The DPDP Paradox: Supreme Court Scrutiny, RTI Casualties, and the Accelerated Compliance Crunch
The year 2026 is shaping up to be a profound stress test for Indian technology and privacy law. As the Digital Personal Data Protection (DPDP) Act, 2023 and the corresponding 2025 Rules transition from legislative theory into operational reality, cor...
The year 2026 is shaping up to be a profound stress test for Indian technology and privacy law. As the Digital Personal Data Protection (DPDP) Act, 2023 and the corresponding 2025 Rules transition from legislative theory into operational reality, corporate India is staring down the barrel of a compressed compliance timeline. Yet, paradoxically, the very foundation of this law is now facing an existential review before a five-judge Constitution Bench of the Supreme Court.
For practicing lawyers, the current landscape is a minefield. You are tasked with advising clients to overhaul their data architectures at breakneck speed, while the Supreme Court debates whether the law itself violates the fundamental rights to free speech and information. Here is a breakdown of why this matters, what is at stake, and how you need to pivot your practice.
The Constitutional Collision: Privacy vs. Transparency
The Supreme Court’s decision to refer multiple petitions challenging the DPDP Act to a Constitution Bench is the most significant development in Indian privacy jurisprudence since Puttaswamy. While the Court rightly refused to grant an interim stay—relying on the well-established presumption of constitutionality for parliamentary statutes—it acknowledged that the petitions raise "serious and arguable" questions.
The primary battleground is Section 44(3) of the DPDP Act, which quietly mutilated the Right to Information (RTI) Act, 2005. Prior to this amendment, Section 8(1)(j) of the RTI Act provided a critical safeguard: personal information could be withheld, unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified its disclosure. Furthermore, information that could not be denied to Parliament or a State Legislature could not be denied to a citizen.
The DPDP Act obliterates this balancing test. It amends Section 8(1)(j) to create an absolute blanket exemption for all "personal information."
This is not merely a statutory tweak; it is the weaponization of privacy against public accountability. By removing the public interest override, the DPDP Act effectively shields corrupt public officials from scrutiny under the guise of protecting their data.
For litigators and civil rights advocates, this is a glaring violation of Article 19(1)(a). The Constitution Bench will have to decide if a law enacted to protect the informational privacy of citizens (Article 21) can constitutionally extinguish their right to know (Article 19). Until the Court rules, expect widespread rejection of RTI applications by public authorities citing the DPDP Act.
The Compliance Crunch: The "GDPR Equivalence" Myth
While the Supreme Court deliberates, the Ministry of Electronics and IT (MeitY) is not hitting the brakes. The government is actively considering compressing the previously expected 18-month transition period for large data fiduciaries. The rationale? A dangerous presumption that large Indian firms and big tech are already compliant with global norms like the EU’s GDPR.
As corporate advisors, you must immediately disabuse your clients of this "GDPR equivalence" myth. The DPDP Act is fundamentally different from the GDPR. It does not recognize "legitimate interest" as a broad catch-all for processing data without consent. Instead, it relies on strict, granular consent (Section 6) and a very narrow window of "Certain Legitimate Uses" (Section 7).
Practice Pointer: If you are advising banks, insurers, or fintechs, you need to forcefully pivot their compliance strategy today. Stop treating DPDP as a mere legal compliance exercise. Consent under Section 6 must be re-engineered as a governance tool. If your client is still relying on pre-checked boxes or bundled privacy policies in their user journeys, they are in direct violation of the mandatory "freely given, specific, informed, unconditional and unambiguous" consent standard. You must mandate verifiable audit trails and revocable consent architectures immediately.
AI Governance by Default: A Risky Bet
In a surprising policy stance, MeitY has signaled that India will not enact a separate, bespoke law for Artificial Intelligence. Instead, the government intends to govern AI through the existing matrix of the DPDP Act and Intellectual Property statutes (primarily the Copyright Act, 1957).
This "regulation by default" approach places an immense, perhaps unbearable, burden on the DPDP Act. Training Large Language Models (LLMs) requires scraping massive datasets, which invariably include personal data. Under the DPDP Act, if an AI startup scrapes personal data from the public web (other than data explicitly made public by the data principal themselves), it triggers the full weight of notice and consent requirements.
The intersection of DPDP and AI creates a massive gray area for tech lawyers. How does an AI developer practice data minimisation (Section 8) when LLMs inherently require maximal data? How do you grant a user the right to erasure (Section 12) when their personal data has already been baked into the weights and parameters of a neural network?
Without specific secondary legislation or sectoral guidelines for AI, advising tech startups has become an exercise in risk management rather than legal certainty. Relying on the DPDP Act to police generative AI is like using a scalpel to chop wood—it is simply not the right tool for the job.
The Verdict for Practitioners
The narrative of 2026 is clear: the DPDP Act is a live wire. The lack of an interim stay from the Supreme Court means that enforcement is imminent, and the compressed timelines leave no room for delayed compliance strategies.
Lawyers must operate on two parallel tracks. Defensively, prepare your corporate clients for aggressive compliance audits and the restructuring of their consent mechanisms. Offensively, monitor the Constitution Bench proceedings closely. If Section 44(3) is struck down or read down to restore the RTI balancing test, it will fundamentally alter how public data is handled in India.
The era of treating personal data as an unregulated corporate asset is over. It is time to advise accordingly.
Tags
Published by AnrakLegal AI