Legal News
16 April 2026
IP & Technology

The DPDP Act Hits the Constitution Bench: Why the RTI Collision and May 2026 Deadline Will Rewrite Indian Data Practice

If 2023 was the year of legislative victory for India’s data protection regime, 2026 is rapidly becoming the year of constitutional reckoning and corporate panic. The Digital Personal Data Protection (DPDP) Act, 2023 is no longer just a theoretical f...

If 2023 was the year of legislative victory for India’s data protection regime, 2026 is rapidly becoming the year of constitutional reckoning and corporate panic. The Digital Personal Data Protection (DPDP) Act, 2023 is no longer just a theoretical framework for seminars; it is actively colliding with fundamental rights in the Supreme Court and causing widespread anxiety across corporate drafting tables.

For practicing lawyers, the latest developments signal a massive shift. We are witnessing a two-front war: a high-stakes constitutional battle over the Right to Information, and a brutal compliance sprint for corporate and technology teams racing toward the May 13, 2026 deadline.

The Constitutional Sledgehammer: Section 44(3) vs. The RTI Act

The most consequential legal development this week is Chief Justice Surya Kant’s decision to refer petitions challenging the DPDP Act to a five-judge Constitution Bench. At the heart of this litigation is Section 44(3) of the DPDP Act, which quietly amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005.

Prior to this amendment, Section 8(1)(j) allowed Public Information Officers (PIOs) to deny personal information unless there was a larger public interest justifying its disclosure. The proviso explicitly stated that information which cannot be denied to the Parliament or State Legislature shall not be denied to any person. The DPDP Act took a sledgehammer to this nuanced balance, removing the public interest carve-out entirely. Now, public authorities can blanket-refuse disclosure simply by claiming the details are "personal in nature."

"We will not thwart a regime introduced by Parliament unless we hear the case... but this is a complex issue requiring a balance between fundamental rights of both sides." — Supreme Court Bench

Why this matters for litigators: This is the ultimate showdown between Article 19(1)(a) (Right to Know) and Article 21 (Right to Privacy). The petitioners—civil rights groups and journalists—rightly argue that this amendment creates an impenetrable shield for corrupt public officials. While the Court refused an interim stay—preventing the immediate dismantling of transparency portals like Rajasthan's Jan Soochna—the upcoming Constitution Bench hearings will essentially draft the sequel to the landmark Puttaswamy judgment. Litigators should anticipate a heavy reliance on the doctrine of proportionality. It is highly likely the Supreme Court will have to read down Section 44(3) to resurrect the public interest exemption; otherwise, the RTI Act is effectively defanged.

The May 2026 Compliance Sprint: Death of the "Clickwrap"

While the Supreme Court debates constitutional philosophy, corporate and in-house counsel are staring down the barrel of a rapidly approaching compliance deadline. With the DPDP Rules notified on November 14, 2025, the government has mandated a strict 14-month compliance window, closing on May 13, 2026.

Despite the ticking clock, reports indicate that most Global Capability Centers (GCCs) and domestic tech firms are woefully unprepared. The core of the panic? The realization that GDPR templates will not save them here. The DPDP Act fundamentally redefines consent.

What changes in your practice: If you are drafting commercial contracts or Terms of Service, the era of the boilerplate "clickwrap" checkbox is dead. Under the DPDP framework, consent is not a one-off transaction; it is a continuing legal relationship between the Data Principal and the Data Fiduciary.

Corporate lawyers must immediately initiate the "re-papering" of Master Service Agreements (MSAs) and Data Processing Agreements (DPAs). You need to categorically define:

  • Role Allocation: Strict demarcation between Data Fiduciaries and Data Processors. The DPDP Act places the primary onus on the Fiduciary, meaning indemnification clauses in vendor contracts are about to become the most fiercely negotiated provisions of 2026.
  • Verifiable Consent Mechanisms: Drafting DPDP-specific notice requirements that are multilingual, itemized, and easily withdrawable.
  • Breach Timelines: Reconciling DPDP breach notification mandates with the existing CERT-In directions under the Information Technology Act, 2000.

Regulatory Wildcards: NHRC Notices and the IT Rules 2026

Adding a bizarre twist to the enforcement landscape is the sudden activism of the National Human Rights Commission (NHRC). The NHRC has begun issuing notices to AI, social media, and edtech platforms for alleged DPDP Act violations.

Why is the NHRC acting as a de facto Data Protection Board (DPB)? This aggressive posturing highlights a temporary regulatory vacuum while the actual DPB scales its operations. For tech lawyers, this means your clients might face quasi-judicial human rights inquiries for data breaches—a reputational nightmare that goes far beyond standard financial penalties.

Furthermore, the newly effective IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (effective Feb 20, 2026) have thrown gasoline on the intermediary liability debate. By explicitly targeting deepfakes and tightening due diligence requirements, the safe harbour protection under Section 79 of the IT Act is shrinking faster than ever. Platforms can no longer hide behind the "dumb conduit" defense if their algorithms actively process or promote manipulated personal data.

The Bottom Line

The DPDP Act is proving to be a highly disruptive force in 2026. For Indian lawyers, the mandate is clear: litigators must prepare for a historic recalibration of constitutional transparency, while corporate counsel must stop treating data protection as a mere IT compliance issue. It is now a core contractual liability. If your clients are still relying on pre-2025 privacy policies and vague vendor agreements, they are walking blindfolded into a regulatory minefield.

Published by AnrakLegal AI