Legal News
7 August 2026
IP & Technology

The Privacy-Transparency Paradox: Why the SC’s Refusal to Stay the DPDP-RTI Amendment Means Corporate India Must Stop Stalling

The End of the Waiting Game For the past three years, the standard advice from corporate privacy teams regarding the Digital Personal Data Protection (DPDP) Act, 2023 has been a hesitant "let's wait and see." As of early 2026, that advice borders on ...

The End of the Waiting Game

For the past three years, the standard advice from corporate privacy teams regarding the Digital Personal Data Protection (DPDP) Act, 2023 has been a hesitant "let's wait and see." As of early 2026, that advice borders on professional negligence.

On February 16, 2026, the Supreme Court referred a batch of writ petitions challenging the DPDP Act’s controversial amendment to the Right to Information (RTI) Act to a larger bench. But the headline for practicing lawyers isn't the referral—it is the Court's explicit refusal to stay the operation of the DPDP Act. By merely noting that there are "some creases to be ironed out," the apex court has effectively signaled that the DPDP machinery is here to stay. The compliance clock is ticking, and the intersection of privacy and state transparency is officially a constitutional battleground.

Weaponizing Privacy: The Section 8(1)(j) Conundrum

To understand why litigators and transparency activists are up in arms, we must look at how the DPDP Act fundamentally neuters the RTI Act, 2005. Section 44(3) of the DPDP Act amended Section 8(1)(j) of the RTI Act, which deals with the exemption from disclosure of personal information.

Pre-amendment, Section 8(1)(j) contained a crucial caveat: a Public Information Officer (PIO) could disclose personal information if they were satisfied that the "larger public interest justifies the disclosure." It was a delicate balancing act between the right to know—cemented in Raj Narain and PUCL—and the right to privacy under Puttaswamy.

The DPDP amendment obliterates this balance. It replaces the nuanced public interest test with a blanket exemption: if the information requested relates to personal information, it cannot be disclosed. Period. This effectively allows the State to weaponize the fundamental right to privacy to shield itself from accountability. Electoral rolls, beneficiary lists for welfare schemes, and details of bureaucratic appointments can now be legally cloaked under the guise of "data protection."

"By refusing to stay this amendment, the Supreme Court has allowed a regime of absolute opacity to take root while we wait for a larger bench to deliberate. For public interest litigators, this is a severe blow. For PIOs, it is a convenient shield."

Corporate Compliance: The Staggered Reality

While constitutional lawyers debate the RTI amendment, transactional and corporate lawyers must pivot to immediate compliance. The Supreme Court's refusal to stay the Act means the Digital Personal Data Protection Rules, 2025 (notified on November 13, 2025) are fully operative.

The Ministry of Electronics and Information Technology (MeitY) has adopted a staggered approach, but the runway is rapidly shrinking. Consent Managers have until November 13, 2026, to fall in line, while major compliance obligations for general Data Fiduciaries take effect on May 13, 2027.

If you are advising tech companies, e-commerce platforms, or financial institutions, your data mapping should have started yesterday. The argument that "the law is still being challenged" holds no water. The Data Protection Board of India is operationalizing. You must immediately advise clients to:

  • Overhaul Notice and Consent Mechanisms: Move away from bundled, legalese-heavy privacy policies to itemized, vernacular-supported consent notices as mandated by the Rules.
  • Implement Verifiable Parental Consent: EdTech and gaming clients are particularly vulnerable here.
  • Audit Third-Party Processors: Data Fiduciaries remain strictly liable for the breaches of their Data Processors. Indemnity clauses in vendor agreements need urgent renegotiation.

DPI and State Accountability: APAAR and Digi Yatra

Perhaps the most fascinating development of 2026 is how the DPDP Act is being wielded against the State’s own Digital Public Infrastructure (DPI). The narrative that the DPDP Act only burdens private enterprises is demonstrably false.

In March 2026, the Kerala High Court demanded answers from the Centre and the Digi Yatra Foundation regarding data collection and facial recognition at airports. More significantly, in August 2026, the Supreme Court explicitly held that the APAAR Scheme (Automated Permanent Academic Account Registry) is subject to the strictures of the DPDP Act. The Court ruled that student data cannot be shared with private entities (read: EdTech platforms and data brokers) without strict legal compliance.

This is a massive precedent. It confirms that the State, acting as a Data Fiduciary, cannot bypass the DPDP Act simply because a scheme is deemed "digital public infrastructure." For lawyers advising private entities that plug into DPI APIs—whether for KYC, academic verification, or travel—the compliance burden is now dual: you must satisfy both your own fiduciary obligations and ensure your State partner isn't passing you tainted, non-consensual data.

The Intermediary Chaser

To compound the compliance headache for tech lawyers, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 came into effect on February 20, 2026. This parallel development tightens platform liability, meaning digital intermediaries are now caught in a pincer movement: strictly govern user-generated content under the IT Rules while strictly protecting user data under the DPDP Act.

The Verdict for Practitioners

The Supreme Court’s "ironing out the creases" will likely take years of jurisprudential back-and-forth. But the operational reality of the DPDP Act is already here. Courts are actively applying it to State schemes, the Data Protection Board is gearing up for enforcement, and the May 2027 deadline for corporate compliance is immovable.

As legal practitioners, our job is no longer to speculate on the constitutionality of the DPDP Act, but to operationalize its mandates. The grace period is over. It is time to get to work.

Published by AnrakLegal AI