
DPDPA Section 44: Targeted Amendments to TRAI Act, IT Act, and RTI Act
DPDPA Section 44 harmonizes India’s data laws. Discover how amendments to the RTI, IT, and TRAI Acts impact data fiduciaries and privacy compliance.
Written by
Himanshu Jotwani
Date
Read time
6 min

New laws do not exist in a vacuum. They crash into old ones. When the Digital Personal Data Protection Act, 2023 arrived, it didn’t just introduce new rules,it collided with decades of existing legislation.
DPDPA Section 44 is the collision management system. It modifies specific provisions in three existing laws to align them with India’s new data protection regime. The goal is simple: remove conflicts, tighten how personal information is handled, and establish clear appellate pathways where required.
What Section 44 Changes
Section 44 introduces precise edits across three Acts:
- Telecom Regulatory Authority of India Act, 1997: In section 14, clause (c), the list of referenced appellate tribunals is replaced with:
- Information Technology Act, 2000: Section 43A is omitted. With IT Act Section 43A replaced by the DPDPA’s overarching framework, the omission is formalized here. In section 81, the proviso is expanded to include the Digital Personal Data Protection Act, 2023. In section 87(2), clause (ob) is omitted.
- Right to Information Act, 2005: In section 8(1), clause (j) is replaced with: “information which relates to personal information”.

These are not cosmetic edits. They are structural, load-bearing changes. They reset references, remove overlap, and prevent legal tension between older frameworks and the DPDPA.
Why These Amendments Matter
Without these amendments, you get legal schizophrenia. One statute might push for the disclosure of personal data while the DPDPA restricts it. Section 44 acts as a harmonizer, ensuring data protection principles apply consistently across public authorities and regulated entities.
- Alignment across tribunals. The TRAI Act amendment DPDP alignment now recognizes the DPDPA’s appellate forum. This supports coherent appellate handling where telecom, information technology, or data protection issues converge.
- Consolidation of data protection standards. The IT Act amendments signal that where personal data is concerned, the DPDPA is the controlling framework. Removing IT Act provisions that would otherwise overlap keeps the standard clean.
- Privacy as a default in public transparency. The RTI Act amendment DPDP change reframes clause (j) to a clear personal information carve-out. It emphasizes privacy protection while preserving the broader transparency intent of the RTI Act.
Practical Effects for Operators and Public Authorities
These changes alter how you receive, process, and disclose personal data. More importantly, they alter how you position your organization in potential disputes or appeals.
1) Handling RTI requests that involve personal data
- The RTI exception for personal information is now explicit. Requests that seek personal information can be refused in line with the revised clause.
- You should triage RTI requests for personal data at intake. Build a clear decision path that identifies personal information early, applies the clause precisely, and documents the rationale for any refusal.
- Redaction protocols need to be ruthless. If a record contains both public information and personal information, separate the two. Disclose only what is not personal, unless another legal basis compels disclosure.
- Train Public Information Officers on the amended clause text and on when to escalate borderline cases.
2) Resetting your legal basis from IT Act to DPDPA
- With section 43A and a rule-making clause removed from the IT Act, policies and controls that referenced those provisions are now citing ghosts. Update them to reference the DPDPA.
- Map your data protection obligations directly to the DPDPA’s requirements instead of legacy IT Act concepts that could create confusion.
- Align your breach response playbooks, notices, and record-keeping with the DPDPA as the primary legal anchor.
3) Appellate pathways and dispute planning
- The TRAI Act’s updated clause signals that where disputes touch the DPDPA, the DPDPA’s appellate tribunal is the correct forum.
- Review your litigation and escalation playbooks. Identify matters that may involve overlapping regimes so that counsel selects the right appellate track from day one.
Interpreting the Boundaries
Section 44 does not rewrite entire laws. It is a scalpel, not a sledgehammer. It targets specific clauses to avoid conflict and preserve intent.

- For the RTI Act: The edit does not negate the transparency framework. It clarifies that personal information is out of scope unless other provisions dictate disclosure. Public authorities must balance transparency with privacy using the revised text.
- For the IT Act: The omissions and insertions point to a unified standard under the DPDPA when dealing with personal data. Do not infer new obligations from what Section 44 does not say. Apply the DPDPA where personal data processing is at issue.
- For the TRAI Act: The tribunal references are harmonized. Treat the DPDPA appellate tribunal as the forum for appeals under the DPDPA. Do not mix forums unless the facts and statutes clearly require it.
Execution Steps for Compliance Teams
Use these focused actions to operationalize Section 44. A policy update is not enough; the operational muscle memory has to change.
- Legal register and policy updates
- Update your legal register to reflect the omission of IT Act section 43A and the changes to sections 81 and 87.
- Replace legacy citations in policies, notices, and contracts with DPDPA references where personal data obligations arise.
- RTI response redesign
- Implement an RTI triage checklist that flags personal information upfront.
- Standardize redaction methods, partial disclosures, and refusal templates citing section 8(1)(j) as amended.
- Maintain an audit trail for RTI decisions that involve personal data.
- Training and awareness
- Brief Public Information Officers, compliance leads, and legal teams on the exact amendment text and its practical effect.
- Run scenario drills where an RTI request overlaps with internal privacy controls to confirm consistent handling.
- Governance and escalation
- Clarify when matters should move to the DPDPA appellate tribunal. Document triggers and responsible roles.
- Ensure board or risk committee oversight of the shift from IT Act based controls to DPDPA based governance.
- Vendor and inter-agency coordination
- If you rely on third parties for RTI processing, ensure they adopt the revised standard and follow your redaction and refusal procedures.
- For public authorities, confirm that inter-departmental data sharing adheres to the DPDPA’s privacy and security baseline, as reinforced by the harmonizing intent of Section 44.
What Changes on the Ground
- Expect stricter gatekeeping around personal information in RTI workflows.
- Expect fewer references to legacy IT Act provisions in privacy policies and more direct reliance on the DPDPA.
- Expect cleaner escalation pathways for appeals tied to data protection issues.
This is not a theoretical clean-up. It is a practical consolidation. The amendments reduce ambiguity and remove the safety blanket of outdated provisions. Your compliance posture should follow suit, with documentation that cites the correct law and processes that resist unnecessary disclosure.
Closing
Section 44 is a precision tool. It aligns adjacent laws with the DPDPA, avoids conflict, and resets disclosure and appellate routes where personal information is at stake. Treat it as a directive to tighten your RTI handling, refresh your legal references, and center your data protection controls on the DPDPA.
Getting this right is about execution. Policies must match the amended statutes. People must know how to apply them. Evidence must show that you did. Because a policy that does not reflect reality is just a well-written lie.
At Regodit, we built our platform because translating legal text like Section 44 into repeatable processes shouldn’t require a consultancy. It requires a structured way to track obligations, update controls, and prove compliance across statutes as they evolve. If you want a clear path from legal text to operational reality without adding friction, it’s time to rethink how you manage compliance.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
