The Privacy Paradox: Constitution Bench Takes on DPDP Act While Corporate India Faces a 12-Month Squeeze
The Supreme Court has officially lobbed India’s Digital Personal Data Protection (DPDP) Act, 2023, into the lap of a five-judge Constitution Bench. But if you are advising corporate clients to hit the pause button on their compliance budgets pending ...
The Supreme Court has officially lobbed India’s Digital Personal Data Protection (DPDP) Act, 2023, into the lap of a five-judge Constitution Bench. But if you are advising corporate clients to hit the pause button on their compliance budgets pending the outcome, you are setting them up for a spectacular failure.
The Court categorically refused to stay the operation of the Act while the constitutional challenges are heard. Simultaneously, the Ministry of Electronics and IT (MeitY) has aggressively compressed the compliance window for the DPDP Rules, 2025, from 18 months down to 12 months. With an enforcement hard-stop now looming in May 2027, the regulatory grace period is officially over. Here is what this dual-track development means for constitutional litigators and corporate practitioners.
The Constitutional Crossfire: Weaponizing Privacy Against Transparency
The core of the Supreme Court challenge, spearheaded by the Mazdoor Kisan Shakti Sangathan (MKSS) and prominent RTI activists, zeroes in on a seemingly innocuous but lethal amendment tucked at the end of the DPDP Act. Section 44(3) of the DPDP Act amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005.
To understand the gravity of this, we must look at the pre-amendment RTI regime. Previously, personal information could be exempted from disclosure unless the Public Information Officer was satisfied that the larger public interest justified the disclosure. It was a balancing act—a statutory codification of proportionality. Furthermore, information that could not be denied to Parliament or a State Legislature could not be denied to a citizen.
The DPDP Act obliterates this proviso. It replaces the nuanced public interest test with a blanket exemption for any "personal information."
"The State has effectively weaponized the fundamental right to privacy to shield itself from administrative transparency. By deleting the public interest caveat in Section 8(1)(j) of the RTI Act, the government has created an absolute embargo on disclosing beneficiary data, social audit records, and bureaucratic accountability metrics."
For litigators, the argument before the Constitution Bench will hinge on whether this blanket exemption violates the proportionality doctrine laid down in Justice K.S. Puttaswamy v. Union of India. If privacy is not an absolute right, how can a statutory exemption protecting it be absolute, especially when it infringes upon the citizen's Article 19(1)(a) right to know? Until the Bench decides, however, expect public authorities to routinely reject RTI applications citing the amended Section 8(1)(j).
The 12-Month Corporate Scramble: What Changes for In-House and Tech Lawyers
While the constitutional debate rages, MeitY’s decision to compress the compliance timeline to 12 months is sending shockwaves through the financial, healthcare, and tech sectors. If you are drafting commercial contracts or advising Data Fiduciaries, the foundational architecture of your practice must shift immediately.
1. The Nightmare of Dual-Reporting:
Under Section 8(6) of the DPDP Act, Data Fiduciaries must intimate personal data breaches to the Data Protection Board and the affected Data Principals. However, this does not supersede the Information Technology Act, 2000. Companies are now looking at a dual-reporting regime. Your incident response policies must reconcile the DPDP Board notifications with the draconian 6-hour reporting mandate to CERT-In under the IT (CERT-In) Rules. Navigating what gets reported to whom, and when, will be a massive compliance headache requiring heavily integrated legal and infosec teams.
2. Rule 3 and the Death of Boilerplate Consent:
Privacy experts are already flagging severe compliance gaps, particularly regarding Rule 3 of the DPDP Rules, 2025. Indian lawyers have developed a bad habit of copy-pasting GDPR consent notices. The DPDP Act is fundamentally different—it relies heavily on explicit, itemized consent and lacks the broad "legitimate interest" ground found in European law. If your client's app is masking mandatory data collection behind a pre-ticked "I Agree" checkbox, they are walking into a regulatory trap. Consent architectures must be completely rebuilt to be granular, multilingual, and easily withdrawable.
3. Vendor Contracts Need Immediate Overhaul:
With the May 2027 deadline approaching, Data Fiduciaries (like hospitals and banks) cannot afford to have data breaches caused by Data Processors (third-party vendors, SaaS providers). The DPDP Act places the liability squarely on the Fiduciary. Commercial lawyers must urgently renegotiate vendor agreements to include stringent indemnity clauses, mandatory sub-processor mapping, and strict audit rights. "Standard ESG and data protection clauses" will not survive regulatory scrutiny under the new regime.
The NHRC Curveball
Perhaps the most fascinating procedural development is the National Human Rights Commission (NHRC) issuing notices over alleged DPDP Act violations by AI, social media, and edtech platforms. This signals a creative forum-shopping trend by civil society. Because the Data Protection Board's adjudicatory mechanisms are still finding their footing, activists are framing data harvesting and algorithmic bias as fundamental human rights violations to trigger NHRC jurisdiction.
The Bottom Line
The Supreme Court’s review of the DPDP Act is a crucial battle for India's democratic transparency, but it is not a stay order. The law, with all its stringent operational rules notified in late 2025, is live. For practicing lawyers, the mandate is absolute: stop waiting for judicial finality. The 12-month compliance window requires immediate, aggressive action in mapping data, restructuring consent, and overhauling vendor contracts. The era of casual data hoarding in India is officially over.
Tags
Published by AnrakLegal AI