DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

How does the DPDP Act 2023 differ from the IT Act 2000? The DPDP Act 2023 replaces the data protection provisions of the IT Act 2000 (specifically Section 43A and the SPDI Rules 2011) with a comprehensive, standalone data protection law. Key differences: the DPDP Act applies to all personal data (not just 'sensitive' data), requires affirmative consent (not just reasonable security practices), establishes an independent Data Protection Board (replacing civil courts for privacy claims), and imposes significantly higher penalties — ₹250 crore vs. ₹5 crore under the IT Act.

🇮🇳 DPDP Act 2023 IT Act 2000 & IT Rules 2011 Updated Jun 2026

DPDP Act 2023 vs IT Act 2000 — What Changed for Indian Businesses

India has a new data privacy law. But the IT Act still exists. Here's exactly how the DPDP Act 2023 changes, replaces, or complements existing IT Act provisions — with practical impact for compliance teams.

Superseded (IT Act provision replaced)
New Requirement (didn't exist in IT Act)
Strengthened (DPDP raises the bar)
Unchanged (still applies as before)
Showing all 20 comparisons

1. Scope & Applicability

STRENGTHENED
🇮🇳 DPDP Act 2023

Specifically targets personal data of natural persons processed digitally; excludes publicly available data. Applies to processing in India and offshore processing linked to offering goods/services in India.

⚖️ IT Act 2000 / IT Rules 2011

Applies broadly to electronic records and computer systems; SPDI Rules apply to body corporates that collect, process, or store sensitive personal data in India.

IMPLICATION FOR COMPLIANCE TEAMS

DPDP narrows scope to personal data specifically but deepens obligations significantly. Your existing IT Act compliance programme does NOT automatically satisfy DPDP.

2. Definition of Personal Data

STRENGTHENED
🇮🇳 DPDP Act 2023

Broad "personal data" covers any data about an identifiable natural person. Separate category for "sensitive personal data" to be notified by government. Publicly available data excluded.

⚖️ IT Act / SPDI Rules 2011

Defined narrow categories of "Sensitive Personal Data or Information" (SPDI) — passwords, financial data, health, sexual orientation, biometric data, etc. Only SPDI had strict protections.

IMPLICATION FOR COMPLIANCE TEAMS

Far more data types now fall under compliance obligations — not just the narrow SPDI list. Re-audit your data inventory: names, email addresses, and device IDs are now "personal data".

3. Consent Requirement

SUPERSEDED
🇮🇳 DPDP Act 2023

Explicit, informed, specific, unconditional, and unambiguous consent required. Must be given through a clear affirmative act. Consent notice must be separate from T&Cs. Purpose must be stated in plain language.

⚖️ IT Act / SPDI Rules 2011

SPDI Rules Rule 5 required consent for SPDI collection. Implied consent was permissible. No requirement for consent to be separate from general terms. Less prescriptive on form of consent.

IMPLICATION FOR COMPLIANCE TEAMS

All existing consent mechanisms need a full review. Pre-ticked boxes, bundled T&C consent, and implied consent for digital data are no longer valid under DPDP.

4. Purpose Limitation

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Data may only be used for the specific purpose for which consent was obtained. Any new use requires fresh consent with a new purpose notice. Purpose must be stated before or at time of collection.

⚖️ IT Act / SPDI Rules 2011

No explicit purpose limitation requirement. Data could be used for multiple purposes within the broad scope of services. No restriction on repurposing collected data.

IMPLICATION FOR COMPLIANCE TEAMS

Repurposing customer data for new analytics, remarketing, or product features now requires fresh consent with a new purpose notice. Audit all secondary data uses.

5. Data Minimisation

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 8(3): Data Fiduciaries must collect only personal data that is necessary for the stated purpose. Collecting additional data "just in case" is a statutory violation.

⚖️ IT Act / SPDI Rules 2011

No data minimisation principle in IT Act or SPDI Rules. Body corporates could collect broad data as long as they maintained reasonable security. "Collect everything, use later" was legally permissible.

IMPLICATION FOR COMPLIANCE TEAMS

Registration forms, onboarding flows, and third-party integrations that collect optional data must be reviewed. Remove non-essential fields or obtain separate consent for them.

6. Right to Access

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 11: Data principals have the right to obtain a summary of personal data held and information on processing activities. Must be provided within a prescribed period (expected: 30 days per Rules).

⚖️ IT Act / SPDI Rules 2011

SPDI Rules Rule 5(6) required body corporates to allow data subjects to review their SPDI, but there was no enforceable right to access a summary of all personal data held.

IMPLICATION FOR COMPLIANCE TEAMS

You must build a mechanism to respond to access requests — a Data Subject Access Request (DSAR) portal or process. This is now a statutory right enforceable before the DPBI.

7. Right to Correction

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 12: Data principals have the right to correct, complete, and update their personal data. Must be fulfilled within a prescribed period. Applies to both accuracy and completeness.

⚖️ IT Act / SPDI Rules 2011

SPDI Rules Rule 5(7) allowed data subjects to withdraw consent, but there was no codified right to correct inaccurate data. Correction was at the body corporate's discretion.

IMPLICATION FOR COMPLIANCE TEAMS

Build or enhance a correction request process. Your CRM and customer-facing systems must be able to propagate corrections across all data stores where the record is held.

8. Right to Erasure

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 12(2): Right to erasure once the purpose for which data was collected is fulfilled, or if consent is withdrawn. Subject to retention obligations under other laws. Data Fiduciary must cease processing.

⚖️ IT Act / SPDI Rules 2011

No right to erasure in IT Act or SPDI Rules. SPDI Rules Rule 5(7) allowed withdrawal of consent for SPDI but did not mandate deletion of already-collected data.

IMPLICATION FOR COMPLIANCE TEAMS

A deletion workflow and data retention policy are now mandatory. You must be able to erase personal data from all systems — including backups — once the lawful basis ends.

9. Grievance Mechanism

UNCHANGED
🇮🇳 DPDP Act 2023

Section 13: Grievance Officer continues to be required. Must respond within a prescribed period. Data principals can escalate to DPBI if response is unsatisfactory. Rules expected to tighten timelines.

⚖️ IT Act / IT Rules 2011

IT (Intermediary Guidelines) Rules required platforms to appoint a Grievance Officer (Rule 5(9) of SPDI Rules + Rule 3(11) of Intermediary Rules). Timelines varied by rule type.

IMPLICATION FOR COMPLIANCE TEAMS

Existing GO appointment may be substantially compliant. Review response timelines — DPDP Rules are expected to mandate specific turnaround periods stricter than current practice.

10. Data Localisation

UNCHANGED
🇮🇳 DPDP Act 2023

Section 16: Central government may restrict cross-border transfers to specific countries by notification. No blanket localisation requirement yet. White-list approach expected. Sector-specific rules (RBI, SEBI) still apply.

⚖️ IT Act / SPDI Rules 2011

No general data localisation requirement under IT Act or SPDI Rules. RBI mandated payment data localisation (Apr 2018). SPDI Rules permitted cross-border transfers with same protection level.

IMPLICATION FOR COMPLIANCE TEAMS

Map all cross-border data transfers now. Prepare impact assessments for when government notifications come. Current cross-border arrangements may need rapid restructuring once notified.

11. Security Safeguards

STRENGTHENED
🇮🇳 DPDP Act 2023

Section 8(5): Appropriate technical and organisational measures must be in place. Rules expected to specify minimum standards. Penalty up to ₹250 Cr for security failures. Data Processors also directly liable.

⚖️ IT Act Section 43A / SPDI Rules

Body corporates required to implement "reasonable security practices" — either IS/ISO/IEC 27001 or industry body codes. Civil compensation to affected individuals under Section 43A.

IMPLICATION FOR COMPLIANCE TEAMS

Existing ISO 27001 certification is a strong foundation but may not satisfy DPDP-specific obligations. Wait for Rules; conduct a gap assessment against anticipated standards in the interim.

12. Breach Notification

SUPERSEDED
🇮🇳 DPDP Act 2023

Section 8(6): Data Fiduciary must notify the Data Protection Board of India (DPBI) of any personal data breach in prescribed form and manner. Notification to affected data principals also required. 72-hour window expected in Rules.

⚖️ IT Act Section 43A

No mandatory notification to any regulator or government body after a breach. Section 43A only required compensation to the affected individual. Body corporate remained liable for damage caused.

IMPLICATION FOR COMPLIANCE TEAMS

Critical change. You must now build a breach detection, escalation, and regulatory notification process. Build for a 72-hour DPBI notification capability — equivalent to GDPR's standard.

13. Data Processor Obligations

STRENGTHENED
🇮🇳 DPDP Act 2023

Data Processors have direct statutory obligations under DPDP. Data Processing Agreements (DPAs) must be in place. Processors must implement security safeguards. Processors can sub-contract only with Fiduciary's permission.

⚖️ IT Act / SPDI Rules 2011

Body corporate (Fiduciary) remained liable even for third-party processor breaches under Section 43A. No direct statutory obligation on processors themselves. Liability flowed through contractual terms.

IMPLICATION FOR COMPLIANCE TEAMS

All vendor contracts involving personal data must be updated with DPA clauses. As a Processor, you now have direct regulatory exposure — not just contractual liability to your clients.

14. Children's Data Protection

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 9: Verifiable parental consent required before processing data of children (under 18). Profiling, tracking, and targeted advertising to children are explicitly prohibited. Violations carry penalty up to ₹200 Cr.

⚖️ IT Act / SPDI Rules 2011

No specific children's data provisions in IT Act or SPDI Rules. General consent requirements applied to all ages. No prohibition on profiling or targeted advertising to children.

IMPLICATION FOR COMPLIANCE TEAMS

Highest-risk new requirement for EdTech, gaming, social platforms, and any service children use. Age verification and parental consent workflows are now mandatory — not optional.

15. Significant Data Fiduciary (SDF)

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 10: Central government can designate entities as SDFs based on volume, sensitivity, national security risk. SDFs must conduct DPIAs, appoint a Data Protection Officer, and engage an independent Data Auditor.

⚖️ IT Act / SPDI Rules 2011

No concept of tiered data fiduciaries. All body corporates subject to SPDI Rules had the same obligations regardless of size, scale, or sensitivity of data processed.

IMPLICATION FOR COMPLIANCE TEAMS

Large platforms, healthcare organisations, and BFSI entities are most at risk of SDF designation. Begin DPIA capabilities and DPO identification now — don't wait for formal notification.

16. Penalties for Data Breach

SUPERSEDED
🇮🇳 DPDP Act 2023

Schedule 1: Penalties up to ₹250 Cr per violation imposed by DPBI. Penalties go to DPBI (not to individuals). No criminal liability under DPDP itself — civil regulatory framework only.

⚖️ IT Act Section 43A / Section 66

Section 43A: Compensation payable to affected individual (no fixed cap). Section 66: Criminal liability with imprisonment up to 3 years. Amounts in practice were very low — rarely exceeded ₹5 Cr.

IMPLICATION FOR COMPLIANCE TEAMS

DPDP penalties are 50–100x higher in practice than IT Act outcomes. Penalties flow to the regulator, not individuals — but regulatory enforcement will be more systematic than individual litigation.

17. Penalties — Security Failure

STRENGTHENED
🇮🇳 DPDP Act 2023

Schedule 1, Item 4: Failure to implement security safeguards — penalty up to ₹250 Cr. Applies even without a breach occurring. Proactive compliance obligation on the organisation.

⚖️ IT Act Section 43A

Compensation triggered only when a breach caused wrongful loss/gain. No penalty for inadequate security standards absent an actual harm event. Amounts were uncapped but practically low.

IMPLICATION FOR COMPLIANCE TEAMS

Security investment now has direct regulatory ROI. Inadequate controls are penalisable even before a breach — making proactive security investment defensible at board level.

18. Cross-Border Data Transfer

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Section 16: Central government may restrict transfers to specific countries or territories by notification. White-list approach (permitted countries). Data Fiduciaries must comply with transfer restrictions once notified.

⚖️ IT Act / SPDI Rules 2011

SPDI Rules Rule 7 permitted cross-border transfer if receiving entity provides same protection level or person consents. No government-level restriction mechanism on cross-border flows.

IMPLICATION FOR COMPLIANCE TEAMS

Map all cross-border data flows now — including third-party SaaS tools, cloud providers, and offshore teams. Build a transfer monitoring process ready to react when government notifications arrive.

19. Data Protection Authority

NEW REQUIREMENT
🇮🇳 DPDP Act 2023

Data Protection Board of India (DPBI) — new independent quasi-judicial body. Handles complaints from data principals, conducts investigations, issues directions, imposes penalties. Digital-first complaint mechanism.

⚖️ IT Act 2000

MeitY (Ministry of Electronics & IT) and Adjudicating Officers under IT Act (Section 46). Civil courts for compensation claims. No dedicated data protection authority with investigation powers.

IMPLICATION FOR COMPLIANCE TEAMS

A fully digital complaint process means your customers can report violations with minimal friction. Expect significantly higher complaint volumes than IT Act adjudication once DPBI is operational.

20. Existing Contracts & IT Rules Compliance

SUPERSEDED
🇮🇳 DPDP Act 2023

DPDP Act supersedes conflicting provisions of IT Act and IT Rules 2011 with respect to personal data. A transition period applies (notified by Central government). Existing SPDI compliance does not automatically satisfy DPDP.

⚖️ IT Act / SPDI Rules 2011

IT Rules 2011 SPDI compliance was the primary regulatory standard for personal data since 2011. Privacy policies, consent forms, and security standards were built to IT Rules benchmarks.

IMPLICATION FOR COMPLIANCE TEAMS

Immediately audit all privacy policies, consent forms, vendor contracts, and internal policies for IT Rules references. Update them for DPDP before enforcement begins. This is a full compliance programme — not a patch.

Summary: The DPDP Compliance Transformation

5
SUPERSEDED
8
NEW REQUIREMENTS
5
STRENGTHENED
2
UNCHANGED

What this means in practice

  • Your IT Rules compliance is a starting point, not a destination. Only 2 of 20 areas are fully unchanged — everything else requires review and likely updates.
  • Consent is the biggest operational change. All existing consent mechanisms — especially bundled T&C consent — must be redesigned for DPDP's explicit, purpose-specific standard.
  • Breach notification is a new operational capability. You must build detection, escalation, and DPBI notification processes from scratch — they do not exist under the IT Act framework.
  • Vendor risk management expands significantly. Data Processors now have direct regulatory exposure — your vendor contracts and due diligence process must reflect this.
  • The DPBI will make enforcement far more systematic. A digital complaint process means higher complaint volumes and faster regulatory action than IT Act adjudication.

Free Tools to Help You Comply

DPDP Act 2023 vs IT Act 2000: The Legal Context

India's data privacy journey began with the Information Technology Act 2000, which established the basic legal framework for electronic transactions and computer-related offences. The IT (Amendment) Act 2008 and the subsequent IT Rules 2011 — specifically the Sensitive Personal Data or Information (SPDI) Rules — introduced the first meaningful data protection obligations for businesses.

However, the SPDI framework was narrow in scope (covering only specific categories of "sensitive" data), reactive in approach (penalties triggered only after harm), and significantly weaker than emerging global standards like GDPR. The Digital Personal Data Protection Act 2023 changes this entirely.

Does the IT Act Still Apply After DPDP?

Yes — but with important caveats. DPDP Act Section 40 states that the Act supersedes provisions of the IT Act "to the extent of inconsistency." This means:

What Is the SPDI Framework and Is It Still Relevant?

The IT Rules 2011 (Sensitive Personal Data or Information Rules) defined a specific list of data categories as "SPDI" — passwords, financial information, health conditions, sexual orientation, biometric data, etc. Under SPDI Rules, body corporates had to obtain consent before collecting SPDI, maintain security standards, and allow data subjects to access or correct their SPDI.

Under DPDP, the concept of SPDI is subsumed into a broader personal data framework. The government may notify categories of "sensitive personal data" with additional protections, but compliance teams should no longer think in terms of "SPDI vs non-SPDI." All personal data now carries compliance obligations.

Key Differences for IT Companies and SaaS Providers

IT companies and SaaS providers in India have a dual exposure: as Data Fiduciaries for their employee data and end-user data, and as Data Processors for their enterprise clients' data. Under IT Act, liability for processor actions fell primarily on the body corporate (Fiduciary). Under DPDP, Processors have direct statutory obligations and must implement security safeguards regardless of contractual terms.

This means IT companies acting as processors for large clients (banks, hospitals, government entities) now carry direct regulatory risk for any data breach or non-compliance in their processing activities.

Not Sure What DPDP Means for Your Organisation?

Our team has helped 50+ Indian organisations understand their DPDP obligations and build compliant programmes. Book a free 30-minute consultation.

No spam. We will respond within 1 business day.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Act 2023 vs PDPB 2019DPDP Act 2023 vs SPDI Rules 2011DPDP Act Penalties ExplainedEmployee Data Audit ToolSee all Reference & Checklists tools →📝 Dpia Under DPDP Act India📝 What to Do Data Breach 72 Hours DPDP