Chapter IX · Miscellaneous
Section 44 — Amendments to certain Acts
What this section requires
Section 44 makes three consequential amendments to other Acts. It adds the Appellate Tribunal under this Act (alongside the existing IT Act and Airports Economic Regulatory Authority tribunals) to the list in Section 14(c) of the TRAI Act, 1997 — reflecting that TDSAT is the Appellate Tribunal for DPDP appeals too. It amends the Information Technology Act, 2000 by omitting Section 43A (the old compensation-for-data-breach provision, now superseded by this Act's own breach regime), adding a cross-reference to this Act in Section 81's proviso, and omitting clause (ob) of Section 87(2) (the IT Act's reasonable-security-practices rule-making power, likewise superseded). It also substitutes Section 8(1)(j) of the Right to Information Act, 2005, narrowing what personal information a public authority must disclose under the RTI Act's exemption.
Who it applies to
No Data Fiduciary directly — these are amendments to the statute book itself (TRAI Act, IT Act, RTI Act), not a standalone obligation.
Checklist
- If you previously relied on IT Act Section 43A for a data-breach compensation framework, note it has been omitted — DPDP's own breach and penalty regime (Sections 8(6), 33, and the Schedule) is what now governs.
- If you handle RTI requests as a public authority, the amended Section 8(1)(j) of the RTI Act is the current text governing personal-information exemptions, not the pre-2023 wording.
Penalty exposure
Not applicable — a consequential-amendments section carries no penalty of its own.
Implementation timeline
Sub-sections (1) and (3) — the TRAI Act and RTI Act amendments — are in force since 13 November 2025.
Sub-section (2) — the Information Technology Act amendments — commences 13 May 2027, with the rest of Chapter II's substantive-obligation timeline.
Section 44
