At a glanceBefore the DPDP Act, India protected personal data through Section 43A of the IT Act, 2000 and the SPDI Rules, 2011 — a narrow regime that only covered sensitive data, only bound body corporates, and was weakly enforced. The DPDP Act omits it and replaces it with a comprehensive law: it covers all digital personal data, binds every Data Fiduciary, adds enforceable rights, and carries penalties up to ₹250 crore.
Educational resource only. This explains how the DPDP Act — India’s Digital Personal Data Protection Act, 2023 (DPDP Act) — replaces the earlier IT Act framework; it is not formal legal advice.
What protected personal data before the DPDP Act?
India’s old data-protection regime was a single clause bolted onto a cyber-law — the Information Technology Act, 2000 (IT Act), and the rules under it. Those rules — the Sensitive Personal Data or Information (SPDI) Rules, 2011 — required a “body corporate” holding sensitive personal data (passwords, financial information, health, biometrics, and a few other categories) to maintain “reasonable security practices and procedures.” In practice, compliance often meant adopting a standard like ISO 27001.
It was, by design, narrow. It reached only sensitive data, only commercial “body corporates,” and offered individuals little beyond a hard-to-use claim for compensation. There was no dedicated regulator and no meaningful penalty regime.
What’s the headline change?
The DPDP Act swaps a narrow, incidental rule for a broad, purpose-built law — wider scope, real rights, and serious penalties. The shift lands on three axes:
- What’s covered: from sensitive data only → all digital personal data (your customers’ names, phone numbers and emails, not just their financial or health data).
- Who’s bound: from body corporates → any Data Fiduciary — a clinic, an agency, a solo professional, a startup — anyone deciding why and how personal data is processed.
- Teeth: from a weak compensation claim with no regulator → a dedicated Data Protection Board, enforceable individual rights (access, correction, erasure, grievance, withdrawal), and penalties up to ₹250 crore.
In short, protection stops being an afterthought inside a cyber-crime statute and becomes a standalone obligation with consequences.
Does DPDP drop the “sensitive personal data” category?
Yes — this is the change that surprises people who built their old compliance around it. The SPDI regime turned on a defined list of sensitive categories; everything outside that list was largely unregulated. The DPDP Act does away with that split. It protects all personal data under one baseline set of obligations — notice, consent, purpose limitation, security, retention limits, and rights — regardless of whether the data feels “sensitive.”
The Act does single out one group for tighter treatment — children’s data, which needs verifiable parental consent — but it does not recreate the old SPDI-style “sensitive data” tier. The working assumption flips: instead of “only sensitive data is regulated,” it’s now “all personal data is, unless a specific exemption applies.”
What if you already did SPDI / ISO 27001 compliance?
Your old security work is a useful foundation — but it covers only a corner of what the DPDP Act now asks. The SPDI Rules were essentially about keeping sensitive data secure. Security is still required (reasonable safeguards remain an obligation, backed by the top ₹250 crore penalty tier), so that effort carries over. But the DPDP Act adds a whole layer the old regime never had:
- a proper notice at the point of collection;
- valid consent, per purpose, and as easy to withdraw as to give;
- purpose limitation and retention limits (erase when done);
- Data Principal rights you must be able to fulfil; and
- breach notification to the Board and affected people.
So an ISO 27001 certificate answers the “are you secure?” question, not the “are you meeting the DPDP Act?” question. The gap between the two is the work of the transition.
Is Section 43A still in force?
It’s on its way out — the DPDP Act omits it, and the SPDI Rules under it fall away with it. The change is part of the DPDP Act’s consequential amendments to the IT Act. Because the Act’s substantive provisions are being switched on in stages (the core obligations become binding on 13 May 2027), this is a transition rather than an overnight swap — but the direction is settled: the old framework is being replaced, not run in parallel indefinitely.
The practical takeaway is not to keep building on the old provision. New compliance work should be aimed at the DPDP Act’s requirements, which are broader and carry the real penalties.
FAQ
Does the DPDP Act replace the IT Act’s data protection rule?
Yes. It omits that old provision and supersedes the SPDI Rules, 2011, replacing that narrow regime with a comprehensive one.
Was only “sensitive” data protected before?
Largely, yes — the SPDI Rules focused on sensitive personal data held by body corporates. The DPDP Act protects all digital personal data.
Is my ISO 27001 certification enough for DPDP?
No. It helps with the security obligation but doesn’t cover notice, consent, rights, retention, and breach notification, which the DPDP Act also requires.
Does DPDP still have a “sensitive personal data” category?
No. It applies one baseline to all personal data, with special rules for children’s data rather than a general sensitive-data tier.