Legal News
25 September 2026
IP & Technology

Schrödinger’s Privacy Law: Why the Supreme Court is Polishing the DPDP Act While the Data Protection Board Remains a Ghost Town

Welcome to the final quarter of 2026, where India’s data protection regime exists in a bizarre state of quantum superposition. On one hand, the Digital Personal Data Protection (DPDP) Act, 2023 is generating high-stakes constitutional litigation and ...

Welcome to the final quarter of 2026, where India’s data protection regime exists in a bizarre state of quantum superposition. On one hand, the Digital Personal Data Protection (DPDP) Act, 2023 is generating high-stakes constitutional litigation and reshaping fintech architecture. On the other, the regulatory body meant to enforce it is entirely missing in action.

For practicing tech and commercial lawyers, 2026 has been a masterclass in advising clients on a law that is simultaneously everywhere and nowhere. With substantive compliance obligations for Data Fiduciaries scheduled to hit like a freight train on 13 May 2027, we can no longer afford to wait for the government to get its house in order. We must look to the Supreme Court, which has effectively become the de facto data protection regulator.

The Constitutional Showdown: DPDP vs. RTI

The most consequential development of the year occurred on 16 February 2026, when the Supreme Court referred challenges against the DPDP Act’s amendment to the Right to Information (RTI) Act to a five-judge Constitution Bench.

At the heart of the dispute is Section 44(3) of the DPDP Act, which amended Section 8(1)(j) of the RTI Act. Previously, the RTI Act allowed the disclosure of personal information if a Public Information Officer (PIO) determined that the larger public interest justified it. The DPDP Act obliterated this balancing test, creating a blanket prohibition on the disclosure of any personal information under the RTI Act.

The Supreme Court’s refusal to stay the amendment pending the Constitution Bench’s decision means that, for now, the "blanket ban" remains operative. The privacy-transparency balance has been heavily tilted toward privacy.

Why this matters for your practice: If you represent corporate clients whose executives or operations intersect with state bodies (e.g., in public-private partnerships, tender awards, or environmental clearances), the current regime provides a formidable shield against RTI fishing expeditions by competitors or activists. Conversely, if you represent journalists or civil rights groups, your immediate litigation strategy must pivot to challenging the definition of "personal data" itself, rather than arguing public interest.

The APAAR Ruling: The Court Drafts Your Consent Forms

If you want to know how strict consent requirements will be under the DPDP Act, look at the Supreme Court’s 25 July 2026 directive regarding the APAAR (Automated Permanent Academic Account Registry) system.

The Court mandated that APAAR consent forms must expressly allow parents or guardians to withhold consent, and heavily restricted the disclosure of student data to private third parties. Crucially, the Court explicitly tethered APAAR’s data collection, processing, and retention to the mandates of the DPDP Act.

This is a massive red flag for in-house counsel and law firms drafting privacy policies. The era of "take-it-or-leave-it" bundled consent is dead. The Supreme Court has signaled that for consent to be valid under the DPDP framework, the refusal of consent must be a clearly presented option, not a buried opt-out clause. If your client’s UI/UX design (such as a pre-ticked box or a missing "Decline" button) constitutes a "dark pattern," it will not survive judicial scrutiny—even before the Data Protection Board is operational.

The Regulatory Vacuum and the May 2027 Cliff edge

Speaking of the Data Protection Board (DPB)—where is it?

Despite the DPDP Rules bringing the Board provisions into force back in November 2025, and government circulars in May and June 2026 seeking nominations, the DPB remains a statutory ghost town. As of late 2026, it lacks a Chairperson and Members.

This executive inertia is creating immense compliance friction. By mid-November 2026, the Consent Manager framework is expected to go live. We are already seeing intense legal friction between this new DPDP infrastructure and the Reserve Bank of India’s existing Account Aggregator (AA) ecosystem. Fintech lawyers are currently tearing their hair out trying to reconcile the data-sharing architectures of both regimes.

Yet, the clock is ticking. Multiple regulatory signals point to 13 May 2027 as the hard deadline for substantive obligations—including mandatory breach reporting, verifiable parental consent mechanisms, and the onerous extra duties for Significant Data Fiduciaries (SDFs).

The Bottom Line for Indian Lawyers

Do not let the absence of the Data Protection Board lull your clients into a false sense of security. The Supreme Court’s proactive stance in the APAAR case and the impending Constitution Bench hearing on the RTI amendment prove that the judiciary is ready to enforce DPDP principles directly through writ jurisdiction.

Here is what you should be doing right now:

  1. Audit Consent Architectures: Review every digital touchpoint where your client collects data. If there is no explicit, granular way for a Data Principal to say "No" (as per the APAAR ruling standard), overhaul it.
  2. Prepare for the May 2027 Deadline: Draft Data Processing Agreements (DPAs) for your clients to execute with their third-party processors. Under the DPDP Act, the Data Fiduciary retains full liability. You need robust indemnity clauses locked in before May 2027.
  3. Monitor Fintech Overlaps: If you advise NBFCs or payment aggregators, prepare for regulatory turf wars between the RBI and the (eventual) DPB regarding Consent Managers versus Account Aggregators.

The DPDP Act is no longer a theoretical piece of legislation. The Supreme Court is writing the compliance manual from the bench. It’s time for lawyers to read it.

Published by AnrakLegal AI