DPDP vs the IT Rules 2011: What Replaced What
Companies with compliance built on the 2011 SPDI Rules are working from a different model. The most important change is one of category.
The structural difference
The 2011 SPDI Rules were built around a defined category of sensitive personal data or information, with heavier obligations for that subset. The DPDP Act does not carry that category forward. Personal data is personal data.
Volume and sensitivity remain relevant, but at a different level: section 10 lists them among the factors for notifying a Significant Data Fiduciary, which changes who carries extra duties rather than which fields do.
Other meaningful changes
- A regulator exists. The Data Protection Board of India was constituted under provisions that commenced on 13 November 2025. The SPDI regime had no dedicated body.
- Penalties are specific and large. The Schedule to the Act sets heads up to two hundred and fifty crore rupees.
- Breach intimation is prescribed. Rule 7 sets out who is told, what they are told and when.
- Rights are enumerated. Rule 14 requires a published route for exercising them.
- Security is itemised. Rule 6 lists minimum measures rather than referring to a reasonable practices standard.
What to do if your programme predates DPDP
- Stop classifying by sensitivity as the primary control decision, and start from a complete inventory.
- Re-assess controls against the Rule 6 list, particularly logging and its one year retention.
- Build the breach and rights processes, which have no real SPDI equivalent.
- Revisit consent, since section 6 is more demanding than the 2011 position.
Common questions
Do the IT Rules 2011 still apply after DPDP?
The DPDP Act establishes a comprehensive framework for digital personal data and section 44 of the Act deals with amendments and repeals. Organisations should confirm the current position with counsel, but as a matter of practical compliance the DPDP Act and DPDP Rules 2025 are now the governing instruments for digital personal data.
Does DPDP have a sensitive personal data category?
No. The 2011 SPDI Rules defined sensitive personal data or information including passwords, financial information, health data and biometrics. The DPDP Act does not replicate that category; all personal data carries the same base obligations.
Migrating from an SPDI-era programme?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment