The DPDP Act’s Messy 2026 Reality: A Gag on RTI, A Ghost Regulator, and a Compliance Nightmare for Tech Counsel
The Illusion of Enforcement: India’s Privacy Law Hits the Ground Stumbling For Indian technology lawyers and data privacy practitioners, 2026 was supposed to be the year we finally transitioned from theoretical debates to practical compliance. With t...
The Illusion of Enforcement: India’s Privacy Law Hits the Ground Stumbling
For Indian technology lawyers and data privacy practitioners, 2026 was supposed to be the year we finally transitioned from theoretical debates to practical compliance. With the Digital Personal Data Protection (DPDP) Rules, 2025 officially notified late last year, the DPDP Act, 2023 is now operational. Yet, instead of regulatory clarity, we are staring down the barrel of constitutional challenges, glaring structural defects, and a regulatory body that currently exists only as a legal fiction.
The recent developments in the Supreme Court, coupled with the bureaucratic inertia surrounding the Data Protection Board of India (DPBI), reveal a disturbing trend. The State has weaponized privacy to dilute transparency, granted itself sweeping exemptions without proportionality, and left Data Fiduciaries scrambling to comply with a framework that lacks an active enforcer. For practicing lawyers, this means advising clients in a vacuum while watching the fundamental jurisprudence of Article 19(1)(a) and Article 21 clash in the apex court.
The Constitutional Showdown: RTI vs. Privacy
The most consequential legal battle of 2026 is currently unfolding in the Supreme Court. In February, the Court issued notices on multiple PILs—including a critical challenge spearheaded by The Reporters’ Collective and journalist Nitin Sethi—challenging the constitutional validity of specific DPDP provisions. While the Court rightfully declined to stay the Act's operation, the core of the dispute demands every public law litigator's attention: the fatal amendment to the Right to Information (RTI) Act, 2005.
Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act. Previously, personal information could be exempt from RTI disclosure unless a larger public interest justified it. The DPDP Act obliterates this nuance, creating a blanket exemption for any "personal information."
"By removing the public interest caveat, the DPDP Act has effectively transformed a privacy shield into a cloak for state opacity. Bureaucrats and public officials can now hide behind the guise of 'personal data' to evade accountability regarding disproportionate assets, appointments, and administrative decisions."
This is a direct perversion of the Supreme Court’s landmark K.S. Puttaswamy v. Union of India judgment. Puttaswamy mandated that privacy restrictions must pass the test of proportionality. Instead, the legislature has created an absolute bar, pitting the citizen’s Right to Know against an overbroad statutory definition of privacy. Litigators should anticipate this to be referred to a Constitution Bench, as it requires harmonizing two fundamental rights that the legislature has clumsily forced into a zero-sum game.
The Phantom Menace: A Board Without Members
If the constitutional challenges weren't enough, the operational reality of the Act borders on the absurd. As reported by LiveLaw in June 2026, the Data Protection Board of India (DPBI) is legally established under Section 18 of the Act, but practically, it is a ghost town. The government initiated nomination and selection steps for the chairperson and members in May and June, but appointments remain pending.
Why does this matter for a corporate lawyer? Section 8(6) of the DPDP Act mandates that Data Fiduciaries must intimate the Board in the event of a personal data breach. But how do you report a breach to a Board that has no personnel? The DPDP Rules, 2025 impose strict timelines for breach disclosures, yet in-house counsel and law firms are left advising clients to send notices into a bureaucratic void, hoping their paper trail is sufficient to avoid future penal action.
This vacuum also means there is zero regulatory guidance on the State’s processing of data without consent. Section 17 allows sweeping exemptions for the government on grounds of sovereignty and public order, but without a functional Board to at least attempt oversight, state surveillance and data processing operate unchecked by the very law designed to regulate it.
Practice Pointers: Navigating the Compliance Minefield
Despite the regulatory vacuum, the law is live, and corporate clients cannot afford to wait for the Supreme Court's final verdict. The new privacy rules fundamentally alter how tech companies, e-commerce platforms, and digital startups operate in India. Boilerplate privacy policies are officially dead.
Here is what transactional and in-house lawyers must immediately action:
1. Strict Purpose Limitation and Notice: Under Section 5, the notice provided to a Data Principal must be itemized, clear, and available in multiple languages. You can no longer bundle consents. If your client’s app collects location data to deliver food, they cannot legally use that same data for targeted advertising without explicit, separate consent. Contracts and UI/UX flows must be legally audited to ensure they allow users to refuse or withdraw consent easily.
2. Overhauling Data Processing Agreements (DPAs): The DPDP Act places the entire liability on the Data Fiduciary. If your client uses a third-party cloud provider (Data Processor) and the processor leaks the data, your client pays the fine (which can run up to INR 250 Crores). Lawyers must redraft commercial contracts to include watertight indemnity clauses, mandatory audit rights, and strict data minimization covenants binding the processors.
3. Breach Readiness: Advise clients to build an internal "data breach triage" protocol. Even if the DPBI is currently unstaffed, the obligation to notify affected users and the government remains. Documented compliance will be your only defense when the Board finally assumes office and inevitably decides to make an example out of a non-compliant tech firm to assert its authority.
The Verdict
As we navigate the latter half of 2026, the DPDP framework remains a paradox. It is simultaneously draconian in its restriction of RTI transparency and toothless in its enforcement of corporate compliance. For the legal fraternity, the mandate is clear: litigate the constitutional overreach aggressively in the courts, but advise corporate clients conservatively in the boardroom. The law may be stumbling, but when it finally finds its footing, the financial penalties will be unforgiving.
Tags
Published by AnrakLegal AI