Quick Answer
What is sensitive personal data under the DPDP Act 2023? The DPDP Act 2023 does not use the term 'sensitive personal data' explicitly — instead, it applies a uniform framework to all personal data and allows the Central Government to notify specific categories of data that require additional protection. Historically, the SPDI Rules under the IT Act categorised passwords, financial information, health data, sexual orientation, biometric data, and caste information as sensitive. Organisations should treat these categories as high-risk under the DPDP Act and apply enhanced consent, security, and retention standards to them until the government issues specific notifications.
What is Sensitive Personal Data under the DPDP Act 2023?
Section 4 of the Digital Personal Data Protection (DPDP) Act 2023 defines sensitive personal data as health and medical records, biometric data (fingerprints, face, iris), financial information, government identity numbers (Aadhaar, PAN), caste or tribe membership, religious beliefs, political opinions, sexual orientation, and criminal records. Processing such data attracts the highest penalty tier — up to ₹250 Cr per violation.
Why do Indian companies need a Sensitive Data Audit?
Many organisations process sensitive personal data without realising it — biometric attendance systems, ESI/medical records, Aadhaar-linked KYC, and salary data are common examples. Without explicit consent mechanisms, encryption, access controls, and documented retention policies specific to each category, companies are exposed to direct Section 4 violations the moment DPDP enforcement begins (expected May 2027).
What is the penalty for mishandling sensitive personal data?
The DPDP Act prescribes penalties of up to ₹200–250 Cr for failure to implement adequate security safeguards for sensitive personal data. These penalties apply per category per violation, meaning an organisation that mishandles biometric data and health records without adequate controls could face cumulative exposure exceeding ₹400 Cr.
What controls are required for sensitive personal data under DPDP?
Organisations must obtain explicit, purpose-specific consent (separate from general T&C) for each sensitive data category; implement encryption at rest and in transit; restrict access on a need-to-know basis; maintain documented retention and deletion schedules; and execute Data Processing Agreements (DPAs) with every third-party vendor handling sensitive data.