4 min read

DPDP Act Amendment to RTI Triggers Supreme Court Challenge: Impact on EdTech Providers

Section 44(3) of the DPDP Act amended the RTI Act to limit personal data disclosures, sparking a constitutional challenge. EdTech platforms partnering with public entities must overhaul data sharing controls and verifiable parental consent mechanics.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What Happened

NASSCOM Community reports that the Digital Personal Data Protection Act, 2023 modified India transparency laws. Section 44(3) of the DPDP Act amended Section 8(1)(j) of the Right to Information Act, 2005. The amendment came into force on 13 November 2025. It restricts public authorities from disclosing personal data under RTI exemptions. The change immediately triggered a constitutional challenge regarding the balance between privacy and public disclosure. The Supreme Court of India is currently hearing the principal challenge in Venkatesh Nayak v. Union of India, W.P. (C) No. 177/2026, alongside connected petitions.

Does The DPDP Act Apply Here?

Section 3 of the DPDP Act applies to the processing of digital personal data within India. The RTI amendment directly impacts public authorities handling citizen data. It also affects private entities, such as EdTech platforms, that manage student data on behalf of state schools or government education boards. These partnerships generate massive volumes of personal data. Under the revised RTI rules, state entities cannot freely release this data to information seekers. Platform operators must build strict data access controls to prevent accidental disclosure during government data requests.

Legal Implications Under DPDP

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDPA amendment elevates Data Principal privacy above historical RTI disclosure norms. For EdTech providers, the legal burden extends far beyond standard consent. Section 9 of the Act strictly prohibits behavioral tracking of children and targeted advertising. The DPDP Rules, 2025 mandate specific verifiable parental consent mechanics under Rule 10. Data Principals also hold duties under Section 15 to furnish verifiably authentic information and refrain from impersonation.

Could This Happen To You

If your EdTech platform powers public school infrastructure, a mishandled data request easily triggers an audit. The Data Protection Board of India will demand your evidence pack. Regulators expect a detailed report within 72 hours of any breach intimation. The Board will look for immutable consent artefacts and clear data segregation between state and private users. Generic bank-focused compliance tools fail here. They do not understand Parental Tokens or the age-gating necessary to keep learning apps legal without halting user registration. A failure to secure valid verifiable parental consent exposes the company to a penalty ceiling of 200 crore rupees.

What Companies Should Do In The Next 30 Days

1. The Head of Legal must audit all state-partnership data flows to ensure RTI requests route to the public authority without unauthorized data sharing.

2. The Chief Product Officer should implement Rule 10 workflows for verifiable parental consent to generate records for every user under 18.

3. Compliance teams need to map control owners for age-gating mechanisms and verify they operate without behavioral tracking.

4. Run a simulated breach response to confirm the team can notify affected Data Principals and submit a detailed report to the DPBI within 72 hours.

What To Watch

The Supreme Court ruling in Venkatesh Nayak v. Union of India will establish the exact boundary between the DPDP Act and the RTI Act. EdTech operators should monitor DPBI enforcement signals regarding state-mandated data processing. 250 days remain until the DPDP hard compliance deadline of 13 May 2027. Evaluate your platform exposure to Rule 10 workflows and parental consent gaps using the assessment at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act change the RTI Act?

Section 44(3) of the DPDP Act amends Section 8(1)(j) of the RTI Act. Public authorities can no longer rely on previous exemptions to disclose personal data. This restricts the public release of citizen data.

What is the penalty for failing to protect children data under the DPDP Act?

Non-compliance with Section 9 obligations regarding children carries a penalty ceiling of 200 crore rupees. EdTech firms must deploy verifiable parental consent mechanics to avoid enforcement actions.

What are Rule 10 workflows for EdTech?

Rule 10 of the DPDP Rules 2025 dictates how platforms obtain verifiable parental consent. EdTech products need age-gating and Parental Tokens that function without behavioral tracking.

When is the DPDP Act hard compliance deadline?

250 days remain until the DPDP hard compliance deadline of 13 May 2027. Companies must finalize consent artefacts and breach intimation protocols before this date.

Can we process data without consent under the DPDP Act?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The law outlines specific exemptions for state functions, medical emergencies, and employment purposes.