Legal News
23 August 2026
IP & Technology

The DPDP Act is Sub Judice, But Your Clients Can’t Hide: Navigating the Supreme Court's RTI Clash and the 2027 Compliance Clock

No Stay, No Excuses: The Supreme Court Draws a Line For tech lawyers and in-house counsel, the temptation to advise clients to "wait and watch" is overwhelming whenever a major regulatory framework is challenged in the Supreme Court. With the Digital...

No Stay, No Excuses: The Supreme Court Draws a Line

For tech lawyers and in-house counsel, the temptation to advise clients to "wait and watch" is overwhelming whenever a major regulatory framework is challenged in the Supreme Court. With the Digital Personal Data Protection (DPDP) Act, 2023, you need to resist that temptation immediately. On 16 February 2026, the Supreme Court issued notice on petitions challenging the DPDP Act’s controversial amendment to the Right to Information (RTI) Act, referring the matter to a larger bench. But the Court made one thing abundantly clear: there is no stay on the Act’s operation.

What this means for your practice is simple. The litigation is sub judice, but the regulatory clock is ticking loudly. The Data Protection Board (DPB) has been fully operational since November 2025, and businesses have a hard deadline of 13 May 2027 for full enforcement of core consent, notice, and processing obligations. If your clients are using the pending Supreme Court challenge as an excuse to delay their data mapping and compliance architectures, they are walking into a regulatory buzzsaw.

The Section 44(3) Conundrum: When Privacy Cannibalizes Transparency

The core of the Supreme Court battle lies in Section 44(3) of the DPDP Act, which fundamentally alters the DNA of India’s transparency regime by amending Section 8(1)(j) of the RTI Act. This isn't just an academic debate; it drastically changes how public authorities process information requests.

Historically, Section 8(1)(j) of the RTI Act provided a qualified exemption for personal information. A Public Information Officer (PIO) could refuse disclosure unless they were satisfied that the "larger public interest justifies the disclosure of such information." It was a delicate balancing act between the right to know and the right to privacy, often leaning on the proportionality test established in K.S. Puttaswamy.

The DPDP Act aggressively deletes this public interest caveat. It creates an absolute, blanket embargo on the disclosure of any personal information under the RTI Act. On 12 March 2026, the Supreme Court noted that it must examine the precise boundary between "public data" and "personal data."

"The absolute exemption created by the DPDP Act risks turning the RTI Act into a dead letter whenever a public document contains even a shred of personal data. The Court's upcoming determination on where public accountability ends and personal privacy begins will redefine administrative law in India."

For lawyers representing media houses, NGOs, or even corporations conducting due diligence via RTI, this amendment is a brick wall. Until the larger bench rules, expect PIOs to use the DPDP Act as a convenient shield to reject virtually any request that tangentially involves a named individual.

The Unseen Intersection: DPDP, Generative AI, and Trade Secrets

While the constitutional lawyers battle over the RTI Act, IP and technology lawyers have a different, quieter crisis on their hands. Recent commentary in 2026 has heavily focused on the intersection of DPDP compliance, enterprise data systems, and Artificial Intelligence.

The risk profile for companies has mutated. As highlighted by recent industry reports, employee use of unauthorized generative AI tools (Shadow AI) is creating a dual threat: an unseen IP leakage and a DPDP data breach. When an employee feeds a prompt into a public AI chatbot to summarize a client contract or debug code, two things happen simultaneously:

First, if the data includes personally identifiable information (PII), the company has just processed data beyond the purpose for which consent was obtained, violating the core tenets of the DPDP Act. Second, if the data includes proprietary algorithms or trade secrets, the company has compromised its IP.

Therefore, drafting a DPDP-compliant privacy policy is no longer enough. Tech lawyers must now draft holistic Workplace Data Governance Policies that simultaneously restrict AI usage to protect IP under the Copyright Act and trade secret jurisprudence, while logging consent and restricting data flows to comply with the DPDP Rules 2025.

The Compliance Countdown: What You Need to Do Now

The transition period granted by the DPDP Rules 2025 is generous, but the technical implementation required is massive. Here are the milestones that should be driving your advisory practice:

1. The Consent Manager Rollout (13 November 2026): Registration for Consent Managers opens this November. These entities will act as the technical intermediaries through which Data Principals can give, manage, and withdraw consent. If you represent digital platforms or consumer-facing apps, your immediate task is to audit their UX/UI to ensure they can integrate with these new Consent Managers. The era of pre-ticked boxes and bundled "Terms and Conditions" is over.

2. Full Enforcement (13 May 2027): By this date, the grace period ends. Notice designs must be localized (available in the 22 languages of the Eighth Schedule), consent logs must be immutable, and proof of lawful processing must be readily available for DPB audits.

The Takeaway: Stop waiting for a judicial deus ex machina. The Supreme Court may eventually strike down or read down the RTI amendment, but it is highly unlikely to dismantle the core compliance obligations of the DPDP Act. Practicing lawyers must pivot from analyzing the law's constitutional vulnerabilities to actually building the compliance architectures their clients desperately need. Sub judice is a legal status, not a business strategy.

Published by AnrakLegal AI