The DPDP Paradox: Supreme Court Steps in as Data Regulator While the Centre Sleeps on Board Appointments
The Statutory Vacuum and the Rise of Judicial Regulation As we navigate the final quarter of 2026, the implementation of the Digital Personal Data Protection (DPDP) Act, 2023 has devolved into a striking paradox. On one hand, the compliance clock is ...
The Statutory Vacuum and the Rise of Judicial Regulation
As we navigate the final quarter of 2026, the implementation of the Digital Personal Data Protection (DPDP) Act, 2023 has devolved into a striking paradox. On one hand, the compliance clock is ticking aggressively for corporate India—Consent Manager provisions are slated to go live this November, and substantive enforcement hits in May 2027. On the other hand, the primary regulatory body, the Data Protection Board of India (DPBI), remains a ghost town. As of September 2026, the Centre has inexplicably failed to appoint a Chairperson or Members.
But the law abhors a vacuum. In the absence of a functional Board, the Supreme Court, High Courts, and surprisingly, the National Human Rights Commission (NHRC), have hijacked the regulatory steering wheel. For practicing lawyers, this shift is critical: data privacy enforcement in India is currently not being shaped by regulatory circulars, but by constitutional writ jurisdiction.
The RTI Crisis: Section 44(3) Reaches a Constitution Bench
The most consequential litigation presently occupying the Supreme Court's docket is the challenge to Section 44(3) of the DPDP Act. This is the provision that quietly gutted the Right to Information (RTI) Act, 2005.
Prior to the DPDP Act, Section 8(1)(j) of the RTI Act provided a nuanced balancing test: personal information could be exempt from disclosure unless a larger public interest justified it. Section 44(3) of the DPDP Act unceremoniously axed this caveat, creating a blanket ban on disclosing any personal information under the RTI framework.
The Supreme Court has rightly treated this as a constitutional crisis, issuing notice to the Centre and indicating the necessity of a Constitution Bench. Furthermore, a separate writ petition has sought—and pressed for—interim relief against the masking and deletion of publicly available data under the guise of DPDP compliance.
"The weaponization of data privacy to dismantle public transparency is the most significant administrative law challenge of this decade. The Supreme Court's intervention prevents the State from using the DPDP Act as an invisibility cloak."
Practice Note for Litigators: If you are representing journalists, whistleblowers, or civil rights groups facing RTI rejections based on the DPDP Act, the doors for Article 32 and Article 226 petitions are wide open. Do not wait for the DPBI. Frame your challenges around the fundamental right to information under Article 19(1)(a) being disproportionately curtailed by a statutory amendment.
Consent Architectures: The APAAR and Digi Yatra Interventions
For corporate lawyers and in-house counsel, the Supreme Court's recent directive regarding the APAAR (Automated Permanent Academic Account Registry) is the most important compliance roadmap of the year.
The Court directed the Centre and the CBSE to explicitly amend the APAAR consent forms, mandating an unequivocal "opt-out" mechanism for parents and guardians. The Court cemented that the collection and sharing of student data remains strictly subject to the DPDP Act.
Why does this matter for your commercial clients? It sets the judicial standard for Section 9 (Processing of personal data of children). Dark patterns, forced consent, or bundled terms of service will not survive judicial scrutiny. If the Supreme Court is forcing the mighty CBSE to rewrite its consent architecture to allow parental refusal, your ed-tech, social media, and gaming clients must immediately overhaul their UI/UX to ensure verifiable, granular parental consent.
Similarly, the Kerala High Court's scrutiny of the Digi Yatra Foundation over biometric data handling proves that public-private partnerships are not immune from DPDP-linked writ petitions. The judiciary is acutely aware of the risks of algorithmic processing and biometric data storage.
The NHRC Steps In: A New Forum for Data Grievances?
In a fascinating development, the National Human Rights Commission (NHRC) has started issuing notices to AI developers, ed-tech platforms, and social media giants over alleged DPDP violations, specifically targeting the tracking of children’s data and the lack of robust grievance redressal mechanisms.
This is a direct consequence of the DPBI's absence. By framing data privacy as a fundamental human right (flowing from Puttaswamy), the NHRC is asserting jurisdiction. For technology lawyers, this means defending data privacy practices on multiple fronts—not just before civil courts or sector-specific regulators, but before human rights commissions.
Looking Ahead: The May 2027 Deadline
Corporate India is sleepwalking into a regulatory minefield. With Consent Manager rules kicking in by November 2026 and substantive obligations enforceable by May 2027, the window for remediation is closing.
What you need to advise your clients immediately:
1. Do not wait for the DPBI: Base your compliance on the bare text of the DPDP Rules 2025 and emerging High Court/Supreme Court jurisprudence (like the APAAR ruling).
2. Audit Children's Data: With the NHRC and the Supreme Court heavily focused on minors, any enterprise dealing with users under 18 must isolate this data and implement verifiable parental consent mechanisms immediately.
3. Prepare for Writ Litigation: Until the Board is fully staffed and an appellate tribunal is functional, aggrieved Data Principals will bypass statutory remedies and file writ petitions citing fundamental rights violations. Your litigation strategy must account for defending privacy practices in High Courts.
The Centre’s failure to operationalize the Data Protection Board has transformed the DPDP Act from a regulatory compliance exercise into a high-stakes constitutional battleground. Lawyers who adapt to this judicialization of data privacy will dominate the practice in 2027.
Tags
Published by AnrakLegal AI