Discuss this page with an LLM

What This Means In Practice

Use this table to brief your legal, product and marketing teams.

Question DPDP Direction DPDP Act 2023 vs IT Act SPDI Rules Direction Practical Impact
Can we process by default? Often consent-first Often depends on a different legal model India flows may need earlier consent design.
Is a global privacy model enough? No Not always Global privacy work does not map one-to-one to DPDP.
Are children protected differently? Under 18 Check local age thresholds Indian child-user products need stricter review.
Is breach risk enough to trigger work? Yes Yes Security, response and evidence matter in both systems.

Three Questions To Ask Internally

  1. Are we copying a non-India privacy model into an Indian product?
  2. Do our consent flows work for Indian users?
  3. Which global privacy controls can be reused, and which must be redesigned for DPDP?

If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

From Sensitive Data to All Digital Data

The SPDI Rules only protected specific types of information like passwords, financial data, and health records. The DPDP Act 2023 expands this to include all digital personal data. This means any data that can identify an individual, such as name, address, or browsing history, now requires full legal protection. Companies that previously ignored “non-sensitive” data must now bring that information into their compliance framework.

Under the SPDI Rules, consent was often buried in broad terms of service or implied through use. The DPDP Act requires consent to be free, specific, informed, and an affirmative action. A major shift is the requirement for a withdrawal mechanism. Individuals must find it as easy to withdraw consent as it was to give it. This requires technical changes to user dashboards and databases to stop processing data immediately upon request.

Side-by-Side Comparison

FeatureIT Act (SPDI Rules)DPDP Act 2023
Data ScopeOnly Sensitive Personal Data (SPDI)All Digital Personal Data
ConsentImplied or writtenExplicit and granular
Children’s DataNo specific age-based restrictionsStrict rules for anyone under 18
Individual RightsLimited access and correctionAccess, correction, and erasure
PenaltiesCompensation-based (uncapped)Fixed penalties up to ₹250 Crore
EnforcementAdjudicating OfficersData Protection Board of India
NoticeBasic privacy policyDetailed notice in English or 22 languages

This week

Identify every data field your company collects that was not considered “sensitive” under the old SPDI Rules, such as names, IP addresses, and email IDs, and add them to your data inventory for DPDP mapping.

FAQ

Q: Does the DPDP Act 2023 replace the SPDI Rules? A: Yes, the DPDP Act will supersede the 2011 SPDI Rules. Businesses must transition their compliance frameworks from focusing only on sensitive data to protecting all digital personal data.

Q: Is there still a separate category for Sensitive Personal Data? A: The DPDP Act does not currently define “sensitive” personal data like the SPDI Rules did. All digital personal data is treated under the same set of compliance requirements regardless of its nature.

Q: Are existing consents under SPDI still valid? A: Existing consents may remain valid if they meet the specific notice and clarity requirements of the DPDP Act. Most companies will need to issue fresh notices to ensure full compliance with the new standards.

Confused by the differences?

Dual compliance is tricky. Our experts can help you navigate both DPDP Act 2023 vs IT Act SPDI Rules and DPDP requirements.

Book Strategy Call
Book clarity call