Legal News
14 August 2026
IP & Technology

The Supreme Court Refuses to Hit Pause on DPDP: Why Tech Lawyers Can’t Wait for the RTI Dust to Settle

The Constitutional Showdown vs. The Compliance Ticking Clock In February 2026, the Supreme Court of India handed corporate and technology lawyers a massive reality check. By issuing notice on the constitutional challenge to the Digital Personal Data ...

The Constitutional Showdown vs. The Compliance Ticking Clock

In February 2026, the Supreme Court of India handed corporate and technology lawyers a massive reality check. By issuing notice on the constitutional challenge to the Digital Personal Data Protection (DPDP) Act but pointedly refusing to stay its operation, the apex court has bifurcated the legal landscape. While activists and constitutional litigators battle over the soul of the Right to Information (RTI) Act in the courtrooms, transactional lawyers, in-house counsel, and tech-law practitioners must immediately scramble to comply with the staggered rollout of the DPDP Rules 2025.

If you are advising Data Fiduciaries—whether they are Big Tech platforms, AI startups, or cloud processors—the Supreme Court’s refusal to grant a stay means the grace period is effectively over. The Data Protection Board (DPB) framework is live, and the practical enforcement of India’s new privacy regime is no longer a theoretical exercise.

Section 44(3): Privacy as a Shield Against Transparency?

To understand the Supreme Court challenge, we must look at the most controversial sleight of hand in the DPDP Act: Section 44(3). This provision amends Section 8(1)(j) of the RTI Act, 2005.

Historically, Section 8(1)(j) exempted personal information from RTI disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It was a delicate, necessary balancing act between the right to privacy (post-Puttaswamy) and the right to know.

Section 44(3) of the DPDP Act obliterates this balance. It removes the "public interest" caveat entirely, creating a blanket exemption for any personal information under the RTI Act.

As a legal journalist, I must call a spade a spade: this is a dangerous dilution of public accountability masquerading as data protection. The petitioners rightly argue that this shields bureaucrats and state actors from legitimate public scrutiny. However, while this constitutional friction makes for excellent Supreme Court briefs, it is a dangerous distraction for technology and IP practitioners. The state's processing of data without consent and the RTI dilution might be sub judice, but your corporate client's obligations are not.

The Tech and IP Angle: Data is the New Liability

For IP and technology lawyers, the DPDP Rules 2025 fundamentally alter the lifecycle of digital products. We are used to looking at digital assets through the lens of copyright (software code) or trade secrets (algorithms). But in 2026, the data feeding these assets is the primary regulatory target.

The new rules enforce strict purpose limitation and data minimization. This is a direct assault on the traditional Silicon Valley model of "collect everything now, figure out how to monetize it later." For lawyers advising AI companies and ad-tech platforms, the implications are severe:

  • AI Training Datasets: Scraping the Indian web for AI training data without explicit, purpose-specific consent from the Data Principal is now a massive liability. AI companies can no longer hide behind "legitimate interest" loopholes, which the DPDP Act notably omits in favor of "certain legitimate uses."
  • Platform Architecture: The obligation to allow users to refuse consent and withdraw it easily means lawyers must work alongside UI/UX designers. "Dark patterns" that trick users into consenting will now invite DPB scrutiny.

What Practicing Lawyers Need to Change Today

With the DPDP Rules moving into practical enforcement, here is what should be on your desk right now:

1. Overhauling Notice and Consent Mechanisms: Section 5 of the DPDP Act requires an itemized notice to the Data Principal. Blanket privacy policies buried in Terms of Service are dead. If your client hasn't implemented modular, multi-lingual consent managers, they are already in breach.

2. Redrafting Data Processing Agreements (DPAs): Under the DPDP Act, the Data Fiduciary remains entirely liable for the actions of the Data Processor. If you represent a Data Fiduciary, your vendor contracts need aggressive indemnity clauses and strict audit rights. If you represent a SaaS or cloud provider (the Processor), you need to cap liability and explicitly define the boundaries of your processing instructions.

3. Breach Notification Protocols: The DPDP framework mandates notifying both the DPB and the affected Data Principal in the event of a personal data breach. There is no materiality threshold. Lawyers must draft incident response playbooks that can be executed in hours, not weeks.

The Bottom Line

The 2026 Supreme Court challenge to the DPDP Act is a critical fight for India's democratic transparency. But for the technology and corporate bar, the Supreme Court's refusal to stay the Act is the only headline that matters. The staggered compliance timeline is compressing, the Data Protection Board is gearing up, and the era of unregulated data harvesting in India is officially over. Stop waiting for the constitutional dust to settle—start auditing your clients' data flows today.

Published by AnrakLegal AI