Legal News
22 July 2026
IP & Technology

The DPDP Act Bites: SC Refuses Stay Amidst RTI Clashes as Corporate India Scrambles for Compliance

The Collision of Article 19 and Article 21 is Now Sub Judice For the better part of three years, Indian data privacy practice has been an exercise in hypothetical compliance. That era officially ended in February 2026. The Supreme Court's decision to...

The Collision of Article 19 and Article 21 is Now Sub Judice

For the better part of three years, Indian data privacy practice has been an exercise in hypothetical compliance. That era officially ended in February 2026. The Supreme Court's decision to issue notice on petitions challenging the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025—while explicitly refusing to stay the operation of the law—sends a definitive message to the bar: the compliance holiday is over, and the litigation floodgates are open.

The petitions, spearheaded by The Reporters’ Collective, journalist Nitin Sethi, and the NCPRI, strike at the most controversial heart of the DPDP Act: its stealthy gutting of the Right to Information (RTI) Act, 2005. This isn't merely an academic debate for constitutional lawyers; it fundamentally alters how journalists, litigators, and citizens hold the state accountable.

The Death of the RTI’s "Public Interest" Test

To understand why this matters to your practice, look at what Section 44(3) of the DPDP Act actually did to Section 8(1)(j) of the RTI Act. Previously, the RTI Act exempted personal information from disclosure unless the Public Information Officer determined that the larger public interest justified the disclosure. Crucially, it contained a proviso: information that cannot be denied to the Parliament or a State Legislature cannot be denied to a citizen.

The DPDP Act surgically removed both the public interest override and the legislative proviso. It created an absolute, blanket exemption for "personal information."

"By weaponizing privacy to shield bureaucratic action, the amendment turns the Puttaswamy judgment on its head. Privacy is a shield for the citizen against the state, not a cloak for the state against the citizen."

As litigators, we must recognize that this absolute exemption fails the proportionality test laid down in K.S. Puttaswamy v. Union of India. An absolute bar on disclosure, without a balancing test for public interest, is a disproportionate restriction on the Article 19(1)(a) right to know. The Supreme Court's eventual ruling on this will dictate whether the DPDP Act survives in its current form or requires judicial reading-down. But for now, the law stands.

The Enforcement Reality: NHRC Notices and the Fintech Scramble

Because the Supreme Court refused a stay, the operational rules enacted in November 2025 are actively biting Data Fiduciaries. Reuters reports that the rules mandating strict purpose limitation, verifiable consent, and immediate breach notification are now in full force.

If you are advising banks, insurers, or fintechs, your gap assessments should already be complete. The Reserve Bank of India (RBI) and the newly empowered Data Protection Board (DPB) will not accept "we are waiting for the Supreme Court" as a valid defense. We are seeing a massive shift in corporate legal departments from generic "privacy policy drafting" to building operational consent architectures.

More alarmingly for tech companies, the National Human Rights Commission (NHRC) has bypassed the DPB entirely, issuing notices to major AI, social media, and EdTech platforms over alleged violations of Section 9 of the DPDP Act. Section 9 strictly prohibits tracking, behavioral monitoring, and targeted advertising directed at children. For EdTech counsel, this is a five-alarm fire. If your client’s platform uses behavioral analytics to "personalize" learning for a minor without explicit, verifiable parental consent, you are in the crosshairs of both the NHRC and the DPB.

The AI Erasure Nightmare: "Machine Unlearning"

Perhaps the most fascinating development for IP and technology lawyers is the emerging jurisprudence around Section 12(3) of the DPDP Act—the right to erasure. A June 2026 legal analysis highlighted the existential threat this poses to Artificial Intelligence platforms operating in India.

Under the Act, when a Data Principal withdraws consent, the Data Fiduciary must erase their personal data. But how do you erase data that has already been ingested and processed by a Large Language Model (LLM)?

This has birthed the legal-technical concept of "machine unlearning." Standard deletion from a database is insufficient if the AI's neural network retains the "memory" or patterns derived from that personal data. For IP lawyers negotiating SaaS agreements or advising AI startups, standard indemnities won't cut it. You must now draft contracts that require technical vendors to guarantee algorithmic unlearning—a process that is currently technologically nascent and commercially expensive.

The Bottom Line for Counsel

The 2026 landscape of Indian data law requires a shift from advisory to deeply operational legal practice. Here is what you need to tell your clients today:

1. Stop waiting for the Supreme Court: The refusal to stay the Act means the November 2025 rules are the law of the land. Penalties under the Act can reach up to ₹250 crores per breach.

2. Audit EdTech and AI strictly against Section 9: Any tracking of minors must be halted immediately unless a robust, verifiable parental consent mechanism is active.

3. Brace for RTI rejections: Litigators relying on the RTI Act to gather evidence against public servants must prepare to challenge blanket "personal data" rejections in High Courts under Article 226, invoking the unconstitutionality of the DPDP amendment.

The DPDP Act has shed its theoretical skin. For Indian lawyers, the era of enforcement has officially arrived.

Published by AnrakLegal AI