August 2026: IJLT Tech-Law Bulletin

This month's bulletin focuses on the PILs Challenging Section 44(3) of the DPDPA in the Supreme Court, and the New Mexico’s First Judicial District Court ruling in the State of New Mexico v Meta Platforms Inc. It was authored by Samik Basu and Jai Kumar Bohara from the IJLT Editorial Board (2025-26).

IJLT Editorial Team

September 18, 2026 8 min read
Share:

Supreme Court hears PILs Challenging Section 44(3) of the DPDPA

On 7 August 2026, the Supreme Court of India heard a batch of Public Interest Litigations (‘PILs’) challenging Section 44(3) of the Digital Personal Data Protection Act, 2023 (‘DPDPA’) which amends Section 8(1)(j) of the Right to Information Act, 2005 (RTI Act’)

Prior to this amendment, Section 8(1)(j) of the RTI Act exempted the disclosure of personal information which (a) had no relationship to public interest or activity or (b) caused unwarranted invasion of privacy. This exemption was subject to important safeguards – it would not apply if the concerned Public Information Officer (‘PIO’) was satisfied that the larger public interest justifies its disclosure or if the information was such as which would not be denied to the Parliament or a State Legislature. The newly substituted clause, however, exempts “information which relates to personal information.” In doing so, it removes the balancing exercise and safeguards embedded in the pre-existing provision.

The primary constitutional challenge rests on the argument that Section 44(3) violates the fundamental right to information anchored in Article 19(1)(a). In Central Public Information Officer, Supreme Court of India v. Subhash Chandra Agarwal (2019), a five-judge Constitution Bench of the SC held that the right to information and the right to privacy are co-equal rights that must be harmonised through a structured proportionality balancing exercise. The SC emphasised that transparency regarding public duties cannot be compromised merely because personal data is incidentally involved.

Against this backdrop, the Petitioners argue that by eliminating the PIO’s mandate to balance competing rights, Section 44(3) fails the necessity and proportionality stricto sensu prongs of the test laid down in K.S. Puttaswamy v. Union of India (2017). They further contend that the breadth of the exemption unreasonably restricts Article 19(1)(a) and renders the provision manifestly arbitrary under Article 14. For instance, it has been argued by Senior Advocate Prashant Bhushan that information such as pending charge sheets against public officials, or details relating to welfare schemes and ration cards, could now be withheld on the ground that they constitute personal information. Similarly, an EPW editorial argues that under the new regime, RTI requests seeking details of individuals who have donated to electoral bonds, electoral rolls or public distribution system lists may now be denied on the grounds that it is personal information.

The challenge extends beyond Section 44(3). A separate writ petition filed by RTI activist Venkatesh Nayak challenges Sections 17(1)(c), 17(2), 33(1), 36 and 44(3) of the DPDPA alongside Rules 17 and 23(2) of the DPDP Rules, 2025 on grounds including Articles 14, 19(1)(a) and 21. Connected petitions have raised concerns relating to journalistic freedom, executive control over the Data Protection Board, governmental access to personal data and the absence of adequate safeguards against continued surveillance. While the arguments of the Petitioners are not yet available in the public domain, reports indicate that there may be another constitutional question warranting the application of the doctrine of harmonious construction because the two central legislations are seemingly in conflict with each other.

These concerns are not entirely new. Public and civil society opinion has been unequivocally against this amendment. The Internet Freedom Foundation has pointed out that the Justice A.P. Shah Committee (2012) explicitly cautioned against allowing data protection to override access rights under the RTI Act. Similarly, a 2018 joint statement by RTI and privacy activists responding to the Srikrishna Committee’s proposed amendments warned against using data protection to dilute the RTI framework. It argued that privacy legislation should complement rather than undermine citizens’ ability to obtain information necessary for accountability. Notably, Section 44(3) did not form a part of the 2019 version of the Personal Data Protection Bill nor did the Joint Parliamentary Committee which reviewed the said Bill made any recommendations of such nature.

The Supreme Court’s consideration of Section 44(3) therefore raises a broader question about how India’s emerging data-protection framework will coexist with its established transparency regime. RTIs remain a strong tool at the hands of the citizenry in their daily struggles, both inside and outside courtrooms, against the state. Any dilution of these rights must necessarily be viewed with caution.

New Mexico v Meta: Platform Design, Public Harm and the Limits of Judicial Regulation

On 6 August 2026, New Mexico’s First Judicial District Court held that Meta had created and substantially contributed to a public nuisance through harms to adolescent mental health and the sexual exploitation of children. It ordered a $567 million abatement fund and safeguards on Facebook and Instagram. The decision connects two concerns often considered separately: how platforms are designed to retain users, and who bears the consequences when that design contributes to harm. Its significance extends beyond the financial award.

The August ruling followed a March jury verdict imposing $375 million in civil penalties under New Mexico’s Unfair Practices Act for misleading consumers about platform safety. The awards serve different purposes. The penalties addressed unlawful representations and omissions; the abatement fund finances measures to address ongoing public harm. The Court found that engagement-maximising features encouraged problematic use and that recommendation systems facilitated connections between children and adult predators.

The nuisance finding matters because it recognises consequences beyond individual users. Meta argued that injuries associated with private platforms did not establish interference with a public right, but the Court emphasised disrupted classrooms, overstretched healthcare services and the demands of investigating online exploitation. These consequences affected shared institutions. Public nuisance law provided a basis for requiring collective remediation, rather than leaving families and public authorities to manage the resulting burdens. The company’s services were private; their effects were not confined to those services.

The reasoning also draws on established nuisance jurisprudence. The Court relied on California’s lead-paint litigation in People v ConAgra Grocery Products Company to support liability for a substantial contributor, even where other companies helped create the nuisance, and the use of a fund to prefund remediation. This applies familiar remedial principles to digital services. It also explains why Meta could be held responsible without being treated as the sole cause of New Mexico’s youth mental health crisis.

The decision fits a developing US distinction between liability for third-party speech and liability for platform design. In Lemmon v Snap, the Ninth Circuit allowed a negligent-design claim involving Snapchat’s Speed Filter and reward system to proceed despite Section 230 immunity. The alleged duty arose independently of publishing users’ content. New Mexico adopted comparable reasoning: the State challenged Meta’s own features and their consequences, so Section 230 did not bar the nuisance claim. That finding establishes a route to accountability, rather than a general withdrawal of platform immunity.

The distinction remains contested. In the Harvard Law Review Blog, Ryan Calo argues that courts should identify actionable platform misconduct without disregarding Congress’s protection for third-party content. New Mexico’s remedies illustrate the difficulty. Although the Court found that algorithms, autoplay and infinite scroll contributed to problematic use, it declined to order their redesign or removal, citing First Amendment, Section 230 concerns, and the competitive effects of restricting one company. Establishing liability did not give the Court unrestricted authority over platform design.

European regulation addresses similar risks through broader obligations. The Commission’s July 2025 guidelines on protecting minors under the Digital Services Act recommend private accounts, recommender-system safeguards and disabling features that encourage excessive use. They guide compliance assessment rather than creating a separate mandatory checklist. Australia has instead required covered platforms to take reasonable steps to prevent under-sixteens from holding accounts since December 2025. These approaches share concern about platform responsibility but differ on whether protection should primarily involve safer services or restricted access.

India is considering related interventions. IFF’s 6 August factsheet records proposals in Karnataka, Andhra Pradesh and Goa for age-based restrictions, while noting that none had enacted an operative restriction at that point. India also has relevant data-protection provisions: Section 9 of the DPDP Act prohibits processing likely to harm children’s well-being and restricts tracking, behavioural monitoring and targeted advertising, subject to specified exemptions. These obligations are being phased into operation. They address children’s data, rather than establishing a comprehensive framework for engagement-based platform design.

Indian commentary has recommended going further. Writing on Vidhi’s blog, Ishika Agarwal argues for safeguards addressing infinite scroll, autoplay and engagement-driven recommendations, rather than relying on bans or age verification. She identifies a gap between existing protections against particular harms and regulation of the systems shaping children’s behaviour. IFF similarly recommends safer design as the first response, including private accounts, restrictions on stranger contact and notification limits, alongside research and consultation involving children. These remain recommendations for a broader Indian framework. They closely resemble several measures ordered in New Mexico.

These concerns have also reached Indian courts. On 16 September 2026, the Delhi High Court asked the Centre whether it intended to regulate potentially addictive social-media features, while hearing a PIL filed by law professor Vikas Kathuria. The petition seeks an expert committee to examine features including infinite scroll and autoplay and recommend safeguards. Like the New Mexico proceedings, it directs attention to platform design and its consequences. The proceedings remain preliminary, however: the Court sought the government’s position without determining liability or ordering changes to these features. 

For users, the practical changes are substantial. The order restricts unconnected adults messaging minors, suppresses notifications during sleeping and school hours, hides like counts by default and caps combined Facebook and Instagram use at ninety hours monthly. It allocates $420 million to treatment, preserves access for qualified independent researchers and requires twice-yearly compliance reports. Their effectiveness will depend on implementation. This ruling demonstrates what funded remediation and enforceable safeguards can involve, while its limits show why proceedings against one company cannot substitute for broader regulatory choices.

A Defensible Result by an Indefensible Route: ANI v. OpenAI and the Limits of Fair Dealing (Part II) August 30, 2026