Legal News
9 October 2026
IP & Technology

The Supreme Court Intervenes in the DPDP-RTI Collision Course While Corporate India Chases Ghost Regulations

The Article 19 vs. Article 21 Showdown Hits the Supreme Court A constitutional collision course has officially reached the Supreme Court of India, and every litigator dealing with writ jurisdiction, transparency, or privacy needs to pay close attenti...

The Article 19 vs. Article 21 Showdown Hits the Supreme Court

A constitutional collision course has officially reached the Supreme Court of India, and every litigator dealing with writ jurisdiction, transparency, or privacy needs to pay close attention. The apex court has referred the mounting constitutional challenges against the Digital Personal Data Protection (DPDP) Act, 2023—specifically its controversial amendment to the Right to Information (RTI) Act, 2005—to a larger bench. Noting that there are “some creases to be ironed out,” the Court has effectively acknowledged the unresolved tension between the fundamental right to information (Article 19(1)(a)) and the fundamental right to privacy (Article 21, post-Puttaswamy).

At the heart of the storm is Section 44(3) of the DPDP Act. For over a decade and a half, Section 8(1)(j) of the RTI Act provided a nuanced exemption: personal information of a citizen could be withheld by a Public Information Officer (PIO) unless the larger public interest justified its disclosure. Section 44(3) of the DPDP Act bulldozes this nuance. It amends Section 8(1)(j) to create a blanket exemption for all personal information, stripping away the public interest test entirely.

"By removing the public interest override, the DPDP Act has inadvertently armed every state instrumentality with an impenetrable shield against transparency. For practicing lawyers, this means your standard RTI applications seeking details of public servant appointments, beneficiary lists, or tender allocations are about to face a wall of automated rejections."

Journalists and rights groups have rightly argued that this expands bureaucratic secrecy. Until the larger bench settles this, lawyers advising clients on RTI appeals before the Central or State Information Commissions should prepare for aggressive use of the amended Section 8(1)(j) by public authorities. If you are drafting a writ petition challenging an RTI rejection, you must now explicitly plead the constitutional invalidity of this amendment as a ground.

The Corporate Mirage: Redrafting Contracts for Inactive Rules

While litigators watch the Supreme Court, transactional and in-house lawyers are navigating a completely different nightmare: phantom regulations. According to recent reports, the DPDP Act’s operational rollout is going to be severely staggered. We are looking at a timeline that stretches from late 2025 all the way to May 13, 2027, for full enforcement covering consent, notice, and data principal rights.

The most glaring paradox right now involves cross-border data transfers. Section 16 of the DPDP Act and its implementing rules are not yet live. Despite this, panic has set in. Tech firms, multinationals, and law firms are preemptively redrafting Data Processing Agreements (DPAs) and cross-border data transfer contracts. Lawyers are trying to draft compliance mechanisms for rules that the Ministry of Electronics and Information Technology (MeitY) hasn't even finalized.

Our take: Stop over-lawyering the unknown. While it is prudent to conduct data mapping and prepare modular consent notices, locking clients into rigid, expensive cross-border compliance structures before the Section 16 Rules are notified is premature risk management. Advise your clients to build agile data architectures rather than rigid contractual silos.

Fintech and Education: Sector-Specific Tremors

The staggered timeline also introduces massive friction for specific sectors. The operationalization of Consent Managers is slated for around mid-November 2026. For the Fintech sector, this creates a bizarre regulatory overlap. Fintech companies are already governed by the RBI’s Account Aggregator (AA) framework, which acts as a financial consent manager. Reconciling the RBI's AA framework with the DPDP's impending Consent Manager rules will require careful regulatory structuring to avoid double-compliance penalties.

Meanwhile, the education sector just received a massive wake-up call. The Supreme Court recently clarified that data collection, processing, storage, and sharing under the government's APAAR Scheme (the "One Nation, One Student ID" registry) is strictly subject to the DPDP Act.

For lawyers advising EdTech platforms or private educational institutions, the mandate is now crystal clear: student data cannot be monetized, profiled, or shared with private third parties without explicit, verifiable consent that meets the rigorous standards of the DPDP Act. The days of schools quietly selling student directory data to coaching institutes are over.

An IP Litigator's Aside: Trademark Forum Shopping Under Scrutiny

In IP-adjacent news that will heavily impact litigation strategy, the Supreme Court has referred the issue of civil courts and their jurisdiction in trademark suits to a larger bench. Trademark litigators in India have long exploited ambiguities in the Trade Marks Act to engage in forum shopping—initiating suits in favorable jurisdictions based on tenuous claims of "carrying on business." This upcoming larger bench decision will likely tighten the jurisdictional leash, forcing IP litigators to rethink where and how they file infringement suits.

Furthermore, in a sign of tightening digital compliance, Google has agreed to report Child Sexual Abuse Material (CSAM) directly to Indian authorities. This is a clear indicator of how India’s broader digital regulation environment—spanning the IT Rules, the upcoming Digital India Act, and the DPDP Act—is forcing global platforms to localize their compliance and law enforcement reporting mechanisms.

The Bottom Line for Practitioners

India's tech and privacy landscape is currently in a state of suspended animation. The laws are passed, but the rules are missing; the constitutional challenges are filed, but the judgments are pending. For practicing lawyers, the next 24 to 36 months will not be about strict compliance, but about strategic risk mitigation. Draft your contracts with severability clauses, prepare your RTI clients for rejections, and tell your tech clients that May 2027 will be here faster than they think.

Published by AnrakLegal AI