Legal News
4 October 2026
IP & Technology

Weaponising Privacy: How the DPDP Act is Killing the RTI While Corporate India Chases Ghosts

The Supreme Court Kicks the Can Down the Road On February 16, 2026, the Supreme Court referred the constitutional challenge against Section 44(3) of the Digital Personal Data Protection (DPDP) Act to a larger bench. While a referral signals the gravi...

The Supreme Court Kicks the Can Down the Road

On February 16, 2026, the Supreme Court referred the constitutional challenge against Section 44(3) of the Digital Personal Data Protection (DPDP) Act to a larger bench. While a referral signals the gravity of the issue—drawing the elusive line between "public data" and "personal data"—the Court’s refusal to stay the amendment pending final adjudication is a severe blow to India's transparency regime. For litigators and public law practitioners, the message is clear: the Right to Information (RTI) Act is currently operating with a massive, state-sanctioned blind spot.

Let’s be direct about what Section 44(3) of the DPDP Act actually does. It amends Section 8(1)(j) of the RTI Act, fundamentally altering the fabric of statutory transparency. The original RTI provision exempted personal information from disclosure unless a Public Information Officer (PIO) determined that a larger public interest justified it. Crucially, it contained a proviso: information which cannot be denied to the Parliament or a State Legislature shall not be denied to any person.

The DPDP Act surgically removed this proviso and the "public interest" test, creating a blanket exemption for anything classified as "personal data."

"By refusing to stay this amendment, the Supreme Court has allowed privacy to be weaponised as a shield for the State. Until the larger bench decides, PIOs have a statutory mandate to reject practically any RTI application that touches upon a public official's conduct, appointments, or assets, simply by labeling it 'personal data.'"

This is a classic misapplication of the Puttaswamy mandate. Privacy was enshrined as a fundamental right to protect the citizen from the State, not to protect the State from the citizen. As this sits in the larger bench's docket, writ courts across the country will grapple with PIO rejections, forcing lawyers to creatively argue that official acts in a public capacity cannot constitute "personal data" under Section 2(t) of the DPDP Act.

The Missing Watchdog and the Digi Yatra Fiasco

While the State uses the DPDP Act to block RTI queries, its own compliance with the Act remains shockingly hollow. This hypocrisy is currently playing out before the Kerala High Court in the ongoing Digi Yatra litigation.

The High Court has rightly sought the status of the Data Protection Board (DPB) while examining passenger data security concerns. We are in 2026. The DPDP Act was passed in 2023. Yet, institutional capacity and the independent functioning of the Board remain glaring question marks. How can the Ministry of Civil Aviation and private airport operators push a biometric facial recognition system like Digi Yatra when the very regulatory body meant to adjudicate data breaches is essentially a ghost ship?

Furthermore, the Kerala High Court’s prima facie view—that Aadhaar cannot be made mandatory for airport access if an alternative ID is available—reiterates the proportionality doctrine laid down in the original Aadhaar judgment. For technology lawyers advising state instrumentalities or private partners, the takeaway is absolute: mandatory biometric collection without giving the user a non-biometric, frictionless alternative is legally fatal. Consent cannot be engineered through coercion.

Corporate Compliance Theater: Stop Redrafting for Section 16

Moving from public law to corporate advisory, there is an epidemic of premature compliance sweeping through law firms and in-house teams. Several 2026 reports highlight that tech companies and Global Capability Centres (GCCs) are frantically redrafting cross-border data transfer agreements.

Here is the reality check: Section 16 of the DPDP Act and Rule 15 (governing cross-border transfers) are not yet live.

The Central Government has not yet published the "restricted country" list (the blacklist). Unlike the EU GDPR, which restricts transfers unless specific Standard Contractual Clauses (SCCs) or adequacy decisions are in place, the Indian framework allows free flow of data unless a country is explicitly blacklisted by MeitY. Redrafting vendor contracts with complex cross-border indemnities right now is billing for imaginary ghosts. It is regulatory arbitrage masquerading as legal prudence.

Instead of chasing phantom cross-border rules, corporate lawyers need to focus on what will actually hit their clients when the substantive obligations for data fiduciaries go live in May 2027:

  • Consent Architecture (Section 6): The era of the "checkbox" is over. The shift is from checkbox to control. If your client's UI/UX doesn't allow a user to withdraw consent as easily as they gave it, you are in breach.
  • Notice Requirements (Section 5): Itemised, multilingual notices are mandatory. Legacy data collected pre-DPDP requires fresh notice. Have you advised your clients on their legacy data mapping?
  • Account Aggregator Overlap: India’s privacy architecture is uniquely interacting with the RBI's Account Aggregator ecosystem. Consent Managers under the DPDP Act will need to interoperate with these existing financial data-sharing protocols.

The Bottom Line

As we navigate this phased rollout in 2026, the legal landscape is entirely skewed. The State has immediately enforced the provisions that benefit it (the RTI amendment) while delaying the substantive compliance burden (May 2027) and the enforcement machinery (the Data Protection Board).

Practicing lawyers must cut through the noise. Litigators need to prepare for a protracted constitutional battle over the RTI-DPDP overlap. Corporate counsels must stop panicking over un-notified cross-border rules and instead start the grueling, unglamorous work of internal data mapping and consent operationalisation. The law is only as good as its enforcement, and right now, India's privacy regime is a watchdog with a loud bark, no teeth, and a blindfold.

Published by AnrakLegal AI