The Old Regime Is Not Gone. It Ends in May 2027.
Almost every summary of the DPDP Act says it repealed section 43A of the IT Act. Read the commencement notification and that is not yet true. The sub-section doing the repealing has not started, which means two data protection regimes apply to Indian organisations at the same time.
The commencement notification issued with the DPDP Rules on 13 November 2025 brought sub-sections (1) and (3) of section 44 into force immediately, and placed sub-section (2) in the eighteen-month tranche. So the Act has already amended the TRAI Act and the Right to Information Act, while the amendments to the Information Technology Act sit and wait.
That single drafting decision is why an Indian organisation today owes duties under a 2011 rule-set and a 2023 statute at once, and why “the DPDP Act replaced the SPDI Rules” is a statement about 2027, not about now.
Four amendments, two start dates
Read the provision yourself: section 44 in full, and section 38 on how the Act sits alongside other laws.
What the 2011 regime still asks of you
Section 43A was inserted by the IT (Amendment) Act, 2008 and took effect in October 2009. The SPDI Rules were framed under it two years later. Between them they are the whole of India's general data protection law until section 44(2) commences.
Nine dimensions that change the work
The DPDP Act is not a bigger version of the SPDI Rules. It changes what counts as protected data, who is answerable, and what happens when something goes wrong.
| Dimension | SPDI Rules, 2011 | DPDP Act, 2023 |
|---|---|---|
| What is protected | Sensitive personal data or information only - a closed list of eight categories in Rule 3. | All digital personal data: any data about an identifiable individual, in digital form or digitised later. No sensitive tier at all. |
| Who is bound | A body corporate: a company, firm, sole proprietorship or association engaged in commercial or professional activity. | Any Data Fiduciary, including the State, subject to the exemptions in sections 7 and 17. |
| Reach outside India | No express extraterritorial provision. | Section 3 reaches processing outside India where it relates to offering goods or services to Data Principals in India. |
| Lawful basis | Consent for collection, plus a lawful-purpose and necessity test. | Consent under section 6, or one of the nine certain legitimate uses in section 7. Consent must be free, specific, informed, unconditional and unambiguous. |
| Telling the individual | A privacy policy published on the website, plus notice at the point of collection. | An itemised notice under section 5, given to the individual before or with the consent request, covering the data, the purpose, how to exercise rights and how to complain to the Board. |
| Security | Reasonable security practices, with IS/ISO/IEC 27001 named as a standard that satisfies the test. | Reasonable security safeguards to prevent a breach, under section 8(5). No named certification; the Rules describe outcomes. |
| Breach reporting | No general obligation to report to a regulator or to affected individuals under the SPDI Rules themselves. | Section 8(6) requires intimation to the Board and to every affected Data Principal, in the form and manner the Rules prescribe. |
| Individual rights | Review and correction of information, and withdrawal of consent. | Access, correction and erasure, grievance redressal and nomination, under sections 11 to 14. |
| Consequence of failure | Compensation to the affected person under section 43A, awarded by adjudication. No statutory ceiling. | Monetary penalties imposed by the Board under the Schedule, up to ₹250 crore for a security-safeguard failure. No individual compensation route. |
Section 38 answers this directly. The DPDP Act is in addition to and not in derogation of any other law in force, so the SPDI obligations are not displaced by implication. Where the two genuinely conflict, the DPDP Act prevails to the extent of that conflict. In practice the two rarely conflict: the DPDP Act asks for more, in more places, of more data.
The safe reading for the transition window is the strict one. Keep the SPDI privacy policy and the named security standard, and build the DPDP notice, consent and breach machinery beside them rather than instead of them.
The change nobody mentions
Section 44(3) rewrote section 8(1)(j) of the Right to Information Act, and it did so on publication rather than on the eighteen-month clock. The clause used to exempt personal information whose disclosure had no relationship to public activity or interest, subject to a public-interest override. It now reads, in full: “information which relates to personal information”.
Whatever view one takes of that, it is the one part of the DPDP Act that is fully operative today and it belongs in any honest account of what the statute did.
Statutory text on this page is quoted from the Act as published in the Gazette. Commencement dates are eighteen months and one year from the 13 November 2025 publication; advisers differ by a day on whether the operative date is the 13th or 14th, so treat mid-May 2027 as the planning horizon rather than a deadline to the hour.
SPDI and the DPDP Act, answered
Has section 43A of the IT Act been repealed?
Not yet. Section 44(2)(a) of the DPDP Act omits it, but that sub-section is in the eighteen-month tranche of the commencement notification and has not commenced. Section 43A remains live law until then, and a claim for compensation under it remains available.
Are the SPDI Rules, 2011 still in force?
Yes. They were made under section 87(2)(ob) of the IT Act, which section 44(2)(c) omits on the same eighteen-month timetable. Until that commences, an organisation handling sensitive personal data is expected to comply with the SPDI Rules and to be preparing for the DPDP Act at the same time.
So do both regimes apply to me right now?
In substance, yes, and that is the practical point of the transition window. The SPDI obligations are live today. Most of the DPDP Act obligations are not, but the Rules are notified, so what they will require is already known rather than speculative.
What happens to a pending section 43A claim after the omission commences?
The Act does not answer this on its face, and the position will depend on the general savings principles in the General Clauses Act, 1897 and on how the courts read the omission. This is a question for a lawyer on specific facts, not one this page can settle.
Did the DPDP Act really change the Right to Information Act?
Yes, and that change is already in force. Section 44(3) substitutes section 8(1)(j) of the RTI Act with a flat exemption for information relating to personal information, removing the earlier structure that allowed disclosure where a larger public interest justified it.