From SPDI compliance to full digital-data accountability
India's privacy law has not merely changed. The entire accountability model underneath it has been rebuilt.
For over a decade, the Information Technology Act, 2000 (IT Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — commonly known as the SPDI Rules — defined privacy compliance in India. That framework focused narrowly on Sensitive Personal Data or Information (SPDI): passwords, financial details, health records. It leaned on a negligence standard: an organisation was liable mainly if it failed to follow "reasonable security practices" and that failure caused wrongful loss or gain.
The Digital Personal Data Protection Act, 2023 (DPDP Act), now paired with the Digital Personal Data Protection Rules, 2025 (DPDP Rules), replaces that model with something structurally different: a rights-based, accountability-first framework that treats all digital personal data as in scope — not just a sensitive subset.
For compliance and legal teams, the distinction matters far more than terminology. This isn't a policy update. It is an operating-model change, and organisations that treat it as the former will be under-prepared when core obligations phase in.
The IT Act 2000 and SPDI Rules 2011 were built for a narrower moment in India's digital economy, before app ecosystems and cross-border data flows became the default mode of doing business. Obligations centred on "body corporates" handling a defined list of SPDI, with compliance largely proven after the fact — through internal audits, and, if something went wrong, compensation claims under Section 43A of the IT Act.
The DPDP Act 2023 and DPDP Rules 2025 start from a different premise. Any entity that determines the purpose and means of processing digital personal data — termed a Data Fiduciary — carries obligations from the outset, regardless of whether the data would have been classified as "sensitive" under the older framework. The law also has extra-territorial reach, applying wherever processing relates to offering goods or services to individuals in India, even if the entity is based abroad. (Sector-specific breach duties under RBI or CERT-In frameworks existed separately from SPDI and should be checked against industry-specific obligations.)
The dates below are drawn from the source infographic and should be cross-checked against the official Gazette notification from MeitY before publishing, as implementation timelines for subordinate rules are frequently subject to amendment.
|
|
|---|---|
|
|
|
|
|
|
|
|
The staggered approach gives organisations lead time — but it is a build phase, not a grace period. Systems for consent management, breach response, and rights fulfilment take months to operationalise properly; starting at the deadline is starting too late.
|
|
|
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Under the earlier regime, a business could largely treat privacy as a documentation exercise: write a policy, secure consent for the data types flagged as sensitive, retain an audit trail, and respond if something went wrong.
The DPDP framework removes that option, for four structural reasons. The law applies to all digital personal data, so "sensitive data" carve-outs no longer limit scope. Consent must be genuinely granular and as easy to withdraw as to give, so front-end products need re-engineering, not a longer terms-of-service page. Breach notification runs on a hard 72-hour clock, so incident response has to be operational, not theoretical. And processors are now contractually and legally on the hook, turning vendor management into a compliance function rather than a procurement afterthought.
The law, in effect, expects continuous and demonstrable governance — evidence produced on an ongoing basis, not a policy statement pointed to only after an incident.
The transition window between now and the 2027 core-obligation deadline should be used to build, not wait. Six priorities stand out:
DPDP compliance is not a privacy-policy update. It is an enterprise-wide shift from proving good intentions after an incident to demonstrating continuous, evidenced governance before one ever happens. Organisations that treat the phased rollout as a waiting period will build under deadline pressure; those that treat it as a build phase will be ready to show — not just claim — that they meet the standard.
| Abbreviation | Full Form |
|---|---|
| IT Act | Information Technology Act, 2000 |
| SPDI | Sensitive Personal Data or Information |
| SPDI Rules | Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 |
| DPDP Act | Digital Personal Data Protection Act, 2023 |
| DPDP Rules | Digital Personal Data Protection Rules, 2025 |
| SDF | Significant Data Fiduciary |
| DPO | Data Protection Officer |
| DPIA | Data Protection Impact Assessment |
| MeitY | Ministry of Electronics and Information Technology |
| RBI | Reserve Bank of India |
| CERT-In | Indian Computer Emergency Response Team |