How does the DPDP Act 2023 differ from the IT Act 2000? The DPDP Act 2023 replaces the data protection provisions of the IT Act 2000 (specifically Section 43A and the SPDI Rules 2011) with a comprehensive, standalone data protection law. Key differences: the DPDP Act applies to all personal data (not just 'sensitive' data), requires affirmative consent (not just reasonable security practices), establishes an independent Data Protection Board (replacing civil courts for privacy claims), and imposes significantly higher penalties — ₹250 crore vs. ₹5 crore under the IT Act.
India has a new data privacy law. But the IT Act still exists. Here's exactly how the DPDP Act 2023 changes, replaces, or complements existing IT Act provisions — with practical impact for compliance teams.
Specifically targets personal data of natural persons processed digitally; excludes publicly available data. Applies to processing in India and offshore processing linked to offering goods/services in India.
Applies broadly to electronic records and computer systems; SPDI Rules apply to body corporates that collect, process, or store sensitive personal data in India.
DPDP narrows scope to personal data specifically but deepens obligations significantly. Your existing IT Act compliance programme does NOT automatically satisfy DPDP.
Broad "personal data" covers any data about an identifiable natural person. Separate category for "sensitive personal data" to be notified by government. Publicly available data excluded.
Defined narrow categories of "Sensitive Personal Data or Information" (SPDI) — passwords, financial data, health, sexual orientation, biometric data, etc. Only SPDI had strict protections.
Far more data types now fall under compliance obligations — not just the narrow SPDI list. Re-audit your data inventory: names, email addresses, and device IDs are now "personal data".
Explicit, informed, specific, unconditional, and unambiguous consent required. Must be given through a clear affirmative act. Consent notice must be separate from T&Cs. Purpose must be stated in plain language.
SPDI Rules Rule 5 required consent for SPDI collection. Implied consent was permissible. No requirement for consent to be separate from general terms. Less prescriptive on form of consent.
All existing consent mechanisms need a full review. Pre-ticked boxes, bundled T&C consent, and implied consent for digital data are no longer valid under DPDP.
Data may only be used for the specific purpose for which consent was obtained. Any new use requires fresh consent with a new purpose notice. Purpose must be stated before or at time of collection.
No explicit purpose limitation requirement. Data could be used for multiple purposes within the broad scope of services. No restriction on repurposing collected data.
Repurposing customer data for new analytics, remarketing, or product features now requires fresh consent with a new purpose notice. Audit all secondary data uses.
Section 8(3): Data Fiduciaries must collect only personal data that is necessary for the stated purpose. Collecting additional data "just in case" is a statutory violation.
No data minimisation principle in IT Act or SPDI Rules. Body corporates could collect broad data as long as they maintained reasonable security. "Collect everything, use later" was legally permissible.
Registration forms, onboarding flows, and third-party integrations that collect optional data must be reviewed. Remove non-essential fields or obtain separate consent for them.
Section 11: Data principals have the right to obtain a summary of personal data held and information on processing activities. Must be provided within a prescribed period (expected: 30 days per Rules).
SPDI Rules Rule 5(6) required body corporates to allow data subjects to review their SPDI, but there was no enforceable right to access a summary of all personal data held.
You must build a mechanism to respond to access requests — a Data Subject Access Request (DSAR) portal or process. This is now a statutory right enforceable before the DPBI.
Section 12: Data principals have the right to correct, complete, and update their personal data. Must be fulfilled within a prescribed period. Applies to both accuracy and completeness.
SPDI Rules Rule 5(7) allowed data subjects to withdraw consent, but there was no codified right to correct inaccurate data. Correction was at the body corporate's discretion.
Build or enhance a correction request process. Your CRM and customer-facing systems must be able to propagate corrections across all data stores where the record is held.
Section 12(2): Right to erasure once the purpose for which data was collected is fulfilled, or if consent is withdrawn. Subject to retention obligations under other laws. Data Fiduciary must cease processing.
No right to erasure in IT Act or SPDI Rules. SPDI Rules Rule 5(7) allowed withdrawal of consent for SPDI but did not mandate deletion of already-collected data.
A deletion workflow and data retention policy are now mandatory. You must be able to erase personal data from all systems — including backups — once the lawful basis ends.
Section 13: Grievance Officer continues to be required. Must respond within a prescribed period. Data principals can escalate to DPBI if response is unsatisfactory. Rules expected to tighten timelines.
IT (Intermediary Guidelines) Rules required platforms to appoint a Grievance Officer (Rule 5(9) of SPDI Rules + Rule 3(11) of Intermediary Rules). Timelines varied by rule type.
Existing GO appointment may be substantially compliant. Review response timelines — DPDP Rules are expected to mandate specific turnaround periods stricter than current practice.
Section 16: Central government may restrict cross-border transfers to specific countries by notification. No blanket localisation requirement yet. White-list approach expected. Sector-specific rules (RBI, SEBI) still apply.
No general data localisation requirement under IT Act or SPDI Rules. RBI mandated payment data localisation (Apr 2018). SPDI Rules permitted cross-border transfers with same protection level.
Map all cross-border data transfers now. Prepare impact assessments for when government notifications come. Current cross-border arrangements may need rapid restructuring once notified.
Section 8(5): Appropriate technical and organisational measures must be in place. Rules expected to specify minimum standards. Penalty up to ₹250 Cr for security failures. Data Processors also directly liable.
Body corporates required to implement "reasonable security practices" — either IS/ISO/IEC 27001 or industry body codes. Civil compensation to affected individuals under Section 43A.
Existing ISO 27001 certification is a strong foundation but may not satisfy DPDP-specific obligations. Wait for Rules; conduct a gap assessment against anticipated standards in the interim.
Section 8(6): Data Fiduciary must notify the Data Protection Board of India (DPBI) of any personal data breach in prescribed form and manner. Notification to affected data principals also required. 72-hour window expected in Rules.
No mandatory notification to any regulator or government body after a breach. Section 43A only required compensation to the affected individual. Body corporate remained liable for damage caused.
Critical change. You must now build a breach detection, escalation, and regulatory notification process. Build for a 72-hour DPBI notification capability — equivalent to GDPR's standard.
Data Processors have direct statutory obligations under DPDP. Data Processing Agreements (DPAs) must be in place. Processors must implement security safeguards. Processors can sub-contract only with Fiduciary's permission.
Body corporate (Fiduciary) remained liable even for third-party processor breaches under Section 43A. No direct statutory obligation on processors themselves. Liability flowed through contractual terms.
All vendor contracts involving personal data must be updated with DPA clauses. As a Processor, you now have direct regulatory exposure — not just contractual liability to your clients.
Section 9: Verifiable parental consent required before processing data of children (under 18). Profiling, tracking, and targeted advertising to children are explicitly prohibited. Violations carry penalty up to ₹200 Cr.
No specific children's data provisions in IT Act or SPDI Rules. General consent requirements applied to all ages. No prohibition on profiling or targeted advertising to children.
Highest-risk new requirement for EdTech, gaming, social platforms, and any service children use. Age verification and parental consent workflows are now mandatory — not optional.
Section 10: Central government can designate entities as SDFs based on volume, sensitivity, national security risk. SDFs must conduct DPIAs, appoint a Data Protection Officer, and engage an independent Data Auditor.
No concept of tiered data fiduciaries. All body corporates subject to SPDI Rules had the same obligations regardless of size, scale, or sensitivity of data processed.
Large platforms, healthcare organisations, and BFSI entities are most at risk of SDF designation. Begin DPIA capabilities and DPO identification now — don't wait for formal notification.
Schedule 1: Penalties up to ₹250 Cr per violation imposed by DPBI. Penalties go to DPBI (not to individuals). No criminal liability under DPDP itself — civil regulatory framework only.
Section 43A: Compensation payable to affected individual (no fixed cap). Section 66: Criminal liability with imprisonment up to 3 years. Amounts in practice were very low — rarely exceeded ₹5 Cr.
DPDP penalties are 50–100x higher in practice than IT Act outcomes. Penalties flow to the regulator, not individuals — but regulatory enforcement will be more systematic than individual litigation.
Schedule 1, Item 4: Failure to implement security safeguards — penalty up to ₹250 Cr. Applies even without a breach occurring. Proactive compliance obligation on the organisation.
Compensation triggered only when a breach caused wrongful loss/gain. No penalty for inadequate security standards absent an actual harm event. Amounts were uncapped but practically low.
Security investment now has direct regulatory ROI. Inadequate controls are penalisable even before a breach — making proactive security investment defensible at board level.
Section 16: Central government may restrict transfers to specific countries or territories by notification. White-list approach (permitted countries). Data Fiduciaries must comply with transfer restrictions once notified.
SPDI Rules Rule 7 permitted cross-border transfer if receiving entity provides same protection level or person consents. No government-level restriction mechanism on cross-border flows.
Map all cross-border data flows now — including third-party SaaS tools, cloud providers, and offshore teams. Build a transfer monitoring process ready to react when government notifications arrive.
Data Protection Board of India (DPBI) — new independent quasi-judicial body. Handles complaints from data principals, conducts investigations, issues directions, imposes penalties. Digital-first complaint mechanism.
MeitY (Ministry of Electronics & IT) and Adjudicating Officers under IT Act (Section 46). Civil courts for compensation claims. No dedicated data protection authority with investigation powers.
A fully digital complaint process means your customers can report violations with minimal friction. Expect significantly higher complaint volumes than IT Act adjudication once DPBI is operational.
DPDP Act supersedes conflicting provisions of IT Act and IT Rules 2011 with respect to personal data. A transition period applies (notified by Central government). Existing SPDI compliance does not automatically satisfy DPDP.
IT Rules 2011 SPDI compliance was the primary regulatory standard for personal data since 2011. Privacy policies, consent forms, and security standards were built to IT Rules benchmarks.
Immediately audit all privacy policies, consent forms, vendor contracts, and internal policies for IT Rules references. Update them for DPDP before enforcement begins. This is a full compliance programme — not a patch.
India's data privacy journey began with the Information Technology Act 2000, which established the basic legal framework for electronic transactions and computer-related offences. The IT (Amendment) Act 2008 and the subsequent IT Rules 2011 — specifically the Sensitive Personal Data or Information (SPDI) Rules — introduced the first meaningful data protection obligations for businesses.
However, the SPDI framework was narrow in scope (covering only specific categories of "sensitive" data), reactive in approach (penalties triggered only after harm), and significantly weaker than emerging global standards like GDPR. The Digital Personal Data Protection Act 2023 changes this entirely.
Yes — but with important caveats. DPDP Act Section 40 states that the Act supersedes provisions of the IT Act "to the extent of inconsistency." This means:
The IT Rules 2011 (Sensitive Personal Data or Information Rules) defined a specific list of data categories as "SPDI" — passwords, financial information, health conditions, sexual orientation, biometric data, etc. Under SPDI Rules, body corporates had to obtain consent before collecting SPDI, maintain security standards, and allow data subjects to access or correct their SPDI.
Under DPDP, the concept of SPDI is subsumed into a broader personal data framework. The government may notify categories of "sensitive personal data" with additional protections, but compliance teams should no longer think in terms of "SPDI vs non-SPDI." All personal data now carries compliance obligations.
IT companies and SaaS providers in India have a dual exposure: as Data Fiduciaries for their employee data and end-user data, and as Data Processors for their enterprise clients' data. Under IT Act, liability for processor actions fell primarily on the body corporate (Fiduciary). Under DPDP, Processors have direct statutory obligations and must implement security safeguards regardless of contractual terms.
This means IT companies acting as processors for large clients (banks, hospitals, government entities) now carry direct regulatory risk for any data breach or non-compliance in their processing activities.
Our team has helped 50+ Indian organisations understand their DPDP obligations and build compliant programmes. Book a free 30-minute consultation.
No spam. We will respond within 1 business day.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.