The DPDP Paradox: Navigating Accelerated Compliance Under the Shadow of a Constitution Bench
The Constitutional Cloud Over the DPDP Act In a move that fundamentally alters the immediate landscape of Indian data privacy law, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2...
The Constitutional Cloud Over the DPDP Act
In a move that fundamentally alters the immediate landscape of Indian data privacy law, the Supreme Court has referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023, and its 2025 Rules to a five-judge Constitution Bench. For practicing advocates, this referral—which crystallized in early April 2026—creates a fascinating, albeit chaotic, dual reality. We are now forced to aggressively counsel clients toward compliance while simultaneously watching the foundational pillars of the Act face constitutional scrutiny.
The crux of the constitutional challenge strikes at the heart of India's transparency regime. Petitioners have correctly zeroed in on Section 44(3) of the DPDP Act, which stealthily amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Before this amendment, public authorities could withhold personal information unless the Public Information Officer (PIO) was satisfied that the larger public interest justified its disclosure. The DPDP Act obliterated this caveat, transforming a qualified exemption into a blanket prohibition on disclosing any personal information.
"By removing the public interest test from the RTI Act, the legislature has effectively weaponized privacy against transparency. It is a dangerous statutory overreach that the Constitution Bench must strike down to preserve Article 19(1)(a)."
For lawyers practicing administrative law or representing journalists and activists, this amendment has been a brick wall. The Supreme Court's decision to examine whether this amendment violates the fundamental right to information—balanced against the Puttaswamy right to privacy—is the most consequential privacy litigation of the decade. However, the Court's refusal to grant a stay on the challenged sections sends a clear, unforgiving message to corporate boards: The law is presumed constitutional until proven otherwise, and enforcement is not waiting for the gavel to drop.
No Stay Means No Delay: The MeitY Acceleration
While the Supreme Court deliberates the vires of the statute, the Ministry of Electronics and IT (MeitY) is hitting the accelerator. The original 18-month transition period is being violently compressed. MeitY’s proposed staggered framework—enforcing provisions in immediate, three-month, and twelve-month phases—is a nightmare for in-house counsel and corporate advisory teams.
Industry pushback, which peaked when stakeholder feedback closed in February 2026, is entirely justified. Startups and SMEs simply do not have the compliance budgets or the technical bandwidth to overhaul their data architecture overnight. As legal advisors, we must be blunt with our clients: the days of copying and pasting boilerplate privacy policies from European websites are over. The accelerated timeline means that Data Fiduciaries must execute data mapping and inventory clean-ups yesterday.
Ground Reality: GCCs, Healthcare, and the Consent Fallacy
Despite the ticking clock toward the looming deadlines (with full enforcement slated for May 13, 2027, and earlier phases kicking in now), the ground reality is alarming. Recent reports indicate that most Global Capability Centres (GCCs) in India—the engine room of offshored global data processing—remain in the nascent stages of compliance.
The bottleneck isn't just technical; it is fundamentally legal. The most misread obligation under the DPDP framework remains Consent Governance. Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous, preceded by a clear notice. Yet, many Data Fiduciaries still mistakenly believe that a pre-ticked box or a buried clause in a Terms of Service agreement will suffice.
For lawyers drafting commercial contracts, this requires an immediate pivot. Your Data Processing Agreements (DPAs) need urgent renegotiation. Vendor management clauses must now explicitly allocate liability for data breaches and outline indemnities for failure to honour Data Principal rights (such as the right to erasure or correction).
Interestingly, the sectors dealing with the most critical data—healthcare and insurance—are showing the most urgency. Hospitals and insurers are actively rejigging operations. Given that health data inherently triggers higher operational risks (even if the DPDP Act dropped the specific "sensitive personal data" classification found in the old IT Rules), medical institutions are wise to treat their data sets with heightened fiduciary duty.
The Takeaway for Counsel
How should lawyers navigate this DPDP paradox? First, separate your litigation strategy from your corporate advisory.
On the litigation front, monitor the Constitution Bench proceedings closely. If Section 44(3) is struck down, we will see a massive revival of stalled RTI applications, requiring swift action for clients seeking government data.
On the corporate front, advise your clients to proceed as if the accelerated MeitY timelines are written in stone. Conduct data audits to identify what personal data is collected, why it is collected, and where it flows. Draft clear, vernacular-friendly notice-and-consent mechanisms. Do not wait for the Supreme Court to bless the Act; the cost of regulatory penalties and the operational paralysis of non-compliance will far outweigh the cost of early adaptation.
Tags
Published by AnrakLegal AI