PCLS

The Progressive Constitutional Law Society
Hidayatullah National Law University

Privacy Cannot Become a Password For Secrecy: Reclaiming the Balance between Data Protection and Information Access

The author, Devansh Awasthi, is a 3rd-year law Student at Dr. Ram Manohar Lohiya National Law University, Lucknow (RMLNLU)

“Privacy should protect citizens from exposure, not the State from explanation.”

Thesis: the privacy-RTI debate is a category error

The debate is not really about whether the Digital Personal Data Protection Act, 2023 (‘DPDP Act’) should prevail over the Right to Information Act, 2005 (‘RTI Act’), or the other way around. Both rights resist domination: privacy restrains exposure of individuals, while RTI restrains unaccountable and unchecked State power. The problem created by Section 44(3) of the DPDP Act is more specific. By amending Section 8(1)(j) of the RTI Act, it treats every record about an identifiable person as if it was equally private. It collapses two different categories: personal information and privacy-sensitive information. This collapse is problematic because the entire domain of public administration is filled with personal information, whether tender evaluations or inspection reports, recruitment records, disciplinary findings, welfare rejections, disclosures of conflict, all concern persons. However, they are not private just because they concern persons. The constitutional question at stake is whether disclosure reveals private life or exercise of public power.

What the amendment shaves off, and why it matters

The old version of Section 8(1)(j) of the RTI Act did three separate stages of sifting: “did the information have relation…with any public activity or interest…[would disclosure] cause unwarranted invasion of privacy…[and] even where privacy is involved, it…protects disclosure when equal or greater public interest justifies”. The amended clause did not, therefore, prioritize the RTI Act over privacy mechanically. It demanded reasons. The amended clause is indeed, narrower in words, but wider in application. This reading also cannot ignore Section 8(2) of the RTI Act, which preserves a public interest override even where an exemption is otherwise available. The point is important because the amended Section 8(1)(j) should not be read as a self-contained wall. It remains part of a statute that was designed to make secrecy the exception and disclosure the norm. If this amended clause is treated as automatically defeating disclosure whenever the record relates to an identifiable person, Section 8(2) is reduced to dead text in precisely the class of cases where it is most needed. Refusal is permissible where the information relates to personal information. If so, understood literally, this takes the inquiry from harm to identifiability. That would be a phenomenal doctrinal rollback. A harm-based exemption asks what disclosure will accomplish, not whom the record relates to. Constitutional privacy cannot be raised out of mere identifiability. In Justice K.S. Puttaswamy v Union of India, privacy is in the nature of decisional autonomy, dignity and informational control against real intrusion. It does not convert any and every fact about a person technologically held into claims of secrecy that can invoke the “RTI should not be preferred to Privacy” conception. The deletion of the old words should under no circumstances be confused with deletion of the constitutional balance itself. The Parliament can change words, but can’t expunge Article 19(1)(a) of the Indian Constitution, which provides for access to information by simply drafting a secrecy exemption widely. The Supreme Court (‘SC’) in State of U.P v Raj Narain recognized right to know and stated, “The obligation to give information to the people has a direct and vital nexus with democratic accountability itself”, which was foundational and intrinsic to meaningful democratic choice, in Union of India v Association for Democratic Reforms. The amended exemption will, therefore, have to be read not as a secrecy rule, but as a privacy one.

Correct unit of analysis is the field, not the file

A broad reading of amended Section 8(1)(j) of the RTI Act is fundamentally indefensible because it treats a file as a seamless whole. In practice, the overwhelming majority of State records are composites. A recruitment file may contain addresses and numbers, but also marks, selection criteria and reasons for appointment. A welfare file may contain bank details and medical information, but also eligibility rules, rejection reasons and allocation data. A contract file may contain personal contact details, but also tender scores, conflict disclosures and inspection findings. Once this is recognised, complete refusal becomes the outlier. Severance should be the norm: protect the privacy-bearing fields, disclose the accountability-bearing fields. This is not external layering; it flows from the very structure of the RTI law itself, including Section 10 of the RTI Act, which itself speaks of partial access to exempt material according to its nature and meaning that is severable from the rest. A public authority that does not give access to an entire file merely because some lines of it may contain personal information, failing to balance the rights, actually permits the most private part of a record to do much to nullify the most public part.

This approach also does not erase the protection presently available to third parties. Where information relates to a third party, Section 11 of the RTI Act continues to require notice and representation. Section 11 of the RTI Act is a consultative safeguard, not a veto. It gives the person concerned a chance to make out the privacy harm, but leaves the ultimate decision with the authority under the statute. Similarly, the law permits neither blind disclosure nor blind refusal.

Case law supports a contextual approach

The case law already supplies the context that a broad reading of the RTI amendments risks losing. In Central Public Information Officer, Supreme Court of India v Subhash Chandra Agarwal (2011), the SC rejected both polar views. It did not accept that a public office extinguished a claim to privacy or that privacy defeated institutional accountability. It left us with an inquiry about the nature of the information sought, the position of the seeker, the purpose of disclosure and particular public interest. In contrast, Girish Ramchandra Deshpande v Central Information Commissioner and Canara Bank v C.S. Shyam are better not read as cases on that fine line between weak public interest and strong privacy in routine service records. They don’t declare that everything about the employee is unconstitutionally off-limits, and the reasoning collapses when the information requested is about recruiting irregularity, conflict of interest, misuse of public money, corruption, exclusion from welfare or the reason for State action. In those cases, the information is personal in form, but public in function.

Accountable privacy: the interpretive test that ought to be undertaken

A narrow constitutional construction of Section 8(1)(j) of the RTI Act as amended, should incorporate an accountable privacy test. The test keeps privacy meaningful, forbidding it as administrative veto. Before refusing information, public authorities should first answer these four questions in writing:

1. Function: Does the information pertain to a public function, have a public appointment, public money, public contract, public welfare scheme, public examination, public disciplinary process, or regulatory approval? If yes, the presumption should shift from secrecy to openness.

2. Harm: What is the specific concrete privacy harm that disclosure will cause? The answer should not be simply that it is private. The authority must identify the injury; it might be called out in exposure of medical history, exposure of family circumstances, exposure of contact details, exposure of financial identifiers, exposure of intimate personal detail.

3. Severance: Can harm to privacy be reduced by severance, redaction, anonymisation, aggregation, delayed public disclosure, partial access? If yes, is that reasonably available to the authority? If yes, they must use that method instead of refusing the record as a whole.

4. Weight: After minimisation, does the public interest in disclosure outweigh the remaining harm to privacy? Special weight should attach to requests relating to corruption, arbitrariness, discrimination, leakage of public funds, recruitment opacity and denial of statutory entitlements.

This test also follows from the burden structure of the RTI Act. Under Section 19(5) of the RTI Act, the burden of proving that a denial of access was justified lies on the Central Public Information Officer or State Public Information Officer who denied the request. Therefore, a privacy-based refusal cannot rest on repeated use of the word personal. The authority must show why the information is privacy-sensitive, why severance is inadequate, and why the public interest in disclosure is outweighed. This keeps privacy as a reasoned legal inquiry, not a label. It is also more faithful to Puttaswamy’s proportionality analysis because it asks whether non-disclosure is necessary, whether lesser measures will work, and whether the remaining privacy interest outweighs the public interest.

How this makes a difference

In this manner, the rule is an anchor to salvation. Where recruitment is concerned, addresses, Aadhaar numbers and phone numbers may be blacked out, but not marks, nor criteria, nor interview allocation, nor panel composition, nor reasons for selection. If not, privacy is merely a raft of nepotism. Where welfare delivery is involved, health identifiers and bank details may not be revealed, but eligibility criteria, reject reasons, beneficiary counts, audit reports, district-wise allocation of notional funds, etc., may be disclosed in anonymised or aggregated form. If not, privacy is a raft of exclusion. Where public contracts are involved, personal contact details may be shielded, but tender scores, inspection reports, disclosures of conflict, reasons for approval, should remain accessible. If not, privacy is a raft of favouritism.

These examples illustrate the power of the distinction between private life and public power versus private and non-private information. The distinction between private life and public power tracks constitutional harm. The distinction between personal information and non-personal information simply tracks the data status of the information. RTI cannot survive if the data status is all that matters for decision about access.

Conclusion: privacy must discipline disclosure, not defeat it

Finally, the current government claims that the DPDP framework preserves privacy while upholding RTI and cites its public explanation for further evidence. There is an obligation to correct this claim from ex gratia to fact. A constitutional challenge in due course may possibly do the trick, but public authorities and information commissions don’t need to photocopy Clause 15 to steer clear of overbreadth. They can read the amended provision through the lens of proportionality and severance and public interest.

The final rule should be that private life is protected, but public power is inspectable. Where both exist in the same record, the constitutional answer is edited disclosure, not total refusal. Privacy cannot masquerade as password for State secrecy, because the purpose of privacy is to protect the citizen, not expose the State.

Leave a Reply

Discover more from PCLS Blog: HNLU

Subscribe now to keep reading and get access to the full archive.

Continue reading