Legal News
1 October 2026
IP & Technology

The DPDP Vacuum: Supreme Court Steps In as the RTI-Privacy Conflict Reaches a Constitution Bench

A Constitutional Collision Course In what is arguably the most consequential privacy law development of 2026, a Supreme Court bench led by Chief Justice Surya Kant has referred the constitutional challenge against the Digital Personal Data Protection...

A Constitutional Collision Course

In what is arguably the most consequential privacy law development of 2026, a Supreme Court bench led by Chief Justice Surya Kant has referred the constitutional challenge against the Digital Personal Data Protection (DPDP) Act’s amendment to the Right to Information (RTI) Act to a five-judge Constitution Bench. While issuing notice on February 16, the Court crucially declined to stay the amendment.

For practicing lawyers, this refusal to grant interim relief dictates the immediate reality on the ground: the blanket exemption from disclosure of personal information under the RTI Act remains fully operative.

To understand why this matters, we must look at the statutory mechanics. Section 44(3) of the DPDP Act 2023 amended Section 8(1)(j) of the RTI Act 2005. Previously, Section 8(1)(j) protected personal information from RTI disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It was a delicate, context-driven balancing act—often relying on the Girish Ramchandra Deshpande standard.

The DPDP Act took a sledgehammer to this balance. By removing the "public interest" caveat, it created an absolute embargo on the disclosure of personal information via RTI.

For civil rights litigators, journalists, and corporate whistleblowers, this is a massive blow. State authorities are already weaponizing this amendment to reject RTI applications en masse, citing "personal data." The Constitution Bench will now have to decide if a statutory privacy right can entirely eclipse a fundamental right to transparency derived from Article 19(1)(a).

The Blurry Line Between Public and Personal Data

Running parallel to the RTI conflict is the Supreme Court’s ongoing examination of a fundamental definitional crisis: what separates "public data" from "personal data"?

Section 2(t) of the DPDP Act defines personal data broadly as any data about an individual who is identifiable by or in relation to such data. But what happens when an individual's data is inherently part of a public record? Think of land registries, electoral rolls, or a public servant's asset declarations. If it is publicly available, does it lose its DPDP protection? If it retains DPDP protection, does it become entirely shielded from RTI scrutiny?

The Supreme Court has rightly noted that this classification is a global issue. For corporate counsels and data fiduciaries, how the Court defines this boundary will dictate data scraping policies, open-source intelligence (OSINT) gathering, and the processing of publicly available information.

Courts Acting as the De Facto Data Protection Board

The most glaring takeaway from the recent slew of DPDP litigation is that constitutional courts are being forced to micro-manage data privacy because the executive machinery is missing in action.

Take the APAAR consent form case from July 2026. The Supreme Court had to directly intervene, directing the Centre and CBSE to amend the Automated Permanent Academic Account Registry (APAAR) forms to include an explicit "opt-out" option and restrict third-party data sharing. The Court was essentially enforcing Section 6 (Consent) of the DPDP Act, which mandates that consent be free, specific, informed, unconditional, and unambiguous.

Similarly, in March 2026, the Kerala High Court, while hearing concerns over passenger data harvesting via the Digi Yatra application, cut straight to the chase: Has the Data Protection Board (DPB) even been constituted?

The answer is a resounding no. More than eight months after the initial DPDP Rules were notified in November 2025, the DPB remains a phantom entity with no Chairperson or Members. Under Section 18 of the Act, the DPB is the primary adjudicatory body for grievances and breaches. Without it, the DPDP Act is a tiger with no teeth, leaving data principals with no choice but to invoke writ jurisdiction under Article 226 or 32 for privacy violations.

Practical Takeaways for Tech & Privacy Lawyers

Despite the lack of an operational Board, the staggered rollout of the DPDP regime is ticking toward a May 2027 deadline for full operational compliance. Here is how practitioners should advise their clients right now:

1. Stop Premature Cross-Border Redrafting:
Transactional lawyers are currently in a frenzy redrafting Data Processing Agreements (DPAs) for foreign transfers. This is premature. Section 16 (cross-border transfers) and Rule 15 are not yet live. The government has not published any "restricted country" list. Until they do, the default position remains that cross-border transfer is permitted. Focus billable hours on domestic compliance instead.

2. Prepare for the 72-Hour Breach Window:
Once the enforcement obligations kick in, data fiduciaries will face a brutal two-stage breach notification duty. Clients must be prepared to notify affected individuals "without delay" and report to the (eventual) DPB within 72 hours. Corporate counsels must stress-test their incident response plans now. The May 2027 deadline is for enforcement, but the architecture to meet that deadline must be built today.

3. Revamp Consent Architecture Immediately:
The Supreme Court’s intervention in the APAAR case is a warning shot for private data fiduciaries. If the apex court will not tolerate bundled, mandatory consent from the government, it certainly will not tolerate it from e-commerce platforms or SaaS providers. "Take-it-or-leave-it" terms of service that bundle data processing with service provision are dead on arrival under this Act.

The Verdict

India’s privacy landscape is currently limping. We have a robust, substantive law that is potent enough to cripple the RTI Act, yet structurally incomplete due to executive delays in appointing the Data Protection Board. Until the Constitution Bench delivers its verdict on the RTI-DPDP clash and the government operationalizes the DPB, the Supreme Court and High Courts will remain the reluctant, de facto regulators of India's digital economy.

Published by AnrakLegal AI