Before the DPDP Act: India’s Data Protection Gap

For over a decade, narrow provisions of the IT Act and SPDI Rules were doing the job a data protection Act should have been doing, they were never built for that job — here’s what it covered, and what it left out.

Before: IT Act, Section 43A + SPDI Rules (2011)

Now: The DPDP Act (2023)

The Information Technology Act, 2000 was written when India had under just a few million internet users, to deal with e-commerce and computer crime — not privacy. A 2008 amendment added Section 43A, and 2011 brought the SPDI Rules alongside it, but both were narrow by design: a small legal patch on a law that was never meant to carry the weight of a full data protection regime.
Common misconception — That India had no data protection rules at all before 2023. It did — just a narrow, limited set that covered a fraction of what the DPDP Act now covers.
The DPDP Act didn’t invent data protection in India. It’s the first law built for that job from the ground up.

SOURCES  Data Protected: India — Linklaters — https://www.linklaters.com/insights/data-protected/data-protected—india   ·   The DPDP Act, 2023 — official text, MeitYhttps://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf 

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.