Dpdp act rti privacy transparency right to know

By a Cybersecurity & Data Protection Perspective
 

What happens when two important principles of a digital democracy appear to collide?

 

The right of an individual to protect personal information.

And the right of a citizen to know how public power is being exercised.

India is currently confronting precisely this question.

 

The Digital Personal Data Protection (DPDP) Act, 2023 amended the Right to Information (RTI) Act, 2005 by changing the language of Section 8(1)(j). The amendment has become the subject of constitutional challenges before the Supreme Court, including petitions raising concerns about transparency, the right to information and journalism. The Court is examining these issues; no final determination has been made on the constitutional validity of the provisions under challenge.

 

For those of us working in cybersecurity and data protection, this is an important moment—not because privacy should lose to transparency, or transparency should automatically defeat privacy, but because both are fundamental to trust in a digital society.

 

 

The change that triggered the debate

Section 44(3) of the DPDP Act substituted Section 8(1)(j) of the RTI Act with a much shorter provision:

 

“information which relates to personal information.”

That is the statutory language now recorded in India Code.

The earlier RTI framework contained a more detailed test concerning information relating to public activity or interest, unwarranted invasion of privacy, and disclosure where the larger public interest justified it.

 

The change therefore raises a significant question:

What happens when information is personal—but also relevant to public accountability?

 

That is not a hypothetical question.

 

Consider a public appointment.

An RTI applicant may want to know whether a person appointed to a public position possessed the qualifications prescribed for that position. The records may contain information identifying an individual. But the purpose of seeking that information may be to examine the integrity of a public process.

 

Or consider government expenditure.

A journalist investigating whether public funds were improperly allocated may encounter names, beneficiary details or other information relating to identifiable individuals.

 

The information is personal.

 

But the context in which that information becomes relevant may be public.

And that is where the debate becomes much more nuanced than “privacy versus RTI.”

 

 

Privacy is not a privilege. It is a constitutional value.

The argument for stronger protection of personal information is compelling.

 

The Supreme Court, in Justice K.S. Puttaswamy (Retd.) v. Union of India, recognised privacy as a constitutionally protected fundamental right and specifically recognised informational privacy—including an individual's ability to exercise control over dissemination of personal information.

 

That principle matters enormously in the digital age.

 

Government departments today hold vast quantities of information about citizens.

 

Healthcare records. Education records. Identification information. Employment records. Financial information. Welfare records.

 

The fact that the State possesses information does not mean that every citizen should automatically have access to it.

 

A privacy framework that protects an ordinary citizen's medical records, financial details or personal contact information from unnecessary disclosure is not an obstacle to democracy.

 

It is part of democracy.

 

From a cybersecurity perspective, this distinction is fundamental.

 

Data minimisation, purpose limitation and controlled access are not merely compliance concepts. They are security principles.

 

Every unnecessary disclosure creates another opportunity for misuse, profiling, identity theft, harassment or fraud.

 

So protecting personal information is not inherently anti-transparency.

 

 

But transparency is also a security mechanism for democracy

There is another side to the equation.

 

Transparency allows citizens, journalists and civil-society organisations to examine the exercise of public power.

* Suppose a journalist is investigating irregularities in a government recruitment process.

* Suppose an RTI applicant is examining the distribution of public funds.

* Suppose an investigation concerns whether a public authority followed its own rules.

 

The underlying records may inevitably contain information relating to identifiable people.

 

The difficult question is not whether that information is “personal.”

The difficult question is whether personal information can also carry legitimate information about public activity, public money or public accountability.

 

The Supreme Court is now examining precisely these kinds of constitutional concerns. The petitions before it include challenges involving the RTI amendment as well as concerns raised by journalism and press-freedom organisations.

 

And the Court has not yet answered the central question.

That distinction is critical.

 

 

Journalism makes the dilemma even sharper

Investigative journalism frequently depends on information that cannot be neatly divided into “personal” and “public.”

 

Imagine an investigation into suspected misuse of a government welfare programme.

 

To establish what happened, a journalist may need to examine records containing names, locations, eligibility information or payment details.

The journalist's objective may not be to expose the private life of an individual.

 

It may be to establish whether public money was used properly.

This is one of the concerns raised in the constitutional challenge brought by The Reporters Collective and others. The petition challenges aspects of the DPDP framework and raises questions concerning freedom of expression, journalism and access to information.

 

But it would be equally problematic to conclude that journalism automatically creates a licence to process or publish anybody's personal data.

It does not.

 

Journalism itself has to operate responsibly.

The real question is therefore much more sophisticated:

 

How should a democratic legal system distinguish legitimate public-interest use of personal information from unjustified exposure of private information?

 

 

A simple example shows why the answer cannot be absolute

Imagine two RTI requests.

 

Request A:

“Provide the private medical records of a government employee.”

The privacy concern is obvious.

 

Request B:

“Provide information necessary to establish whether the same employee was legally qualified for a public appointment.”

The public-interest dimension is equally obvious.

Both requests may involve the same individual.

 

But treating them identically would ignore the purpose and context of the disclosure.

 

This is why the DPDP–RTI debate cannot responsibly be reduced to:

“DPDP protects privacy, therefore RTI is weakened.”

Nor can it be reduced to:

“RTI promotes transparency, therefore personal data should be disclosed.”

Both propositions are too simplistic.

 

 

The Supreme Court's role is particularly important

The Supreme Court has already recognised privacy as a constitutional right. It is now examining challenges concerning the DPDP framework and its interaction with the RTI regime.

 

In February 2026, the Court referred core challenges concerning the DPDP Act—including the RTI amendment—to a larger bench, while declining at that stage to stay the operation of the framework.

 

More recently, in August 2026, the Court again considered challenges to the RTI amendment, with petitioners arguing that the amended provision creates an excessively broad protection for personal information. The Centre has been asked to respond.

 

The matter remains before the Court.

Therefore, any claim today that the Supreme Court has decided that the DPDP Act is unconstitutional—or that it has definitively weakened RTI—is premature.

The Court's eventual interpretation will determine how these competing constitutional and statutory interests are reconciled.

 

 

Perhaps the better question is not “DPDP or RTI?”

That framing itself may be misleading.

 

A mature digital democracy should not have to choose between:

 

privacy without accountability

and

transparency without privacy.

We need both.

 

The challenge is creating rules that recognise that some information is genuinely private, while some information—even when it contains personal elements—may be relevant to public power and public accountability.

 

Consider three principles:

* Private information should not become public merely because a government authority holds it.

* Information relevant to legitimate public accountability should not become inaccessible merely because it contains personal elements.

* Where privacy and public interest overlap, the legal framework must provide a clear and constitutionally sound way of resolving that conflict.

 

Whether the existing framework achieves that balance is precisely what remains to be determined.

 

 

The cybersecurity perspective: this is ultimately about trust

Cybersecurity professionals often speak about the confidentiality, integrity and availability of information.

 

The DPDP–RTI debate reminds us that information governance is not only about keeping information secure.

It is also about deciding:

* Who should have access?

* For what purpose?

* Under what authority?

* For how long?

* With what safeguards?

* And when does legitimate access become unjustified disclosure?

 

These are familiar questions in cybersecurity.

They are now becoming equally important questions in constitutional governance.

 

A system that exposes citizens' personal information without justification cannot claim to protect privacy.

But a system that makes legitimate scrutiny of public power unnecessarily difficult cannot easily claim to promote accountability.

Good data governance must therefore protect both the individual and the public interest.

 

 

The question India should continue asking

The Supreme Court will ultimately determine the legal position.

Until then, perhaps the most constructive approach is not to predict the outcome but to examine the principle at stake.

 

How do we build a digital India where citizens can trust the State with their personal data—and still retain the ability to question the State about how power, money and information are being used?

 

That is the real challenge.

Because privacy protects the citizen from unnecessary intrusion.

And transparency protects the citizen from unaccountable power.

 

A democratic digital society needs both.



Comments

No Comments Found.