NEWS ANALYSIS4 min read

Constitutional Challenge Targets DPDP Act 2023 Amendment to RTI Act

A recent query challenges the constitutionality of the DPDP Act 2023, focusing on its amendment to Section 8(1)(j) of the RTI Act and the restriction of information regarding public functionaries. This analysis breaks down the impact on data disclosures and what fintech compliance leaders must learn from this transparency conflict.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

Recent reports highlight a constitutional query raised against the Digital Personal Data Protection Act, 2023. The issue centres specifically on the Act enacting an amendment to Section 8(1)(j) of the Right to Information Act. This text scrutinises whether the DPDP amendment unlawfully restricts the scope of information that citizens can seek against public functionaries. By removing previous exemptions that allowed disclosure in the larger public interest, the amendment alters how personal information is handled by state entities.

Does The DPDP Act Apply Here

The DPDP Act covers this scenario under Section 3, which dictates the scope for processing digital personal data within the territory of India. The information of public functionaries qualifies as personal data. Previously, the RTI Act provided a mechanism to access this data if public interest outweighed privacy concerns. The DPDP Act changes this by amending the RTI Act to create a blanket exemption for personal data, bringing these disclosures strictly under DPDP jurisdiction.

Legal Implications Under DPDP

Section 4 of the DPDP Act mandates that processing personal data requires a lawful purpose, where consent is the primary basis for processing, except where Section 7 legitimate uses apply. This constitutional challenge questions if completely blocking the disclosure of public functionary information violates constitutional rights to information. The DPDP Rules, 2025 add operational weight to these restrictions. They mandate that entities maintain precise records of processing activities and valid consent artefacts, removing the leeway for informal data sharing.

Could This Happen To You

While a fintech enterprise is not a public functionary, this conflict mirrors the regulatory friction financial institutions face daily. Fintech compliance heads frequently handle data requests from law enforcement, regulatory bodies, and third party APIs like account aggregators. If your compliance team discloses borrower or payments data based on outdated exemptions, you risk immediate DPDP violations. The Data Protection Board of India would demand a complete evidence pack detailing the exact legal basis for the disclosure. For high growth lending startups, manual legal reviews for every data sharing request will bottleneck rapid product cycles. Your platform needs programmatic control owners to automate these decisions safely.

What Companies Should Do In The Next 30 Days

1. Map all external data sharing channels, including RBI reporting and account aggregator flows, assigning a clear control owner to each.

2. Update your Record of Processing Activities to explicitly document the lawful basis for these external disclosures under Section 4 or Section 7.

3. Implement system level checks to generate verifiable consent artefacts for all digital lending onboarding paths, as outlined in the DPDP Rules, 2025.

4. Document a strict breach intimation workflow that guarantees a detailed report reaches the Data Protection Board within 72 hours if unauthorized disclosure occurs.

What To Watch

Legal teams must closely monitor the progress of this constitutional query, as any judicial reading of the RTI amendment could influence how exemptions are interpreted across the board. The operationalisation of the Data Protection Board of India will soon clarify how strictly unauthorized disclosures will be penalized. Remember that exactly 275 days remain until the DPDP hard compliance deadline of 13 May 2027. To evaluate if your internal data disclosure controls are regulator ready, test your exposure today at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act 2023 override the RTI Act?

Yes, the DPDP Act amends Section 8(1)(j) of the RTI Act. It removes the previous public interest exemption, effectively blocking the disclosure of personal data under RTI requests.

What is the primary basis for processing data under the DPDP Act?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Companies must maintain valid consent artefacts to prove compliance with these requirements.

How does this impact fintech companies handling external data requests?

Fintechs must ensure every data disclosure, such as to account aggregators or authorities, has a documented lawful basis. Without clear audit trails and evidence packs, companies risk severe DPDP penalties.

What are the breach reporting requirements under the DPDP Rules 2025?

Entities must provide an intimation to affected Data Principals without delay. They must also submit a detailed report to the Data Protection Board within 72 hours of identifying the breach.

What is the deadline for DPDP Act compliance?

The Central Government has set a hard compliance deadline for all entities. Organisations must fully align their data processing practices by 13 May 2027.