Back to Interaction with Other Laws

IT Act, 2000 and SPDI Rules

How the DPDPA interacts with the Information Technology Act, 2000 and the SPDI Rules - the pending Section 43A omission, and continuing provisions.

7 min read

Overview of the IT Act Framework

The Information Technology Act, 2000 has been India's foundational cyber law, governing electronic commerce, cybersecurity, intermediary liability, and - through Section 43A - data protection. The SPDI Rules, 2011 under Section 43A established requirements for handling Sensitive Personal Data or Information. Section 44(2) of the DPDPA will, once commenced, omit Section 43A of the IT Act. That commencement has not yet occurred: the Central Government has notified only Rules 1-2 and Rules 17-21 of the DPDP Rules so far, and section 44(2) itself has not been brought into force by separate notification. Until it is, Section 43A of the IT Act and the SPDI Rules, 2011 remain fully in force and continue to govern Sensitive Personal Data or Information alongside the DPDPA provisions already in effect.

Pending Omission of Section 43A

Section 44(2) of the DPDPA provides for the omission of Section 43A of the IT Act, which underpins the SPDI Rules governing consent for collection of sensitive personal data, reasonable security practices, and transfer restrictions. That omission takes effect only when the Central Government notifies the commencement of section 44(2); as things stand, that notification has not been issued, so Section 43A and the SPDI Rules remain in force. Organisations should continue to comply with the SPDI framework while preparing to transition once section 44(2) is commenced and the DPDPA's operational provisions take effect. Key differences to plan for include the broader scope of 'personal data' (vs. 'sensitive personal data'), the consent framework (Section 6 vs. SPDI Rule 5), and the regulatory architecture.

Continuing IT Act Provisions

Section 43A remains in force pending commencement of DPDPA section 44(2), and the rest of the IT Act continues to operate alongside the DPDPA in any event. Key continuing provisions include: Sections 66B, 66C, 66D, and 66E covering offences such as receiving stolen computer resources, identity theft, cheating by personation, and violation of privacy/voyeurism (note: Section 66A was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India (2015) and is no longer enforceable); Section 69 on interception and monitoring; Section 70B on CERT-In; Section 79 on intermediary liability; and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Organisations must comply with both the DPDPA and these continuing IT Act provisions.

Practical Transition Considerations

Organisations should: (a) audit existing SPDI-based consent mechanisms and update them to DPDPA standards; (b) review privacy policies that reference the IT Act/SPDI Rules; (c) update vendor contracts that incorporate SPDI obligations; (d) ensure security practices meet both IT Act and DPDPA requirements; and (e) maintain compliance with CERT-In reporting obligations alongside DPDPA breach notification.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.