News Analysis • 4 mins
Constitutionality Challenge Hits DPDP Act Exemptions and DPBI Formation
A Supreme Court challenge scrutinises the DPDP Act's government data exemptions and mandatory data sharing rules. We analyse what this means for EdTech platforms managing verifiable parental consent and state data requests.
Last updated:
What Happened
According to a report from the Supreme Court Observer, petitioners and the Union government of India are engaged in a legal challenge regarding the constitutionality of the Digital Personal Data Protection Act, 2023 and its Rules. The petitioners argue that Rules 17(1) and 17(2) of the DPDP Rules, 2025, which dictate the selection committee for the Data Protection Board under Section 18, violate the separation of powers due to executive dominance.
The challenge heavily targets Section 17 exemptions for government processing and Section 36 powers. Section 36 requires data fiduciaries to furnish information to the state, a provision petitioners argue lacks statutory guidance. Rule 23(2) is also contested because it creates a mandatory gag order, compelling fiduciaries to withhold disclosure from Data Principals when their information is furnished to the Union government for state security.
Does The DPDP Act Apply Here
The DPDP Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. For large EdTech enterprises, this applies directly to student profiles, learning analytics, behavioral tracking, and parental billing records.
While the current constitutional challenge focuses on state access to data and regulatory structure, the underlying data rights and obligations for private sector data fiduciaries remain fully active. Until a court orders otherwise, companies must treat all Section 36 data demands and Rule 23(2) non-disclosure obligations as binding law.
Legal Implications Under DPDP
Under Section 4 of the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. The constitutional challenge highlights a major friction point between these standard data principal rights and sweeping state exemptions, specifically Section 17(1)(c) for offence prevention and Section 17(2) for state security.
For EdTech platforms holding massive volumes of minor data, this creates competing obligations. Teams must build systems that enforce verifiable parental consent transparency under Rule 10 of the DPDP Rules, 2025, while simultaneously enforcing mandatory government data sharing under Section 36. This requires advanced data architecture to isolate state-mandated disclosures from routine Data Principal access requests to comply with Rule 23(2) gag orders.
Could This Happen To You
If the Union government issues a Section 36 data demand for a specific student's records or an educator's platform activity, your compliance team must comply while strictly adhering to Rule 23(2) non-disclosure requirements. An auditor or the DPBI will demand an evidence pack showing exactly who accessed this data, the legal basis used, and how the gag order was technically enforced within your systems.
If your team accidentally discloses data outside these strict Section 36 channels, it constitutes a personal data breach. The DPDP Rules, 2025 require intimation to affected Data Principals without delay, plus a detailed report to the DPBI within 72 hours. Standard GRC tools or basic banking consent managers often fail here because they do not understand EdTech specific Rule 10 workflows, verifiable parental tokens, or how to suppress state disclosures in a user-facing dashboard.
What Companies Should Do In The Next 30 Days
1. Map your data sharing workflows. The Head of Compliance must document standard operating procedures for handling Section 36 government requests, ensuring they bypass automated user transparency dashboards to avoid violating Rule 23(2).
2. Audit your verifiable parental consent architecture. Ensure your product team is capturing consent artefacts that satisfy Rule 10 of the DPDP Rules, 2025, without introducing friction that harms student onboarding.
3. Isolate disclosure logs. Configure your backend to separate state-mandated data transfers from standard cross-border transfers or commercial disclosures, assigning a specific control owner for government requests.
4. Prepare DPBI-ready audit trails. Establish tracking that can generate evidence of compliance for any specific user profile, capturing both the original parental consent and any subsequent regulated actions.
What To Watch
Monitor the Supreme Court proceedings for any interim orders that might pause or alter the enforcement of Section 36 data sharing mandates or Rule 23(2) non-disclosure obligations. Also watch for the formal establishment of the Data Protection Board of India, noting if the executive selection process under Rules 17(1) and 17(2) is modified by the court.
The regulatory window is closing fast, as exactly 274 days remain until the 13 May 2027 hard deadline. EdTech companies must act now to build compliant consent and disclosure workflows. Visit freescan.complydp.com to evaluate if your current platform can handle verifiable parental consent and Section 36 state disclosures simultaneously.
Sources
Frequently asked questions
Does the DPDP Act apply to student data stored by EdTech platforms?
Yes. The Act applies to digital personal data processed within India, or outside India if connected to offering goods or services to Data Principals in India. This directly covers student profiles, learning analytics, and parental billing records.
What is the primary legal basis for processing student data under the DPDP Act?
Under the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. For minors, EdTech platforms must obtain verifiable parental consent per Rule 10 of the DPDP Rules, 2025, while avoiding prohibited behavioral tracking.
Are data fiduciaries required to share data with the government under the DPDP Act?
Yes. Section 36 of the Act mandates that data fiduciaries furnish information required by the Union government. Furthermore, Rule 23(2) of the DPDP Rules, 2025 prohibits fiduciaries from disclosing this data sharing to the affected Data Principals if state security is involved.
What happens if an EdTech platform suffers a data breach while handling state requests?
If an accidental disclosure occurs, it constitutes a personal data breach. The DPDP Rules, 2025 require intimation to affected Data Principals without delay, plus a detailed report submitted to the Data Protection Board within 72 hours.
When is the final deadline for DPDP Act compliance?
The regulatory window is actively closing. Exactly 274 days remain until the 13 May 2027 hard deadline, meaning compliance and product teams must finalise their audit trails and verifiable parental consent workflows immediately.
ComplyDP