules to a five-judge Constitution Bench. The hearing is slated for March 23, 2026. But for practicing lawyers, the real headline isn't the referral—it is the Court's categorical refusal to grant an interim stay on the law's operation.
Make no mistake: the Court’s reluctance to hit pause creates a dual reality for the Indian legal profession. On one hand, civil rights litigators are fighting to save the Right to Information (RTI) Act from being gutted via the back door. On the other, corporate and in-house counsel are staring down the barrel of compressed compliance timelines, forced to overhaul enterprise architectures before the hammer drops in May 2027.
The Death of the Public Interest Override
To understand the constitutional friction, we must look at the surgical strike the DPDP Act executes on the RTI Act, 2005. Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act. Historically, Section 8(1)(j) provided a nuanced exemption: personal information could be withheld unless the Public Information Officer (PIO) was satisfied that the larger public interest justified its disclosure. Crucially, it contained a proviso: "Provided that the information, which cannot be denied to the Parliament or a State Legislature shall not be denied to any person."
The DPDP Act wipes this nuance off the statute books. It amends Section 8(1)(j) to blindly exempt all "personal information" from disclosure, deleting the public interest override entirely.
By weaponizing the fundamental right to privacy, the state has effectively shielded public servants from the fundamental right to know.
This is precisely why activists like Venkatesh Nayak, Aruna Roy, and the Mazdoor Kisan Shakti Sangathan have approached the Court. If a citizen files an RTI to uncover corrupt MGNREGA beneficiary allocations or discrepancies in the Rajasthan Jan Soochna Portal, public authorities can now blanket-deny the request by citing the presence of "personal data." The Supreme Court will now have to balance the Article 19(1)(a) right to information against the Article 21 right to privacy. Until they do, litigators representing journalists and activists must prepare for a wave of stonewalling by PIOs relying on the un-stayed DPDP Act.
Transactional Lawyers: The Compliance Clock is Ticking
While the constitutional debate rages, transactional lawyers and tech counsel do not have the luxury of waiting for the Constitution Bench’s verdict. The Ministry of Electronics and Information Technology (MeitY) notified the DPDP Rules in November 2025, triggering a phased rollout. Sectoral compliance timelines have been aggressively compressed from 18 to 12 months.
If you are drafting commercial contracts, advising fintech startups, or representing healthcare providers, your practice must pivot immediately in three key areas:
1. Consent Architecture vs. Contractual Boilerplates: Gone are the days of the pre-ticked "I Agree" checkbox buried in a 50-page Terms of Service. Section 6 of the DPDP Act demands itemized, clear, and affirmative consent. MeitY is cracking down on "dark patterns." Transactional lawyers must tear up their 2023 boilerplate data protection clauses. By 2026, commercial contracts must distinctly delineate Data Fiduciary and Data Processor roles, explicitly spelling out indemnity cascades for data breaches.
2. The Dual-Reporting Nightmare: Incident response teams must now navigate a fractured regulatory landscape. A data breach doesn't just trigger the DPDP Act's Data Protection Board (DPB) notifications; it still triggers the stringent 6-hour reporting window to CERT-In under the Information Technology Act, 2000. Corporate counsel must draft incident response playbooks that satisfy both regulators without creating contradictory admissions of liability.
3. Vendor Management and Privacy-by-Design: Sectors handling massive sensitive data—like banking and health insurance—must implement privacy-by-design immediately. Phase 1 compliance focuses heavily on data mapping. If your client uses third-party SaaS vendors, the liability for the vendor's DPDP non-compliance rests squarely on your client (the Data Fiduciary). Data Processing Agreements (DPAs) must be renegotiated to include strict audit rights and unconditional breach notification clauses.
The NHRC Curveball: Fragmented Enforcement Begins
Complicating matters further is the recent move by the National Human Rights Commission (NHRC) to issue notices to AI, social media, and edtech platforms over alleged DPDP violations. This is a fascinating jurisdictional stretch. With the DPB still finding its feet, the NHRC is leveraging the constitutional dimension of privacy to act as an interim watchdog.
For tech lawyers, this means regulatory risk is no longer confined to MeitY or the upcoming DPB. A failure to safeguard student data on an edtech platform is now being framed not just as a statutory breach, but as a human rights violation.
The Bottom Line
The Supreme Court's refusal to stay the DPDP Act forces the Indian legal market into immediate action. Litigators challenging administrative opacity must find creative ways to bypass the amended Section 8(1)(j) of the RTI Act—perhaps by relying directly on Article 32 or 226 for matters of grave public importance.
Meanwhile, corporate counsel must act under the assumption that the DPDP Act will survive constitutional scrutiny largely intact. The May 2027 deadline is an absolute limit, not a suggestion. The grace period is over; the era of data governance litigation has begun.
Tags
Published by AnrakLegal AI