DPDP vs the Old SPDI Rules: What Actually Changed
How the DPDP Act 2023 differs from the older SPDI Rules under the IT Act - scope, consent, penalties and enforcement timelines compared for Indian businesses.
The Digital Personal Data Protection Act 2023 (DPDP) replaces the narrower, older SPDI Rules under the IT Act with a broader law covering all personal data, stronger consent mechanics, and far higher penalties - though its substantive obligations only become enforceable from 13 May 2027.
Key facts at a glance
- The old SPDI Rules covered only "sensitive personal data" (passwords, financial data, health data, biometrics); DPDP covers all personal data.
- DPDP's Consent Manager registration framework (Rule 4) becomes operational 13 November 2026.
- DPDP's full substantive obligations become enforceable 13 May 2027, with no stated grace period after that date.
- DPDP penalties can reach up to Rs 250 crore per instance for failing to implement reasonable security safeguards.
- The Data Protection Board of India provisions under DPDP took effect immediately upon notification.
- SPDI Rules obligations were narrower and did not include a dedicated regulator like the Data Protection Board.
- DPDP introduces data-principal rights (access, correction, erasure) that the SPDI Rules did not provide in comparable form.
Why SPDI Existed and What It Actually Required
The SPDI Rules (Sensitive Personal Data or Information Rules), notified under the Information Technology Act, were India's main data-protection instrument before DPDP. They applied narrowly: only to "sensitive personal data" such as passwords, financial information, health records, biometric data and sexual orientation, and only to body corporates. Businesses needed a privacy policy, had to obtain written consent before collecting sensitive data, and had baseline security-practice obligations, but the framework had no dedicated regulator and comparatively limited enforcement teeth.
What DPDP Changes
DPDP is a purpose-built data-protection law, not an IT Act appendage. It covers all personal data (not just "sensitive" categories), applies to any entity - "data fiduciary" - that determines the purpose and means of processing personal data of individuals in India, and establishes the Data Protection Board of India as a dedicated enforcement body. It introduces defined data-principal rights, a structured consent architecture including registered Consent Managers, mandatory breach notification, and a much higher penalty ceiling.
Side-by-Side Comparison
| Aspect | SPDI Rules (old) | DPDP Act (new) |
|---|---|---|
| Scope of data covered | Sensitive personal data only | All personal data |
| Legal basis | Rules under the IT Act | Dedicated standalone Act |
| Regulator | None dedicated | Data Protection Board of India |
| Consent mechanism | Written consent for sensitive data | Structured consent, Consent Manager framework |
| Data-principal rights | Limited | Access, correction, erasure and more |
| Breach notification | Not clearly mandated | Mandatory |
| Maximum penalty | Comparatively limited | Up to Rs 250 crore per instance |
| Applicability | Body corporates handling sensitive data | Any data fiduciary processing personal data of individuals in India |
| Enforcement status (2026) | Existing but narrower | Consent Manager framework live 13 Nov 2026; full obligations enforceable 13 May 2027 |
What This Means for a Business That Was Already SPDI-Compliant
Being SPDI-compliant is a reasonable starting point but not sufficient under DPDP. A business that only had a privacy policy and consent capture for sensitive data now needs to map all personal data it processes (not just sensitive categories), build a compliant consent and notice flow, prepare for breach notification obligations, and be ready for a materially higher penalty exposure if security safeguards are inadequate.
The Compliance Runway You Actually Have
Because full DPDP obligations become enforceable only from 13 May 2027, and the Consent Manager framework activates 13 November 2026, businesses have a defined window to close gaps rather than facing an overnight requirement. That runway is a planning advantage, not a reason to delay - security safeguards, consent flows and data mapping typically take longer to implement properly than businesses expect.
If you are not sure how your current data practices compare to DPDP requirements, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology, DPDP Act and Rules - meity.gov.in
- Data Protection Board of India
- Ministry of Electronics and Information Technology, IT Act and SPDI Rules - meity.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Do the old SPDI Rules still apply now that DPDP exists?
- The DPDP Act is India's dedicated data protection law and is intended to eventually supersede the SPDI framework for personal data, but businesses should track official notifications on transition timing rather than assume an immediate, total repeal.
- What personal data did the SPDI Rules cover that DPDP does not?
- The SPDI Rules only covered 'sensitive personal data or information' such as passwords, financial information, health records and biometric data, whereas DPDP covers all personal data, sensitive or not, that can identify a person.
- When do DPDP's main obligations actually become enforceable?
- Full substantive DPDP obligations - notice, consent, security safeguards, breach reporting and data-principal rights - become enforceable from 13 May 2027, with the Consent Manager registration framework becoming operational earlier, on 13 November 2026.
- How much higher are DPDP penalties compared to the old SPDI regime?
- DPDP penalties can reach up to Rs 250 crore per instance for failing to implement reasonable security safeguards, a materially higher ceiling than penalties typically associated with the SPDI Rules under the IT Act.
- Does DPDP apply only to companies that had SPDI obligations before?
- No, DPDP applies more broadly to any entity that processes personal data of individuals in India, including many businesses that were outside the narrower scope of the SPDI Rules.
- Is consent handled differently under DPDP compared to SPDI?
- Yes, DPDP introduces a more structured consent framework including the concept of registered Consent Managers, whereas the SPDI Rules relied on simpler written consent requirements limited to sensitive data collection.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.