All articles
News & Analysis 7 min read 27 September 2026 Primitra

The DPDP Act Supreme Court Challenge: Why Indian SMEs Shouldn't Pause Compliance

A Constitution Bench will decide challenges to the DPDP Act's RTI amendment, but there is no stay. Here is what the case covers, where it stands in September 2026, and why your May 2027 deadline has not moved.

If you run a startup or a growing business in India, you may have seen headlines this year about a Supreme Court challenge to the DPDP Act. Some founders have taken them as a reason to pause: if the law might be struck down, why spend on compliance now? So here is what the DPDP Act Supreme Court challenge covers, where it stands in September 2026, and what it does and does not change for a private company.

What the DPDP Act Supreme Court challenge is about

Three writ petitions are pending before the Supreme Court: Venkatesh Nayak v. Union of India (W.P.(C) No. 177/2026), The Reporters Collective Trust & Anr. v. Union of India (W.P.(C) No. 211/2026) and National Campaign for People's Right to Information v. Union of India (W.P.(C) No. 212/2026).

The main target is Section 44(3) of the Digital Personal Data Protection Act, 2023. That section rewrote Section 8(1)(j) of the Right to Information Act, 2005. The old RTI provision let public authorities withhold personal information only where it had no link to public activity or would cause an unwarranted invasion of privacy, and it allowed disclosure where the larger public interest justified it. The amended version drops that public-interest override and exempts personal information far more broadly. The petitioners, who include RTI activists and a journalists' collective, say this guts transparency. They also argue the Act fails to give any exemption for processing personal data for journalistic purposes.

Where the case stands in September 2026

Here is the timeline, drawn from reporting by Business Standard, LiveLaw and the Internet Freedom Foundation:

  • 16 February 2026: A bench led by Chief Justice Surya Kant issued notice and referred the core questions to a five-judge Constitution Bench, calling them complex and constitutionally sensitive. The Court declined to grant an interim stay.
  • 7 August 2026: The Court gave the Centre two weeks to file its reply. The bench noted that the DPDP Act and the RTI Act are both central laws and need to be harmonised.

There has been no stay. The DPDP Act and the DPDP Rules, 2025 (notified on 13 November 2025) continue to operate exactly as notified while the case runs. Nobody can predict when the Constitution Bench will rule, or how.

What the challenge does not touch

This is the part most business owners miss. The litigation is about how the DPDP Act affects citizens' access to information held by public authorities under RTI, and about journalism. It is not an attack on the everyday obligations that apply to a D2C brand, a SaaS company, a clinic chain or a fintech.

Nothing in the petitions, as reported, asks the Court to remove:

  • your duty to give a clear notice and take valid consent before processing personal data;
  • data-principal rights such as access, correction, erasure and grievance redressal;
  • reasonable security safeguards and personal data breach reporting to the Data Protection Board and affected individuals;
  • retention limits and the duty to erase data once the purpose is served;
  • the extra duties that fall on Significant Data Fiduciaries.

Even in the unlikely event that Section 44(3) were struck down, the likely result would be the old RTI wording coming back. Your consent flows, vendor contracts and breach plan would still be needed.

The deadlines have not moved

The DPDP Rules are phased. The Data Protection Board was set up in the first phase. The Consent Manager registration framework becomes operational around 13 November 2026. The core substantive obligations (notice, consent, data-principal rights, breach notification, and Significant Data Fiduciary duties) take full effect around 13 May 2027, about seven and a half months from today.

The penalties are also unchanged. The Schedule to the Act allows the Board to impose up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to notify the Board and affected individuals of a breach. Under the Rules, a detailed breach report is expected within 72 hours of becoming aware of it.

Seven months sounds like plenty. In practice, an SME that has not yet mapped its data will spend six to eight weeks just finding out where personal data sits: in the CRM, in WhatsApp groups, in old Google Sheets, with a payroll vendor. Then come the notice rewrite, the consent changes in the app or website, the vendor contract updates and staff training.

Who should watch the case closely

A few types of business do have a real stake in the outcome:

Media, publishing and news-tech startups. If the Court reads in, or pushes Parliament toward, a journalistic exemption, your consent obligations for reporting could change. Until then, assume the Act applies in full and document why each piece of personal data is processed.

Companies that deal heavily with public authorities. Government contractors, CSR-heavy organisations and firms that use RTI for due diligence may find what they can obtain under RTI shifts depending on the ruling.

For everyone else, the case is worth following but it is not a planning variable.

A practical plan for the next 90 days

If you have been waiting on the Court, here is a sensible way to restart without overspending:

  1. Map your data. List every place you collect personal data, why, who can access it and which vendors touch it. Our DPDP compliance checklist is a free starting point.
  2. Rewrite your notice. Plain language, itemised purposes, and a clear way to withdraw consent. Older boilerplate policies rarely pass.
  3. Fix your breach playbook. Name who decides, who drafts the notice to the Board and to affected people, and how you will hit 72 hours for the detailed report.
  4. Update vendor contracts. Your processors need written obligations on security, deletion and breach reporting.
  5. Run a privacy impact assessment on any high-risk processing, such as health data, children's data or AI-driven profiling. See our privacy impact assessment service if you want help.

None of these steps depend on how the Constitution Bench rules on RTI. All of them lower your risk from May 2027 onward. For a fuller picture of what the law demands, our DPDP Act compliance guide walks through each obligation.

The bottom line

The DPDP Act Supreme Court challenge is a serious constitutional case about transparency and press freedom, and it deserves attention. For most Indian SMEs and startups it changes nothing about what must be ready by 13 May 2027. There is no stay, the Rules are in force as notified, and "we were waiting for the Supreme Court" is unlikely to count for much with the Board.

This article is general guidance based on public reporting as of 27 September 2026 and is not legal advice. For advice on your specific situation, consult a qualified professional.

Want to know where you stand? Start with our free DPDP readiness checklist, or talk to our team about a scoped compliance plan.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation