The Privacy Paradox: Why the Supreme Court’s DPDP Act Showdown Matters More Than Your 2027 Compliance Deadlines
The Collision of Privacy and Transparency For the last three years, the Indian corporate bar has treated the Digital Personal Data Protection (DPDP) Act, 2023, as a looming, abstract boogeyman—a lucrative compliance exercise for the future. But as we...
The Collision of Privacy and Transparency
For the last three years, the Indian corporate bar has treated the Digital Personal Data Protection (DPDP) Act, 2023, as a looming, abstract boogeyman—a lucrative compliance exercise for the future. But as we navigate through the first quarter of 2026, the future has abruptly arrived. With the Data Protection Board of India (DPBI) operational since November 2025 and the Supreme Court actively hearing constitutional challenges to the regime, the DPDP Act is no longer just a boardroom discussion. It is an active jurisprudential battleground.
While tech lawyers are busy mapping out the May 13, 2027, substantive compliance deadline for their Data Fiduciary clients, a far more consequential fight is unfolding in the apex court. In February and March 2026, the Supreme Court issued notice on petitions challenging the DPDP Act and its 2025 Rules. Crucially, the Court refused to grant an interim stay. The focal point of this litigation? Section 44(3) of the DPDP Act, which subtly but violently amputated Section 8(1)(j) of the Right to Information (RTI) Act, 2005.
The RTI Amendment: Privacy as a Shield for Opacity
Let’s call a spade a spade: the amendment to the RTI Act is the most insidious provision of the DPDP Act. Prior to this amendment, Section 8(1)(j) of the RTI Act protected personal information from disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It was a balancing test, born from the constitutional equilibrium between the right to know (Article 19(1)(a)) and the right to privacy (Article 21, post-Puttaswamy).
Section 44(3) of the DPDP Act obliterated this balance. It removed the "public interest" carve-out entirely, creating an absolute exemption for anything classified as "personal information."
"By stripping the public interest override, the legislature has effectively handed the state a statutory shield to deny access to crucial public records—from electoral rolls to beneficiary lists and bureaucratic accountability metrics—under the convenient guise of 'data protection'."
For practicing lawyers, this is not just a human rights issue; it is a massive procedural hurdle. Due diligence, background checks, and asset tracing often rely on state-held records. If CPIOs begin blanket-rejecting RTI applications citing the amended Section 8(1)(j), litigators and corporate investigators will find themselves blindfolded. The Supreme Court's decision on whether to strike down or read down this amendment will dictate the future of public accountability and legal research in India.
What the DPBI’s Operational Status Means for Tech & IP
While the Supreme Court wrestles with the RTI conflict, the regulatory machinery is already humming. The DPBI was constituted in November 2025, and the phased rollout of the DPDP Rules is underway. Consent Manager registrations open on November 13, 2026, and full substantive compliance kicks in by May 2027.
For IP and technology practitioners representing platforms, ad-tech firms, and AI developers, the grace period is effectively over. The operationalization of the DPBI means that the era of ambiguous "implied consent" is dead. Here is what needs to change in your practice immediately:
- Consent and Notice Overhaul: Platforms can no longer rely on 50-page privacy policies wrapped in legalese. Under the new Rules, notice must be itemized, multilingual, and explicitly tied to a specific purpose. If your client is still using pre-ticked boxes for data collection, they are sitting ducks for DPBI penalties.
- The AI Scraping Conundrum: Intellectual property lawyers advising generative AI startups face a unique crisis. The DPDP Act exempts personal data that is "made publicly available" by the Data Principal. But what constitutes "publicly available"? If an AI firm scrapes public social media feeds to train its LLM, is it violating the DPDP Act? The Supreme Court’s current scrutiny of what constitutes "public data" versus "personal data" will directly impact the legality of AI training datasets in India.
- Data Minimization as a Hard Rule: Ad-tech companies must pivot from "collect everything, monetize later" to strict data minimization. Processing must be limited to what is strictly necessary for the specified purpose.
The Strategic Takeaway
The Supreme Court’s refusal to stay the DPDP Act sends a clear signal: the judiciary will not halt the regulatory train while it deliberates on constitutional nuances. Therefore, advising clients to "wait and see" how the Supreme Court rules is professional malpractice.
Practitioners must dual-track their strategy. First, audit and overhaul your clients' data collection architectures to meet the strict notice and consent requirements before the Consent Manager ecosystem goes live in November 2026. Second, watch the Supreme Court’s handling of the RTI amendment closely. If the Court strikes down the absolute exemption in Section 8(1)(j), it will set a precedent that privacy cannot be weaponized to defeat transparency—a ruling that will inevitably bleed into how private platforms govern user data.
India’s privacy jurisprudence is finally moving from the theoretical heights of Puttaswamy to the gritty reality of compliance and enforcement. It is time for the legal fraternity to catch up.
Tags
Published by AnrakLegal AI