4 min read

DPDPA Amendment to RTI Act Tests Legal Boundaries of Personal Data Disclosure

Section 44(3) of the DPDP Act amended the RTI Act to limit personal data disclosure, sparking a Supreme Court review. For enterprise compliance heads, this signals stricter regulatory enforcement on purpose limitation and third-party data sharing.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

On 13 November 2025, Section 44(3) of the Digital Personal Data Protection Act, 2023 officially amended Section 8(1)(j) of the Right to Information Act, 2005. NASSCOM reports that this change alters the specific disclosure exemptions for public authorities. The amendment removes the former language allowing personal data disclosure if the information had a relationship to public activity or interest. The Union of India is currently defending this legislative choice to prioritise privacy protections over broad transparency mandates. The principal challenge is before the Supreme Court of India in Venkatesh Nayak v. Union of India, W.P. (C) No. 177/2026, alongside other connected petitions.

Does the DPDP Act apply here

Section 3 governs the processing of digital personal data within the territory of India. The Act applies equally to private entities and public authorities acting as Data Fiduciaries. While the Supreme Court is reviewing public sector obligations, the legal definition of lawful processing directly impacts private sector compliance. A Head of Compliance at a large enterprise needs to track this case because it defines the absolute boundaries of data protection rights. Section 15 also places duties on the Data Principal, including the obligation not to register false or frivolous complaints during information requests.

Legal implications under DPDP

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The DPDPA amendment to the RTI Act establishes a rigid approach to data disclosure without explicit consent. Under the DPDP Act, 2023 and the DPDP Rules, 2025, Data Fiduciaries face stringent notice requirements before sharing data with external entities. An e-commerce platform cannot bundle consent for shipping and third-party data sharing. The Rules require an itemised notice that specifies every exact purpose for processing. The compliance team retains an auditable consent artefact for every user before fulfilling external data requests.

Could this happen to you

D2C and e-commerce companies frequently manage requests for consumer data from government agencies, vendors, and aggregators. If your team hands over raw consumer data without verifying a valid legal basis, the Data Protection Board of India will scrutinise your internal approval processes. A wrongful disclosure constitutes a personal data breach under the Act. The Rules, 2025 dictate that a detailed breach intimation report goes to the Board within 72 hours. Failing to secure personal data carries penalty ceilings of up to Rs 250 crore. An external auditor will require complete evidence packs showing how your control owners validated the disclosure against user consent records.

What companies should do in the next 30 days

1. Document all external data sharing channels in your enterprise Record of Processing Activities to identify immediate exposure.

2. Separate shipping data requirements from marketing data flows to eliminate non-compliant bundled consent practices across your D2C platforms.

3. Implement a strict internal approval workflow for control owners handling third-party information requests to prevent unlawful data disclosures.

4. Configure automated systems to generate and translate privacy notices into 22 regional languages as required by Rule 3 for Tier-2 market customers.

5. Build a regulator-ready audit trail that captures exact consent artefacts and links them directly to the corresponding data sharing event.

What to watch

The Supreme Court decision in Venkatesh Nayak v. Union of India will set a binding precedent on how competing fundamental rights interact under the new framework. The Data Protection Board is anticipated to release formal guidelines on handling statutory information requests without violating purpose limitation. Corporate compliance leaders should monitor these proceedings to ensure their internal audit tools meet the evolving legal standard. Exactly 251 days remain until the 13 May 2027 hard deadline. Run a focused gap analysis of your consent architecture at freescan.complydp.com before regulatory enforcement begins.

Sources

Frequently asked questions

Does the DPDP Act apply to public information requests?

Yes, the Act regulates how any digital personal data is processed within India. Section 44(3) specifically amends the RTI Act to limit the disclosure of personal information without an appropriate lawful basis.

How does the RTI Act amendment affect private D2C companies?

The amendment signals a strict legal interpretation of purpose limitation and data sharing. Private enterprises are required to verify a valid legal basis or explicit consent before disclosing user data to external parties.

What are the penalties for unlawful data disclosure?

Disclosing personal data without a valid legal basis or consent constitutes a breach of obligations under the DPDP Act. The maximum penalty ceiling for failing to implement reasonable security safeguards reaches Rs 250 crore.

How long do we have to report a data breach under DPDP?

The DPDP Rules, 2025 require Data Fiduciaries to submit a detailed breach intimation report to the Data Protection Board within 72 hours. The affected Data Principals receive notification without delay.

Can we bundle consent for shipping and marketing data?

No, the DPDP Act prohibits bundled consent structures. The Rules require an itemised notice that clearly separates operational data from marketing purposes to obtain explicit consent for each.