Legal News
18 June 2026
IP & Technology

Supreme Court Refuses Stay on DPDP Act: Why the Constitution Bench Referral Means Zero Respite for Data Fiduciaries

The Illusion of a Reprieve In a move that has sent ripples through boardrooms and law firm corridors alike, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules,...

The Illusion of a Reprieve

In a move that has sent ripples through boardrooms and law firm corridors alike, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025 to a five-judge Constitution Bench. But for practicing lawyers, the headline isn’t the referral—it is what the Court refused to do. By declining to stay the operation of the Act and the 2025 Rules, the apex court has made one thing abundantly clear: the Indian privacy regime is officially live, and the compliance clock is aggressively ticking.

If your corporate clients are waiting for the Supreme Court to rescue them from compliance costs, they are playing a dangerous game of regulatory Russian roulette. The government is already executing a staggered rollout of the 2025 Rules. For tech and commercial lawyers, the denial of an interim stay is the only order that matters right now.

The Constitutional Crosshairs: What the 5-Judge Bench Will Scrutinize

The referral to a larger bench under Article 145(3) of the Constitution was inevitable. When the DPDP Act was passed, it was immediately criticized for reading less like a privacy statute and more like a carte blanche for state surveillance. The Constitution Bench will have to measure the Act against the proportionality test laid down in the landmark K.S. Puttaswamy v. Union of India (2017) judgment, which recognized privacy as a fundamental right under Article 21.

Expect the legal fireworks to center on two massive vulnerabilities in the statute:

1. Section 17 (Exemptions for the State): This provision grants the Central Government sweeping powers to exempt its own instrumentalities from the Act's obligations citing sovereignty, state security, and public order. Unlike the GDPR, which maintains a tighter leash on state processing, Section 17 creates a dual-track privacy regime—strict for private enterprises, practically non-existent for the government. The challengers will argue this fails the Puttaswamy test of necessity and proportionality.

2. Excessive Delegation and the Data Protection Board (DPB): The 2023 Act left an unprecedented amount of operational mechanics to delegated legislation (now manifesting in the 2025 Rules). Furthermore, the lack of statutory independence for the DPB—whose members are appointed by the Union—raises serious questions about administrative fairness and the separation of powers.

"The Constitution Bench may eventually read down Section 17 or mandate structural independence for the Data Protection Board, but they are highly unlikely to strike down the legislation in its entirety. The core obligations of private Data Fiduciaries will survive this constitutional stress test."

The 2025 Rules: A Phased Rollout with Immediate Headaches

While the constitutional debate simmers, the Ministry of Electronics and Information Technology (MeitY) is pushing forward. The strategy for 2026 is a staggered enforcement of the DPDP Rules, 2025. What does this mean for your practice?

While the complex Consent Manager framework (Section 6) has been delayed to give the tech infrastructure time to catch up, the foundational obligations are knocking at the door. Industry bodies are lobbying fiercely against compressed timelines, citing existential threats to startups and SMEs. However, highly regulated sectors like banking and fintech aren't waiting. They are already conducting aggressive gap assessments and appointing Data Protection Officers (DPOs).

Actionable Steps for Privacy Practitioners

The absence of a stay means lawyers must pivot from theoretical advisory to aggressive implementation. Here is how your practice needs to adapt immediately:

1. Overhauling Notice and Consent (Sections 5 & 6): The days of hiding behind 50-page boilerplate privacy policies in English are over. Section 5 mandates itemized, clear, and multi-lingual notices. If you are drafting Terms of Service in 2026, you must separately map out the exact data collected and its specific purpose. Bundled consent is now a statutory violation.

2. Drafting Ironclad Data Processing Agreements (DPAs): Under Section 8, the Data Fiduciary remains entirely liable for the sins of its Data Processors. If your client outsources payroll, cloud storage, or customer support, their vendor contracts need immediate renegotiation. You must draft stringent DPAs featuring robust indemnity clauses, strict audit rights, and mandatory 24-hour breach notification silos.

3. Prepping Significant Data Fiduciaries (SDFs): Under Section 10, entities processing large volumes of sensitive data (like fintechs, health-tech, and large e-commerce platforms) will be notified as SDFs. They require an India-based DPO, an independent data auditor, and periodic Data Protection Impact Assessments (DPIAs). If you represent these companies, you should be drafting DPIA frameworks and DPO mandates today.

The Bottom Line

The Supreme Court’s decision to refer the DPDP Act to a Constitution Bench validates the serious fundamental rights concerns raised by civil society. However, the refusal to grant a stay is a pragmatic nod to the reality that India cannot afford to operate in a data protection vacuum any longer.

For Indian lawyers, the grace period is officially over. The DPDP Rules 2025 are the new reality, and the staggered rollout is a runway, not a parking lot. Advise your clients to build their compliance architecture now, because when the Data Protection Board starts levying penalties of up to ₹250 crores for breaches, "we were waiting for the Supreme Court" will not be a valid defense.

Published by AnrakLegal AI