Dpdp act vs it act what changed

From SPDI compliance to full digital-data accountability

India's privacy law has not merely changed. The entire accountability model underneath it has been rebuilt.

 

For over a decade, the Information Technology Act, 2000 (IT Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — commonly known as the SPDI Rules — defined privacy compliance in India. That framework focused narrowly on Sensitive Personal Data or Information (SPDI): passwords, financial details, health records. It leaned on a negligence standard: an organisation was liable mainly if it failed to follow "reasonable security practices" and that failure caused wrongful loss or gain.

 

The Digital Personal Data Protection Act, 2023 (DPDP Act), now paired with the Digital Personal Data Protection Rules, 2025 (DPDP Rules), replaces that model with something structurally different: a rights-based, accountability-first framework that treats all digital personal data as in scope — not just a sensitive subset.

 

For compliance and legal teams, the distinction matters far more than terminology. This isn't a policy update. It is an operating-model change, and organisations that treat it as the former will be under-prepared when core obligations phase in.

 

 

Two Laws, Two Eras

The IT Act 2000 and SPDI Rules 2011 were built for a narrower moment in India's digital economy, before app ecosystems and cross-border data flows became the default mode of doing business. Obligations centred on "body corporates" handling a defined list of SPDI, with compliance largely proven after the fact — through internal audits, and, if something went wrong, compensation claims under Section 43A of the IT Act.

 

The DPDP Act 2023 and DPDP Rules 2025 start from a different premise. Any entity that determines the purpose and means of processing digital personal data — termed a Data Fiduciary — carries obligations from the outset, regardless of whether the data would have been classified as "sensitive" under the older framework. The law also has extra-territorial reach, applying wherever processing relates to offering goods or services to individuals in India, even if the entity is based abroad. (Sector-specific breach duties under RBI or CERT-In frameworks existed separately from SPDI and should be checked against industry-specific obligations.)

 

 

The Phased Rollout Timeline

The dates below are drawn from the source infographic and should be cross-checked against the official Gazette notification from MeitY before publishing, as implementation timelines for subordinate rules are frequently subject to amendment.

 

  • Date
  • Milestone
  • 2011
  •             IT Act + SPDI Rules baseline
  • 14 Nov 2025
  •             DPDP Rules notified; Board-related provisions begin
  • Nov 2026
  •             Consent Manager framework commences
  • May 2027
  •             Core DPDP obligations phase in for Data Fiduciaries

 

The staggered approach gives organisations lead time — but it is a build phase, not a grace period. Systems for consent management, breach response, and rights fulfilment take months to operationalise properly; starting at the deadline is starting too late.

 

Side-by-Side: What Changed, Clause by Clause

 

  • Dimension
  • Earlier: IT Act 2000 + SPDI Rules 2011
  • Now: DPDP Act 2023 + DPDP Rules 2025
  • Who / Scope
  • Body corporates; duties centred on SPDI.
  • Data Fiduciaries and processors handling digital personal data, with extra-territorial reach.
  • Data Covered
  • A defined list of sensitive data — passwords,  financial data, health, sexual orientation, biometric information.
  • All digital personal data, no separate "sensitive" tier. Children's data gets distinct, elevated protection.
  • Notice & Lawful Use
  • Written consent required for SPDI, subject to lawful purpose and necessity.
  • Consent or a specified "legitimate use," with granular notice; consent must be an affirmative act and as easy to withdraw as to give.
  • Individual Rights
  • Review/correction of data, consent withdrawal, grievance mechanism.
  • Access, correction, completion, erasure, grievance redressal, and nomination of a representative after death or incapacity.
  • Security Obligations
  • "Reasonable security practices," a documented programme, periodic audit.
  • Encryption/masking, access controls, monitoring, backups, mandatory processor clauses, one-year log retention.
  • Data Breach
  • No direct duty to notify affected individuals or a dedicated regulator.
  • Notify affected individuals without delay; notify the Data Protection Board within 72 hours.
  • Children's Data
  • No dedicated child-data framework.
  • Verifiable parental consent; restrictions on tracking, behavioural monitoring, targeted ads to children.
  • Cross-Border Transfer
  • Recipient must ensure equivalent protection; contractual/consent-based transfer.
  • Permitted by default, subject to government-notified restrictions and specified transfer requirements.
  • Regulator & Penalty
  • No dedicated regulator; Section 43A compensation for negligent security causing loss/gain.
  • Data Protection Board of India; Significant Data Fiduciaries face added duties (DPO, DPIA, audits); penalties up to INR 250 crore.

 

Why This Is an Operating-Model Shift, Not a Policy Tweak

Under the earlier regime, a business could largely treat privacy as a documentation exercise: write a policy, secure consent for the data types flagged as sensitive, retain an audit trail, and respond if something went wrong.

 

The DPDP framework removes that option, for four structural reasons. The law applies to all digital personal data, so "sensitive data" carve-outs no longer limit scope. Consent must be genuinely granular and as easy to withdraw as to give, so front-end products need re-engineering, not a longer terms-of-service page. Breach notification runs on a hard 72-hour clock, so incident response has to be operational, not theoretical. And processors are now contractually and legally on the hook, turning vendor management into a compliance function rather than a procurement afterthought.

 

The law, in effect, expects continuous and demonstrable governance — evidence produced on an ongoing basis, not a policy statement pointed to only after an incident.

 

 

What Organisations Should Build Now

The transition window between now and the 2027 core-obligation deadline should be used to build, not wait. Six priorities stand out:

 

  1. Data inventory and mapping — Know what digital personal data you hold, where it lives, and who processes it.
  2. Consent, notice, and withdrawal mechanisms — Rebuild consent flows so notice is genuinely granular and withdrawal is as easy as opt-in.
  3. Rights and grievance workflows — Operationalise access, correction, erasure, and grievance handling with real turnaround times.
  4. Processor and vendor contracts — Audit every vendor relationship involving personal data and update contracts to reflect DPDP-mandated processor obligations.
  5. 72-hour breach-response playbook — Build and rehearse an incident response process that can meet the notification and reporting clock.
  6. DPO, DPIA, and audit governance — Entities likely to be classified as Significant Data Fiduciaries should build DPO, DPIA, and audit structures well ahead of the deadline.

 

The Bottom Line

DPDP compliance is not a privacy-policy update. It is an enterprise-wide shift from proving good intentions after an incident to demonstrating continuous, evidenced governance before one ever happens. Organisations that treat the phased rollout as a waiting period will build under deadline pressure; those that treat it as a build phase will be ready to show — not just claim — that they meet the standard.

 

Reference: Key Full Forms

Abbreviation Full Form
IT Act Information Technology Act, 2000
SPDI Sensitive Personal Data or Information
SPDI Rules Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
DPDP Act Digital Personal Data Protection Act, 2023
DPDP Rules Digital Personal Data Protection Rules, 2025
SDF Significant Data Fiduciary
DPO Data Protection Officer
DPIA Data Protection Impact Assessment
MeitY Ministry of Electronics and Information Technology
RBI Reserve Bank of India
CERT-In Indian Computer Emergency Response Team



Comments

No Comments Found.