Legal News
3 October 2026
IP & Technology

The Privacy Paradox: Supreme Court’s Constitution Bench to Weigh RTI Act Against the DPDP Regime Amidst Regulatory Paralysis

The Constitutional Showdown: Transparency vs. Privacy In what is shaping up to be the defining constitutional battle of 2026, the Supreme Court has referred the clash between the Right to Information (RTI) Act, 2005 and the Digital Personal Data Prot...

The Constitutional Showdown: Transparency vs. Privacy

In what is shaping up to be the defining constitutional battle of 2026, the Supreme Court has referred the clash between the Right to Information (RTI) Act, 2005 and the Digital Personal Data Protection (DPDP) Act, 2023 to a five-judge Constitution Bench. The February 2026 referral strikes at the heart of a fundamental jurisprudential tension: how do we reconcile the fundamental right to know under Article 19(1)(a) with the fundamental right to privacy under Article 21?

For practicing advocates and corporate counsel, this is not merely an academic debate over K.S. Puttaswamy v. Union of India. The petitions, spearheaded by journalist Nitin Sethi and The Reporters Collective, challenge a legislative sleight of hand. Section 44(3) of the DPDP Act amended Section 8(1)(j) of the RTI Act. Previously, personal information could be disclosed under the RTI Act if the Public Information Officer (PIO) determined that the larger public interest justified the disclosure. The DPDP Act obliterated this public interest test, creating a blanket exemption for any "personal information."

"By removing the public interest override, the state has effectively weaponized privacy to dismantle administrative transparency. A blanket exemption protects corrupt public servants just as much as it protects private citizens."

The Supreme Court’s refusal to stay the amendment pending the Constitution Bench’s decision leaves a gaping hole in India’s transparency regime. For lawyers utilizing the RTI Act for litigation fact-finding, due diligence, or uncovering administrative overreach, the doors remain firmly shut. Any request remotely touching upon "personal data" is currently being summarily rejected by PIOs across the country.

The Regulatory Vacuum: A Board Without Members

While the constitutional validity of the DPDP Act hangs in the balance, the administrative reality of its enforcement is bordering on farcical. The DPDP Rules were notified in 2025, theoretically breathing life into the Data Protection Board of India (DPBI). Yet, as of mid-2026, the Board remains a ghost town. Despite the government initiating the appointment process in May and June 2026, the DPBI lacks both a Chairperson and its requisite Members.

Why does this regulatory paralysis matter to your practice? Because the compliance clock is ticking aggressively. While some procedural provisions took effect in November 2025, the substantive obligations for Data Fiduciaries and Data Processors are set in stone for 13 May 2027.

Corporate lawyers are currently advising clients in the dark. How can a Data Fiduciary seek regulatory guidance, report data breaches, or test the waters on legitimate use exemptions when the adjudicatory body does not exist? The impending rollout of the Consent Manager framework, expected by November 2026 under the DPDP Rules, further complicates matters. Fintech companies, account aggregators, and digital platforms are being forced to invest millions into compliance architecture to integrate with Consent Managers, without a functioning Board to clarify technical ambiguities.

Sectoral Spillovers: From APAAR to AI

The absence of a functioning DPBI hasn't stopped the DPDP Act from aggressively bleeding into sectoral disputes. The Supreme Court recently clarified the data protection obligations surrounding the APAAR (Automated Permanent Academic Account Registry) ID system. The Court explicitly ruled that the collection, storage, and retention of student data squarely falls under the DPDP Act, prohibiting disclosure to private third-party ed-tech entities except strictly according to the law.

This ruling is a massive wake-up call for the education and ed-tech sectors, which have historically treated student data as a freely tradable commodity. We are also seeing the DPDP Act heavily disrupt fintech consent management and the deployment of AI in the workplace. Employers utilizing AI to monitor employee productivity or process HR data are now squarely within the crosshairs of the DPDP regime's notice and consent requirements.

The Path Forward for Practitioners

It is tempting for corporate clients to view the Supreme Court’s constitutional review and the government’s failure to constitute the DPBI as reasons to delay DPDP compliance. Counsel must strongly advise against this.

The May 2027 deadline for substantive compliance is the Sword of Damocles. Building an enterprise compliance architecture—conducting data mapping, revising privacy notices, renegotiating data processor agreements, and implementing verifiable parental consent mechanisms—takes 12 to 18 months for a mid-to-large enterprise.

Lawyers must take a proactive stance:

  • For Litigators: Prepare for a surge in writ petitions challenging arbitrary RTI rejections based on the amended Section 8(1)(j). The Constitution Bench will eventually lay down the law, but intermediate high court interventions may be necessary to curb blatant PIO overreach.
  • For Corporate Counsel: Treat the November 2026 Consent Manager rollout as a hard deadline for tech-readiness. Do not wait for the DPBI to be fully staffed to begin compliance audits. When the Board is finally constituted, it will likely be under immense political pressure to demonstrate its teeth by penalizing early violators.

The intersection of technology and law in India is currently defined by high legislative ambition and poor administrative execution. As the Constitution Bench prepares to untangle the privacy-transparency paradox, practitioners must ensure their clients are shielded from the fallout of this regulatory vacuum.

Published by AnrakLegal AI