Legal News
11 August 2026
IP & Technology

The DPDP Act’s Constitutional Collision: Why the Supreme Court’s Refusal to Stay the Law Changes Your 2026 Compliance Strategy

The Illusion of a Reprieve: Supreme Court Keeps DPDP Alive For corporate lawyers and privacy practitioners holding their breath, the Supreme Court has officially exhaled. On February 16, 2026, the Apex Court issued notice in the batch of petitions ch...

The Illusion of a Reprieve: Supreme Court Keeps DPDP Alive

For corporate lawyers and privacy practitioners holding their breath, the Supreme Court has officially exhaled. On February 16, 2026, the Apex Court issued notice in the batch of petitions challenging the constitutional validity of the Digital Personal Data Protection (DPDP) Act, 2023 and the newly minted 2025 Rules. But the headline for practicing advocates isn't the notice—it’s the refusal to grant a stay.

By explicitly refusing to stay the operation of the DPDP Act while simultaneously referring the matter to a larger bench to iron out "some creases," the Court has created a fascinating dichotomy. The constitutional validity of the Act—specifically its controversial dilution of the Right to Information (RTI) Act—remains under a dark cloud. Yet, the regulatory machinery is marching forward. The Data Protection Board (DPB) is fully operational, and the substantive compliance deadline of May 13, 2027, is approaching with the subtlety of a freight train.

If you are advising Data Fiduciaries to "wait and see" how the Supreme Court litigation pans out, you are committing borderline malpractice. Here is why the intersection of this litigation, the RTI amendments, and recent judicial interpretations of consent demand an immediate overhaul of your clients' data architecture.

Weaponizing Privacy: The RTI Dilution (Section 44(3))

The crux of the constitutional challenge lies in Section 44(3) of the DPDP Act, which surgically amputated a vital caveat in Section 8(1)(j) of the RTI Act, 2005.

Prior to this amendment, personal information of public officials could be disclosed under the RTI Act if the Public Information Officer (PIO) determined that the larger public interest justified the disclosure. It was the statutory embodiment of the proportionality test. The DPDP Act obliterated this balance. Now, Section 8(1)(j) provides a blanket exemption against the disclosure of any personal information, effectively weaponizing the right to privacy to shield bureaucratic opacity.

"The DPDP Act has achieved what decades of bureaucratic lobbying could not: an absolute statutory shield against public scrutiny, cloaked in the noble garb of data protection."

This is precisely why the Supreme Court has referred the matter to a larger bench. The sweeping exemptions granted to State instrumentalities under Section 17 of the DPDP Act (on grounds of national security and public order), combined with the RTI dilution, strike at the heart of the social contract envisioned in the Puttaswamy judgment. But while the State fights to keep its exemptions, private entities have no such luxury.

The APAAR Precedent: Courts Are Already Enforcing DPDP Principles

If you doubt that the judiciary will enforce DPDP principles before the 2027 deadline, look no further than the Supreme Court’s recent ruling on the APAAR (Automated Permanent Academic Account Registry) student ID system.

In a landmark late-July 2026 decision, the Court mandated that the APAAR consent form must include a clear opt-out option. The Court emphatically stated that the collection, processing, storage, retention, and sharing of student data are strictly subject to the DPDP Act.

For practitioners, this is a massive red flag regarding Notice and Consent. The days of pre-ticked boxes and sprawling, legalese-heavy privacy policies are over. Under the DPDP framework, consent must be free, specific, informed, unconditional, and unambiguous. Furthermore, the withdrawal of consent must be as frictionless as granting it. Once a Data Principal withdraws consent, the right to erasure triggers instantly. Processing must halt, and data must be purged unless a specific parallel law mandates retention.

The AI and IP Frontier: A Ticking Compliance Bomb

The operationalization of the DPDP Act is colliding violently with India's booming Artificial Intelligence sector. If your clients are scraping data to train Large Language Models (LLMs) or utilizing AI agents, the DPDP Act changes the game entirely.

Using personal data for algorithmic training without specific, unambiguous consent is no longer a grey area—it is a direct violation of the DPDP Act. Furthermore, the intersection of IP law and data protection is creating novel liabilities. Who is accountable for algorithmic bias generated from non-consensual personal data? How do you execute a "right to erasure" request (machine unlearning) when a user's data has already been baked into a neural network's weights and biases?

These aren't academic questions; they are the exact issues currently being dissected in legal circles and soon to be heavily litigated.

Actionable Takeaways for Indian Practitioners

The Supreme Court’s referral to a larger bench guarantees that the DPDP Act will dominate constitutional litigation for the rest of 2026. However, your corporate advisory strategy must operate in the reality of the present:

  • Audit Consent Architectures immediately: Work with your clients' UI/UX teams. If an opt-out or consent-withdrawal button takes more than two clicks, it fails the DPDP test.
  • Map the Erasure Pipelines: Ensure your clients have technical mechanisms for "digital erasure." A legal policy promising erasure is useless if the engineering team cannot actually locate and delete the data across distributed servers.
  • Review AI Training Logs: If your tech clients cannot trace the provenance and consent status of their training data, advise them to ring-fence that data immediately.

The DPDP Rules are notified. The Board is watching. The Supreme Court has refused a stay. The grace period is an illusion—act accordingly.

Published by AnrakLegal AI