DPDP Act VS DPDP Act 2023 vs IT Act 2000
Compare India's DPDP Act 2023 with the legacy IT Act 2000. Understand how compliance rules for data fiduciaries have changed under the. See what to fix.
Discuss this page with an LLM
What This Means In Practice
Use this table to brief your legal, product and marketing teams.
| Question | DPDP Direction | DPDP Act 2023 vs IT Act 2000 Direction | Practical Impact |
|---|---|---|---|
| Can we process by default? | Often consent-first | Often depends on a different legal model | India flows may need earlier consent design. |
| Is a global privacy model enough? | No | Not always | Global privacy work does not map one-to-one to DPDP. |
| Are children protected differently? | Under 18 | Check local age thresholds | Indian child-user products need stricter review. |
| Is breach risk enough to trigger work? | Yes | Yes | Security, response and evidence matter in both systems. |
Three Questions To Ask Internally
- Are we copying a non-India privacy model into an Indian product?
- Do our consent flows work for Indian users?
- Which global privacy controls can be reused, and which must be redesigned for DPDP?
If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.
Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
The transition from the IT Act 2000 to the Digital Personal Data Protection (DPDP) Act 2023 changes how Indian businesses handle information. The previous framework focused on a narrow set of sensitive data. The new law covers all digital personal data and introduces stricter operational requirements for every data fiduciary in India.
Shifts in Data Classification
The IT Act and its SPDI Rules only protected specific categories like passwords, financial info, and health data. If a business leaked a customer’s name or phone number, the old rules often did not apply. The DPDP Act removes this distinction. Any data that can identify an individual is now protected. This means marketing lists, IP addresses, and basic contact forms must meet the same compliance standards as financial records.
Enforcement and Governance
Under the old system, enforcement happened through Adjudicating Officers who primarily managed compensation claims. There was no dedicated body to monitor privacy practices. The DPDP Act establishes the Data Protection Board of India. This Board has the power to investigate data breaches and issue penalties for failing to implement reasonable security safeguards. This moves the legal focus from individual lawsuits to regulatory oversight.
| Feature | IT Act 2000 (SPDI Rules) | DPDP Act 2023 |
|---|---|---|
| Primary Scope | Sensitive Personal Data (SPDI) | All Digital Personal Data |
| Consent | Written consent for sensitive data | Notice-based consent for all data |
| Children’s Data | No specific age-based rules | Verifiable parental consent for under 18s |
| Enforcement | Adjudicating Officers | Data Protection Board of India |
| Data Subject Rights | Access and correction | Access, correction, erasure, and nomination |
| Data Localization | Limited requirements | Government-notified transfer rules |
| Compliance Roles | Not defined | Data Fiduciaries and Processors |
This week
Map every data point your business collects and tag it as personal data. Delete any legacy customer files, such as old lead lists or expired KYC documents, that your business no longer has a legal reason to keep.
FAQ
Q: Does the DPDP Act 2023 replace the IT Act 2000? A: The DPDP Act overrides Section 43A of the IT Act 2000. While the IT Act remains for cybercrime and electronic records, the DPDP Act is now the primary law for personal data protection.
Q: Can I use my existing SPDI consent forms? A: Existing forms likely need updates. The DPDP Act requires specific notice and consent available in multiple languages, which was not a requirement under the older SPDI rules.
Q: Are the penalties different between the two laws? A: Yes. The IT Act focused on individual compensation for losses. The DPDP Act focuses on statutory penalties for non-compliance, regardless of whether an individual proves financial loss.
Confused by the differences?
Dual compliance is tricky. Our experts can help you navigate both DPDP Act 2023 vs IT Act 2000 and DPDP requirements.
Book Strategy Call