Legal News
26 August 2026
IP & Technology

The DPDP Act is Here to Stay (For Now): Why the Supreme Court’s Refusal to Halt the Privacy Law Changes Everything for Tech and Media Counsel

The Compliance Clock Will Not Be Paused For corporate counsel and technology lawyers secretly hoping the Supreme Court would hit the pause button on India's sweeping new privacy regime, the verdict is in: stop waiting and start complying. On 16 Febru...

The Compliance Clock Will Not Be Paused

For corporate counsel and technology lawyers secretly hoping the Supreme Court would hit the pause button on India's sweeping new privacy regime, the verdict is in: stop waiting and start complying. On 16 February 2026, the Supreme Court issued notice on the constitutional challenge to the Digital Personal Data Protection (DPDP) Act, 2023, and the accompanying DPDP Rules, 2025. Crucially, while the Court referred the matter to a larger bench, it explicitly refused to stay the operation of the Act.

This is a defining moment for Indian tech law. By allowing the DPDP framework to remain operational while the constitutional lis remains sub judice, the Supreme Court has forced the hand of every data fiduciary in the country. With substantive commencement looming in 2027 and critical compliance milestones—such as the operationalization of Consent Managers—due by November 2026, the luxury of a "wait-and-watch" approach has officially evaporated.

The RTI Amendment: A Shield for Corruption or a Victory for Privacy?

At the heart of the Supreme Court challenge lies Section 44(3) of the DPDP Act, which fundamentally alters the Right to Information (RTI) Act, 2005. For practicing lawyers, understanding this amendment is critical, as it completely reshapes how we approach transparency and corporate governance.

Prior to this amendment, Section 8(1)(j) of the RTI Act provided a qualified exemption for personal information. Public Information Officers (PIOs) could refuse disclosure unless they determined that the larger public interest justified the release. Section 44(3) of the DPDP Act obliterates this balancing test, replacing it with a blanket prohibition on the disclosure of personal data.

"The dilution of the public interest test under the RTI Act effectively weaponizes privacy against transparency. We are looking at a regime where state actors and corporate entities interfacing with the state can use 'personal data' as an impenetrable shield against journalistic and legal scrutiny."

The Supreme Court has rightly flagged this for a larger bench. But until that bench rules, media houses, investigative journalists, and lawyers relying on RTI queries for fact-finding or litigation strategy will find the doors of government departments slammed shut under the guise of DPDP compliance.

The "Public vs. Personal Data" Conundrum: A Ticking Time Bomb for AI and IP

Perhaps the most intellectually stimulating—and commercially dangerous—aspect of the Court's upcoming examination is its promise to define the boundary between "public data" and "personal data." This is where the DPDP Act crashes headfirst into Intellectual Property and Technology law.

Under Section 3(c)(ii) of the DPDP Act, the provisions do not apply to personal data that is made publicly available by the Data Principal themselves or under a legal obligation. For the booming Indian Artificial Intelligence sector, this section has been interpreted as a safe harbor. Tech companies and LLM developers have been scraping the Indian internet, operating under the assumption that if a user posted it publicly, it is fair game for algorithmic training.

This assumption is legally fragile. If the Supreme Court adopts a narrow interpretation of what constitutes "publicly available" data—or rules that the original context of publication matters—the IP and data-scraping workflows of major tech firms will be paralyzed. We are already seeing this friction in copyright law under Section 52 of the Copyright Act, 1957 (fair dealing), but the DPDP Act adds a draconian layer of privacy penalties. Lawyers advising AI platforms must immediately audit their clients' data scraping protocols. If your client's LLM is trained on scraped Indian personal data, you are currently operating in a massive legal gray area.

The Headless Board and the ₹250 Crore Threat

The regulatory reality on the ground is paradoxical. As of July 2026, the Data Protection Board of India (DPB) exists in law but lacks a fully functioning leadership structure. However, practitioners must not mistake a headless regulator for a toothless one.

The enforcement framework is substantively operational. The DPDP Act imposes staggering penalties under the Schedule, reaching up to ₹250 crore for failing to take reasonable security safeguards to prevent personal data breaches. We are already seeing the private sector react. Banks and fintech startups are aggressively executing gap assessments, integrating consent tooling, and aligning their DPDP breach-reporting obligations with the existing CERT-In cyber reporting regime under the IT Act.

What Counsel Must Do Now

The Supreme Court's refusal to grant a stay is a clear directive to the legal profession. Here is what you need to be advising your clients today:

  • Stop Relying on the Litigation Excuses: Inform your boards that the constitutional challenge is not a free pass. The November 2026 deadline for integrating Consent Manager infrastructure is hard and fast.
  • Audit Platform Governance: For media and tech intermediaries, content workflows must be overhauled. If your client publishes data that might be construed as "personal," the lack of a public interest defense under the new RTI regime signals a broader judicial and legislative pivot toward absolute privacy.
  • Prepare for the Breach: Incident response plans must be updated immediately to handle simultaneous reporting to CERT-In and the soon-to-be-operational DPB.

The DPDP Act is no longer just a theoretical piece of legislation debated in webinars; it is a live, enforceable compliance juggernaut. The Supreme Court will eventually have its say on the constitutional limits of data privacy, but until then, the cost of non-compliance is simply too high to ignore.

Published by AnrakLegal AI