NEWS ANALYSIS4 min read

Supreme Court Hears Constitutional Challenge to DPDP Act 2023 Exemptions

A Supreme Court petition challenges the constitutionality of DPDP Act exemptions and Board independence, raising critical questions for BFSI compliance leaders managing government data requests under Rule 23(2).

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

Petitioners have challenged the constitutionality of specific sections of the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025, before the Supreme Court of India, according to the Supreme Court Observer. The petition argues that executive dominance in the Data Protection Board of India selection committee, defined under Section 18 of the Act and Rules 17(1) and 17(2), violates the separation of powers. Furthermore, the challenge targets broad government exemptions for data collection and processing. Petitioners claim these provisions grant the Union government excessive authority without sufficient statutory guidance.

Does The DPDP Act Apply Here

Section 3 of the Act mandates that it applies to the processing of digital personal data within India, and to processing outside India if connected to offering goods or services to Data Principals in India. This constitutional challenge directly impacts how the state interacts with the Act, but it does not diminish the compliance burden for private sector Data Fiduciaries. Banks, NBFCs, and insurers must continue to build compliance frameworks for their customer and employee data. The exemptions contested under Section 17 primarily affect law enforcement and state security agencies, leaving commercial processing obligations fully intact.

Legal Implications Under DPDP

Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. However, Section 36 permits the Central Government to demand information from a Data Fiduciary for specific lawful purposes. The petition contests this section, alongside Rule 23(2) of the DPDP Rules, 2025, which explicitly prohibits fiduciaries from disclosing to Data Principals that their information was shared with the government. For a Chief Compliance Officer, this creates a complex intersection of transparency rights and strict confidentiality mandates. The challenge to the regulatory enforcement structure under Section 18 also introduces uncertainty regarding how the Data Protection Board of India will handle future adjudications.

Could This Happen To You

Large BFSI enterprises frequently receive data requests from law enforcement and regulatory bodies. If a government agency demands customer records under Section 36, your systems must process this extraction without triggering automated privacy notices to the affected customer. Furthermore, any internal leak during this manual extraction triggers a separate crisis, requiring intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours, per the Rules, 2025. In the event of an audit, the Board would demand a precise evidence pack detailing exactly what data was extracted, who authorized it, and how the gag order was enforced. Relying on legacy GRC tools or manual workflows to isolate these requests exposes the firm to severe compliance failures and immediate board-level scrutiny.

What Companies Should Do In The Next 30 Days

1. Map existing law enforcement workflows. The Chief Compliance Officer must document exactly how data is currently extracted and shared with state agencies across all legacy systems to ensure control owners are clearly identified.

2. Isolate transparency notices. The IT and Legal teams must configure customer portals and automated communication channels with a bypass mechanism to guarantee compliance with Rule 23(2) gag orders during government data demands.

3. Establish a secure audit trail. Implement a centralized logging system to record the receipt, evaluation, and fulfillment of government data requests, ensuring access is strictly limited to authorized personnel.

4. Brief the board on regulatory continuity. Prepare an evidence pack confirming that the firm will maintain compliance readiness regarding consent records and breach response workflows regardless of the Supreme Court ruling on the independence of the regulatory body.

What To Watch

Monitor the Supreme Court proceedings for any interim orders that might modify the application of Section 36 or Rule 23(2) of the DPDP Rules, 2025. Pay close attention to the formal notification of the Data Protection Board of India and whether the government alters the search cum selection committee structure in response to the petition. Organizations must maintain their implementation velocity, as exactly 273 days remain until the DPDP hard compliance deadline of 13 May 2027. To evaluate if your current workflows can handle complex government requests and audit trails, assess your exposure at freescan.complydp.com.

Sources

Frequently asked questions

Does the Supreme Court challenge delay the DPDP Act implementation?

No, the constitutional challenge does not automatically stay or delay the Act. Data Fiduciaries must continue their compliance preparations for handling personal data under the DPDP Act, 2023 and the DPDP Rules, 2025.

What is Rule 23(2) of the DPDP Rules, 2025?

Rule 23(2) mandates that a Data Fiduciary must not disclose to a Data Principal that their information was furnished to the Union government. This acts as a confidentiality gag order during lawful government data demands.

How does Section 36 affect banks and NBFCs?

Section 36 allows the Central Government to demand information from Data Fiduciaries. BFSI entities must fulfill these requests securely while ensuring automated systems do not alert customers, avoiding violations of confidentiality rules.

What is the penalty for failing to comply with DPDP requirements?

The Act establishes penalty ceilings up to 250 crore rupees for severe breaches of fiduciary duties. Failing to manage confidentiality orders or lacking a secure audit trail can invite significant regulatory scrutiny and financial exposure.

When is the DPDP Act compliance deadline?

The government is implementing a phased rollout, but exactly 273 days remain until the DPDP hard compliance deadline of 13 May 2027. Companies must implement verifiable consent and data governance workflows before this date.