DPDPAcademyKnow the law. Prove it.
Home/SPDI Rules vs DPDP
§ 44 · IT Act § 43A · SPDI Rules, 2011

The Old Regime Is Not Gone. It Ends in May 2027.

Almost every summary of the DPDP Act says it repealed section 43A of the IT Act. Read the commencement notification and that is not yet true. The sub-section doing the repealing has not started, which means two data protection regimes apply to Indian organisations at the same time.

SPDI Rules still liveCurrent as of 13 August 2026
Section 44 was split across two commencement dates

The commencement notification issued with the DPDP Rules on 13 November 2025 brought sub-sections (1) and (3) of section 44 into force immediately, and placed sub-section (2) in the eighteen-month tranche. So the Act has already amended the TRAI Act and the Right to Information Act, while the amendments to the Information Technology Act sit and wait.

That single drafting decision is why an Indian organisation today owes duties under a 2011 rule-set and a 2023 statute at once, and why “the DPDP Act replaced the SPDI Rules” is a statement about 2027, not about now.

Section 44, provision by provision

Four amendments, two start dates

§ 44(1)In force
TRAI Act, 1997 - section 14(c)Substitutes the sub-clauses listing which appeals the Telecom Disputes Settlement and Appellate Tribunal hears, adding the Appellate Tribunal under the DPDP Act. This is what makes TDSAT the appeal route from the Data Protection Board.
§ 44(3)In force
RTI Act, 2005 - section 8(1)(j)Replaces the old public-interest balancing clause with a flat exemption: “information which relates to personal information”. This is the least-discussed change in the Act and the only one that narrows a right rather than creating one.
§ 44(2)(a)Not yet in force
IT Act, 2000 - section 43A“Section 43A shall be omitted.” Until this commences, the compensation regime for negligent handling of sensitive personal data continues to operate alongside the DPDP Act.
§ 44(2)(c)Not yet in force
IT Act, 2000 - section 87(2)(ob)Omits the rule-making power under which the SPDI Rules, 2011 were framed. This is the provision that ultimately strands the SPDI Rules, and it is why their fate is tied to section 44(2) rather than to the DPDP Rules.

Read the provision yourself: section 44 in full, and section 38 on how the Act sits alongside other laws.

Still binding today

What the 2011 regime still asks of you

Section 43A was inserted by the IT (Amendment) Act, 2008 and took effect in October 2009. The SPDI Rules were framed under it two years later. Between them they are the whole of India's general data protection law until section 44(2) commences.

IT Act § 43ACompensation without a ceilingA body corporate that possesses, deals with or handles sensitive personal data in a computer resource it owns, controls or operates, and is negligent in implementing and maintaining reasonable security practices, is liable to pay damages by way of compensation to the person affected. The section names no upper limit.
SPDI Rule 3A narrow definition of sensitive dataPasswords, financial information such as bank account or card details, physical and mental health condition, sexual orientation, medical records and history, and biometric information. The DPDP Act abandons this category entirely: it regulates all digital personal data at one standard.
SPDI Rule 4A published privacy policyThe body corporate must publish a policy covering the type of information collected, the purpose, the disclosure practice and the security practices followed. The DPDP Act replaces this with the itemised notice under section 5, which is given to the individual rather than posted on a website.
SPDI Rule 8A named security standardReasonable security practices are satisfied by a documented programme, and IS/ISO/IEC 27001 is named as one such standard. The DPDP Act and Rules take the opposite approach and describe outcomes rather than certifying to a named standard.
Side by side

Nine dimensions that change the work

The DPDP Act is not a bigger version of the SPDI Rules. It changes what counts as protected data, who is answerable, and what happens when something goes wrong.

DimensionSPDI Rules, 2011DPDP Act, 2023
What is protectedSensitive personal data or information only - a closed list of eight categories in Rule 3.All digital personal data: any data about an identifiable individual, in digital form or digitised later. No sensitive tier at all.
Who is boundA body corporate: a company, firm, sole proprietorship or association engaged in commercial or professional activity.Any Data Fiduciary, including the State, subject to the exemptions in sections 7 and 17.
Reach outside IndiaNo express extraterritorial provision.Section 3 reaches processing outside India where it relates to offering goods or services to Data Principals in India.
Lawful basisConsent for collection, plus a lawful-purpose and necessity test.Consent under section 6, or one of the nine certain legitimate uses in section 7. Consent must be free, specific, informed, unconditional and unambiguous.
Telling the individualA privacy policy published on the website, plus notice at the point of collection.An itemised notice under section 5, given to the individual before or with the consent request, covering the data, the purpose, how to exercise rights and how to complain to the Board.
SecurityReasonable security practices, with IS/ISO/IEC 27001 named as a standard that satisfies the test.Reasonable security safeguards to prevent a breach, under section 8(5). No named certification; the Rules describe outcomes.
Breach reportingNo general obligation to report to a regulator or to affected individuals under the SPDI Rules themselves.Section 8(6) requires intimation to the Board and to every affected Data Principal, in the form and manner the Rules prescribe.
Individual rightsReview and correction of information, and withdrawal of consent.Access, correction and erasure, grievance redressal and nomination, under sections 11 to 14.
Consequence of failureCompensation to the affected person under section 43A, awarded by adjudication. No statutory ceiling.Monetary penalties imposed by the Board under the Schedule, up to ₹250 crore for a security-safeguard failure. No individual compensation route.
Which law wins while both apply

Section 38 answers this directly. The DPDP Act is in addition to and not in derogation of any other law in force, so the SPDI obligations are not displaced by implication. Where the two genuinely conflict, the DPDP Act prevails to the extent of that conflict. In practice the two rarely conflict: the DPDP Act asks for more, in more places, of more data.

The safe reading for the transition window is the strict one. Keep the SPDI privacy policy and the named security standard, and build the DPDP notice, consent and breach machinery beside them rather than instead of them.

The change nobody mentions

Section 44(3) rewrote section 8(1)(j) of the Right to Information Act, and it did so on publication rather than on the eighteen-month clock. The clause used to exempt personal information whose disclosure had no relationship to public activity or interest, subject to a public-interest override. It now reads, in full: “information which relates to personal information”.

Whatever view one takes of that, it is the one part of the DPDP Act that is fully operative today and it belongs in any honest account of what the statute did.

Primary sourcesMeitY commencement notification, 13 November 2025Information Technology Act, 2000 (India Code, updated)IT (Reasonable Security Practices … SPDI) Rules, 2011

Statutory text on this page is quoted from the Act as published in the Gazette. Commencement dates are eighteen months and one year from the 13 November 2025 publication; advisers differ by a day on whether the operative date is the 13th or 14th, so treat mid-May 2027 as the planning horizon rather than a deadline to the hour.

See the full DPDP Rules 2025 commencement timeline
FAQ

SPDI and the DPDP Act, answered

Has section 43A of the IT Act been repealed?

Not yet. Section 44(2)(a) of the DPDP Act omits it, but that sub-section is in the eighteen-month tranche of the commencement notification and has not commenced. Section 43A remains live law until then, and a claim for compensation under it remains available.

Are the SPDI Rules, 2011 still in force?

Yes. They were made under section 87(2)(ob) of the IT Act, which section 44(2)(c) omits on the same eighteen-month timetable. Until that commences, an organisation handling sensitive personal data is expected to comply with the SPDI Rules and to be preparing for the DPDP Act at the same time.

So do both regimes apply to me right now?

In substance, yes, and that is the practical point of the transition window. The SPDI obligations are live today. Most of the DPDP Act obligations are not, but the Rules are notified, so what they will require is already known rather than speculative.

What happens to a pending section 43A claim after the omission commences?

The Act does not answer this on its face, and the position will depend on the general savings principles in the General Clauses Act, 1897 and on how the courts read the omission. This is a question for a lawyer on specific facts, not one this page can settle.

Did the DPDP Act really change the Right to Information Act?

Yes, and that change is already in force. Section 44(3) substitutes section 8(1)(j) of the RTI Act with a flat exemption for information relating to personal information, removing the earlier structure that allowed disclosure where a larger public interest justified it.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →