DPDP Act vs IT Act SPDI Rules: What Changed in India's Data Protection Law
From Section 43A and the 2011 SPDI Rules to the Digital Personal Data Protection Act, 2023.
What are the IT Act SPDI Rules and how does the DPDP Act replace them?
Why this comparison matters
Most Indian privacy policies, vendor contracts and ISO 27001 statements of applicability were written against the SPDI Rules. Those documents reference "sensitive personal data or information", "body corporate", "reasonable security practices" and IS/ISO/IEC 27001 as the safe harbour. The DPDP Act changes the vocabulary, widens the scope and shifts enforcement from compensation claims to regulatory penalties. Updating these artefacts is one of the first tasks in any DPDP programme.
For the new framework end to end, see our plain-English guide to the DPDP Act and the annotated Act and Rules.
SPDI Rules and DPDP Act: Key Terms
The vocabulary change is the part that breaks existing documents: "body corporate" becomes Data Fiduciary and Data Processor, and a new Consent Manager role appears that the 2011 Rules had no place for.
- IT Act
- Information Technology Act, 2000, India's primary law on electronic records, cybercrime and intermediaries.
- Section 43A
- Provision inserted in 2008 making a body corporate liable to pay compensation if negligent in implementing reasonable security practices for sensitive personal data, causing wrongful loss or gain. Omitted by the DPDP Act.
- SPDI Rules
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, issued under Section 43A.
- Sensitive personal data or information (SPDI)
- Under Rule 3: passwords; financial information such as bank account, card or payment details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; and related information received for service.
- Body corporate
- The SPDI Rules applied only to companies, firms, sole proprietorships and associations engaged in commercial or professional activities.
- Section 72A
- IT Act offence for disclosure of personal information in breach of lawful contract; punishable with imprisonment up to three years or fine up to INR 5 lakh. Continues alongside the DPDP Act.
- Reasonable security practices
- Rule 8: documented security programme; IS/ISO/IEC 27001 named as an acceptable standard, subject to audit by a Government-approved auditor.
- Data Protection Board of India
- Adjudicating authority created by the DPDP Act; replaces the Adjudicating Officer route under the IT Act for personal data matters.
DPDP Act vs SPDI Rules: Comparison Table
| Dimension | IT Act Section 43A and SPDI Rules 2011 | DPDP Act 2023 and DPDP Rules 2025 |
|---|---|---|
| Nature of law | Delegated rules under a cybersecurity statute. | Standalone parliamentary data protection law. |
| Data covered | Sensitive personal data or information (narrow list) plus limited duties for other personal information. | All digital personal data, and non-digital data that is subsequently digitised. |
| Who is covered | Body corporates only. Government excluded. | Any person processing digital personal data, including the State (with exemptions). |
| Extraterritorial reach | None expressly. | Applies to processing outside India connected to offering goods or services in India. |
| Roles defined | Body corporate and provider of information. | Data Fiduciary, Data Processor, Data Principal, Significant Data Fiduciary, Consent Manager. |
| Consent | Consent in writing (including electronic) for SPDI collection; opt-out option required. | Free, specific, informed, unconditional, unambiguous consent by affirmative action, with a prescribed notice; withdrawal as easy as giving. |
| Privacy policy | Publish a privacy policy covering type of data, purpose, disclosure and security practices. | Itemised notice at or before consent, plus publication of grievance and withdrawal channels; policy remains good practice. |
| Purpose limitation and retention | Retain no longer than lawfully required; use for stated purpose. | Erase when purpose is served or consent withdrawn; Third Schedule sets three-year inactivity rule for large e-commerce, gaming and social media intermediaries. |
| Individual rights | Review and correction of information; option to withdraw consent. | Access, correction, completion, updating, erasure, grievance redressal, nomination. |
| Children | No specific provisions. | Verifiable parental consent for under-18s; ban on tracking, behavioural monitoring and targeted advertising. |
| Security standard | Reasonable security practices; ISO 27001 as safe harbour if audited annually. | Reasonable security safeguards defined in Rule 6 (encryption, access control, logging, monitoring, backups, contractual controls); no named safe harbour. |
| Breach notification | None under SPDI Rules; CERT-In directions (2022) require reporting of cyber incidents within six hours. | Mandatory notification of every personal data breach to the Board and affected individuals; detailed report to Board within 72 hours. |
| Cross-border transfer | Permitted where the recipient ensures the same level of protection and transfer is necessary or consented. | Permitted except to countries restricted by the Central Government; additional SDF restrictions possible. |
| Governance roles | Grievance officer to be designated and published. | Grievance contact for all Fiduciaries; India-based DPO and independent auditor for SDFs. |
| Regulator | Adjudicating Officer (Section 46) for compensation claims; no dedicated authority. | Data Protection Board of India with inquiry and penalty powers; appeals to TDSAT. |
| Enforcement outcome | Civil compensation to the affected person; no cap under Section 43A. | Monetary penalties paid to the Consolidated Fund: up to INR 250 crore per instance; no statutory compensation route. |
| Individual duties | None. | Data Principals must not impersonate, suppress information or file false complaints; penalty up to INR 10,000. |
| Status | Section 43A omitted and SPDI Rules superseded on full commencement of the DPDP Act. | Phased commencement: definitions and Board from 14 November 2025; full obligations from 13 May 2027. |
What Carries Over, What Changes and What Is New
Carries over from the SPDI Rules
- The principle of reasonable security practices. An ISO 27001 certified ISMS remains the most efficient evidence base, though it is no longer an explicit safe harbour.
- Grievance officer designation and published contact.
- Purpose limitation and retention discipline.
- CERT-In incident reporting obligations under the IT Act continue in parallel with DPDP breach reporting.
- Section 72A criminal liability for disclosure in breach of contract.
Changes under the DPDP Act
- Scope widens from an SPDI list to all digital personal data. Names, phone numbers, email addresses and addresses are now in scope.
- Consent moves from "written consent with opt-out" to a prescribed notice and affirmative, purpose-specific consent with withdrawal parity.
- Enforcement moves from victim-initiated compensation claims to regulator-imposed penalties.
- Coverage extends from body corporates to all persons, including government bodies, with defined exemptions.
New under the DPDP Act
- Mandatory breach notification to the Board and to every affected individual.
- Children's data regime with verifiable parental consent.
- Significant Data Fiduciary tier with DPO, audit, DPIA and algorithmic due diligence duties.
- Consent Managers as Board-registered intermediaries.
- Data Principal rights to erasure and nomination.
- Extraterritorial application and Central Government power to restrict transfers to specific countries.
The SDF tier is the largest of these additions — Significant Data Fiduciary (SDF) explained covers who is likely to be notified and what it costs.
SPDI to DPDP Migration Checklist
- Rewrite the privacy policy and all consent language: replace "sensitive personal data or information" and "body corporate" with DPDP terminology and add the prescribed notice elements.
- Extend the data inventory from SPDI categories to all personal data, including employee, vendor and marketing data.
- Re-paper vendor and customer contracts: DPDP Processor clauses, breach cooperation, erasure and sub-processing.
- Upgrade the incident response plan: add DPDP breach classification, Board notification within 72 hours and individual notification templates, alongside the CERT-In six-hour report.
- Map ISO 27001 Annex A controls to Rule 6 security safeguards and document the gaps (particularly logging retention of one year and data-flow monitoring).
- Implement Data Principal rights workflows and publish grievance timelines.
- Assess SDF likelihood and, if likely, appoint an India-based DPO and independent auditor.
- Set retention schedules and automated erasure, with the Third Schedule three-year rule where applicable.
If you also carry an EU obligation, the mapping runs three ways — DPDP vs GDPR: key differences sets out which GDPR artefacts survive the move.
Frequently Asked Questions: DPDP Act vs IT Act
Key takeaways
- SPDI Rules covered a narrow list of sensitive data held by body corporates; the DPDP Act covers all digital personal data held by anyone.
- Enforcement shifts from compensation claims to Board-imposed penalties of up to INR 250 crore.
- Breach notification, children’s data, SDF tier, Consent Managers and erasure rights are entirely new.
- ISO 27001 remains the practical security backbone but no longer provides a statutory safe harbour.
- Both regimes overlap until 13 May 2027; update policies and contracts now.