The Privacy Shield or a Transparency Gag? Supreme Court’s 5-Judge Bench to Weigh DPDP Act’s Lethal Blow to the RTI
In a jurisprudential showdown that will define the hierarchy of fundamental rights in digital India, the Supreme Court has referred a batch of challenges against the Digital Personal Data Protection (DPDP) Act, 2023 , to a five-judge Constitution Ben...
In a jurisprudential showdown that will define the hierarchy of fundamental rights in digital India, the Supreme Court has referred a batch of challenges against the Digital Personal Data Protection (DPDP) Act, 2023, to a five-judge Constitution Bench. At the heart of this legal storm is a singular, deeply controversial provision: Section 44(3) of the DPDP Act.
For practitioners, this is not merely an academic debate over constitutional theory. It is an immediate, two-front war. On one side, public law litigators are watching the slow asphyxiation of the Right to Information (RTI) Act, 2005. On the other, corporate and technology lawyers are scrambling to drag thoroughly unprepared Global Capability Centres (GCCs) and Data Fiduciaries across a ticking compliance finish line.
The Death of the "Public Interest" Caveat
To understand why Section 44(3) triggered a Constitution Bench referral, we must look at the surgical strike it performs on the RTI Act. Previously, Section 8(1)(j) of the RTI Act exempted personal information from disclosure unless the Central Public Information Officer (CPIO) was satisfied that the "larger public interest justifies the disclosure of such information." Furthermore, it contained a powerful proviso: information that cannot be denied to Parliament or a State Legislature cannot be denied to a citizen.
Section 44(3) of the DPDP Act deletes this nuance entirely. It replaces Section 8(1)(j) with a blanket exemption for any information that relates to "personal information."
The implication is staggering: the DPDP Act has effectively weaponized the Right to Privacy (Article 21) to amputate the Right to Information (Article 19(1)(a)). By removing the public interest override, the statute creates an impenetrable shield for public officials.
As a lawyer arguing before the Central Information Commission (CIC) or High Courts today, you are now operating in the dark. Because the Supreme Court, led by Chief Justice Surya Kant, refused to grant an interim stay on these provisions, the amended Section 8(1)(j) is currently live. Litigators representing activists, journalists, or whistleblowers will find their RTI requests routinely stonewalled under the guise of "data protection." Proactive disclosure portals, like Rajasthan’s Jan Soochna Portal, face existential threats as masking and deletion of public expenditure records become the default administrative stance.
The Constitution Bench will eventually have to reconcile K.S. Puttaswamy v. Union of India (the privacy mandate) with SP Gupta and Raj Narain (the transparency mandate). But until that verdict arrives, administrative opacity remains the law of the land.
The Corporate Compliance Nightmare: May 2027 Approaches
While constitutional lawyers battle over Part III rights, commercial and technology practices are facing a distinctly different crisis. Four months following the notification of the DPDP Rules in November 2025, the corporate reality is grim. Most Indian Global Capability Centres (GCCs) remain in the nascent stages of compliance, staring down a brutal 12-to-14-month deadline that ends on May 13, 2027.
If you are an in-house counsel or an advisory lawyer, the era of relying on boilerplate data privacy clauses is over. The DPDP Act fundamentally shifts how we must draft commercial contracts in 2026. Here is what needs immediate attention in your practice:
- Fiduciary-Processor Matrix: Contracts must clearly demarcate the obligations of Data Fiduciaries versus Data Processors. The fiduciary retains the ultimate liability under Section 8 of the Act. Indemnification clauses must be aggressively renegotiated to account for the heavy penalties (up to ₹250 crores) for data breaches.
- Consent as a Continuous Relationship: Consent is no longer a static, one-time clickwrap agreement. As recent enforcement trends show, it is a "continuing legal relationship." Your clients' UI/UX and backend systems must allow Data Principals to withdraw consent as easily as they gave it, triggering immediate data erasure protocols.
- Significant Data Fiduciaries (SDFs): If your client is classified as an SDF, the compliance burden multiplies. You must immediately advise them on conducting mandatory Data Protection Impact Assessments (DPIAs), especially if they deploy AI-driven HR or consumer analytics tools.
Enforcement is Already Here
Do not mistake the Supreme Court's pending constitutional review for a pause in enforcement. Regulatory bodies are already flexing their muscles. The National Human Rights Commission (NHRC) has recently issued notices over alleged DPDP Act violations by AI, social media, and edtech platforms.
This intersection of data protection with human rights and sector-specific rules (like RBI guidelines for banking or digital health data rules) means lawyers must adopt a matrixed approach to compliance. A breach is no longer just an IT Act, 2000 violation; it is a multi-regulatory disaster.
The Bottom Line
The Supreme Court’s decision to elevate the DPDP-RTI clash to a five-judge bench underscores the profound, structural changes this law imposes on Indian democracy and business. For practitioners, the takeaway is dualfold. If you are in litigation, prepare for a frustrating period of RTI rejections and frame your High Court writ petitions around the unconstitutionality of blanket exemptions. If you are in corporate advisory, ring the alarm bells for your clients. The May 2027 deadline may seem distant, but auditing vendor contracts, restructuring data inventories, and building verifiable consent mechanisms will take every day of that timeline.
The DPDP Act is no longer a looming legislative concept; it is an active, litigious, and highly disruptive reality.
Tags
Published by AnrakLegal AI