The DPDP Act’s 2026 Limbo: Constitutional Showdowns, Phantom Boards, and the Epidemic of Premature Compliance
The Paradox of India's Data Protection Regime For Indian technology and privacy lawyers, 2026 is proving to be a year characterized by a bizarre legal paradox: we are fiercely litigating and aggressively complying with a data protection regime that i...
The Paradox of India's Data Protection Regime
For Indian technology and privacy lawyers, 2026 is proving to be a year characterized by a bizarre legal paradox: we are fiercely litigating and aggressively complying with a data protection regime that is, in practical terms, only half-alive. The Digital Personal Data Protection (DPDP) Act, 2023, and its subsequent 2025 Rules have created a regulatory environment that is simultaneously hyper-active in the constitutional courts and severely paralyzed at the institutional level.
With major substantive obligations—including the consent architecture, breach notifications, and cross-border transfer conditions—not expected to become fully enforceable until May 2027, practitioners are navigating a dangerous twilight zone. Here is what the current landscape means for your practice, your clients, and the rule of law.
The RTI vs. Privacy Collision: A Constitutional Bench Awaits
The most consequential litigation of the year is undoubtedly the Supreme Court’s examination of the DPDP Act’s impact on the Right to Information (RTI) Act, 2005. In February 2026, a bench led by Chief Justice Surya Kant referred challenges against the RTI amendment to a five-judge Constitution Bench.
At the heart of this dispute is Section 44(3) of the DPDP Act, which fundamentally rewrote Section 8(1)(j) of the RTI Act. Previously, personal information could be disclosed under the RTI Act if a Public Information Officer (PIO) determined that the larger public interest justified the disclosure. The DPDP Act obliterated this balancing test, introducing a blanket exemption for personal data.
"By removing the public interest caveat, the legislature has weaponized privacy to shield administrative opacity. The state can now legitimately reject a vast swath of RTI applications simply by citing the presence of personal data."
Why this matters for your practice today: Crucially, the Supreme Court did not stay the amendment while referring it to the Constitution Bench. For litigators practicing administrative law, this means the blanket exemption remains good law right now. PIOs are routinely (and legally) rejecting RTI requests on privacy grounds. If you are relying on RTI responses to gather evidence for writ petitions or commercial disputes, you must immediately pivot your strategy to seek information through judicial discovery or Section 91 CrPC/Order XI CPC applications, rather than relying on the RTI framework.
The Institutional Vacuum: Where is the Data Protection Board?
While the Supreme Court debates the constitutional validity of the Act, a more pragmatic crisis is unfolding: the Data Protection Board of India (DPBI) remains essentially non-existent. Despite the Rules being notified in November 2025, reports in August 2026 confirmed that the Board still lacks appointed leadership.
This institutional vacuum is forcing constitutional courts to step into regulatory shoes. The Kerala High Court’s recent intervention in the Digi Yatra passenger data security case is a prime example. The High Court explicitly sought the status of the DPBI's constitution, highlighting a critical flaw in the state's rollout strategy: you cannot mandate data security for digital public infrastructure without an adjudicatory body to oversee breaches.
For corporate counsel, this headless regulatory state is a double-edged sword. On one hand, the immediate threat of regulatory penalties is low. On the other hand, the lack of a functioning Board means there is no authoritative body to issue clarifications, leaving Data Fiduciaries to guess at compliance standards.
Consent Jurisprudence Taking Shape: The APAAR Order
Even without a functioning Board, the Supreme Court is actively shaping how Section 6 (Consent) of the DPDP Act will be interpreted. In July 2026, the Court directed the Centre and CBSE to amend the APAAR (Automated Permanent Academic Account Registry) consent form.
The Court mandated the inclusion of a clear opt-out/refuse option and strictly restricted the third-party sharing of student data. This judicial intervention is a massive signal to the private sector.
The takeaway for drafting: If you are drafting consent notices for Data Fiduciaries, the APAAR ruling is your new baseline. "Take-it-or-leave-it" consent models, or bundled consents where primary services are contingent on agreeing to third-party data sharing, will not survive judicial scrutiny. Your client's consent architecture must be granular, severable, and feature an unambiguous mechanism for withdrawal.
The Epidemic of Premature Compliance
Perhaps the most frustrating trend of 2026 is what we can call "phantom compliance." Driven by panic and overzealous advisory, Data Fiduciaries are redrafting cross-border data transfer contracts as if Section 16 and Rule 15 are currently operative.
They are not. As commentaries have rightly pointed out, the cross-border transfer obligations are not yet live, and the Central Government has not published any "restricted country" list. Yet, Indian companies are locking themselves into rigid, expensive indemnities and Standard Contractual Clauses (SCCs) that the law does not yet require.
The strategic imperative: Transactional lawyers must advise clients to pump the brakes. The DPDP rollout is staggered, with the consent manager registration not opening until November 2026, and full substantive compliance expected in May 2027.
Instead of over-engineering vendor contracts for a cross-border regime that hasn't fully crystallized, legal budgets should currently be directed inward. Focus on data mapping, establishing the two-stage breach-notification protocols internally, and classifying what actually constitutes "personal data" versus "public data"—a distinction the Supreme Court is currently examining in pending civil-society writ petitions.
The DPDP Act is the most significant overhaul of Indian commercial and privacy law in a decade. But litigating and advising on it requires recognizing the difference between what the law will be in 2027, and what the courts are actually enforcing in 2026.
Tags
Published by AnrakLegal AI