The Supreme Court Refuses to Hit Pause on DPDP: Why Tech Lawyers Must Stop Waiting for a Judicial Rescue
The Compliance Clock is Ticking, Sub Judice or Not For every Data Privacy Officer, General Counsel, and tech lawyer who secretly hoped the constitutional challenges to the Digital Personal Data Protection (DPDP) Act, 2023 would buy them another year ...
The Compliance Clock is Ticking, Sub Judice or Not
For every Data Privacy Officer, General Counsel, and tech lawyer who secretly hoped the constitutional challenges to the Digital Personal Data Protection (DPDP) Act, 2023 would buy them another year of compliance lethargy, the Supreme Court just delivered a harsh reality check. While the apex court has referred multiple writ petitions challenging the DPDP Act’s controversial amendments to the Right to Information (RTI) Act to a larger bench, it made one thing absolutely clear: there will be no stay on the operation of the DPDP Act.
The message from the bench is unmistakable. The judiciary is treating the privacy-versus-transparency debate as a serious constitutional question requiring a larger bench, but it is not going to derail India’s $1 trillion digital economy ambitions while it deliberates. Parallel challenges, like the PIL currently before the Delhi High Court attacking key provisions of the DPDP Act and the newly notified DPDP Rules, 2025, are progressing. But litigation risk is no longer an excuse for compliance delay.
The RTI Clash: When Privacy Swallows Transparency
To understand why these writ petitions matter to everyday practice, you have to look at the mechanics of the amendment. The DPDP Act fundamentally altered the RTI framework, specifically Section 8(1)(j) of the RTI Act, 2005.
Previously, Section 8(1)(j) allowed Public Information Officers (PIOs) to deny the disclosure of personal information unless they were satisfied that the larger public interest justified the disclosure. It was a balancing test born out of the friction between transparency and privacy. The DPDP Act obliterated that balance. By amending the RTI Act, it essentially created a blanket ban on the disclosure of personal information, completely removing the "public interest" override.
"By elevating the statutory right to data protection to a level that eclipses the fundamental right to information, the legislature has created a paradox. How do you hold the state accountable when the state can simply invoke 'personal data' to draw the curtains?"
For litigators, the larger bench referral is a goldmine. We are about to witness the most significant testing of the boundaries of the K.S. Puttaswamy judgment since the Aadhaar verdict. But for corporate lawyers, this clash is secondary to the immediate operational realities.
The APAAR Ruling: Courts Are Already Enforcing DPDP Principles
If you think the courts are waiting for the 13 May 2027 full enforcement deadline to apply DPDP principles, look at the Supreme Court's recent stance on the APAAR (Automated Permanent Academic Account Registry) Scheme. The Court held that student information collection and sharing is strictly subject to the DPDP Act, 2023, and cannot be disclosed to private parties except in accordance with the law.
Crucially, the Court mandated that parental/guardian consent forms must include a clear, unambiguous option to withhold consent. The Court used specific phrasing: consent must be "meaningful and informed."
This is a direct judicial endorsement of Section 6 of the DPDP Act. It signals the death of the "take-it-or-leave-it" privacy policies that Indian tech platforms have relied on for a decade. If you are advising a tech client today, you need to audit their user interfaces immediately. If a user cannot easily opt-out or withdraw consent without losing access to the core non-data-reliant service, your client is looking at immediate regulatory exposure.
Section 8(5), AI, and the IP/Tech Overlap
The most dangerous blind spot for Indian tech companies right now is the intersection of generative AI and Section 8(5) of the DPDP Act, which mandates that Data Fiduciaries implement "reasonable security safeguards" to prevent personal data breaches.
As highlighted in recent legal commentary, employees feeding proprietary code, client databases, or customer workflows into third-party AI models isn't just an Intellectual Property leakage issue anymore—it is a statutory data breach under the DPDP Act. When tech law and IP silos operate independently, companies fail. Data governance, platform consent, and AI training are no longer separate regulatory buckets. An IP leak through an employee's unauthorized use of an AI tool now triggers mandatory reporting to the Data Protection Board of India.
The Practice Shift: Timelines and Takeaways
With the DPDP Rules notified on 13 November 2025, the runway is clearly marked. The Consent Manager framework becomes operational on 13 November 2026, and the broader compliance regime drops the hammer on 13 May 2027.
Yes, the Data Protection Board is currently functioning with significant appointment gaps, a practical reality that might slow initial enforcement. But relying on administrative bottlenecks is a terrible legal strategy.
What practicing lawyers need to do right now:
1. Stop drafting policies, start architecting flows: Moving forward, privacy compliance is an engineering problem, not just a legal one. Lawyers must sit with product teams to ensure "meaningful consent" is coded into the UI/UX.
2. Revise Employment Agreements: Insert specific clauses restricting the input of personal data (managed by the company as a fiduciary) into unauthorized AI models to mitigate Section 8(5) liabilities.
3. Prepare for the Consent Manager Era: By late 2026, data principals will manage their consents through centralized platforms. Fiduciaries must have the API infrastructure ready to honor withdrawal requests instantly.
The Supreme Court has spoken. The DPDP Act is live, it is evolving, and it is not waiting for anyone to catch up.
Tags
Published by AnrakLegal AI