Mid-week update — events through 13 May 2026. W20 (11–17 May 2026) is defined by three convergent events: the Supreme Court's Constitution Bench holds its first substantive listing in the DPDP Act constitutional challenge (Section 44(3) vs. RTI) on 13 May — the most consequential data-protection hearing in 2026 to date; CERT-In has formally institutionalised its post-Operation Sindoor cyber-defence posture through a series of DDoS-protection advisories, new space-sector cybersecurity guidelines co-released with SIA-India, and the SAMVAAD 2026 audit conference; and the Reserve Bank of India and the European Central Bank signed a revised bilateral MoU on 10 May 2026 in Basel, creating an ESMA recognition pathway for Indian clearing corporations and laying the technical groundwork for UPI–eurozone remittance interlinking.
Partial-week caveat (as of 13 May 2026, today): Events from 14–17 May — including post-hearing orders from the DPDP Constitution Bench, any TRAI V2X-related submissions activity, and MeitY's TPEC next working session — will be the anchor items in the W21 tracker.
Top 3 Developments This Week
1. Supreme Court DPDP–RTI Constitution Bench — 13 May First Substantive Hearing
What changed: The Supreme Court of India's larger bench — presided over by Chief Justice Surya Kant with Justices Joymalya Bagchi and Vipul M. Pancholi — is today (13 May 2026) conducting its first substantive hearing in the consolidated challenge to the Digital Personal Data Protection Act, 2023 ('DPDP Act'). The lead matter, The Reporters Collective Trust v. Union of India (W.P.(C) 211/2026), is listed alongside four connected petitions filed by Mazdoor Kisan Shakti Sangathan (MKSS) and its founders Aruna Roy, Nikhil Dey, and Shankar Singh; Venkatesh Nayak (NCPRI); and others.
Issuer and date: Supreme Court of India; matter referred to larger bench on 16 February 2026; Government counter-affidavit filed by 23 March 2026; first substantive larger-bench hearing today, 13 May 2026.
Why it matters: The central constitutional question is whether Section 44(3) of the DPDP Act — which substitutes Section 8(1)(j) of the Right to Information Act, 2005 ('RTI Act') with a broader, blanket privacy exemption — is constitutionally permissible. The original Section 8(1)(j) RTI Act contained a public-interest balancing test for personal information; Section 44(3) DPDP Act removes that test, potentially enabling the government and public bodies to refuse RTI disclosure of any personal information without a public-interest override. Petitioners argue this violates Articles 14 (equality), 19(1)(a) (freedom of speech and expression), and 21 (right to life and dignity) read through the K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 proportionality framework. The Government has not sought a stay of RTI applications pending the outcome but will defend the DPDP Act's design as a constitutionally sound balancing of the right to privacy (Article 21) against other rights. For data-protection officers, compliance lawyers, and newsroom legal teams, today's hearing will signal whether the Constitution Bench is inclined toward issuing any proportionality directions on the new Section 8(1)(j) while the case proceeds — or whether full arguments are deferred to a future date. The DPDP Board has not yet been constituted (Section 18 not notified), and the Foundation of Data Protection Professionals in India (FDPPI) has filed an intervention application (IA No. 85635/2026) to place practitioners' perspectives before the Court.
Link: Supreme Court — Latest Orders.
Score: 14/15 (legal significance 5, practical impact 5, novelty 4 — first DPDP Constitution Bench listing).
2. CERT-In Post-Operation Sindoor Institutional Cyber-Defence Response
What changed: CERT-In has progressively institutionalised its cybersecurity response following the unprecedented cyber-warfare dimension of Operation Sindoor (7–10 May 2025). As of mid-May 2026, three concrete outputs define this institutional posture. First, CERT-In issued an urgent advisory on DDoS-protection for critical infrastructure — directed specifically at sectors targeted during Operation Sindoor: financial institutions (Income Tax Department, BSNL, banking portals), power infrastructure (Power Grid Corporation), and defence-adjacent government systems. Maharashtra Cyber's 'Road of Sindoor' report confirmed 1.5 million cyberattack attempts during Operation Sindoor, of which approximately 150 breached Indian digital infrastructure. Second, at the DefSat Conference & Expo 2026 (held in New Delhi in May 2026), CERT-In and the Satcom Industry Association of India (SIA-India) jointly released comprehensive space-sector cybersecurity guidelines — the first framework specifically addressing satellite communication system resilience. Third, CERT-In's SAMVAAD 2026 conference (held at BITS Pilani Goa Campus, May 2026) launched AMBAK, a blockchain-enabled cybersecurity audit platform, and a new certification course developed with NABARD and BIRD. On the vulnerability-notes front, CERT-In published CIVN-2026-0217 through CIVN-2026-0222 in the 7–8 May window, covering Microsoft ASP.NET Core (privilege escalation), Windows Shell spoofing, Android OS remote code execution, Cisco IoT Field Network Director, Apache HTTP Server, and Notepad++.
Issuer and date: Indian Computer Emergency Response Team (CERT-In) under Ministry of Electronics and Information Technology; post-Operation Sindoor advisory series continuing into W20; space-sector guidelines released at DefSat 2026 (May 2026); CIVN-2026-0219 through 0222 issued 7–8 May 2026.
Why it matters: The institutionalisation of Operation Sindoor's cyber-lessons has two direct compliance triggers. First, CERT-In's DDoS-protection advisory carries the same mandatory compliance weight as all CERT-In advisories under Section 70B(6) of the Information Technology Act, 2000 ('IT Act') — organisations in critical infrastructure sectors (as listed in the IT (Critical Information Infrastructure Protection) Rules, 2013) that experience a DDoS incident must file a six-hour incident report with CERT-In under Direction (ii) of the CERT-In Directions dated 28 April 2022 ('CERT-In Directions 2022'). Second, the space-sector guidelines create a new compliance reference for satellite operators, ground station operators, and ADAS/V2X infrastructure providers — a sector that intersects directly with TRAI's ongoing V2X consultation (comments due 28 May 2026). Organisations that relied on the defence-sector's operational silence around Operation Sindoor to defer their cyber-upgrade roadmaps should reconsider that posture: CERT-In's institutional escalation signals that the wartime experience is being codified into permanent compliance expectations.
Link: CERT-In official website | DD News — CERT-In, SIA-India space guidelines.
Score: 13/15 (legal significance 4, practical impact 5, novelty 4 — wartime cyber response institutionalised as compliance framework for first time).
3. RBI–ECB MoU Signed 10 May 2026 in Basel — ESMA Recognition and UPI–Eurozone Interlinking
What changed: On 10 May 2026, on the sidelines of the Bank for International Settlements (BIS) meetings in Basel, RBI Governor Sanjay Malhotra and ECB President Christine Lagarde signed a revised Memorandum of Understanding on cooperation in central banking. The 2026 MoU replaces the bilateral cooperation framework established in 2015 and introduces two new structural provisions: (a) a formal pathway for ESMA (European Securities and Markets Authority) recognition of Indian clearing corporations, particularly the Clearing Corporation of India Limited (CCIL); and (b) a policy architecture for interlinking India's Unified Payments Interface (UPI) with eurozone fast payment systems to facilitate cross-border remittances.
Issuer and date: Reserve Bank of India and European Central Bank; MoU signed 10 May 2026 in Basel on the sidelines of BIS meetings. Contemporaneous with RBI's gazette notification of the Foreign Exchange Management (Authorised Persons) Regulations, 2026.
Why it matters: The ESMA-recognition pathway is the most immediately operational provision. Indian clearing corporations — particularly CCIL, which serves as the central counterparty for government securities, money market, and forex transactions — have previously faced friction in facilitating cross-border transactions involving European counterparties because ESMA recognition requires bilateral regulatory information-sharing commitments that the 2015 MoU did not fully cover. The 2026 MoU creates the supervisory cooperation framework that ESMA's recognition process requires. For capital-market intermediaries, foreign portfolio investors, and custodians active in Indian government securities markets, this materially reduces settlement and counterparty risk in cross-border transactions. The UPI–eurozone interlinking roadmap is structural rather than operational: it provides the regulatory basis for technical working groups to design interoperability between UPI's NPCI-run rails and the euro area's fast payment systems (particularly the Eurosystem's TIPS infrastructure). India is currently a top-ten recipient of euro area remittances — the Central Bank data supporting this finding makes the interlinking commercially significant for the diaspora-remittance corridor. The concurrent notification of the Foreign Exchange Management (Authorised Persons) Regulations, 2026 (PRID 62691) signals that RBI is updating its authorised-dealer and money-changer regulatory framework alongside the MoU — watch for implementing circulars on authorised dealer category compliance.
Link: ECB Press Release — RBI–ECB MoU | RBI Press Releases.
Score: 11/15 (legal significance 4, practical impact 4, novelty 3 — expands existing cooperation, new ESMA + UPI provisions).
Regulatory Action Log
| Date | Regulator | Pillar | Action | Source |
|---|---|---|---|---|
| 2026-05-13 (today) | Supreme Court of India | data-protection | First substantive hearing in DPDP–RTI Constitution Bench (Section 44(3) challenge); five petitions including MKSS, Reporters Collective, NCPRI; no interim stay in force; FDPPI intervention IA 85635/2026 also listed | sci.gov.in |
| 2026-05-10 | RBI / ECB | fintech-payments | RBI–ECB revised MoU signed in Basel; ESMA recognition pathway for CCIL; UPI–eurozone interlinking architecture; concurrent FEMA (Authorised Persons) Regulations 2026 notified | ecb.europa.eu |
| 2026-05-08 | Gujarat HC | platforms-intermediaries | SAHYOG counter-affidavit hearing in C/WPPIL/9/2026: Meta, Google, X, Reddit, Scribd filed counter-affidavits; X's 14% formal-response rate (13 of 94 intimations) on record; next date expected June 2026 | gujarathighcourt.nic.in |
| 2026-05-07 to 08 | CERT-In | cybersecurity | Vulnerability Notes CIVN-2026-0217 through 0222 published: Microsoft ASP.NET Core (privilege escalation), Windows Shell spoofing (CIVN-0218), Android OS RCE (CIVN-0219), Cisco IoT Field Network Director (CIVN-0220), Apache HTTP Server (CIVN-0221), Notepad++ (CIVN-0222) | cert-in.org.in |
| 2026-05-05 | SEBI | cybersecurity | AI cybersecurity advisory circular: all SEBI regulated entities directed to adopt AI-augmented SOC monitoring, implement Zero Trust Network Access, reinforce API security, and participate in cyber-suraksha.ai task force; no grace period stated | sebi.gov.in |
| 2026-04-30 | Delhi HC | ai-governance | Order in Akasa Air appeal (Justice Pratibha Singh and Justice Madhu Jain): ₹1.08 crore decree stayed; prima facie impression of AI-generated content in District Court judgment; non-existent provisions + misattributed SC precedents noted; referred for inquiry | delhihighcourt.nic.in |
| 2026-04-30 to May 13 | MeitY / TPEC | ai-governance | TPEC second working fortnight; Secretary MeitY chairs; no public consultation published; first deliverable (AI governance gap analysis) expected mid-2027; constituent members include IIT Madras (Prof. B. Ravindran), IIT Gandhinagar (Prof. Rajat Moona), Nasscom, DSCI, MAIT | pib.gov.in PRID 2252739 |
| 2026-05-12 | RBI | fintech-payments | RBI issues Amendment Directions on CET1 capital computation — quarterly profits inclusion review (PRID 62705); Prudential Norms on Specified Non-financial Assets (SNFA) Directions issued (PRID 62686); Mission SAKSHAM launched for Urban Co-operative Banking capacity building (PRID 62639) | website.rbi.org.in |
What's Next
- 2026-05-13 (today) — DPDP Constitution Bench hearing: watch for any directions from the Chief Justice's bench on the Government's counter-affidavit, proportionality arguments, and whether the FDPPI intervention (IA 85635/2026) is admitted. Any interim direction on Section 44(3) implementation pending final hearing would be significant.
- 2026-05-13 — DPDP Rules 2025 six-month marker: monitor egazette.gov.in for any Phase 2 sub-rule activation notification from MeitY, particularly on Rule 4 Consent Manager obligations and DPDP Board constitution under Section 18.
- 2026-05-28 — TRAI V2X consultation deadline: written comments due to Advisor (Networks, Spectrum and Licensing), TRAI, at advmn@trai.gov.in. The spectrum-band question (5.9 GHz dedicated ITS vs. C-V2X on cellular) and licensing model (Unified Licence variant vs. new class) are the pivotal issues. V2X data handling has an unresolved DPDP Act intersection — TRAI's framework is silent on personal data generated by V2X vehicle-communication systems; practitioners advising automotive clients should address this in their submissions.
- 2026-06-11 — TRAI V2X counter-comments deadline.
- 2026-06-01 (expected) — DoT sub-rule notifications under Chapter IV of the Telecommunications Act, 2023; monitor dot.gov.in for authorisation and spectrum sub-rules.
- 2026-06-30 (watch) — SEBI CSCRF Phase-3 reporting: Mutual Funds and AMC compliance reporting window; entities should complete third-party vendor assessments against the cyber-suraksha.ai task force framework by this date.
- 2026-07-31 (approx.) — OGAI 90-day determination window closes for gaming platforms that filed on 1 May 2026; operators awaiting determination must suspend money-game operations until a determination is received.
- 2026-11-13 — DPDP Rules 2025 Rule 4 trigger: Consent Manager registration and obligations come into force (12 months from gazette notification).
Founder Action Items
- Review your DPDP-RTI intersection posture — if your organisation holds personal data of individuals who might make RTI requests (e.g., data of government employees, public servants, or anyone engaged in a publicly-funded activity), brief your legal and compliance team on the Section 44(3) constitutional challenge before today's Supreme Court hearing produces an order. If the Constitution Bench issues any interim proportionality direction, your RTI response protocol may need immediate updating. Follow sci.gov.in for today's order upload.
- DDoS resilience audit — now mandatory, not discretionary — CERT-In's post-Operation Sindoor advisory framework effectively elevates DDoS-protection from a best-practice to a compliance expectation for all organisations designated as critical information infrastructure and for financial-sector entities. If your organisation has not completed: (i) firewall and server vulnerability audit; (ii) deployment of real-time DDoS anomaly detection; and (iii) a documented 24x7 incident response plan — prioritise these ahead of any SOC expansion initiative.
- SEBI regulated entities: AI-augmented SOC is now a regulatory expectation — the SEBI circular of 5 May 2026 on AI-driven cybersecurity risks (circular series HO/ITD-1) directs all regulated entities — from stock brokers to mutual funds to research analysts — to begin adopting AI-augmented monitoring. The circular is advisory in tone but compliance with CSCRF (the 20 August 2024 framework) is mandatory and auditable. Entities that have not completed CSCRF Phase-2 controls should use the cyber-suraksha.ai task force's output (when published) as a roadmap for AI-augmented controls in Phase-3.
- FEMA update — verify your authorised dealer / money changer classification — the Foreign Exchange Management (Authorised Persons) Regulations, 2026 (issued concurrently with the RBI–ECB MoU) update the authorised dealer and money-changer regulatory framework under the Foreign Exchange Management Act, 1999. Any fintech or payment platform that operates as an authorised dealer category-II or money changer should confirm classification, authorisation limits, and compliance with the new regulations before implementing any cross-border UPI payment product.
- V2X-DPDP compliance gap is emerging now — if your product roadmap includes connected-vehicle features, ADAS systems, or smart-road infrastructure for the Indian market, the TRAI V2X consultation (comments by 28 May) is the only current formal channel to address the data-handling silence in TRAI's draft framework. V2X systems collect location, speed, braking pattern, and route data — all personal data under the DPDP Act, 2023 — and the consultation paper does not address consent, purpose limitation, or breach reporting for this data category. File a submission.
Practitioner Watch-list
- DPDP Constitution Bench — strategic litigation pipeline: the five consolidated petitions collectively raise four distinct constitutional grounds (manifestly arbitrary in Section 44(3), Data Protection Board institutional independence, Section 36 government information-call-up power under Rule 23, and absence of a journalistic/public-interest data-processing exemption). Practitioners should map their client's position on each ground separately. The absence of an interim stay means Section 44(3) DPDP Act is operative today — RTI appellate tribunals are applying the new Section 8(1)(j) standard; advise clients accordingly while the Constitution Bench matter proceeds.
- CERT-In Directions 2022 — six-hour report for DDoS as a reportable incident: a DDoS attack that results in "unavailability of a service" is a reportable incident type under Direction (ii) of the CERT-In Directions, 28 April 2022. The post-Operation Sindoor advisory has placed DDoS on the front of CERT-In's enforcement radar — a first formal regulatory examination of DDoS reporting compliance could follow in H2 2026. Verify that clients' incident-response runbooks include the six-hour window and the mandatory upload to the CERT-In reporting portal (https://incident.cert-in.org.in/).
- SAHYOG June hearing — safe harbour risk assessment for non-major intermediaries: the Gujarat HC SAHYOG matter (C/WPPIL/9/2026) is expected to list again in June 2026. While the five named intermediaries (Meta, Google, X, Reddit, Scribd) are the respondents, the Court's eventual order on SAHYOG integration standards will set a compliance benchmark for all Significant Social Media Intermediaries (SSMIs) — defined as platforms with over 50 lakh Indian monthly active users under Rule 2(1)(v) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Audit SAHYOG technical integration status now, not after the order.
- Delhi HC AI-generated judgment inquiry — judicial integrity risk: the Akasa Air matter (order of 30 April 2026) creates a precedent for appellate courts to flag AI-generated content in subordinate-court judgments using AI-detection tools. Practitioners should audit their own drafting practice — particularly for grounds of appeal, submissions, and research memos produced with AI assistance — and ensure all AI-generated content is independently verified against the actual statutory text and case reports before filing. The Court's specific concern was non-existent statutory provisions and misattributed Supreme Court propositions: both of which are hallucination patterns documented in commercial LLMs. A single instance of filing AI-hallucinated precedent in a court proceeding carries the risk of professional misconduct under the Advocates Act, 1961.
- RBI CET1 directions (PRID 62705) and SNFA directions (PRID 62686) — issued by RBI in the week of 11–13 May 2026, these are banking-regulation instruments with direct implications for fintech lenders operating as NBFCs or through lending partnerships with banks. Legal teams at fintech companies should read the CET1 quarterly-profits-inclusion amendment and the SNFA directions alongside the RBI's November 2025 consolidated master-direction framework to confirm capital-treatment and asset-classification compliance.
FAQ
What is the immediate compliance impact of the DPDP Act Section 44(3) constitutional challenge being before the Supreme Court today?
Section 44(3) of the Digital Personal Data Protection Act, 2023 ('DPDP Act') is in force and operative. The Supreme Court declined to grant an interim stay at the February 2026 hearing, meaning the substituted Section 8(1)(j) of the Right to Information Act, 2005 ('RTI Act') — which removes the earlier public-interest balancing test for personal information — applies to all current RTI requests and appeals. Data fiduciaries, government bodies, and public servants who are RTI respondents must apply the current (post-Section 44(3)) standard when deciding whether to disclose personal information. If the Constitution Bench eventually strikes down or modifies Section 44(3), a corrective remedy will issue prospectively — but in-flight RTI decisions made under the current standard may need review. Practitioners advising public bodies or large data fiduciaries should document the legal basis for every RTI refusal made on personal-information grounds while the constitutional challenge is pending.
Does the SEBI AI cybersecurity circular of May 5, 2026 create new binding compliance obligations beyond CSCRF?
The May 5 SEBI circular on AI-driven cybersecurity risks (circular series HO/ITD-1) is an advisory within the CSCRF framework established under the 20 August 2024 circular. It does not create new regulatory instruments outside CSCRF — rather, it clarifies that AI-augmented monitoring, Zero Trust Network Access, and vendor oversight of third-party application service providers are expected CSCRF compliance measures. Non-compliance with CSCRF Phase-2 and Phase-3 controls (the mandatory framework) can attract regulatory scrutiny, enforcement proceedings, and reputational risk. The cyber-suraksha.ai task force's future output may produce additional technical specifications that become annexures to or amendments of the CSCRF. Regulated entities should treat the advisory as a forward signal and begin architecture assessments for AI-augmented SOC capabilities before the task force's first report.
What practical steps should legal and compliance teams take in response to the Delhi HC's concerns about AI-generated content in court judgments?
The Delhi High Court's 30 April 2026 order in the Akasa Air matter flagged two hallucination patterns in the impugned District Court judgment: (i) references to non-existent statutory provisions and (ii) legal propositions attributed to Supreme Court decisions that those decisions do not actually state. These are known failure modes of large language models in legal drafting. Practitioners should immediately implement a three-step verification protocol: (a) for any AI-assisted research output, independently verify every statutory citation against the actual gazette text or an authoritative consolidated act (indiacode.nic.in or the local BareActs corpus); (b) for any case-law proposition, verify the attribution against the full judgment text on sci.gov.in or the relevant High Court portal before relying on it; and (c) before filing in any court, run the document against Section 70B of the IT Act 2000's professional-liability framework and applicable Bar Council of India Rules on professional conduct — a filing based on AI-hallucinated authority may constitute professional misconduct. The Court's observation stops short of a conclusive finding in the Akasa Air matter, but the language ("prima facie impression", "would be a matter of serious concern") signals that further instances will invite stronger judicial response.
Source policy: This tracker cites only Tier 1 sources — government ministries, regulators, the official gazette, court portals, and official central bank communications. Discovery-only sources are not cited.
Next edition: W20 supplement or W21 tracker covering the DPDP Constitution Bench order (post-13 May), Gujarat HC SAHYOG next date, and any TRAI V2X submission activity — scheduled for publication Sunday 17 May 2026 (22:00 IST).