The RTI Blackout and AI’s ‘Fair Dealing’ Pass: Why 2026 is Stress-Testing India’s Tech Laws
For Indian technology and privacy lawyers, 2026 is shaping up to be a crucible. The courts are currently grappling with the operational reality of the Digital Personal Data Protection (DPDP) Act, 2023, and the existential intellectual property threat...
For Indian technology and privacy lawyers, 2026 is shaping up to be a crucible. The courts are currently grappling with the operational reality of the Digital Personal Data Protection (DPDP) Act, 2023, and the existential intellectual property threats posed by Generative AI. But if we look closely at the Supreme Court and Delhi High Court dockets over the past few months, a disturbing trend is emerging: privacy is being weaponized to choke transparency, while commercial AI is getting a remarkably generous reading of our archaic copyright exceptions.
The DPDP Act vs. The RTI Act: A Sanctioned Blackout
The most consequential litigation right now is the constitutional challenge to Section 44(3) of the DPDP Act. For the uninitiated, this is the Trojan horse provision that amended Section 8(1)(j) of the Right to Information (RTI) Act, 2005.
Historically, Section 8(1)(j) protected personal information from RTI disclosure unless a larger public interest justified it. More importantly, it contained a vital proviso: information which cannot be denied to the Parliament or a State Legislature shall not be denied to any person. Section 44(3) of the DPDP Act completely deleted this proviso, turning "personal data" into a blanket, absolute exemption under the RTI Act.
In February 2026, the Supreme Court referred this challenge to a larger bench, noting that there are "some creases to be ironed out." However, the Court explicitly declined to grant an interim stay on the operation of the DPDP Act.
"By refusing an interim stay on Section 44(3), the Supreme Court has practically sanctioned an information blackout. Public Information Officers (PIOs) across the country are already using the DPDP Act as a convenient shield to reject legitimate RTI requests by simply labeling the requested information as 'personal data'."
The Court did note that it needs to deeply examine the jurisprudential distinction between public data and personal data under the DPDP framework. For practicing lawyers, this means if you are advising journalists, NGOs, or corporate investigators relying on the RTI Act, you must now prepare to litigate the very definition of "personal data" at the appellate stages, because PIOs will default to rejection.
Consent Gets Teeth: The APAAR Precedent
While the DPDP Act is shrinking the RTI Act, the Supreme Court is simultaneously forcing the State to take DPDP consent principles seriously. In a landmark July 2026 order concerning the APAAR (Automated Permanent Academic Account Registry) rollout, the Supreme Court mandated that the government must provide an opt-out/refuse option in the consent form and strictly restricted third-party data sharing.
This is a massive development for EdTech companies and corporate data fiduciaries. Until now, standard practice in India was "bundled consent"—take-it-or-leave-it terms of service. By tying school-data processing directly to the rigorous consent framework of Section 6 of the DPDP Act, the Court has signaled the death of illusory consent.
Practice pointer: If your clients are collecting user data, especially children's data, their privacy policies need an immediate audit. The APAAR ruling means courts will look for granular, affirmative, and revocable consent. If your client's UI/UX doesn't have a clear "refuse" button, they are sitting ducks for regulatory action once the Data Protection Board fully awakens.
Generative AI and the Stretched Limits of Section 52
Away from the privacy battlefield, the Delhi High Court dropped a bombshell on Indian copyright law in August 2026. Hearing the dispute between news agency ANI and OpenAI (creators of ChatGPT), the High Court held, prima facie, that OpenAI’s ingestion and storage of ANI’s copyrighted works for training its Large Language Models (LLMs) fell within the "fair dealing" exception under Section 52(1)(a) of the Copyright Act, 1957.
This is a highly controversial stance. Section 52(1)(a) allows fair dealing for private or personal use, including research. To stretch this exception to cover the mass, automated scraping of proprietary data by a multi-billion-dollar commercial entity for training a commercial product requires judicial gymnastics.
Unlike the US, which has a broad, four-factor "fair use" doctrine that heavily weighs "transformative use," India has an exhaustive, closed-list "fair dealing" doctrine. The Delhi High Court's interim view suggests a willingness to aggressively modernize Indian IP law from the bench to avoid stifling AI innovation.
For IP litigators, this completely changes the playbook. You can no longer merely prove reproduction of your client's work in the AI's training data. You must now build extensive arguments on why commercial LLM training fails the traditional tests of "fairness" in dealing, focusing on market substitution and commercial intent to defeat the Section 52 defense.
The Elephant in the Room: An Empty Board
The great irony binding all these 2026 developments is that while courts are creating binding jurisprudence on data protection, the actual regulator is a ghost town. As of mid-2026, the Data Protection Board of India is operational in law, but appointments for its chairperson and members remain pending.
We are currently operating in a dangerous regulatory vacuum where the DPDP Act is live enough to destroy the RTI Act, but lacks the institutional machinery to actually protect citizens' data from corporate misuse. For legal practitioners, this means your primary avenue for immediate relief remains writ jurisdiction under Article 226 or PILs under Article 32, bypassing a statutory board that exists only on paper.
The creases aren't just waiting to be ironed out—they are currently defining the fabric of Indian tech law.
Tags
Published by AnrakLegal AI