Legal News
16 July 2026
IP & Technology

The SC’s DPDP-RTI Referral is a Green Light for Corporate Compliance (and a Red Flag for Transparency)

The Death of the Public Interest Test in RTI? For Indian technology and privacy lawyers, July 2026 has delivered a defining moment of legal clarity—wrapped in a profound constitutional dilemma. The Supreme Court’s recent decision to refer the pleas c...

The Death of the Public Interest Test in RTI?

For Indian technology and privacy lawyers, July 2026 has delivered a defining moment of legal clarity—wrapped in a profound constitutional dilemma. The Supreme Court’s recent decision to refer the pleas challenging the Digital Personal Data Protection (DPDP) Act’s amendment to the Right to Information (RTI) Act to a larger bench is monumental. But for the practicing lawyer, the real headline isn't the referral itself; it is what the Court explicitly refused to do. The Supreme Court did not stay the operation of the DPDP Act.

By refusing to hit the brakes, the apex court has effectively signaled that the corporate compliance clock, accelerated by the DPDP Rules 2025 notified last November, continues to tick toward the immovable May 2027 deadline. If your clients were hoping for a judicial reprieve to delay their data mapping exercises, it is time to disabuse them of that notion.

But while corporate India exhales, transparency advocates are suffocating. The writ petitions filed by The Reporters’ Collective and journalist Nitin Sethi strike at the heart of the DPDP Act’s most insidious Trojan horse: Section 44(3). This provision surgically amended Section 8(1)(j) of the RTI Act, 2005. Previously, personal information could still be disclosed under the RTI Act if a Public Information Officer (PIO) determined that the larger public interest justified it. The DPDP Act obliterated this public interest test, creating a blanket exemption for all personal information. We are witnessing the weaponization of privacy to shield the administrative state, a stark departure from the delicate balance envisioned in the Puttaswamy judgment.

The Executive Grip: The Delhi High Court PIL

The RTI amendment isn't the only constitutional friction point. Parallel to the Supreme Court's larger bench referral, the Delhi High Court is currently hearing a PIL challenging Sections 17–21, 23, 29, and 44 of the DPDP Act. Why does this matter for your practice?

These sections structure the Data Protection Board (DPB) of India. The petitioners rightly argue that the Act creates an executive-dependent enforcement system. Unlike the Competition Commission of India (CCI) or the Securities and Exchange Board of India (SEBI), the DPB lacks the structural independence necessary to hold the State—the largest Data Fiduciary in the country—accountable. For lawyers advising clients facing potential DPB inquiries, you must prepare to navigate an adjudicatory body that is tethered heavily to the Central Government’s rule-making powers, complete with opaque exemption mechanisms for State instrumentalities.

Drafting for 2026: Boilerplate is Professional Negligence

With the DPDP Rules 2025 now fully operational and the 12-month compliance window rapidly closing, commercial contracting has fundamentally shifted. Treating data protection clauses as boilerplate "compliance with applicable laws" jargon is now bordering on professional negligence.

"The burden of proving that consent was validly obtained now rests squarely on the Data Fiduciary. If your contracts do not operationalize this burden, you are exposing your client to crippling penalties."

Here is what needs to change in your drafting immediately:

1. Consent Architecture (Section 6): The Act mandates that consent must be free, specific, informed, unconditional, and unambiguous. More importantly, the right to withdraw consent must be as frictionless as granting it. Tech companies—most notably Meta, Google, and OpenAI, who were hit hard by the November 2025 data minimization rules—are already overhauling their UI/UX. Lawyers must work alongside product teams to ensure that Terms of Service (ToS) agreements don't bundle unconditional consent into general service provisions.

2. The Section 8(5) AI Blindspot: A critical emerging risk is the intersection of AI, Intellectual Property, and Data Protection. Section 8(5) requires Data Fiduciaries to protect personal data in their possession. However, when employees feed customer data into generative AI tools, they are not just risking IP leakage; they are triggering unseen data breaches under the DPDP Act. Significant Data Fiduciaries (SDFs) must now implement algorithmic due diligence and strictly prohibit unvetted "shadow IT" AI usage in their employment agreements.

3. Data Localization for SDFs: While the DPDP Act originally promised a relaxed, "black-list" approach to cross-border data transfers, the reality for SDFs is different. Enhanced localization requirements for specified traffic and personal data mean that your vendor agreements with offshore cloud providers (like AWS or Azure) must include strict auditing rights and geographic ring-fencing indemnities.

The Strategic Takeaway

The Supreme Court’s larger bench will eventually decide whether privacy can be used as a blunt instrument to defeat the RTI Act. However, constitutional challenges move at their own pace. The regulatory reality is moving at breakneck speed.

Lawyers must pivot from debating the Act’s legislative flaws to architecting robust compliance frameworks. The May 2027 deadline for substantive obligations leaves just enough time for organizations to conduct Data Protection Impact Assessments (DPIAs), rewrite third-party data sharing agreements, and train their personnel. The Supreme Court has left the DPDP engine running—it is your job to make sure your clients know how to drive.

Published by AnrakLegal AI