Do You Still Need to Comply With the SPDI Rules?
Whether India's SPDI Rules under the IT Act still apply now that the DPDP Act exists, and what businesses should do during the transition period.
Yes, for now: the SPDI Rules under the IT Act have not been formally repealed, and since the DPDP Act's full obligations are not enforceable until 13 May 2027, businesses are effectively operating under both frameworks during this transition period.
Key facts at a glance
- The SPDI Rules (Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011) were notified under the IT Act and remain relevant unless formally repealed.
- The DPDP Act 2023's full substantive obligations, including notice, consent, security safeguards and breach reporting, become enforceable only on 13 May 2027, under the DPDP Rules 2025.
- SPDI Rules apply narrowly to sensitive personal data or information (passwords, financial data, health data, biometric data, sexual orientation, and similar categories) handled by body corporates.
- The DPDP Act applies more broadly, to all personal data processed digitally, not just a defined sensitive-data list.
- The Consent Manager registration framework under DPDP Rule 4 becomes operational earlier, on 13 November 2026.
- Penalties under DPDP for security-safeguard failures can reach up to Rs 250 crore per instance once the Act's obligations bite.
Why this question keeps coming up
Many businesses assume that once a newer, more comprehensive law like the DPDP Act exists, an older rule like SPDI automatically stops mattering. That is not how Indian law transitions typically work. Unless a provision is expressly repealed or the DPDP framework's commencement notifications say otherwise, the SPDI Rules continue to apply to sensitive personal data or information, especially since DPDP's own substantive obligations are not yet enforceable for most businesses.
The scope difference matters
SPDI Rules were always narrower than DPDP in scope: they focused specifically on a defined list of sensitive data categories handled by "body corporates," largely aimed at practices like requiring consent for collection of sensitive data and mandating a published privacy policy. The DPDP Act covers all personal data, sensitive or not, processed digitally by a much wider range of entities, with its own separate compliance architecture built around consent, notice, data-principal rights and security.
| Aspect | SPDI Rules (IT Act) | DPDP Act |
|---|---|---|
| Scope of data | Defined sensitive personal data or information | All personal data processed digitally |
| Who it applies to | Body corporates handling sensitive data | Data Fiduciaries generally, more broadly defined |
| Full enforceability | Notified since 2011 | Substantive obligations enforceable from 13 May 2027 |
| Core requirement | Consent, privacy policy, reasonable security practices | Notice, consent, data-principal rights, breach reporting, security safeguards |
What businesses should actually do during the overlap
Treat existing SPDI-compliant practices, a published privacy policy, documented consent capture for sensitive data collection, and reasonable security practices, as the floor, not the ceiling. These elements substantially overlap with what DPDP will also require, so a business that already has a solid SPDI-based privacy policy is not starting from zero when it builds out DPDP compliance; it is extending an existing foundation.
Do not treat DPDP's later deadline as permission to pause
Because the DPDP Act's full obligations are not enforceable until 13 May 2027, it can be tempting to treat data-protection compliance as something to revisit closer to that date. That reasoning ignores that SPDI obligations are current and active right now for any sensitive personal data a business handles, and that the operational work of building proper notice, consent and security processes takes real time regardless of which specific law is cited as the trigger.
The practical transition plan
Keep SPDI-based practices running as-is for now. In parallel, start building the broader DPDP-aligned foundation, a data map covering all personal data (not just the sensitive categories SPDI defined), updated notices, and stronger security safeguards, so that by the time DPDP's obligations become enforceable, the business is extending an existing system rather than building one under deadline pressure.
If you are not sure whether your current privacy practices cover both frameworks properly, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology — meity.gov.in
- Data Protection Board of India (as established under the DPDP Rules)
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Are the SPDI Rules still in force now that DPDP exists?
- As of 2026, the SPDI Rules under the IT Act have not been formally repealed, and the DPDP Act's full substantive obligations are not yet enforceable until 13 May 2027, so businesses should treat both frameworks as relevant during this transition period.
- What is the difference between SPDI Rules and the DPDP Act?
- The SPDI Rules, notified under the IT Act, apply narrowly to sensitive personal data or information handled by body corporates, while the DPDP Act is a broader, dedicated data-protection law covering all personal data processed digitally, with its own consent, notice and security framework.
- Which sensitive data categories did the SPDI Rules originally cover?
- The SPDI Rules covered categories such as passwords, financial information, health data, biometric data, sexual orientation and similar sensitive categories, requiring consent and a documented privacy policy for their collection and use.
- Should a business stop following its SPDI-based privacy policy once DPDP is fully enforceable?
- Not necessarily; many practical elements of an SPDI-compliant privacy policy, such as clear notice and consent for sensitive data, overlap with what the DPDP Act will also require, so a well-built SPDI policy is a reasonable starting point to evolve rather than discard.
- When does DPDP fully take over as the enforceable standard?
- Full substantive DPDP obligations, including notice, consent, security safeguards and breach reporting, become enforceable on 13 May 2027 under the DPDP Rules 2025, with no stated grace period after that date.
- What should businesses do right now given this transition?
- Keep existing SPDI-compliant practices such as documented consent and a published privacy policy in place, while building toward the broader DPDP requirements so the transition in 2027 does not require starting from scratch.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.