4 mins

DPDP Amendment Limits RTI Disclosures: Defensibility for D2C General Counsel

Section 44(3) of the DPDP Act eliminates the public interest test for personal data under the RTI Act, setting a strict privacy precedent that impacts how e-commerce General Counsel must structure consent and vendor indemnities.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

NASSCOM Community reports that the Supreme Court of India is hearing a challenge to Section 44(3) of the Digital Personal Data Protection Act, 2023. This provision officially came into force on 13 November 2025. It amends Section 8(1)(j) of the Right to Information Act, 2005. Prior to this, public authorities could disclose personal information if justified by public interest. The amendment removes this test entirely. It grants a blanket exemption for all personal data from RTI disclosure. The principal constitutional challenge is Venkatesh Nayak v. Union of India, W.P. (C) No. 177/2026.

Does the DPDP Act apply here?

Section 3 of the DPDP Act applies to digital personal data processed within India. This amendment directly binds public authorities holding citizen data. For D2C and e-commerce enterprises, the implications run deeper than government transparency. The removal of the public interest exemption signals a strict judicial and regulatory posture on purpose limitation. General Counsel must recognise that broad exemptions for data sharing are narrowing. If a government department cannot release data without explicit backing, private fiduciaries face even stricter scrutiny. Courts are prioritising privacy rights over general disclosure.

Legal implications under DPDP

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDPA amendment restricts how the government shares data. It establishes an overriding effect on other statutes. For private enterprises, this elevates the required standard of defensibility. When regulators evaluate your data handling, they will look for explicit consent records. Rule 3 of the DPDP Rules, 2025 mandates itemised notices. D2C companies must provide these notices in 22 regional languages. If your e-commerce platform bundles shipping and marketing data, that practice violates the Act. Outside counsel spend will increase if you lack a clear audit trail proving data was collected for a specified purpose.

Could this happen to you

An e-commerce legal head faces massive exposure if consent practices remain outdated. You cannot deploy heavy banking GRC tools that fail to handle high-velocity consumer transactions. The Data Protection Board will demand immediate proof of consent if a consumer files a grievance. D2C brands often force users to accept promotional emails to complete a purchase. If a user challenges this, you lack a legal defence. Your vendor contracts must contain strict limitation of liability and indemnity clauses regarding data handling. Regulator engagement requires instant access to verifiable consent logs, not scattered database queries.

What companies should do in the next 30 days

1. Legal Head: Draft indemnity clauses transferring liability to vendors who process customer data outside permitted purposes. Update all active master service agreements.

2. CMO: Separate shipping data collection from promotional mailing lists. Deploy a consent unbundler to allow users to check out without subscribing to marketing.

3. CTO: Implement multi-language privacy notices. Rule 3 of the Rules, 2025 mandates these regional options for consumers.

4. General Counsel: Establish a privileged review of current data flows to identify areas where consent is bundled. Document the findings in a compliance gap report.

What to watch

The Supreme Court decision in Venkatesh Nayak v. Union of India will define the boundaries of DPDP exemptions. A ruling that upholds the absolute block on data disclosure will cement the strict enforcement posture of the Data Protection Board. 251 days remain until the DPDP hard compliance deadline of 13 May 2027. GCs must prepare their defensibility strategies now. To see how exposed your current consent flows are to these strict standards, run a self-assessment at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act amend the RTI Act?

Section 44(3) of the Digital Personal Data Protection Act, 2023 amends Section 8(1)(j) of the RTI Act. It removes the public interest test for data disclosure, making personal information exempt from RTI requests.

What does the removal of the public interest test mean for businesses?

It shows a strict regulatory interpretation of privacy over general disclosure. Companies cannot rely on broad legal carve-outs to share customer data and must maintain defensible consent records.

How does Rule 3 of the DPDP Rules, 2025 affect e-commerce consent?

Rule 3 requires Data Fiduciaries to provide itemised notices in 22 regional languages. E-commerce platforms must separate shipping data collection from marketing consent.

What is the compliance deadline for the DPDP Act?

251 days remain until the DPDP hard compliance deadline of 13 May 2027. Enterprises must update vendor contracts and consent flows before this date.