Legal News
17 June 2026
IP & Technology

The DPDP Reality Check: Supreme Court Elevates RTI Clash to Constitution Bench as the Compliance Clock Starts Ticking

The End of the Waiting Game For nearly three years, Indian tech lawyers and privacy professionals have been shadowboxing with the Digital Personal Data Protection (DPDP) Act, 2023. We advised clients on theoretical frameworks, drafted speculative con...

The End of the Waiting Game

For nearly three years, Indian tech lawyers and privacy professionals have been shadowboxing with the Digital Personal Data Protection (DPDP) Act, 2023. We advised clients on theoretical frameworks, drafted speculative consent notices, and waited. As of 2026, the waiting game is definitively over. The Centre has officially notified the administrative rules, pulling the trigger on a phased 12-to-18-month compliance runway that culminates on May 13, 2027.

But while corporate law firms are busy sending out compliance alerts and billing clients for data audits, the real battle for the soul of India's privacy jurisprudence is playing out in the Supreme Court. The apex court has rightly refused to treat the DPDP Act as a mere regulatory framework, referring overlapping challenges—specifically regarding the Act's chilling effect on the Right to Information (RTI) Act—to a five-judge Constitution Bench.

For practicing lawyers, this split screen—mandatory compliance on one side, constitutional uncertainty on the other—creates a uniquely volatile advisory environment.

The Constitutional Clash: Privacy as a Shield for State Secrecy?

The most consequential litigation surrounding the DPDP Act currently before the Supreme Court isn’t about tech companies; it is about state transparency. At the heart of the dispute is Section 44(3) of the DPDP Act, which quietly executed a surgical strike on the RTI Act, 2005.

Prior to this amendment, Section 8(1)(j) of the RTI Act provided a nuanced balancing test. Personal information of public officials could be withheld unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified disclosure. It was a statutory embodiment of the proportionality test.

The DPDP Act obliterates this balance. Section 44(3) amends the RTI Act to create a blanket exemption for all personal information. No public interest exception. No balancing test.

"By weaponizing privacy to dismantle transparency, the legislature has effectively shielded the bureaucracy from public scrutiny. A blanket ban on disclosing personal information under the RTI fails the very proportionality test laid down in Puttaswamy."

The Supreme Court’s decision to refer this to a Constitution Bench is a massive development. It signals that the Court recognizes the tension between two fundamental rights: the right to privacy (Article 21) and the right to know (Article 19(1)(a)). However, the Court's refusal to grant an interim stay on the Act's operation means practitioners cannot wait for the dust to settle. The law is live, and the RTI blackout is already in effect.

The Ticking Clock: What Corporate Counsel Must Do Now

With the rules notified, the "grace period" is a ticking clock. The phased implementation means Data Fiduciaries cannot wait until May 2027 to overhaul their systems. Here is where the rubber meets the road for tech and corporate lawyers:

1. The Death of Boilerplate Consent: Section 5 and Section 6 of the DPDP Act mandate that consent must be free, specific, informed, unconditional, and unambiguous. The days of 50-page privacy policies with pre-ticked boxes are over. If you are advising consumer tech startups, you need to draft modular, multilingual consent notices that specifically itemize the purpose of data collection.

2. The Processor Indemnity Squeeze: Under Section 8(1), the Data Fiduciary remains entirely legally responsible for the actions of the Data Processor. If a third-party vendor leaks your client's data, the Data Protection Board will penalize your client, not the vendor. Practice tip: Every single vendor agreement, SaaS contract, and cloud-hosting SLA needs to be reopened immediately. You must insert aggressive back-to-back indemnity clauses and mandatory audit rights against Data Processors.

The AI Blindspot: DPDP as India’s Defacto AI Law

Perhaps the most fascinating strategic positioning by the Government is the Ministry of Electronics and Information Technology's (MeitY) recent declaration that India will not enact a separate AI law, opting instead to rely on existing IP laws and the DPDP Act.

This fundamentally alters the landscape for IP and technology lawyers. Large Language Models (LLMs) and generative AI systems rely on massive web-scraping for training data. While IP lawyers have historically viewed this through the lens of Section 52 of the Copyright Act, 1957 (fair dealing), the DPDP Act introduces a lethal new vector of liability.

If an AI company scrapes the Indian web and captures personally identifiable information (PII), they are "processing" personal data under the DPDP Act. Because the DPDP Act does not contain a broad "legitimate interest" exemption for corporate scraping (unlike the EU's GDPR), AI developers are technically required to obtain verifiable consent from millions of Data Principals—an impossible task.

Therefore, advising AI startups in India is no longer just about patentability or copyright infringement. It is a dual-track risk assessment where a breach of IP law might cost damages, but a breach of the DPDP Act could result in penalties up to ₹250 crore per instance under the Schedule to the Act.

The Bottom Line

The DPDP Act is no longer a drafting exercise; it is an active minefield. While the Constitution Bench deliberates on whether the Act has unconstitutionally maimed the RTI framework, corporate India must march forward with compliance. For Indian lawyers, the mandate is clear: bridge the gap between abstract privacy rights and hard-nosed transactional reality. The transition period is not a break—it is the sound of the starting gun.

Published by AnrakLegal AI