Infosek
INFOSEK

DPDP vs the IT Rules 2011: What Replaced What

Companies with compliance built on the 2011 SPDI Rules are working from a different model. The most important change is one of category.

DPDP vs the IT Rules 2011: What Replaced What

The structural difference

The 2011 SPDI Rules were built around a defined category of sensitive personal data or information, with heavier obligations for that subset. The DPDP Act does not carry that category forward. Personal data is personal data.

Volume and sensitivity remain relevant, but at a different level: section 10 lists them among the factors for notifying a Significant Data Fiduciary, which changes who carries extra duties rather than which fields do.

Other meaningful changes

What to do if your programme predates DPDP

Common questions

Do the IT Rules 2011 still apply after DPDP?

The DPDP Act establishes a comprehensive framework for digital personal data and section 44 of the Act deals with amendments and repeals. Organisations should confirm the current position with counsel, but as a matter of practical compliance the DPDP Act and DPDP Rules 2025 are now the governing instruments for digital personal data.

Does DPDP have a sensitive personal data category?

No. The 2011 SPDI Rules defined sensitive personal data or information including passwords, financial information, health data and biometrics. The DPDP Act does not replicate that category; all personal data carries the same base obligations.

Migrating from an SPDI-era programme?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment