Legal News
24 August 2026
IP & Technology

The DPDP Act is in the Supreme Court, But Your Clients Must Comply Today: Navigating the RTI Collision and the End of 'Checkbox Consent'

The Dual Reality of India’s Data Protection Regime in 2026 For Indian technology and privacy lawyers, 2026 has fractured into two distinct realities. In the corridors of the Supreme Court, the constitutional validity of the Digital Personal Data Prot...

The Dual Reality of India’s Data Protection Regime in 2026

For Indian technology and privacy lawyers, 2026 has fractured into two distinct realities. In the corridors of the Supreme Court, the constitutional validity of the Digital Personal Data Protection (DPDP) Act, 2023 and the subsequent DPDP Rules, 2025 is facing intense judicial scrutiny. Yet, in the boardrooms of Data Fiduciaries, the luxury of waiting for jurisprudential clarity has evaporated. The Data Protection Board is now fully operational, and the Supreme Court has made one thing abundantly clear: there will be no stay on the Act’s operation while the constitutional challenges pend.

If your clients are treating the ongoing Supreme Court litigation as a grace period to delay their compliance rollouts, you need to correct their course immediately. The shift from "law on the books" to "operational compliance" is absolute.

Section 44(3): The Collision Between Privacy and Transparency

The most consequential legal battle currently playing out is the challenge to Section 44(3) of the DPDP Act. For litigators and public law practitioners, this is the ground zero of the DPDP framework. Section 44(3) amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005, effectively exempting all personal data from RTI disclosure.

Previously, the RTI Act allowed the disclosure of personal information if the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified it. The DPDP Act has taken a sledgehammer to this public interest override. By creating a blanket exemption, the legislature has weaponized a privacy statute to erect an impenetrable shield against transparency.

"The fundamental tension the Supreme Court is grappling with is whether a statute designed to protect citizens from corporate and state surveillance can be constitutionally inverted to protect the state from citizen scrutiny."

On 13 April 2026, a targeted Public Interest Litigation (PIL) was filed seeking interim relief against the masking and deletion of already available public data under the guise of DPDP compliance. Earlier, on 12 March 2026, the Supreme Court rightly flagged the urgent need to distinguish between "public data" and "personal data." For practicing lawyers, this distinction is critical. If a client is scraping public government portals for data analytics, the definition of what constitutes "personal data" under the shadow of the amended RTI Act could fundamentally alter their risk exposure.

The Refusal to Stay: Why Corporate Lawyers Must Act Now

Despite issuing notice on these sweeping constitutional challenges on 16 February 2026, the Supreme Court explicitly refused to stay the operation of the Act or the 2025 Rules. As reported throughout July 2026, the litigation does not suspend compliance obligations.

This is where advisory practice meets hard reality. The November 2025 implementation of the DPDP Rules introduced stringent expectations regarding data minimization, clear user disclosures, and strict breach notification timelines. You can no longer draft a generic, 50-page privacy policy, slap an "I Agree" button at the bottom, and call it a day.

The Death of the 'Checkbox': A Stricter Consent Architecture

Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous. But the 2025 Rules have elevated this from a mere definitional standard to an evidentiary burden. The prevailing compliance theme among tech lawyers in mid-2026 is that consent management is now a high-stakes, evidence-heavy model.

If the Data Protection Board knocks on your client's door tomorrow, relying on a user's click on a pre-ticked checkbox will not suffice. You must be able to prove:

1. Granularity: Did the user consent to this specific purpose?
2. Notice: Was the itemized notice under Section 5 presented in clear, plain language, and available in multiple languages specified in the Eighth Schedule?
3. Verifiability: Can the Data Fiduciary produce an unalterable log proving when and how the consent was obtained?

This means lawyers must step out of the legal department and sit with the UI/UX and backend engineering teams. The legal mandate has become a software architecture mandate. If your client's frontend interface obscures the withdrawal of consent—making it harder to opt-out than it was to opt-in—they are in direct violation of the framework.

The Takeaway for Practitioners

While the Supreme Court untangles the complex web of Section 44(3), the RTI Act, and the dichotomy of public versus personal data, commercial practitioners must proceed under the assumption of maximum regulatory enforcement. The Data Protection Board is not a paper tiger; it is an operational reality.

Advise your clients to audit their existing data inventories, map their consent architectures, and prepare for a regime where the burden of proof rests entirely on the Data Fiduciary. The days of "move fast and break things" with user data are officially over in India. The law demands that you move carefully, document everything, and be ready to prove it.

Published by AnrakLegal AI