The DPDP Era Arrives: What the Evidentiary Shift in Consent and the Supreme Court’s RTI Dilemma Mean for Your Practice
The Grace Period is Officially Over For the past three years, the Digital Personal Data Protection (DPDP) Act, 2023, has been treated by many corporate counsel as a looming, but abstract, specter. As of July 2026, that specter has materialized into a...
The Grace Period is Officially Over
For the past three years, the Digital Personal Data Protection (DPDP) Act, 2023, has been treated by many corporate counsel as a looming, but abstract, specter. As of July 2026, that specter has materialized into a hard regulatory reality. With the Ministry of Electronics and Information Technology (MeitY) fully operationalizing the DPDP Rules 2025, and the compliance timeline for banks and fintechs aggressively compressed to May 2026, the era of theoretical privacy compliance is dead. We are now in the enforcement era.
For practicing lawyers, the recent developments present a dual challenge: a massive overhaul of corporate compliance architectures and a fundamental constitutional friction at the Supreme Court regarding the Right to Information (RTI) Act. If you are still relying on boilerplate "I Agree" privacy policies drafted in 2022, your clients are already operating in breach of the law.
The Evidentiary Burden: Why "Clickwrap" is on Life Support
The most immediate practice shift stems from the phased rollout of the DPDP Rules 2025, specifically regarding consent governance. Under Section 6 of the DPDP Act, read with the newly activated Rules, the evidentiary burden of proving that consent was freely given, specific, informed, unconditional, and unambiguous now rests squarely on the Data Fiduciary.
Practically, this means the traditional clickwrap agreement—where users blindly check a box next to a 50-page Terms of Service document—is legally defunct. The new regulations compel tech giants like Meta, Google, and OpenAI, along with domestic startups, to provide transparent rationales for data collection and explicitly allow users to decline without losing access to the core service.
"The legal departments can no longer work in isolation. Proving valid consent under the DPDP Rules requires lawyers to audit UI/UX design. If a user interface employs 'dark patterns' to nudge consent, courts and the Data Protection Board will deem that consent vitiated."
Furthermore, the operationalization of Consent Managers—interoperable platforms allowing Data Principals to give, track, and revoke consent—means withdrawal must be as frictionless as granting it. Corporate counsel must immediately advise clients to implement systems that automatically trigger data erasure protocols upon withdrawal, unless retention is mandated under other statutes (like the PMLA or Companies Act).
The Financial Sector Crunch: Dual-Reporting and Compressed Timelines
If you advise banks, NBFCs, or fintechs, your timeline has evaporated. Industry compliance timelines have been slashed from 18 to 12 months, with strict enforcement kicking in by May 2026. What does this mean for your advisory practice?
First, prepare for the nightmare of the dual-reporting regime. When a data breach occurs, your client can no longer just look at the DPDP Board. They must navigate a multi-headed regulatory hydra. You are now looking at parallel reporting obligations to CERT-In (under the Information Technology Act's stringent 6-hour rule), the DPDP Board, and sectoral regulators like the RBI or IRDAI. Conflicting definitions of a "breach" across these regimes will require highly sophisticated, pre-drafted incident response playbooks. Gap assessments cannot wait until the next financial quarter; they must happen yesterday.
The RTI Act Collision: A Blow to Transparency?
While corporate lawyers scramble for compliance, litigators and constitutional lawyers are watching a high-stakes battle unfold at the Supreme Court. In February 2026, the Apex Court referred pleas challenging the DPDP Act’s amendments to the RTI Act to a larger bench. Crucially, the Court did not stay the operation of the DPDP Act during these proceedings.
This is where the law gets dangerously opaque. Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act, 2005. Previously, Section 8(1)(j) exempted personal information from disclosure unless the Public Information Officer (PIO) was satisfied that the larger public interest justified the disclosure. The DPDP Act entirely deletes this "public interest" caveat, creating a blanket exemption for anything classified as "personal information."
For practitioners relying on the RTI Act for evidence gathering, corporate intelligence, or public interest litigation (PIL), this is a devastating blow. Public authorities are already weaponizing this amendment to reject RTI applications arbitrarily.
Until the Supreme Court's larger bench rules on the constitutionality of this blanket exemption—argued by petitioners like The Reporters’ Collective and NCPRI to be a violation of the fundamental right to information under Article 19(1)(a)—litigators must pivot. You must now be prepared to file writ petitions challenging arbitrary PIO rejections, arguing that the definition of "personal data" is being misapplied to shield administrative malfeasance.
The Verdict for Practitioners
The DPDP landscape of 2026 is uncompromising. The transition period is over. As legal professionals, the mandate is clear:
- For Corporate/Tech Lawyers: Rewrite privacy notices into plain English (and the Eighth Schedule languages). Shift your focus from drafting defensive liability shields to building verifiable consent architectures.
- For Banking/Fintech Counsel: Establish immediate, cross-functional breach reporting protocols that satisfy CERT-In, RBI, and the DPDP Board simultaneously.
- For Litigators: Brace for a severe drought of information from public authorities under the RTI Act, and prepare administrative law challenges to combat the overbroad application of the DPDP's privacy shield.
Data is no longer just an asset; under the fully operationalized DPDP framework, it is a strict liability. Advise your clients accordingly.
Tags
Published by AnrakLegal AI