The DPDP-RTI Collision: SC Refuses Stay as Government Force-Fits AI Regulation into Privacy Laws
For technology and privacy lawyers, 2026 is rapidly shaping up to be the year of the compliance crucible. The Supreme Court has just referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023 to a five-judge ...
For technology and privacy lawyers, 2026 is rapidly shaping up to be the year of the compliance crucible. The Supreme Court has just referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023 to a five-judge Constitution Bench. Yet, the real headline for practicing advocates isn’t the referral—it is the Court’s categorical refusal to grant an interim stay on the impugned provisions.
Led by Chief Justice Surya Kant, the bench made it abundantly clear that there is "no question of stay," refusing to thwart the regime introduced by Parliament until the substantive hearings conclude. For corporate counsel and tech advisors, the takeaway is absolute: you cannot hit the snooze button on compliance. The May 13, 2027 operationalization deadline remains etched in stone, and for large tech players, the transition period may be compressed even further.
The Death of the Public Interest Exemption
At the heart of the Supreme Court battle—spearheaded by The Reporters' Collective—is a fundamental conflict between data privacy and democratic transparency. The DPDP Act didn't just introduce a privacy regime; it executed a surgical strike on the Right to Information (RTI) Act, 2005.
Specifically, Section 44(3) of the DPDP Act amended Section 8(1)(j) of the RTI Act. Previously, public information officers (PIOs) could disclose personal information if the larger public interest justified the disclosure. The DPDP amendment obliterates this caveat, imposing a blanket ban on the disclosure of any personal information.
"The amendment transforms the DPDP Act from a shield for citizen privacy into an impenetrable bunker for the State. It fundamentally alters the constitutional balance between the right to privacy (Puttaswamy) and the right to know (Raj Narain)."
For lawyers advising media houses, civil society NGOs, or whistleblowers, this severely truncates the legal avenues available to extract government data. The DPDP Act has effectively weaponized privacy against accountability. Until the Constitution Bench rules otherwise, any RTI request even tangentially involving personal details—be it beneficiary lists, bureaucratic appointments, or electoral data—will be summarily rejected.
The AI Governance Cop-Out
Equally concerning for the legal fraternity is the government’s stated approach to Artificial Intelligence. MeitY Secretary S. Krishnan recently confirmed that India will not introduce a bespoke AI law. Instead, the government intends to govern AI through the existing DPDP Act and the Intellectual Property Act.
This is a regulatory pipe dream that will inevitably result in a litigation nightmare. For IP and tech lawyers, force-fitting generative AI into archaic legal frameworks is legally precarious.
Consider the realities of practice: How does Section 2(m) of the Copyright Act, 1957 (defining an 'infringing copy') apply to the weights and biases of a Large Language Model (LLM) trained on scraped data? The DPDP Act, meanwhile, only governs personal data. If an AI model is trained on non-personal, proprietary corporate data, the DPDP Act offers absolutely no protection or regulatory oversight. Relying on existing IP laws to govern AI scraping, deepfakes, and algorithmic bias is tantamount to using a scalpel to chop wood.
What This Means for Tech & Corporate Practice
With the Supreme Court refusing a stay and the government confirming its reliance on the DPDP Act for broader tech governance, the compliance mandate for law firms and in-house counsel is immediate and severe.
Here is what changes in practice right now:
- Dual-Reporting Chaos: Under the DPDP Rules notified in November 2024, data fiduciaries face strict penalties for failing to report breaches. Lawyers must now navigate a dual-reporting regime: notifying the Data Protection Board (DPB) under the DPDP Act, while simultaneously complying with the 6-hour reporting mandate to CERT-In under Section 70B of the Information Technology Act, 2000.
- Compressed Timelines for Big Tech: The government is actively debating compressing the 18-month transition period for large data fiduciaries. If you represent major banks, fintechs, or multinational tech firms, the May 2027 deadline is a mirage. You must advise clients to "hardwire privacy" into their IT architecture immediately.
- The Startup Rethink: For startup counsel, the era of "growth at all costs" data harvesting is dead. You must conduct immediate data audits, ensuring that consent managers are integrated and that data minimization principles are strictly enforced. Startups can no longer afford to ask for data they do not strictly need for their core service.
The DPDP Act is no longer just a privacy statute; it is the cornerstone of India's technology, AI, and information law landscape. While the five-judge bench deliberates on the constitutional friction between privacy and public accountability, the regulatory machinery is moving forward at breakneck speed. Lawyers waiting for the Supreme Court to hit the brakes will find their clients crashing into the compliance wall.
Tags
Published by AnrakLegal AI