Legal News
6 October 2026
IP & Technology

The DPDP Paradox: RTI Act Bleeds While the Data Protection Board Remains a Ghost Town

The Constitutional Collision: Privacy vs. Transparency The Digital Personal Data Protection (DPDP) Act, 2023 was sold to the nation as a shield for the digital citizen. Instead, it is rapidly mutating into an iron curtain for the State. The Supreme C...

The Constitutional Collision: Privacy vs. Transparency

The Digital Personal Data Protection (DPDP) Act, 2023 was sold to the nation as a shield for the digital citizen. Instead, it is rapidly mutating into an iron curtain for the State. The Supreme Court of India has finally acknowledged the gravity of this mutation, referring the constitutional challenges against the DPDP-linked amendments to the Right to Information (RTI) Act to a larger Constitution Bench. For practicing advocates, this is not just an academic debate on constitutional law—it is a fundamental shift in how we will litigate transparency, state accountability, and corporate compliance for the next decade.

The crux of the litigation, spearheaded by groups like The Reporters’ Collective and Nitin Sethi, targets Section 44(3) of the DPDP Act. This seemingly innocuous provision wields a sledgehammer against Section 8(1)(j) of the RTI Act, 2005. Previously, Section 8(1)(j) exempted "personal information" from disclosure unless the Central Public Information Officer (CPIO) or the appellate authority was satisfied that the larger public interest justified the disclosure. It was a delicate, statutory embodiment of the proportionality test laid down in K.S. Puttaswamy v. Union of India.

"By stripping away the public interest caveat, the DPDP Act effectively creates a blanket ban on the disclosure of any personal information under the RTI Act. It weaponizes the fundamental right to privacy to assassinate the fundamental right to information."

The Supreme Court’s decision to refer this to a Constitution Bench indicates that the bench recognizes the colourable nature of this amendment. However, as it stands, the amendment remains operative. For lawyers advising journalists, activists, or even corporate whistleblowers, the immediate reality is grim: the State now has a statutory carte blanche to reject RTI applications by merely pointing to the presence of "personal data."

Advising into the Void: The DPBI Vacuum and Imminent Deadlines

While the constitutional validity of the DPDP Act is being debated in the apex court, corporate and technology lawyers are facing a completely different nightmare: a ticking compliance clock with no regulator in sight.

According to the latest timelines, following the notification of the DPDP Rules in November 2025, the Consent Manager registration regime is slated to become operational by mid-November 2026. More critically, the heavy-lifting business obligations—encompassing stringent notice requirements, breach reporting, child-data safeguards, and the onerous duties of Significant Data Fiduciaries (SDFs) under Section 10—are scheduled to go live by May 13, 2027.

Yet, as of August 2026, the Data Protection Board of India (DPBI) remains a ghost town, operating without an appointed Chairperson or Members. How exactly does the Ministry of Electronics and Information Technology (MeitY) expect Data Fiduciaries to prepare for a May 2027 deadline when the very adjudicatory and regulatory body responsible for clarifying these rules does not exist?

This regulatory vacuum creates immense malpractice risks for legal advisors. We are currently forced to advise clients on implementing Consent Manager frameworks and redesigning data architectures based on incomplete rules and zero regulatory guidance. Without a functional DPBI to issue clarifications or safe harbor guidelines, companies are flying blind. We strongly advise counsels to take a conservative approach: implement the strictest interpretation of data minimization and purpose limitation now, rather than waiting for a newly constituted Board to issue retrospective penalties.

Sectoral Ripples: APAAR, Digi Yatra, and the AI Blindspot

The courts are not waiting for the DPBI to wake up. We are already seeing the DPDP Act being actively invoked in sector-specific litigation, setting precedents that will bind Data Fiduciaries across the board.

In the education-tech sector, the Supreme Court recently clarified that the handling of student data under the government's APAAR Scheme is strictly subject to the DPDP Act. The Court drew a hard line: student information cannot be shared with private entities or third parties except according to established law. This is a massive wake-up call for EdTech platforms that have historically monetized student data through opaque third-party sharing agreements. Your terms of service are no longer a defense if they violate the DPDP’s strict consent architecture.

Similarly, the Kerala High Court has intensified its scrutiny of the Digi Yatra facial recognition system and passenger-data protection, directly questioning the status of the Data Protection Board. The judiciary is clearly losing patience with the State’s implementation lag, signaling that constitutional courts will step in to enforce data protection norms via writ jurisdiction (Article 226/32) if the statutory regulator remains paralyzed.

Finally, technology lawyers must address the looming Section 8(5) "blindspot" regarding Artificial Intelligence. Section 8(5) of the DPDP Act mandates Data Fiduciaries to protect personal data from breaches. However, as employees increasingly feed confidential client or customer data into generative AI tools (like ChatGPT or proprietary LLMs) to draft emails or analyze trends, they are technically triggering unauthorized data sharing. Indian IT laws and the DPDP Act currently lack specific safe harbors for AI-driven data processing by employees. If your corporate clients have not yet implemented a strict, written AI Acceptable Use Policy that specifically references DPDP compliance, they are already in breach of their data fiduciary obligations.

The Road Ahead

The Indian privacy landscape is currently defined by a profound paradox: the State is hyper-efficient in using the DPDP Act to block RTI requests, yet entirely negligent in operationalizing the Data Protection Board required to regulate corporate data exploitation. Until the Constitution Bench rules on the RTI amendment and the Central Government appoints a functioning DPBI, Indian lawyers must navigate this volatile terrain by drafting defensively, advising conservatively, and preparing for sudden judicial interventions.

Published by AnrakLegal AI