Legal News
29 June 2026
IP & Technology

The Privacy Paradox: Supreme Court Steps In as the DPDP Act Threatens to Consume the RTI Act

June 2026 has delivered the constitutional showdown that privacy advocates and transparency activists have been dreading for three years. The Supreme Court has finally referred the constitutional challenges against the Digital Personal Data Protectio...

June 2026 has delivered the constitutional showdown that privacy advocates and transparency activists have been dreading for three years. The Supreme Court has finally referred the constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023, and its 2025 Rules to a five-judge Constitution Bench. At the heart of this litigation is a fundamental question for our democracy: Can the fundamental right to privacy be weaponized to annihilate the statutory right to information?

The Legislative Sleight of Hand: Section 44(3)

For practicing lawyers, especially those handling writ petitions, public interest litigations, or corporate due diligence involving state instrumentalities, the DPDP Act has introduced a fatal roadblock. Section 44(3) of the DPDP Act quietly but lethally amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005.

Before this amendment, Section 8(1)(j) protected personal information from RTI disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It also contained a powerful proviso: information which cannot be denied to Parliament or a State Legislature shall not be denied to any person. Section 44(3) wiped this public interest override completely off the statute books.

"By removing the public interest test, the legislature has created an absolute exemption for anything classified as 'personal information.' This is not data protection; it is state protection disguised as privacy."

Why does this matter for your practice? If you are representing a whistleblower, investigating non-performing assets (NPAs) of public sector banks, or trying to unearth the beneficiaries of dubious government tenders, the state now has a blanket statutory shield. The names of defaulting corporate promoters or corrupt contractors are simply categorized as "personal information," and the RTI application is summarily dismissed. The Editors Guild and the National Campaign for People's Right to Information are entirely correct in their assertion that this amendment fundamentally alters the citizen-state dynamic.

The Supreme Court's Reluctance on Interim Relief

While Chief Justice Surya Kant's bench rightly recognized the gravity of this constitutional friction by referring it to a larger bench, their refusal to grant an interim stay on the impugned provisions is highly problematic. The Court noted there is "no question of stay" without hearing the matter fully.

In practice, this refusal creates a dangerous vacuum. While we wait for the Constitution Bench to deliberate—a process that could take months, if not years—public authorities will aggressively rely on the amended Section 8(1)(j) to reject RTI queries. The jurisprudence established in K.S. Puttaswamy v. Union of India made it clear that privacy is not an absolute right; it must be balanced against other competing rights. Yet, currently, administrative opacity enjoys absolute statutory backing.

The Tech & IP Squeeze: No New AI Law, Just Brutal IT Rules

While constitutional lawyers battle over the RTI Act, corporate and technology counsels are facing their own nightmare. The Ministry of Electronics and IT (MeitY) has confirmed it will not draft a standalone Artificial Intelligence (AI) regulation. Instead, the government is force-fitting AI governance into the existing Intellectual Property Act frameworks and the DPDP Act.

But the real hammer dropped in February 2026 with the amendment to the Information Technology (Intermediary Guidelines) Rules. If you advise social media platforms, intermediaries, or AI startups, your compliance matrices just caught fire.

The amendment mandates a draconian 3-hour takedown window for Synthetically Generated Information (SGI)—including deepfakes and AI-generated art—down from the previous 72 hours. This is a 92% reduction in response time. Furthermore, the standard for verifying user declarations has shifted from a best-effort "endeavour to deploy" to a mandatory "shall."

Let’s be direct: a 3-hour takedown window for complex, AI-generated deepfakes is practically impossible without relying entirely on automated, algorithmic censorship. This severely undermines the safe harbour protection under Section 79 of the IT Act and resurrects the ghost of pre-Shreya Singhal censorship, where intermediaries will simply take down lawful content rather than risk crippling penalties.

The Compliance Clock is Ticking Faster

Finally, tech lawyers must take note of the shifting sands of DPDP compliance. While the November 2025 notification originally granted an 18-month transition period (ending May 13, 2027), the Centre is already threatening to compress this timeline for large companies and "Significant Data Fiduciaries."

The takeaway for practitioners: Do not wait for 2027. If you represent data fiduciaries, you must establish explicit consent mechanisms and breach-reporting protocols immediately. The government intends to use the DPDP Act as its primary weapon to regulate everything from basic data scraping to complex AI training models. With the Delhi High Court also issuing notices on a separate PIL challenging sections 17-21 and 33-37 of the DPDP Act, the litigation landscape surrounding data privacy is only going to get more volatile.

India's data protection regime has arrived, but it has arrived with a heavy hand, sacrificing transparency and intermediary safe harbours at the altar of state control and rapid-fire compliance.

Published by AnrakLegal AI