The DPDP Act is Now a Live Wire: Why the Supreme Court’s Refusal to Grant a Stay Changes Everything for Tech and Privacy Lawyers
The End of the "Wait and Watch" Era For the past three years, the Indian corporate sector has treated the Digital Personal Data Protection (DPDP) Act, 2023, as a looming but distant threat. That grace period officially ended on February 16, 2026. Whe...
The End of the "Wait and Watch" Era
For the past three years, the Indian corporate sector has treated the Digital Personal Data Protection (DPDP) Act, 2023, as a looming but distant threat. That grace period officially ended on February 16, 2026. When the Supreme Court referred the constitutional challenges against the DPDP Act and the newly minted 2025 Rules to a larger bench, it made one thing abundantly clear: there will be no stay on the operation of the law.
For practicing technology and privacy lawyers, this is a clarion call. You can no longer advise your clients to delay their compliance audits pending judicial review. The compliance clock is not just ticking; it is screaming. The refusal to grant a stay, grounded in the traditional presumption of constitutionality of statutes, means that the Data Protection Board (DPB) can and will begin wielding its enforcement powers. If your clients are not already operationalizing consent management platforms and drafting stringent data processing agreements, they are exposed to catastrophic penalties.
The RTI Paradox: Privacy as a Shield for Opacity
The crux of the Supreme Court litigation—and arguably the most dangerous provision in the DPDP Act—is Section 44(3), which amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005.
Historically, Section 8(1)(j) contained a delicate, vital balancing test: personal information of a citizen could be exempt from RTI disclosure unless the Public Information Officer was satisfied that the larger public interest justified its release. It was this exact proviso that allowed journalists and activists to uncover corruption, disproportionate assets, and electoral anomalies.
Section 44(3) of the DPDP Act obliterates this balance. It creates a blanket exemption for all "personal information," severing the public interest exception entirely. In our view, this is a legislative overreach of the highest order. By weaponizing the fundamental right to privacy (as recognized in K.S. Puttaswamy v. Union of India) to shield the state from transparency, the Act creates an irreconcilable conflict between the citizen's right to know and the right to privacy.
"The amendment to the RTI Act fundamentally alters the DNA of Indian administrative transparency. Privacy was meant to protect the citizen from the State, not to protect the State from the citizen."
The Supreme Court’s decision to refer this to a larger bench acknowledges the gravity of this constitutional friction. However, until the larger bench rules, public authorities will absolutely use the amended Section 8(1)(j) to reject RTI queries en masse. Lawyers representing civil rights groups or journalists must be prepared to challenge these rejections by arguing that the definition of "personal data" is being misapplied by public authorities.
The "Public vs. Private" Data Conundrum
On March 12, 2026, the Supreme Court flagged another massive doctrinal issue: the legal distinction between public data and personal data. Under Section 3(c)(ii) of the DPDP Act, the law does not apply to personal data that is made publicly available by the Data Principal themselves or under a legal obligation.
But in the age of ubiquitous data scraping and generative AI, what constitutes "publicly available" is highly contested. If a user posts their professional history on LinkedIn, is it fair game for a Data Fiduciary to scrape that data to train an AI model without consent? The Court’s acknowledgment of this gray area indicates that the judiciary is acutely aware of the complexities of modern data architectures. For practitioners, this means you must rigorously document how your clients are sourcing their data. Relying on the "publicly available" exception is a high-risk strategy that could easily collapse depending on how the larger bench interprets this boundary.
The Hidden IP Minefield: AI, Employees, and Data Breaches
While the constitutional drama unfolds in the Supreme Court, a quieter but equally significant crisis is brewing in enterprise compliance. Recent reports from the tech-law sector highlight a massive overlap between AI usage by employees, Intellectual Property (IP) risk, and DPDP compliance.
Consider a common scenario: an employee feeds a dataset containing customer information or proprietary source code into a public Generative AI tool to generate a report or debug a program.
Under the DPDP Act, this is an unauthorized processing activity and a personal data breach (failure to implement reasonable security safeguards under Section 8(4)). Simultaneously, under IP law, this constitutes a leakage of trade secrets and a breach of confidentiality.
IP and technology lawyers must stop treating data protection and IP as siloed practice areas. The 2026 landscape demands unified Acceptable Use Policies (AUPs) for AI in the workplace. Your immediate action items should include:
- Drafting explicit prohibitions on feeding personal data or proprietary IP into unsanctioned LLMs.
- Updating employment contracts to classify DPDP breaches via AI as gross misconduct.
- Implementing technological guardrails (like enterprise-gated AI environments) to ensure that any data processed by AI remains within the Data Fiduciary's controlled perimeter.
The Bottom Line
The Supreme Court’s handling of the DPDP Act in early 2026 is a masterclass in judicial caution, but it leaves businesses in the crosshairs of immediate compliance. The larger bench will eventually settle the RTI conflict and the nuances of public data, but the enforcement machinery will not wait for that judgment. For Indian lawyers, the mandate is clear: bridge the gap between abstract constitutional privacy rights and the granular realities of enterprise AI and data flows. The grace period is over; it is time to litigate, comply, and adapt.
Tags
Published by AnrakLegal AI