DPDP vs IT Act 2000 — what changes and what continues

DPDP vs IT Act 2000 — what changes and what continues
DPDP vs Other Laws

DPDP vs IT Act 2000 — what changes and what continues

The DPDP Act 2023 partially supersedes the IT Act 2000. Here is what changes, what continues, and what every compliance team needs to know.

Quick Answer: The DPDP Act 2023 and its Rules will supersede the SPDI Rules (Sensitive Personal Data or Information Rules 2011 under the IT Act 2000) once enforcement begins. Until enforcement, the SPDI Rules continue to apply. Key changes: DPDP introduces a dedicated data protection regulator (the Data Protection Board); creates clear consent requirements; establishes data principal rights; and sets a comprehensive penalty framework. What continues: the IT Act's cybersecurity provisions (Section 43A for negligent security handling, Section 66 and 66E for privacy violations, Section 72A for confidentiality breaches) remain in force alongside DPDP. Criminal and civil liability under the IT Act supplements DPDP's regulatory penalties. The intersection of both regimes means Indian data protection compliance has always been dual-layered — DPDP adds a more comprehensive privacy layer on top of the IT Act's cyber security focus.

What were the SPDI Rules 2011 and how did they differ from DPDP?

The SPDI Rules defined 'sensitive personal data or information' (SPDI) — financial information, passwords, health data, sexual orientation, biometric data — and required companies handling SPDI to: obtain consent; provide a privacy policy; implement security practices; and allow correction and withdrawal of SPDI. The Rules were narrow (only SPDI, not all personal data), had no independent enforcement regulator, and predated digital India's scale. DPDP dramatically expands scope (all personal data, not just SPDI), establishes a dedicated regulator, sets clear rights, and imposes much larger penalties.

Does DPDP repeal the SPDI Rules?

The DPDP Act and its Rules are expected to supersede the SPDI Rules once they come into force. Until the DPDP Rules are notified and the enforcement regime begins, the SPDI Rules remain the applicable privacy regulation. Organisations that are currently compliant with the SPDI Rules must not assume they are DPDP-ready — the gap between SPDI compliance and DPDP compliance is significant. Build your DPDP programme now; do not wait for the SPDI Rules to be formally superseded.

What IT Act provisions continue alongside DPDP?

Even after DPDP enforcement begins, the IT Act provisions remain: Section 43A (civil liability for negligent security practices causing data loss — the body corporate must pay compensation); Section 66E (criminal punishment for capturing, publishing, or transmitting a person's image in a private area — up to 3 years imprisonment); Section 66C and 66D (identity theft and cheating by personation — relevant for credential theft breaches); Section 72A (punishment for disclosure of information in breach of a lawful contract — 3 years or ₹5 lakh). A data breach can attract both DPDP penalties from the Board and IT Act criminal proceedings.

How do DPDP and IT Act penalties interact in a breach?

A single data breach can attract multiple enforcement actions: DPDP penalty from the Data Protection Board (up to ₹250 crore for inadequate security); IT Act Section 43A civil liability (compensation to affected persons for negligent security — no penalty ceiling); IT Act criminal provisions if the breach involves identity theft or privacy violations (imprisonment and fines). These are separate legal proceedings under separate statutes with separate enforcement mechanisms. Your legal response team must manage all three tracks simultaneously in a significant breach.

Does DPDP change corporate liability for cybersecurity?

DPDP strengthens corporate accountability for cybersecurity through the security safeguard obligation — all Fiduciaries must implement 'appropriate technical and organisational security measures.' This supplements IT Act Section 43A's 'reasonable security practices' standard. In practice, a company that has implemented DPDP-compliant security controls will have a stronger defence under Section 43A — its security practices were more than reasonable. Invest in DPDP-level security even before DPDP enforcement, because the IT Act's enforcement mechanism is already live.

Does DPDP affect the CERT-In incident reporting obligations?

The CERT-In directions of April 2022 require all organisations to report cyber incidents to CERT-In within 6 hours of becoming aware of the incident. This is separate from DPDP's breach notification (expected 72 hours) and SEBI/RBI sector notification requirements. In a significant cyber incident, you must simultaneously: report to CERT-In within 6 hours (IT Act/CERT-In directions); notify the Data Protection Board within 72 hours (DPDP); report to RBI/SEBI as applicable; and notify affected individuals as directed. Build a multi-destination notification plan that covers all four tracks.

Frequently asked questions

Are the SPDI Rules still legally enforceable in mid-2026?

Yes. Until the DPDP Rules are notified by the government and come into force, the SPDI Rules remain the applicable privacy regulation for sensitive personal data. Enforcement of the SPDI Rules has been rare in practice, but they are legally enforceable through civil courts under IT Act Section 43A. Do not abandon SPDI compliance while transitioning to DPDP — you must be compliant with both until DPDP formally supersedes the SPDI Rules.

Does DPDP remove the right to sue a company in civil court for a data breach?

No. The IT Act's civil liability under Section 43A (compensation for negligent data handling) continues alongside DPDP. DPDP creates a separate regulatory enforcement track (Data Protection Board penalties) but does not remove private civil rights of action under the IT Act. An individual affected by a data breach can: file a complaint with the Data Protection Board (for DPDP violations); seek compensation in a civil court (for IT Act 43A negligent security); and report criminal offences to the police (for IT Act Section 66-series offences). All three remain available.

Is the IT Act's 'intermediary' concept relevant to DPDP?

The IT Act's intermediary safe harbour (Section 79) protects platforms from liability for third-party content they transmit or host, subject to following due diligence guidelines. The DPDP Act does not use the intermediary concept in the same way — under DPDP, the relevant distinction is Data Fiduciary vs Data Processor, based on who determines the purpose of processing. A platform that merely transmits user data without controlling the purpose may argue it is a Data Processor (or not a Fiduciary at all for that data), but the analysis under DPDP is different from the IT Act intermediary framework.

Understand your dual compliance obligations under DPDP and IT Act

Niti Bharat's DPDP Readiness Assessment covers both DPDP and IT Act obligations — mapping your current compliance gaps against both regimes with a priority remediation roadmap.

Start Dual-Law Assessment
Previous Post Next Post

Get Free DPDP Checklist