Legal News
27 September 2026
IP & Technology

Weaponizing Privacy? The Supreme Court’s 5-Judge Bench Over RTI, and Why Your Client’s Consent Forms Are Already Illegal

As we barrel toward the substantive compliance deadline of the Digital Personal Data Protection (DPDP) Act in May 2027, the Indian tech-law landscape is in a state of preemptive chaos. For practicing lawyers and corporate counsel, the days of leisure...

As we barrel toward the substantive compliance deadline of the Digital Personal Data Protection (DPDP) Act in May 2027, the Indian tech-law landscape is in a state of preemptive chaos. For practicing lawyers and corporate counsel, the days of leisurely drafting boilerplate privacy policies are officially over. The Supreme Court of India is making it abundantly clear: the DPDP Act will not be allowed to act as a Trojan horse to dismantle constitutional transparency, nor will it tolerate the illusion of consent.

If you are advising fintechs, ed-tech platforms, or any data fiduciary, the developments of the past few months require an immediate audit of your client's data practices. Here is why the legal tectonic plates are shifting, and what you need to change in your practice today.

The Constitutional Showdown: RTI vs. Privacy

The most consequential legal battle of 2026 is arguably the Supreme Court’s decision to refer the challenges against the DPDP Act’s RTI-related amendments to a five-judge Constitution Bench. While the Court declined to stay the operation of the Act, the scrutiny on Section 44(3) of the DPDP Act is intense, and rightly so.

For context, Section 44(3) amends Section 8(1)(j) of the Right to Information (RTI) Act, 2005. Previously, personal information could be disclosed under the RTI Act if the Public Information Officer (PIO) determined that the larger public interest justified the disclosure. The DPDP Act obliterates this balancing test, creating a near-blanket exemption for personal information.

"By removing the public interest caveat, the State has effectively weaponized data privacy to shield itself from public scrutiny. It is a classic case of using a shield as a sword."

A separate Public Interest Litigation (PIL) filed this year seeks interim relief against the masking and deletion of already available public data. Why this matters for practice: If you are representing journalists, activists, or even corporate intelligence firms relying on RTI for due diligence, you must prepare for a severe dry spell in information access. PIOs are already using the DPDP Act as a convenient excuse to reject RTI applications en masse. Until the Constitution Bench rules on whether this amendment violates Article 19(1)(a) (Right to Freedom of Speech and Expression), practitioners must creatively leverage other exceptions in the RTI Act or challenge the PIO’s interpretation of what constitutes "personal data" in the first place.

The APAAR Ruling: "Take-It-Or-Leave-It" Consent is Dead

If your client’s user interface relies on forced consent, they are sitting on a regulatory landmine. On July 25, 2026, the Supreme Court directed the Centre and the CBSE to amend the APAAR (Automated Permanent Academic Account Registry) consent form. The directive was simple but devastating to standard industry practice: add an opt-out/refuse option and restrict third-party sharing of data.

This is a direct judicial enforcement of Section 6 of the DPDP Act, which mandates that consent must be free, specific, informed, unconditional, and unambiguous. For years, ed-tech platforms and consumer apps have relied on "consent fatigue"—forcing users to accept all terms to access a service. The Supreme Court has just signaled that "conditional consent" is legally invalid.

Practice pointer: You need to immediately review your clients' UX/UI flows. If a user cannot access the core service after refusing to share non-essential data (like location or third-party marketing access), your client is violating the law. Granular consent is no longer a best practice; it is a strict legal mandate.

The Consent Manager Conundrum and May 2027

With the DPDP framework moving into the Consent Manager registration phase by November 2026, we are seeing massive confusion regarding the overlap between the DPDP Rules, 2025, and the RBI’s existing Account Aggregator (AA) framework. Regulators are scrambling to integrate these infrastructures.

Simultaneously, law firms are reportedly billing thousands of hours redrafting cross-border data transfer agreements under Section 16 of the DPDP Act. Here is the blunt truth: the cross-border transfer rules aren't even live yet.

While Section 16 defaults to a "blacklisting" approach (meaning data can be transferred anywhere unless the government explicitly restricts a geography), the operative restrictions under Rule 15 remain ambiguous. General Counsel are jumping the gun out of fear of the May 2027 enforcement deadline.

What you should be doing instead:

Stop over-engineering cross-border contracts based on draft rules. Instead, focus your clients' budgets on internal data mapping and operationalizing the Consent Manager integration. The immediate enterprise risk for banks, fintechs, and GCCs (Global Capability Centres) isn't necessarily where the data is going, but whether they have a verifiable, immutable log of the user's consent to process it in the first place.

The Bottom Line

The staggering of the DPDP Act’s rollout has created a false sense of security. The Supreme Court's active intervention in the APAAR case and the RTI clash proves that the judiciary is not waiting for May 2027 to enforce the spirit of the data protection regime. Indian lawyers must shift from a mindset of "paper compliance" to "architectural compliance." If the privacy isn't built into the code and the user interface, no amount of clever legal drafting will save your client from the impending regulatory hammer.

Published by AnrakLegal AI