The DPDP-RTI Collision: Supreme Court’s Refusal to Stay Section 44(3) Leaves Tech Counsel in a Compliance Limbo
The Constitutional Tug-of-War Over "Personal" Data For technology lawyers and in-house counsel across India, the Digital Personal Data Protection (DPDP) Act, 2023, has shifted from a theoretical compliance exercise to an active litigation minefield. ...
The Constitutional Tug-of-War Over "Personal" Data
For technology lawyers and in-house counsel across India, the Digital Personal Data Protection (DPDP) Act, 2023, has shifted from a theoretical compliance exercise to an active litigation minefield. The most consequential development this month isn't a new notification from MeitY, but rather the Supreme Court’s handling of the direct conflict between the DPDP Act and the Right to Information (RTI) Act, 2005.
By referring the challenge against Section 44(3) of the DPDP Act to a larger bench—while crucially declining to stay the legislation—the Apex Court has placed data fiduciaries in an unenviable position. Under Section 44(3), the DPDP Act amends Section 8(1)(j) of the RTI Act, effectively creating a blanket exemption for the disclosure of "personal information." Previously, the RTI Act allowed such disclosure if the larger public interest justified it. Now, that public interest caveat has been surgically removed.
"The Supreme Court’s refusal to grant interim relief against the masking and deletion of available data under W.P.(C) No. 358/2026 means companies and state instrumentalities must proceed with aggressive data-masking protocols, even as the constitutional validity of this mandate remains sub-judice."
For practicing lawyers, this matters immensely. We are advising clients to build expensive compliance architectures and data-masking protocols based on a statutory definition of "personal data" versus "public data" that the Supreme Court itself admits requires constitutional scrutiny. If the larger bench ultimately reads down Section 44(3) to preserve transparency, millions of rupees spent on aggressive data-masking and redaction systems by tech platforms and public-private partnerships could be rendered obsolete.
The Phantom Regulator: Section 18 and the Digi Yatra Dilemma
Adding to the chaos is the glaring absence of a fully operational regulatory body. As highlighted in a recent Kerala High Court matter concerning passenger data under the Digi Yatra scheme, the judiciary is increasingly questioning the status of the Data Protection Board (DPB) established under Section 18 of the DPDP Act.
How does a legal practitioner advise a client on breach reporting timelines or penalty mitigation when the adjudicatory body is functionally a phantom? With the DPDP Rules, 2025 rolling out in phases, the current landscape is forcing courts to step into the regulatory vacuum. We are seeing a dangerous trend where constitutional courts are being asked to act as de facto Data Protection Officers for state-backed tech initiatives.
The APAAR Scheme: Courts Define "Meaningful Consent"
While the Supreme Court hesitates on the RTI front, it is aggressively enforcing DPDP principles in adjacent technology cases. The recent ruling on student-data governance under the APAAR scheme is a wake-up call for EdTech companies and educational institutions.
The Court categorically held that the collection, retention, and sharing of student data are strictly subject to the DPDP Act. More importantly, it mandated that parental consent forms must include an explicit opt-out option. This judicial intervention gives teeth to Section 6 of the DPDP Act, signaling that "meaningful and informed consent" cannot be a pre-checked box or a take-it-or-leave-it proposition.
For EdTech counsel, the APAAR ruling necessitates an immediate audit of your client's UI/UX designs. If your platform's consent architecture relies on dark patterns or lacks granular opt-out mechanisms for children's data, you are now in direct violation of Supreme Court directives, not just pending statutory rules.
Timeline Pressures: Preparing for the November 2026 Rollout
Litigation aside, the compliance clock is ticking loudly. With the Consent Manager framework slated to go live around 13 November 2026, and broader substantive obligations enforceable by 13 May 2027, the runway is short.
Tech lawyers must immediately focus on the overlap between Consent Managers under the DPDP Rules, 2025, and the RBI's existing Account Aggregator (AA) framework. The debate over whether AAs will automatically qualify as Consent Managers, or if dual-registration will be required, remains unresolved.
Here is what you should be advising your tech and SaaS clients right now:
- Consent Architecture Overhaul: Move away from monolithic privacy policies. Implement granular, verifiable consent mechanisms, especially for verifiable parental consent.
- Data Minimization Protocols: Given the pending Supreme Court scrutiny on what constitutes public vs. personal data, default to aggressive masking of user data in public-facing interfaces.
- Vendor Contracts: Renegotiate Data Processor agreements now. If your client is a Data Fiduciary, ensure indemnities are airtight before the substantive obligations hit in May 2027.
The intersection of data protection, platform governance, and public transparency is currently the most volatile area of Indian tech law. The DPDP Act is no longer a looming threat; it is an active disruptor. Lawyers who treat this merely as a compliance checklist, rather than a fundamental shift in digital commerce architecture, will find themselves—and their clients—severely exposed.
Tags
Published by AnrakLegal AI