Legal News
15 April 2026
IP & Technology

The Privacy Paradox: As SC Refers DPDP Act to Constitution Bench, Corporate India's 'Wait and Watch' Strategy Becomes Legal Malpractice

The Supreme Court’s recent decision to refer the challenges against the Digital Personal Data Protection (DPDP) Act, 2023, and its 2025 Rules to a five-judge Constitution Bench is a watershed moment for Indian technology and constitutional law. But f...

The Supreme Court’s recent decision to refer the challenges against the Digital Personal Data Protection (DPDP) Act, 2023, and its 2025 Rules to a five-judge Constitution Bench is a watershed moment for Indian technology and constitutional law. But for practicing lawyers, the real headline isn't the referral itself—it is the bench’s categorical refusal to grant an interim stay on the Act's implementation. Led by Chief Justice Surya Kant, the Court termed the issues "complex but interesting," effectively telling corporate India and its legal advisors: the compliance clock is ticking, and you cannot litigate your way out of a deadline.

The RTI Conundrum: Shielding the State Under the Guise of Privacy

At the heart of the constitutional challenge mounted by groups like the Mazdoor Kisan Shakti Sangathan (MKSS) is Section 44(3) of the DPDP Act. For litigators and activists accustomed to using the Right to Information (RTI) Act, 2005 as a scalpel against state opacity, this provision acts as a blunt force trauma.

Section 44(3) amends Section 8(1)(j) of the RTI Act. Previously, personal information could be disclosed under the RTI Act if a Public Information Officer (PIO) determined that the larger public interest justified it. The DPDP Act entirely strips away this public interest override. By blanketly exempting "personal information," the DPDP Act effectively creates an impenetrable shield for public officials. Want to pull muster rolls for NREGA? Need beneficiary data from Rajasthan’s Jan Soochna Portal to expose a scam? Under the new regime, the state can easily deny these requests citing the privacy of the individuals involved.

"We are witnessing the weaponization of privacy against transparency. The DPDP Act, in its current form, threatens to dismantle two decades of RTI jurisprudence by treating the privacy of a corrupt public servant with the same sanctity as the medical records of a private citizen."

The petitioners rightly argue this violates the fundamental right to information embedded in Article 21. While the landmark K.S. Puttaswamy v. Union of India judgment recognized privacy as a fundamental right, it also demanded a nuanced balancing act between privacy and transparency. The DPDP Act’s brute-force amendment of the RTI Act fails the proportionality test spectacularly. As lawyers, we must prepare for a surge of writ petitions in High Courts as PIOs begin rejecting legitimate RTI applications using the DPDP Act as a shield.

The Compliance Cliff: Why In-House Counsel Must Panic Now

While the constitutional battle brews, transactional and in-house lawyers face a brutal reality. The DPDP Rules, notified in late 2025, triggered a compressed 14-month compliance window ending May 13, 2027. Yet, industry reports indicate that most Global Capability Centres (GCCs) and domestic tech firms are lagging dangerously behind.

If your clients are still relying on standard boilerplate data protection clauses drafted under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), they are stepping onto a landmine. The DPDP Act demands an entirely new contractual architecture.

Under Rule 3 of the 2025 Rules, consent is no longer a static, one-time checkbox. It is a "continuing legal relationship." This means tech platforms in AI, fintech, and telemedicine must overhaul their UI/UX to ensure verifiable, granular consent, alongside robust mechanisms for data principals to withdraw that consent. Furthermore, Data Fiduciaries can no longer passively trust Data Processors. Your vendor agreements desperately need DPDP-specific indemnities, mandatory audit rights, strict data breach notification timelines, and precise clauses on data logging and pseudonymisation.

Forum Shopping and the NHRC Overreach

Perhaps the most fascinating—and alarming—development for tech lawyers is the sudden entry of the National Human Rights Commission (NHRC) into the data protection fray. In early 2026, the NHRC issued notices to the Ministry of Electronics and Information Technology (MeitY) over alleged DPDP violations by AI, social media, and edtech platforms, specifically citing child safety.

The Internet and Mobile Association of India (IAMAI) predictably argued that such interventions are premature given the pending enforcement deadlines. However, NHRC member Priyank Kanoongo’s defense—that child safety and privacy are fundamental human rights overriding statutory rollout periods—signals a dangerous trend of forum shopping.

Before the Data Protection Board (DPB) is fully functional and adjudicating, plaintiffs and activists are leveraging human rights bodies to force compliance. For lawyers representing tech platforms, this means defending privacy practices not just before sectoral regulators or the DPB, but under the broad, unpredictable mandate of the Protection of Human Rights Act, 1993.

The Bottom Line for Practitioners

The refusal of the Supreme Court to stay the DPDP Act shifts the burden entirely onto practitioners. Advising clients to delay compliance investments until the Constitution Bench delivers its verdict is essentially legal malpractice.

The intersection of data privacy, intellectual property, and technology is undergoing a seismic shift. Whether you are drafting a data transfer agreement for a multinational GCC, fighting an RTI rejection before the Central Information Commission, or defending a social media giant against an NHRC notice, the DPDP Act is no longer a theoretical framework—it is the law of the land, heavily armed and already firing.

Published by AnrakLegal AI