4 min read

DPDP Act Amendment to RTI Act Faces Supreme Court Challenge Over Privacy Exemptions

Section 44(3) of the DPDP Act amended the Right to Information Act on 13 November 2025, restricting public authorities from disclosing personal data. General Counsel must evaluate how state bodies handle their corporate filings as the Supreme Court reviews a constitutional challenge.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

The Supreme Court of India is hearing a constitutional challenge regarding the balance between privacy rights and the right to information. According to a Nasscom community report, Section 44(3) of the Digital Personal Data Protection Act, 2023 officially amended Section 8(1)(j) of the Right to Information Act, 2005 on 13 November 2025. This statutory change alters the disclosure exemptions public authorities use when processing requests for personal data. The principal legal challenge is Venkatesh Nayak v. Union of India, W.P. (C) No. 177/2026, alongside other connected petitions.

Does the DPDP Act apply here?

The Act applies directly to public authorities handling these information requests. Under Section 3(a) of the DPDP Act, the framework governs the processing of digital personal data within the territory of India where the data is collected in digital form or digitised subsequently. When a state instrumentality receives an RTI request asking for personal data, that authority acts as a Data Fiduciary. The amendment forces a conflict between the mandate to protect digital personal data and the transparency requirements of the RTI framework.

Legal implications under DPDP

Section 44(3) restricts the ability of state bodies to disclose personal data to third-party RTI applicants. Under the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Disclosing third-party personal data without consent now faces a strict exemption barrier under the amended RTI Act. Section 15 also imposes duties on Data Principals. They must furnish only verifiably authentic information and cannot register false or frivolous grievances with a Data Fiduciary or the Data Protection Board.

Could this happen to you

General Counsel at large enterprises must evaluate how their corporate data interacts with public authorities. Companies routinely submit employee personal data, board member details, and customer information to regulators and state bodies. If a citizen files an RTI request targeting your regulatory filings, the public authority must apply the amended Section 8(1)(j) to block the release of that personal data. A failure by your legal team to classify and separate corporate IP from personal data in these filings could result in unintended disclosures. Defensibility relies on clearly marking personal data before it leaves your control.

What companies should do in the next 30 days

1. Legal teams should audit recurring regulatory filings to identify where digital personal data goes to state instrumentalities.

2. Outside counsel must review vendor contracts and update limitation of liability clauses regarding data exposed through statutory disclosures.

3. Compliance heads should establish a privileged review process for separating corporate data from personal data before submitting documents to government portals.

4. General Counsel should evaluate their regulator engagement strategy to ensure protective measures are documented.

What to watch

Legal and compliance leaders should monitor the Supreme Court proceedings in Venkatesh Nayak v. Union of India for binding interpretations of Section 44(3). The outcome will dictate how public authorities process third-party data requests. Companies must also prepare for the operational requirements introduced by the DPDP Rules, 2025. Exactly 253 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal teams can assess their current defensibility and readiness for these enforcement dates using the assessment tool at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act amendment to the RTI Act affect our regulatory filings?

Section 44(3) of the DPDP Act amends the RTI Act to limit the disclosure of personal data by public authorities. When your enterprise submits filings containing employee or board member data, state bodies must restrict public disclosure of that personal data under RTI requests.

Are public authorities considered Data Fiduciaries under the DPDP Act?

Yes. Any entity determining the purpose and means of processing digital personal data operates as a Data Fiduciary. Public authorities must follow DPDP Act obligations when handling personal data in RTI requests.

Do we need consent to share employee personal data with government bodies?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Sharing personal data to fulfill a legal obligation or comply with a state mandate falls under legitimate uses, meaning specific consent for that transfer is not required.

Can Data Principals file complaints about RTI data disclosures?

Data Principals can file grievances regarding unauthorized processing. However, Section 15 of the Act requires them not to register false or frivolous grievances with a Data Fiduciary or the Data Protection Board.

What timeline should our legal team track for full DPDP compliance?

253 days remain until the DPDP hard compliance deadline of 13 May 2027. Legal teams must finalize their vendor contract updates, liability limits, and internal processing audits before this date.