News Analysis • 4 min read
Supreme Court Challenges DPDP Act 2023 Over Broad Government Exemptions and Board Independence
Petitioners have challenged the constitutionality of the DPDP Act 2023 and Rules 2025, scrutinising executive exemptions, mandatory information sharing under Section 36, and Data Protection Board independence. General Counsel must evaluate how these provisions impact enterprise indemnity and law enforcement data request workflows.
Last updated:
What happened
According to a report by the Supreme Court Observer, petitioners have challenged the constitutionality of several provisions of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The challenge targets the administrative independence of the Data Protection Board of India, specifically arguing that Rules 17(1) and 17(2) create executive dominance in the selection committee, violating the separation of powers. Additionally, the petition contests the broad government processing exemptions under Section 17 and the mandatory information sharing directives under Section 36.
Does the DPDP Act apply here?
Under Section 3 of the Act, the law applies to the processing of digital personal data within the territory of India, and processing outside India if connected to offering goods or services to Data Principals in India. For General Counsel and Legal Heads at large enterprises, this constitutional challenge directly impacts how you handle government data requests involving data governed by these applicability criteria. When law enforcement demands access to your corporate data repositories, your legal team must navigate the conflict between complying with state directives under Section 36 and maintaining defensibility with your commercial clients.
Legal implications under DPDP
The legal implications centre on how Data Fiduciaries manage exceptions to standard notice and processing obligations. Under the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. However, Section 17(1)(c) permits data processing for the prevention, detection, or investigation of offences, while Section 17(2) broadly exempts the Union government acting in the interests of state security. Furthermore, Section 36 allows the government to compel fiduciaries to furnish information, while Rule 23(2) of the DPDP Rules, 2025 acts as a gag order prohibiting fiduciaries from notifying Data Principals that their data was shared.
Could this happen to you
If your enterprise receives a broad data access request from a state agency, your legal department faces immediate defensibility and indemnity risks. Complying without a privileged review could trigger breach of contract claims from enterprise clients whose data you surrendered. Conversely, refusing the request exposes your organisation to severe regulatory penalties. If this scenario happens to you, the Data Protection Board of India or your commercial partners will demand an audit trail showing exactly which data was handed over and whether the gag order conditions under Rule 23(2) were legitimately met.
What companies should do in the next 30 days
General Counsel should immediately review and update their law enforcement request policies to handle statutory demands defensibly. 1. Establish a privileged review protocol for all Section 36 data access requests to evaluate their legal validity before any data is transferred. 2. Revise limitation of liability and indemnity clauses in enterprise customer contracts to explicitly carve out forced disclosures made under Section 17 exemptions.
3. Deploy automated access logging tools to ensure you have an immutable record of what data was accessed, which is critical for regulator engagement. 4. Document a clear workflow for Rule 23(2) compliance to ensure your legal team can justify why a Data Principal was not notified regarding a government data request.
What to watch
Legal teams must closely monitor the Supreme Court proceedings, as any ruling could alter the compliance environment for government data requests and redefine the independence of the Data Protection Board of India. In the meantime, the countdown to enforcement continues, and exactly 274 days remain until the DPDP hard compliance deadline of 13 May 2027. Outside counsel spend will rise if standard operating procedures are left to the last minute. To assess how well your current data handling protocols would survive a regulatory audit, run a baseline evaluation at freescan.complydp.com.
Sources
Frequently asked questions
How does the DPDP Act handle government data requests?
Section 36 of the Act empowers the government to require Data Fiduciaries to furnish information. Additionally, Section 17 provides broad exemptions for data processed for state security, and Rule 23(2) of the Rules, 2025 prohibits fiduciaries from notifying Data Principals if sharing the data affects state sovereignty.
What are the liability risks for General Counsel under Section 36?
Legal Heads face contract breach risks if they surrender enterprise data to law enforcement without a privileged legal review. Limitation of liability and indemnity clauses in client contracts must be updated to specifically carve out forced statutory disclosures under the DPDP Act.
How should legal teams respond to the gag orders under Rule 23(2)?
Enterprises must establish a formal legal review protocol to assess every state access request before transferring data. They should also maintain immutable access logs to prove defensibility during future regulator engagement.
Does the DPDP Act require consent for all processing activities?
No, under the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Processing for law enforcement or state security often falls under specific statutory exemptions like Section 17 rather than requiring individual consent.
When is the final enforcement date for the DPDP Act?
Exactly 274 days remain until the DPDP hard compliance deadline of 13 May 2027. General Counsel must finalise their compliance frameworks and update commercial contracts well before this date to avoid escalating outside counsel spend.
ComplyDP