The Privacy-Transparency Collision: Why the Supreme Court’s DPDP Act Hearings Will Redefine Indian Tech Law in 2026
The honeymoon phase for India’s landmark privacy legislation is officially over. As we move deeper into 2026, the Digital Personal Data Protection (DPDP) Act, 2023 and its corresponding 2025 Rules are facing a barrage of constitutional challenges acr...
The honeymoon phase for India’s landmark privacy legislation is officially over. As we move deeper into 2026, the Digital Personal Data Protection (DPDP) Act, 2023 and its corresponding 2025 Rules are facing a barrage of constitutional challenges across the Supreme Court and the Delhi High Court. But this is not just an academic debate over privacy rights—it is a high-stakes tug-of-war between the fundamental right to privacy and the fundamental right to information.
For practicing lawyers, corporate counsel, and privacy professionals, the Supreme Court’s recent refusal to stay the operation of the Act while issuing notice on these petitions creates a chaotic reality. Compliance is mandatory today, yet the very foundation of the law might be restructured by the apex court tomorrow.
The Mutilation of the RTI Act: Section 44(3) Under Fire
The most consequential battleground in the current DPDP litigation is Section 44(3) of the Act. For years, legal practitioners, investigative journalists, and civil rights activists have relied on the Right to Information (RTI) Act, 2005 to unearth systemic corruption, verify public records, and gather evidence. Section 44(3) quietly guts this transparency regime.
Prior to the DPDP Act, Section 8(1)(j) of the RTI Act allowed Public Information Officers (PIOs) to deny requests for personal information unless the disclosure served a "larger public interest." The DPDP Act obliterates this public interest test. It amends the RTI Act to create a blanket prohibition on the disclosure of any personal information.
"By removing the public interest caveat, the DPDP Act effectively weaponizes privacy, turning it into a statutory shield for bureaucratic secrecy. It is a backdoor amendment that severely compromises the RTI Act."
In April 2026, a critical Public Interest Litigation (PIL) challenged this exact provision. The petitioners sought interim relief against the aggressive masking and deletion of public data already available on government portals—a panic-reaction by state departments trying to avoid DPDP penalties. The Supreme Court’s notice on this issue is crucial. If the Court does not read down Section 44(3) to reintroduce a proportionality test, lawyers conducting due diligence, tracing assets, or investigating public tenders will find the doors of the RTI Act permanently slammed shut.
The "Public vs. Private" Data Conundrum
During the February 16 hearings, the Supreme Court astutely pointed out that the core dispute hinges on the fluid distinction between public data and private data. This observation strikes at the heart of modern data practice.
Under the DPDP Act, personal data that is made publicly available by the Data Principal (the user) is exempted from the Act's core consent requirements. But what constitutes "publicly available"? If a user posts their resume on a public job board, does a Data Fiduciary have carte blanche to scrape that data, feed it into a generative AI model, and monetize it?
The Supreme Court is now tasked with drawing the line that the legislature left blurry. The jurisprudence flowing from KS Puttaswamy v. Union of India dictates that individuals do not entirely forfeit their expectation of privacy simply by stepping into the public square. For technology lawyers advising clients on data scraping, AI training datasets, and commercial data brokering, the Supreme Court’s eventual definition of "public data" will dictate whether current business models are legally sound or fundamentally unlawful.
APAAR Scheme Ruling: The End of Boilerplate Consent
While the constitutional challenges brew, the DPDP Act is already showing its teeth in targeted sectors. In a landmark ruling in late July/early August 2026, the Supreme Court held that the collection and sharing of student data under the government's APAAR (Automated Permanent Academic Account Registry) Scheme must strictly comply with the DPDP Act.
The Court’s mandate was clear: consent for minors cannot be a rubber stamp. It must be meaningful and informed. This ruling sends shockwaves through the EdTech sector and government contractors.
Practice Point: Section 9 of the DPDP Act mandates "verifiable consent" from a parent or lawful guardian before processing a minor's data. The APAAR ruling signals that courts will interpret this strictly. EdTech companies relying on passive clickwrap agreements or assuming parental consent via the use of a credit card are operating on borrowed time. Corporate lawyers must immediately audit their clients' UI/UX flows to ensure explicit, documented parental consent mechanisms are in place, lest they face the severe financial penalties prescribed under the Act.
The Road Ahead for Legal Practitioners
The Delhi High Court’s concurrent notices challenging the DPDP Act's wide exemptions (particularly those granted to state instrumentalities) and its penalty structures further complicate the landscape. The state has essentially exempted itself from the stringent data protection norms it enforces on the private sector.
Because the Supreme Court has refused to stay the DPDP Act, lawyers must advise their clients to push forward with full compliance under the 2025 Rules. However, this advice must come with a massive asterisk. Contracts, consent notices, and Data Processing Agreements (DPAs) drafted today must be agile enough to accommodate potential judicial read-downs of the Act by late 2026 or 2027.
The DPDP Act was sold as a shield for the digital citizen. As the Supreme Court dissects it, we will soon find out if it is actually a shield for the state.
Tags
Published by AnrakLegal AI