4 min read

DPDPA Amends RTI Act: Assessing Compliance Costs and Enterprise Exposure

Section 44(3) of the DPDP Act removes the public interest test from the RTI Act, establishing strict non-disclosure rules for personal data. CFOs must evaluate their contingent liability and compliance provisioning as government data sharing faces severe limitations.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

According to a 13 November 2025 report published by Nasscom, Section 44(3) of the Digital Personal Data Protection Act, 2023 has officially come into force. Section 1 of the DPDP Act grants the Central Government authority to activate specific provisions on different dates. Using this mechanism, the government amended Section 8(1)(j) of the Right to Information Act, 2005. Prior to this notification, the RTI Act allowed the disclosure of personal information if justified by a larger public interest. The DPDPA amendment removes this public interest test. It establishes a blanket exemption for all personal information from RTI disclosure. The constitutionality of this amendment is under active challenge before the Supreme Court of India in the case of Venkatesh Nayak v. Union of India, W.P. (C) No. 177/2026.

Does the DPDP Act apply here

Section 3 determines the territorial and material scope of the DPDP Act. The law applies to the processing of digital personal data within India. It also covers processing outside India connected to offering goods or services to Data Principals in India. Government bodies and public authorities function as Data Fiduciaries when they collect citizen data. This amendment resolves a conflict between public transparency mandates and data protection obligations. Corporate finance leaders must observe this development closely. It demonstrates the rigid boundaries the new legal framework places around personal data. The Act governs public and private fiduciaries alike, meaning state instrumentalities face the same restrictions on data sharing as enterprise processors.

Legal implications under DPDP

Section 44(3) alters how third-party data requests are handled by public authorities. The removal of the public interest test eliminates the discretionary balancing act previously performed by public information officers. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Section 15 of the Act requires Data Principals to furnish verifiably authentic information for state documents. The new amendment ensures the State cannot transfer this collected data to third parties through RTI mechanisms. This strict non-disclosure baseline impacts any enterprise dealing with government data repositories. Improper release of data by either a public or private fiduciary constitutes a breach under the DPDP Rules, 2025.

Could this happen to you

Finance leaders evaluate compliance as a function of total cost versus penalty exposure. If your enterprise operates in a public-private partnership or supplies services to government entities, your data sharing protocols face severe scrutiny. A failure in vendor oversight or a wrongful data disclosure carries penalty ceilings up to 250 crore rupees. The Data Protection Board of India will demand detailed breach reports within 72 hours under the DPDP Rules, 2025. Your incident response capabilities determine your contingent liability. Relying on manual compliance processes inflates audit fees and threatens cyber insurance premium rates. A data breach directly impacts EBITDA through unbudgeted legal costs and remediation requirements.

What companies should do in the next 30 days

1. Direct your legal and IT functions to map all data sharing agreements with state entities.

2. Quantify your penalty exposure to determine an appropriate budget for compliance automation.

3. Drive vendor consolidation by identifying platforms that handle consent records, breach notification, and vendor oversight in a single environment.

4. Task your DPO with reviewing internal disclosure policies against the newly enforced strict privacy requirements.

5. Provision funds for verifiable evidence trail software before the next financial quarter begins.

What to watch

Corporate boards and CFOs must track the Supreme Court proceedings regarding this amendment. A successful constitutional challenge could force rapid changes to data sharing frameworks across both public and private sectors. Exactly 253 days remain until the DPDP hard compliance deadline of 13 May 2027. Enterprise budget cycles require immediate action to procure and deploy necessary compliance systems before enforcement begins. Assess your current risk profile and provisioning requirements at freescan.complydp.com.

Sources

Frequently asked questions

How does Section 44(3) of the DPDP Act impact RTI requests?

Section 44(3) amends the RTI Act to remove the public interest test for personal information. It establishes a blanket exemption, preventing public authorities from disclosing digital personal data under RTI requests.

Does the DPDP Act apply to public authorities and government bodies?

Yes. Public authorities act as Data Fiduciaries under the DPDP Act when processing digital personal data. They must adhere to the same non-disclosure and security standards as private enterprises.

What financial risks do enterprises face from improper data disclosures?

Unauthorised disclosures can result in penalty ceilings up to 250 crore rupees per breach. Such events increase contingent liability, inflate cyber insurance premiums, and require heavy provisioning that impacts EBITDA.

What are the breach notification requirements under the DPDP Rules, 2025?

Data Fiduciaries must intimate affected Data Principals without delay. They are also required to submit a detailed report to the Data Protection Board within 72 hours of discovering the breach.

When is the final deadline for DPDP Act compliance?

The hard compliance deadline is set for 13 May 2027. Enterprises must complete their compliance budgeting, vendor consolidation, and system deployment before this date to avoid penalties.