The DPDP Act Marches On: Supreme Court Refuses Stay, Puts Corporate India on the Clock Amidst RTI Battle
The Supreme Court’s Refusal to Hit Pause On February 16, 2026, the Supreme Court of India drew a definitive line in the sand regarding the Digital Personal Data Protection (DPDP) Act, 2023. While hearing a batch of Public Interest Litigations (PILs) ...
The Supreme Court’s Refusal to Hit Pause
On February 16, 2026, the Supreme Court of India drew a definitive line in the sand regarding the Digital Personal Data Protection (DPDP) Act, 2023. While hearing a batch of Public Interest Litigations (PILs) challenging the constitutionality of the Act—specifically its crippling amendments to the Right to Information (RTI) Act, 2005—the apex court issued notice and referred the matter to a larger bench. But for practicing tech and corporate lawyers, the real headline was what the Court refused to do: it categorically declined to stay the operation of the DPDP Act and the recently notified DPDP Rules, 2025.
By refusing to grant a stay, the Supreme Court has sent a stark message to boardrooms and general counsels across the country. The constitutional challenges brought by digital rights groups and journalists will grind through the judicial machinery, but corporate India must march forward with compliance. If your clients were hoping that a stay order would buy them another year to overhaul their data architectures, that hope is now dead. The law is live, the Rules are in play, and the phased enforcement deadlines are looming.
The RTI Conundrum: Weaponizing Privacy Against Transparency?
To understand why this larger bench referral matters, we must look at the substantive law. Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act. Under the old Section 8(1)(j) regime, personal information was exempt from RTI disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It was a delicate, necessary balancing act between Article 19(1)(a) (the right to know) and Article 21 (the right to privacy).
The DPDP Act obliterates this balance. The amendment replaces the nuanced public-interest carve-out with a blanket exemption for all personal information. From a legal standpoint, this is a highly suspect legislative maneuver.
The DPDP Act’s amendment to the RTI Act effectively weaponizes the fundamental right to privacy to shield the state from transparency. It ignores the core tenet of K.S. Puttaswamy v. Union of India: that privacy is not an absolute right, and must be balanced against compelling state interests and competing fundamental rights.
The referral to a larger bench is a tacit admission by the Supreme Court that resolving this clash requires reconciling the constitutional jurisprudence of Puttaswamy with the transparency mandates of a democracy. However, until that larger bench rules, Section 8(1)(j) remains mutilated. For lawyers advising journalists, NGOs, or activists, this means RTI applications seeking anything remotely resembling "personal data" of public officials will be summarily rejected by CPIOs citing the DPDP Act.
What This Means for Practice: The Compliance Clock is Ticking
For IP, Tech, and Corporate lawyers, the Supreme Court’s refusal to stay the Act means shifting focus entirely to the impending compliance milestones. The DPDP Rules were notified in November 2025, and the phased implementation is now in full swing.
First, lawyers must prepare for the Consent Manager framework. Current analyses indicate that Consent Manager registrations will commence around November 13, 2026. If you represent fintechs, Account Aggregators, or large consumer-facing digital platforms, your clients need to finalize their integrations with these Consent Managers immediately. The paradoxical overlap between RBI’s Account Aggregator framework and the DPDP’s Consent Manager rules requires careful legal structuring to ensure dual-compliance.
Second, the substantive compliance obligations—including notice requirements, verifiable parental consent, and data principal rights—are staged for strict enforcement by May 2027. The Data Protection Board of India (DPBI) is already taking shape. Lawyers must advise clients to stop waiting for the courts and start executing data mapping, revising privacy policies, and implementing technical safeguards.
Ed-Tech and Employment: Expanding the DPDP Footprint
Beyond the RTI clash, the Supreme Court has already begun citing the DPDP Act in peripheral litigation, signaling its deep integration into Indian jurisprudence. In the recent 2026 APAAR scheme litigation regarding student surveillance and data tracking, the Court explicitly tied the handling of student data to the DPDP Act. The Court emphasized that verifiable parental consent and mandatory opt-out safeguards are not just policy recommendations—they are statutory mandates under Section 9 of the DPDP Act.
For counsels representing Ed-Tech companies or educational institutions, this is a massive red flag. Blanket consent forms tucked into school admission packets will no longer survive judicial scrutiny. Consent must be granular, informed, and easily revocable.
Furthermore, the intersection of Artificial Intelligence, Intellectual Property, and the DPDP Act is creating a new minefield in employment law. As employees increasingly feed proprietary company data and personal data into generative AI tools, the risk of a "personal data breach" under the DPDP Act skyrockets. Employment contracts and internal IT policies must be aggressively redrafted to explicitly prohibit the unauthorized processing of personal data through third-party AI models, shielding the employer (the Data Fiduciary) from crippling DPBI penalties.
The Verdict for Counsels
The Supreme Court’s February 2026 order is a defining moment. It separates the academic constitutional debate from the harsh reality of corporate compliance. While scholars and litigators will rightly debate the chilling effect of the RTI amendments before a larger bench, transactional and in-house lawyers have their marching orders. The DPDP Act is the law of the land, it is operational, and the grace period is rapidly evaporating. Advise your clients to build their privacy architectures now, because when the May 2027 enforcement cliff arrives, "pending constitutional challenges" will not serve as a valid legal defense before the Data Protection Board.
Tags
Published by AnrakLegal AI