SC Refuses to Stay the DPDP Act: Why the Ticking Compliance Clock and the RTI Collision Demand Immediate Action
The Judicial Reprieve That Never Came For corporate counsel and technology lawyers secretly hoping that the Supreme Court would hit the pause button on the Digital Personal Data Protection (DPDP) Act, 2023 , the 16 February 2026 order was a heavy rea...
The Judicial Reprieve That Never Came
For corporate counsel and technology lawyers secretly hoping that the Supreme Court would hit the pause button on the Digital Personal Data Protection (DPDP) Act, 2023, the 16 February 2026 order was a heavy reality check. While the Apex Court issued notice on pleas challenging the constitutional vires of specific provisions of the Act and the newly minted DPDP Rules, 2025, it pointedly refused to grant a stay on the Act’s operation.
The message from the bench is unequivocal: the law is live, the compliance clock is ticking, and the era of the regulatory vacuum is over. With the Ministry of Electronics and Information Technology (MeitY) having notified the final Rules in November 2025, data fiduciaries have an 18-month transition period ending 13 May 2027. If you are advising clients to wait for the Supreme Court to resolve the constitutional challenges before overhauling their data architectures, you are giving them dangerous advice.
The RTI Act Collision: A Blanket Exemption?
The most consequential battleground at the Supreme Court right now is not about corporate compliance, but about the fundamental tension between the fundamental right to privacy (Puttaswamy) and the fundamental right to information (Article 19(1)(a)).
The petitioners have rightly targeted Section 44(3) of the DPDP Act, which surgically amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005. To understand why this matters to practicing lawyers, we have to look at the statutory history.
Previously, Section 8(1)(j) protected personal information from RTI disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. This "public interest override" was the safety valve that allowed journalists, activists, and lawyers to uncover corruption involving public servants. It was a delicate balancing act, heavily litigated and guided by precedents like Girish Ramchandra Deshpande v. CIC.
The DPDP Act obliterates this balance. By amending Section 8(1)(j), it creates an absolute, blanket exemption for personal information. The public interest test is gone.
From a legal strategy perspective, this is a massive shift. Public Information Officers (PIOs) now have a statutory shield to reject virtually any RTI application that contains a public official's personal data. Litigators practicing in the High Courts under Article 226 will need to prepare for a surge in writ petitions challenging these rejections, arguing that an absolute bar on disclosure violates the basic structure of transparency inherent in Article 19(1)(a).
Advising Data Fiduciaries: The 2027 Deadline
While the constitutional litigators battle over the RTI Act, transactional and corporate lawyers must focus on the 13 May 2027 deadline. The recent legal commentaries highlight two areas where existing corporate practices are severely out of step with the new regime: Consent and Erasure.
Under the DPDP Rules 2025, consent cannot be buried in a 40-page Terms of Service agreement. It must be free, specific, informed, unconditional, and unambiguous. For lawyers auditing client platforms, this means:
- Pre-ticked boxes are dead. Opt-out mechanisms are no longer legally defensible.
- Notice requirements are strict. The request for consent must be accompanied by a clear notice detailing the personal data to be collected and the specific purpose of processing.
- Withdrawal must be frictionless. The law mandates that withdrawing consent must be as easy as giving it. If your client requires three clicks to give consent but a phone call to customer service to withdraw it, they are in breach.
Furthermore, the Right to Erasure is emerging as a major compliance hurdle. When a Data Principal withdraws consent, or when the specified purpose is met, the Data Fiduciary must erase the data. Practicing lawyers must ensure that client contracts with third-party data processors include strict indemnity clauses and back-to-back erasure obligations. If your client deletes the data but their vendor retains it, your client remains on the hook.
The AI Blindspot: MeitY’s Hands-Off Approach
Perhaps the most fascinating development for technology lawyers is what the government is not doing. MeitY has explicitly stated that it prefers to use existing laws to govern Artificial Intelligence, rather than passing a bespoke "AI Act." The government’s view is that the DPDP Act and the existing Intellectual Property (IP) framework are sufficient to foster innovation while protecting rights.
This is a highly optimistic, if not legally precarious, position. Can the DPDP Act adequately address the mass scraping of personal data used to train Large Language Models (LLMs)? Can the Copyright Act, 1957—drafted decades before generative AI—effectively govern AI-generated outputs and training data infringement without statutory amendments?
We believe it cannot do so without significant judicial friction. However, for IP and Tech practitioners, this government stance is a clear directive: stop waiting for new AI regulations. You must creatively apply existing doctrines. You will need to litigate AI copyright disputes using Section 52 (fair dealing) of the Copyright Act, and you will need to defend AI data scraping under the "legitimate uses" framework of the DPDP Act.
The Bottom Line
The Supreme Court’s refusal to stay the DPDP Act is the starting gun for a massive shift in Indian technology and privacy law. Whether you are drafting privacy policies, fighting for transparency under the RTI Act, or advising tech startups on AI training data, the theoretical debates of the past five years are over. The law is here, the enforcement timeline is set, and the courts are open for business.
Tags
Published by AnrakLegal AI