DPDP Act 2023 + RTI course - final certificate
Quick Reply: Final certificate page for the DPDP Act 2023 + RTI course - 5 modules on data fiduciary duties, Section 44(3) RTI amendment, consent + significant data fiduciary obligations.
You have completed the 5-module DPDP + RTI course. The course trains compliance officers, data protection officers (DPOs), RTI activists and tech professionals to navigate the Digital Personal Data Protection Act, 2023 (Act 22 of 2023) and its overlap with the Right to Information Act, 2005. One correction to memorise before you print the certificate: the DPDP Act was not switched on in one go. Gazette notifications dated 13 November 2025 brought the institutional framework into force on 14 November 2025, but the substantive obligations on data fiduciaries — sections 3 to 17 — follow on a notified phase running to May 2027, and the DPDP Rules, 2025 phase in alongside (Rules 1, 2 and 17 to 21 immediately; Rule 4 after one year; Rules 3, 5 to 16, 22 and 23 after eighteen months). The most important overlap, the §44(3) DPDP amendment that substituted §8(1)(j) of the RTI Act, is already live — it was in the first phase.
What you covered
- Module 1: DPDP Act architecture - data principal, data fiduciary, consent, processing grounds, the Data Protection Board of India, and the penalty schedule: up to ₹250 crore for breach of security-safeguard obligations (§8(5)), ₹200 crore for breach-notice and children's obligations, ₹150 crore for Significant Data Fiduciary breaches, ₹50 crore for other provisions, ₹10,000 for data-principal duties.
- Module 2: Significant Data Fiduciary obligations - the Act requires an SDF to appoint a Data Protection Officer (§10(2)(a); defined in §2(l)); the DPDP Rules, 2025, Rule 13 require an annual Data Protection Impact Assessment and audit, with the report's significant observations furnished to the Board.
- Module 3: §44(3) and the RTI Act - §44(3) substitutes clause (j) of §8(1) of the RTI Act with a bare exemption: “information which relates to personal information”. The old proviso — larger public interest justifying disclosure — is gone, so the public-interest balance now runs entirely through §8(2) of the RTI Act.
- Module 4: Consent + cross-border transfer - the DPDP consent-manager framework (Rule 4, phasing in one year after notification), child data, and the Rule 13(4) restriction under which government-specified personal data cannot leave India.
- Module 5: How to file a DPDP complaint vs an RTI - the right route depending on what you want.
Certificate
- Issued to: [download from the link sent to your registered email]
- Issued by: RTI Wiki Editorial Team
- Verifies: Completion of 5-module DPDP + RTI overlap training
- Verification URL: https://righttoinformation.wiki/verify-cert.html
Course modules
What to do next
- Follow the Board's rollout. The Data Protection Board of India is constituted under §18 of the Act, and the Rules already in force (17 to 21) cover its appointment, meetings and digital-office functioning. Watch meity.gov.in for the Board's complaint portal as the later phases go live.
- File an RTI to read your data fiduciary's audit trail (if it is a public authority) - an SDF subject to Rule 13 must run an annual DPIA and audit; ask for the report's significant observations. Use the AI RTI Drafter.
- Track your own deadlines - first appeal within 30 days, second appeal within 90 days - in the Timeline Tracker.
- Read the canonical pillar: Complete DPDP Act 2023 guide.
Citations grounded in this course
- Digital Personal Data Protection Act, 2023 (Act 22 of 2023), brought into force in phases by notifications dated 13 November 2025, first phase effective 14 November 2025.
- Digital Personal Data Protection Rules, 2025 - notification G.S.R. 846(E), New Delhi, 13 November 2025, Gazette of India (Extraordinary); commencement per its Rule 1.
- DPDP Act, §44(3) - substitutes §8(1)(j) of the RTI Act 2005 with “information which relates to personal information”.
- CPIO, Supreme Court of India v. Subhash Chandra Agarwal (2020) 5 SCC 481 - the personal-information balance test for judges' assets; its reasoning on public interest remains the touchstone post-DPDP, now read with §8(2).
- Justice K S Puttaswamy v. Union of India (2017) 10 SCC 1 - constitutional foundation of privacy as a fundamental right, the decision the DPDP Act operationalises.
Example. Priya, a compliance lead at a Himachal fintech startup, finished this course in April 2026 and audited her firm the same month: DPO named and published (§10(2)(a)), a ₹25,000 DPIA consultancy engagement scheduled against Rule 13's annual cycle, and an RTI filed to her district authority using the First Appeal Builder after a PIO cited §8(1)(j) on a contract file — the appeal invoked §8(2) balancing and won partial disclosure in 3 weeks.
FAQ
Is the whole DPDP Act in force now?
No — and this is the exam answer. The notifications dated 13 November 2025 switched on the institutional framework from 14 November 2025; the consent-manager phase follows a year on, and the core data-fiduciary obligations and penalty provisions complete the phase that ends May 2027. Check meity.gov.in before dating any compliance claim.
Is the RTI amendment already applicable?
Yes. §44(1) and §44(3) were in the first phase, so §8(1)(j) of the RTI Act now reads as substituted: “information which relates to personal information”. PIOs citing the old proviso wording are citing deleted text.
Did §44(3) delete the proviso to §8(1)(j)?
It substituted the whole clause, which is broader: the old clause (j), including its proviso and its public-activity carve-out, was replaced by the bare personal-information exemption. The balance now lives in §8(2).
Do all data fiduciaries need a Data Protection Officer?
No. The Act's DPO requirement sits on Significant Data Fiduciaries (§10(2)(a)). Every fiduciary must still publish a contact point for data principals, but a formal DPO is an SDF obligation.
What exactly does Rule 13 require of an SDF?
A Data Protection Impact Assessment and an audit once every twelve months from notification as an SDF, the report's significant observations furnished to the Board, due diligence on algorithmic software, and the transfer restriction for government-specified data.
Where do I file a DPDP complaint?
With the Data Protection Board of India under §18 as its portal phases in — watch meity.gov.in. Note the difference: an RTI under RTI Act 2005 gets you records; a DPDP complaint seeks action on data misuse. The case-law database tracks RTI-side rulings.
Can a public authority refuse an RTI citing the DPDP Act now?
It can cite §8(1)(j) as substituted — personal information is exempt on its face — but §8(2) still commands disclosure where public interest in a democratic country outweighs the harm. That is the post-DPDP battleground; grounds for rejection tracks the rulings.
Does the ₹250 crore penalty apply per breach?
The schedule sets ₹250 crore as the ceiling for breach of the §8(5) security-safeguard obligation — “may extend to” per instance, in the Board's discretion. Lesser ceilings apply to the other breach categories.
Related on RTI Wiki
Sources
- Digital Personal Data Protection Act, 2023 (Act 22 of 2023) — text from meity.gov.in
- Digital Personal Data Protection Rules, 2025 — notification G.S.R. 846(E) dated 13 November 2025, Gazette of India (Extraordinary), meity.gov.in
- Right to Information Act, 2005, §8(1)(j) as substituted
- MeitY commencement notifications dated 13 November 2025 (first phase effective 14 November 2025)
Last reviewed: 26 August 2026. Verified the phased commencement and G.S.R. 846(E) Rule 1 text, the §44(3) substitution wording, the penalty schedule and the §10(2)(a) DPO obligation directly against the DPDP Act and Rules PDFs hosted on meity.gov.in, and confirmed dpb.gov.in is offline.
