For over a decade, narrow provisions of the IT Act and SPDI Rules were doing the job a data protection Act should have been doing, they were never built for that job — here’s what it covered, and what it left out.
Before: IT Act, Section 43A + SPDI Rules (2011)
- Applied only to “body corporates” — not government bodies, individuals or partnerships
- Covered only narrow categories of “personal and sensitive” data — passwords, financial and health data among them
- No dedicated regulator or enforcement body
- No defined set of individual rights
Now: The DPDP Act (2023)
- Applies to any Data Fiduciary, government and private, that processes digital personal data.
- Covers all digital personal identifiable data, not just a sensitive subset
- A dedicated Data Protection Board of India
- Defined rights to access, correction, erasure, grievance redressal and nomination
The Information Technology Act, 2000 was written when India had under just a few million internet users, to deal with e-commerce and computer crime — not privacy. A 2008 amendment added Section 43A, and 2011 brought the SPDI Rules alongside it, but both were narrow by design: a small legal patch on a law that was never meant to carry the weight of a full data protection regime.
Common misconception — That India had no data protection rules at all before 2023. It did — just a narrow, limited set that covered a fraction of what the DPDP Act now covers.
The DPDP Act didn’t invent data protection in India. It’s the first law built for that job from the ground up.
SOURCES Data Protected: India — Linklaters — https://www.linklaters.com/insights/data-protected/data-protected—india · The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf