DPDP Act VS DPDP vs IT Act: Comparing India Data Laws
India has moved from the 2011 SPDI Rules to the DPDP Act 2023. Understand the differences in scope, penalties, and compliance for Indian. See what to fix.
Discuss this page with an LLM
What This Means In Practice
Use this table to brief your legal, product and marketing teams.
| Question | DPDP Direction | DPDP vs IT Act: Comparing India Data Laws Direction | Practical Impact |
|---|---|---|---|
| Can we process by default? | Often consent-first | Often depends on a different legal model | India flows may need earlier consent design. |
| Is a global privacy model enough? | No | Not always | Global privacy work does not map one-to-one to DPDP. |
| Are children protected differently? | Under 18 | Check local age thresholds | Indian child-user products need stricter review. |
| Is breach risk enough to trigger work? | Yes | Yes | Security, response and evidence matter in both systems. |
Three Questions To Ask Internally
- Are we copying a non-India privacy model into an Indian product?
- Do our consent flows work for Indian users?
- Which global privacy controls can be reused, and which must be redesigned for DPDP?
If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.
Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
The Shift to Comprehensive Protection
The IT Act 2000 and its 2011 SPDI Rules only protected “Sensitive Personal Data.” This was a short list including passwords, financial information, and health records. Most business data, like customer names or phone numbers, was not strictly regulated. The DPDP Act 2023 changes this by protecting all digital personal data. If a piece of information can identify an individual, your business must now follow strict rules to process it.
Expanded Rights and Enforcement
Under the old SPDI Rules, enforcement was rare. Businesses only needed to provide a basic privacy policy and secure sensitive data. The DPDP Act creates a dedicated Data Protection Board of India with the power to investigate and penalize. Individuals, called “Data Principals,” now have the right to ask for a summary of their data, request it be erased, or nominate someone to manage it in the future. These rights require new internal workflows that did not exist under the IT Act.
| Feature | IT Act / SPDI Rules (2011) | DPDP Act (2023) |
|---|---|---|
| Data Scope | Sensitive Personal Data only | All digital personal data |
| Notice Requirement | General privacy policy | Specific, granular notice in 22 languages |
| Individual Rights | Access and correction only | Access, correction, erasure, nomination |
| Compliance Officer | Grievance Officer | Data Protection Officer (for SDFs) |
| Children’s Data | No specific age-based rules | Strict rules for users under 18 |
| Max Penalty | Compensation based on loss | Up to ₹250 Crore per incident |
| Storage Limit | Not explicitly restricted | Must delete when purpose is served |
| Government Access | Broad exemptions | Specific exemptions for security/order |
This week
Review your database fields. Identify any “general” personal data you currently store, such as names, IP addresses, or location history. Under the IT Act, these were likely unregulated. Prepare a plan to bring these fields under the same security and consent standards you previously used only for sensitive data.
FAQ
Q: Does DPDP replace the IT Act? A: The DPDP Act will override the SPDI Rules under the IT Act for personal data protection. However, the IT Act still governs cybercrime and general electronic records.
Q: If I comply with SPDI Rules, am I safe for DPDP? A: No. The SPDI Rules only focused on sensitive data like passwords or financial info. DPDP covers all digital personal data and requires much stricter consent and user rights.
Q: What happens to physical records under DPDP vs the IT Act? A: Neither law applies to non-digitized physical records. However, if you scan a physical document or enter the data into a computer, it must comply with DPDP standards.
Confused by the differences?
Dual compliance is tricky. Our experts can help you navigate both DPDP vs IT Act: Comparing India Data Laws and DPDP requirements.
Book Strategy Call