Legal News
10 October 2026
IP & Technology

The DPDP-RTI Collision: Why the Supreme Court’s Constitution Bench Reference Changes the Game for Tech and Privacy Lawyers

The Constitutional Showdown We Knew Was Coming On February 16, 2026, the Supreme Court of India drew the battle lines for what will undoubtedly be the defining privacy litigation of the decade. By referring the challenge against the Digital Personal ...

The Constitutional Showdown We Knew Was Coming

On February 16, 2026, the Supreme Court of India drew the battle lines for what will undoubtedly be the defining privacy litigation of the decade. By referring the challenge against the Digital Personal Data Protection (DPDP) Act’s amendment of the Right to Information (RTI) Act to a five-judge Constitution Bench, the Court has acknowledged a fundamental crisis: the collision between the fundamental right to privacy and the fundamental right to information.

But for practicing lawyers, the real news isn't the reference itself—it is the Court’s refusal to stay the amendment while the matter remains sub judice. For litigators, corporate counsel, and tech advisors, this creates an immediate, highly volatile operational reality.

The Section 44(3) Black Hole: Litigators, Take Note

To understand the gravity of this development, we must look at the statutory mechanics. Section 44(3) of the DPDP Act fundamentally altered Section 8(1)(j) of the RTI Act, 2005. Previously, Section 8(1)(j) protected personal information from RTI disclosure unless a larger public interest justified it. It was a delicate balancing act born out of years of transparency jurisprudence.

The DPDP Act took a sledgehammer to this balance. By removing the public interest caveat, it created a blanket exemption: if it is personal data, the State will not disclose it. Period.

"The Supreme Court has effectively allowed the State to pull down the shutters on transparency while the constitutional gears slowly grind. Until the Constitution Bench rules, the State possesses an impenetrable shield against RTI inquiries involving any personal data."

Why this matters for your practice: If you are a litigator who relies on RTI applications to gather evidence against state instrumentalities—whether for service matters, tender disputes, or environmental PILs—your toolkit has just been severely compromised. Public Information Officers (PIOs) are already weaponizing the amended Section 8(1)(j) to reject applications en masse. You must now pivot your strategy, relying more heavily on discovery applications under the CPC or writ jurisdictions to compel document production, bypassing the RTI route entirely.

The Cross-Border Contract Panic: Stop Over-Lawyering

While litigators grapple with the RTI blackout, corporate tech teams are engaged in what can only be described as compliance theatre. Reports from the commercial sector indicate widespread panic over cross-border data transfers, with law firms rushing to redraft Data Processing Agreements (DPAs) for their tech clients.

Here is the sharp truth: You are jumping the gun.

As recently clarified, the DPDP Act’s cross-border transfer provisions—specifically Section 16 and the corresponding Rule 15—are not yet live. Operationalization is not expected until around May 2027. More importantly, the Central Government has not yet published the "black-list" of restricted countries.

Drafting restrictive cross-border clauses based on a phantom list is not just premature; it is bad commercial lawyering. Imposing contractual friction on tech platforms, startups, and SaaS providers for a regime that does not yet exist stifles business operations. Corporate counsel should focus on baseline data mapping and wait for MeitY’s definitive restricted-country notification before overhauling entire enterprise tech stacks.

The Section 8(5) Blind Spot: AI and Employee Data

While the market is distracted by the RTI debate and cross-border hypotheticals, a massive liability risk is quietly brewing at the intersection of DPDP compliance, Artificial Intelligence, and Intellectual Property.

Under Section 8(5) of the DPDP Act, employers are permitted to process employee data without explicit consent for "employment purposes" or to safeguard the employer from loss/liability. However, Indian tech companies are discovering a severe blind spot in how this interacts with generative AI.

When employees feed proprietary code, client datasets, or internal communications into third-party AI models to optimize their workflows, they are often inadvertently triggering massive data breaches. If those prompts contain personal data of customers or co-workers, the employer is strictly liable as a Data Fiduciary under the DPDP Act. Furthermore, any inference drawn by AI systems from user data—such as profiling from workplace photos or behavioral analytics—blurs the line of what constitutes "employment purposes."

The Practice Pivot: IP and tech lawyers need to immediately draft and enforce Acceptable AI Use Policies integrated with DPDP compliance frameworks. Section 8(5) is a narrow safe harbor, not a free pass. If your client’s employees are using unauthorized AI tools, the company is exposed to both DPDP penalties and catastrophic IP dilution.

The Road to November 2026

The DPDP regime is no longer a theoretical framework; it is actively reshaping constitutional rights and commercial drafting. With the Consent Manager framework slated to go live in November 2026, digital platforms have less than a year to overhaul their UX/UI architectures to accommodate verifiable, revocable consent.

For Indian lawyers, the mandate is clear. Stop treating the DPDP Act as a standalone privacy statute. It is an omnibus disruption that impacts constitutional litigation, IP safeguarding, and everyday commercial contracting. The Constitution Bench will eventually decide the fate of the RTI amendment, but in the corporate trenches, the compliance war has already begun.

Published by AnrakLegal AI