Legal News
5 October 2026
IP & Technology

The Transparency Paradox: Supreme Court Tests the RTI-DPDP Collision While India's Data Protection Board Remains a Ghost Town

The Collision of Privacy and Transparency When the Supreme Court of India recently noted that there are "some creases to be ironed out" regarding the interplay between the Right to Information (RTI) Act, 2005 and the Digital Personal Data Protection ...

The Collision of Privacy and Transparency

When the Supreme Court of India recently noted that there are

"some creases to be ironed out"
regarding the interplay between the Right to Information (RTI) Act, 2005 and the Digital Personal Data Protection (DPDP) Act, 2023, it was executing a judicial understatement of massive proportions. The apex court has now referred the constitutional challenge against the DPDP-linked amendments to the RTI Act to a larger bench, officially acknowledging the high-stakes friction between Article 19(1)(a) (the right to know) and Article 21 (the right to privacy).

For practicing advocates—whether you are litigating civil rights or advising tech conglomerates—this development is the epicenter of India’s evolving tech-law jurisprudence. The crux of the dispute lies in Section 44(3) of the DPDP Act, which surgically altered Section 8(1)(j) of the RTI Act. Previously, personal information could be disclosed under the RTI Act if the Public Information Officer (PIO) determined that the larger public interest justified the disclosure. The DPDP Act obliterated this public interest test, instituting a blanket exemption on the disclosure of any personal information.

We must call this what it is: a legislative overreach that weaponizes privacy to enforce state opacity. By refusing to grant an interim stay on this amendment while the matter remains sub judice, the Supreme Court has left this blanket exemption operative. For litigators, this means your pending RTI appeals before the Central Information Commission (CIC) involving any trace of "personal data" (even of public servants) are currently hitting a brick wall. The balance meticulously crafted in Justice K.S. Puttaswamy v. Union of India is being tested, and until the larger bench rules, transparency is effectively on life support.

The Sword of Damocles: A Sweeping Constitutional Challenge

The RTI amendment is just one front in a broader constitutional war. A separate, comprehensive batch of petitions filed by digital media groups, journalists, and civil society actors is currently challenging the DPDP Act in its entirety. The petitioners have trained their sights on the operational core of the Act—specifically Sections 5, 6, 8, 10, 17, 18, 19, 36, and 44(3)—arguing that they fall foul of Articles 14, 19, and 21.

Why does this matter for corporate counsel? Because the very provisions under constitutional fire are the ones you are currently drafting compliance frameworks for. Section 5 and 6 govern notice and consent. Section 8 dictates the overarching obligations of Data Fiduciaries. Section 17 grants sweeping exemptions to the State. If the Supreme Court reads down or strikes down any of these provisions, the multimillion-dollar compliance architectures being built by Global Capability Centres (GCCs) and domestic tech giants will have to be dismantled and rebuilt.

The Administrative Farce: Compliance Without a Regulator

Here is where the situation shifts from legally complex to administratively absurd. As of August 2026, the Data Protection Board of India (DPBI)—the primary adjudicatory and enforcement body under the DPDP Act—remains a ghost town. It has no appointed Chairperson and no Members.

Yet, the regulatory clock is ticking loudly. Industry commentary indicates that the registration for Consent Managers is slated for mid-November 2026, with the substantive operational duties for Data Fiduciaries going live on 13 May 2027.

How exactly does the Ministry of Electronics and Information Technology (MeitY) expect Data Fiduciaries to operationalize Consent Managers without a functioning Board to oversee their registration? For tech lawyers, advising clients in this vacuum is a nightmare. You are forced to draft Data Processing Agreements (DPAs) and cross-border data transfer protocols based on the DPDP Rules, 2025, knowing fully well that the rulebook is untested, the regulator is missing, and cross-border transfer rules are not even fully live yet.

Practice Notes: Navigating the Limbo

Despite the constitutional challenges and the missing Board, lawyers cannot advise their clients to hit pause. Here is how you need to pivot your practice immediately:

  • Education & Ed-Tech Compliance: The Supreme Court has unequivocally clarified that the handling of student data under the APAAR Scheme is strictly subject to the DPDP Act. If you represent private ed-tech entities or private schools, ensure that your data-sharing agreements are airtight. Student information cannot be shared with third parties absent explicit, verifiable consent, barring strict legal mandates.
  • Contract Redrafting: Do not wait for the DPBI to be constituted. Proceed with updating your vendor agreements, privacy policies, and DPAs to align with the May 2027 deadline. Structure these contracts with severability clauses that anticipate potential Supreme Court modifications to Sections 5, 6, and 8.
  • RTI Strategy: If you are filing RTIs, meticulously frame your queries to avoid asking for "personal information" as defined under the DPDP Act. Focus strictly on institutional processes, financial outlays, and policy documents to bypass the Section 8(1)(j) roadblock.

India’s data protection regime is currently caught in a paradoxical loop: demanding rigorous corporate compliance while offering zero regulatory infrastructure, all while the Supreme Court debates whether the law itself is fundamentally unconstitutional. For the Indian tech lawyer, 2026 is not the year of implementation; it is the year of drafting in the dark.

Published by AnrakLegal AI