Legal News
22 September 2026
IP & Technology

The DPDP-RTI Collision: Why the Supreme Court’s Refusal to Stay the Data Protection Act is a Compliance Nightmare for Practitioners

For the Indian technology and IP bar, the days of leisurely debating the abstract contours of data privacy are officially over. The operational reality of the Digital Personal Data Protection (DPDP) Act, 2023 has arrived, and it has brought with it a...

For the Indian technology and IP bar, the days of leisurely debating the abstract contours of data privacy are officially over. The operational reality of the Digital Personal Data Protection (DPDP) Act, 2023 has arrived, and it has brought with it a chaotic mix of high-stakes constitutional litigation and looming compliance deadlines.

The biggest story of 2026 is undoubtedly the Supreme Court’s decision to refer the challenge against the DPDP-linked amendments of the Right to Information (RTI) Act, 2005 to a larger bench. But the critical takeaway for practicing lawyers isn't just the reference itself—it is the apex court's explicit refusal to stay the operation of the legislation while the constitutional questions are ironed out. For in-house counsel and tech lawyers, this creates a deeply uncomfortable mandate: you must build expensive, enterprise-wide compliance architectures for a law whose very boundaries are currently up for grabs.

The Constitutional Tug-of-War: Section 44(3) and the Death of the Public Interest Test

To understand why this litigation matters to your corporate clients, you have to look at the mechanics of the amendment. Prior to the DPDP Act, Section 8(1)(j) of the RTI Act provided a qualified exemption for personal information. If information had no relationship to any public activity, or would cause unwarranted invasion of privacy, it was exempt—unless the Public Information Officer (PIO) was satisfied that the larger public interest justified its disclosure.

Section 44(3) of the DPDP Act gutted that balancing test. It amended Section 8(1)(j) to create a blanket exemption for "information which relates to personal information."

"The Court has correctly framed the current PILs as a fundamental battle over the boundary between privacy and transparency. By seeking interim relief against the masking or deletion of available public data, the petitioners are asking the Court to define where the State's duty to be transparent ends, and the citizen's right to privacy—as crystallized in K.S. Puttaswamy v. Union of India—begins."

For practitioners, this isn't just an academic debate over public law. If your client scrapes public government databases for data analytics, credit scoring, or background verification, the Supreme Court's ultimate definition of "public data" versus "personal data" in this larger bench reference will directly dictate the legality of their business model.

The Compliance Clock is Ticking: The 2025 Rules

Because the Supreme Court refused to grant a stay, the compliance timelines triggered by the DPDP Rules, 2025 remain fully in force. The staggered implementation schedule means the market is rapidly shifting from drafting boilerplate privacy policies to architecting operational, code-level compliance.

Here is the timeline that should be dominating your advisory practice:

  • 13 November 2025: The Rules were officially notified, making the Act enforceable in a framework sense.
  • 13 November 2026: The Consent Manager framework becomes operational.
  • 13 May 2027: The core operational obligations—verifiable parental consent for children's data, breach reporting, granular notice requirements, and the honoring of data principal rights—must be fully functional.

If you are advising Data Fiduciaries, the runway to May 2027 is shockingly short. Compliance is no longer just about updating Terms of Service. It requires auditing enterprise consent systems, ensuring interoperability with other regulated data frameworks, and completely overhauling contracts with third-party Data Processors to ensure back-to-back indemnity under Section 8(2) of the Act.

The Phantom Regulator: A Glaring Structural Flaw

Herein lies the great irony of advising on the DPDP Act in 2026. We have a live statute, enforceable rules, and strict timelines, but we lack the actual umpire. As of late 2026, the Data Protection Board of India exists on paper but still lacks an appointed Chairperson and Members.

This structural vacuum raises massive questions about enforcement readiness. Under the Act, Data Fiduciaries are obligated to report personal data breaches to the Board. But how do you advise a client on the nuances of a breach notification when the regulatory body meant to receive it is effectively a ghost ship? The lack of a functioning Board means there is zero regulatory guidance or soft law being generated to help interpret the 2025 Rules, leaving lawyers to guess how strictly the government will interpret "verifiable consent."

The Takeaway for Practice

It is tempting to tell clients to adopt a "wait and see" approach until the larger bench of the Supreme Court resolves the RTI-DPDP conflict, or until the Data Protection Board is actually staffed. Do not make this mistake.

The regulatory clock hits zero in May 2027. The technological infrastructure required to manage enterprise risk—specifically, mapping data flows, setting up consent managers, and renegotiating processor agreements—takes 12 to 18 months to implement. The Supreme Court's refusal to stay the legislation is a clear signal that the judiciary will not bail out companies that fail to prepare.

The era of paper compliance is dead. For Indian tech lawyers, the immediate mandate is clear: bridge the gap between legal obligations and IT architecture, because the DPDP regime is moving forward, with or without a fully seated Board.

Published by AnrakLegal AI