Back to Interaction with Other Laws
IT Act, 2000 and SPDI Rules
How the DPDPA interacts with the Information Technology Act, 2000 and the SPDI Rules - amendments, supersession, and continuing provisions.
7 min read
Overview of the IT Act Framework
The Information Technology Act, 2000 has been India's foundational cyber law, governing electronic commerce, cybersecurity, intermediary liability, and - through Section 43A - data protection. The SPDI Rules, 2011 under Section 43A established requirements for handling Sensitive Personal Data or Information.
The DPDPA fundamentally alters this landscape by omitting Section 43A of the IT Act (through Section 44 of the DPDPA), effectively superseding the SPDI Rules. As a transitional matter, the SPDI Rules, 2011 remain the practical 'floor' for compliance until the full 18-month implementation window for DPDPA obligations (ending May 2027) is complete.
Omission of Section 43A
Section 44 of the DPDPA explicitly amends the IT Act by omitting Section 43A. This removes the statutory basis for the SPDI Rules, which governed consent for collection of sensitive personal data, reasonable security practices, and transfer restrictions.
Organisations that relied on the SPDI framework must transition to the DPDPA's requirements. Key differences include the broader scope of 'personal data' (vs. 'sensitive personal data'), the consent framework (Section 6 vs. SPDI Rule 5), and the regulatory architecture.
Continuing IT Act Provisions
While Section 43A is omitted, the rest of the IT Act continues to operate alongside the DPDPA. Key continuing provisions include: Sections 66B, 66C, 66D, and 66E covering offences such as receiving stolen computer resources, identity theft, cheating by personation, and violation of privacy/voyeurism (note: Section 66A was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India (2015) and is no longer enforceable); Section 69 on interception and monitoring; Section 70B on CERT-In; Section 79 on intermediary liability; and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
Organisations must comply with both the DPDPA and these continuing IT Act provisions.
Practical Transition Considerations
Organisations should: (a) audit existing SPDI-based consent mechanisms and update them to DPDPA standards; (b) review privacy policies that reference the IT Act/SPDI Rules; (c) update vendor contracts that incorporate SPDI obligations; (d) ensure security practices meet both IT Act and DPDPA requirements; and (e) maintain compliance with CERT-In reporting obligations alongside DPDPA breach notification.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
