Information Technology Act, 2000
DPDP Act, 2023 and the IT Act: Omission of Section 43A and Data Protection Transition
For over a decade, India's data protection law lived inside a cyber law statute: Section 43A of the IT Act and the SPDI Rules made under Section 87(2)(ob). The Digital Personal Data Protection Act, 2023 moves data protection into a statute of its own and, through Section 44(2), removes the old provisions from the IT Act. Topics 8 and 25 covered the substance of the two regimes. This note looks at the transition itself: exactly what Section 44(2) changes, when, how the two Acts relate once both are running, and why the IT Act keeps its role as India's cybersecurity law.
1. The Building and the Files
Think of a large office building. One set of rules governs its locks, alarms, guards and fire drills; another governs what the staff may do with the files of the people whose records they hold. For years India wrote both sets into one rulebook, the IT Act. The DPDP Act takes the file rules out into a new book of their own, while the building rules (hacking, breaches, incident reporting, critical infrastructure) stay where they were.
Figure 1: Two branches of digital law
2. What Section 44 of the DPDP Act Does
Section 44(2), Digital Personal Data Protection Act, 2023 (substance) The Information Technology Act, 2000 shall be amended in the following manner, namely: (a) section 43A shall be omitted; (b) in section 81, in the proviso, after the words and figures "the Patents Act, 1970", the words and figures "or the Digital Personal Data Protection Act, 2023" shall be inserted; and (c) in section 87, in sub-section (2), clause (ob) shall be omitted. |
Figure 2: The amendments made by Section 44
- Omission of Section 43A. The civil remedy against a body corporate negligent in securing sensitive personal data or information disappears. The duty to secure personal data moves to Section 8(5) of the DPDP Act, enforced by Board penalties rather than compensation.
- Amendment to Section 81. Section 81 gives the IT Act overriding effect, but its proviso protects rights under the Copyright and Patents Acts. Adding the DPDP Act means the IT Act's overriding clause can never be used to cut down a Data Principal's rights. Read with Section 38 of the DPDP Act, which makes the DPDP Act prevail in a conflict, the DPDP Act wins any clash.
- Omission of Section 87(2)(ob). The rule-making power for 'reasonable security practices and procedures and sensitive personal data or information' goes, so the SPDI Rules, 2011 lose their parent provision.
- The other amendments. Section 44(1) amends the TRAI Act so that TDSAT hears appeals from the Data Protection Board, and Section 44(3) rewrites the personal information exemption in Section 8(1)(j) of the RTI Act.
3. Proposed or Commenced? The Timing
Figure 3: Phased commencement of the DPDP Act
- Notification. G.S.R. 843(E) and the DPDP Rules, 2025, notified on 13 November 2025, bring the Act into force in three phases.
- Already in force. From 13 November 2025: definitions, the Data Protection Board and rule-making powers, together with Section 44(1) (TRAI Act) and Section 44(3) (RTI Act)
- Not yet in force. Section 44(2), the IT Act amendments, commences with the core duties and penalties on 13 May 2027. Until then Section 43A, Section 87(2)(ob) and the SPDI Rules remain law.
- Shortened timeline? Reports in early 2026 said MeitY was considering compressing the 18-month window to 12 months, but no amending notification has been issued. Check the Gazette before an exam.
⚠ Exam trap Do not write that Section 43A 'has been repealed by the DPDP Act'. As of now its omission is enacted but not yet commenced; it takes effect on 13 May 2027. Claims arising before that date are preserved by Section 6 of the General Clauses Act, because omission is a form of repeal (Fibre Boards (P) Ltd. v. CIT, (2015) 10 SCC 333). |
4. The Relationship between the Two Acts
- Borrowed vocabulary. The DPDP Act adopts the IT Act's definition of 'intermediary' and uses IT Act concepts such as 'computer resource', so the two statutes speak the same technical language.
- Overlap and priority. Section 38(1) of the DPDP Act says it is in addition to, and not in derogation of, other laws; Section 38(2) says it prevails in a conflict. The amended Section 81 proviso ensures the IT Act does not claim the opposite.
- Blocking. Section 37 of the DPDP Act lets the Central Government, on a reference from the Board after penalties in two or more instances, direct an intermediary to block a Data Fiduciary's platform in the public interest. It works alongside Section 69A of the IT Act, not through it.
- Remedies. The IT Act gives individuals compensation (s.43) and criminal complaints (ss.66, 66C, 66E); the DPDP Act gives regulatory penalties payable to the State and bars civil courts on matters before the Board (s.39)
Figure 4: Which law applies: common situations
5. Continuing Cybersecurity Obligations under the IT Act
- CERT-In (s.70B). The CERT-In Directions of 28 April 2022 require cyber incidents to be reported within 6 hours, logs kept for 180 days within India, clocks synchronised, and VPN and cloud providers to keep subscriber records for five years. Non-compliance: up to one year or fine up to ₹1 crore or both (s.70B(7), as amended in 2023)
- Critical infrastructure (ss.70, 70A). Protected systems and NCIIPC are untouched by the DPDP Act.
- Offences and contraventions. Unauthorised access (ss.43, 66), identity theft (s.66C), privacy of the body (s.66E) and disclosure in breach of contract (s.72A, now a civil penalty) all continue.
- Intermediaries. Due diligence under Section 79 and the IT Rules, 2021, including reporting incidents to CERT-In, remains in the IT Act.
Figure 5: One breach, two reports
📖 Illustration: a ransomware attack on an online retailer Facts: Attackers encrypt a retailer's servers and copy the names, addresses and phone numbers of two lakh customers. IT Act: Report to CERT-In within 6 hours; attackers liable under Sections 43 and 66, and Section 66F if critical systems are threatened. DPDP Act: Once the core duties commence: intimate the Board and each affected customer, and send a detailed report within 72 hours. If security safeguards were unreasonable, the Board may impose up to ₹250 crore; failure to notify, up to ₹200 crore. Lesson: The two regimes run in parallel, and one incident can trigger both. |
6. The Future Division of Digital Law
Figure 6: How India's digital law is dividing
- Cyber law. The IT Act, and eventually the proposed Digital India Act, governs systems, platforms, intermediaries, cyber crimes and cybersecurity. No Digital India Bill has yet been introduced.
- Data protection. The DPDP Act governs how personal data is collected and used, with the Board as a specialised regulator.
- Interception. Telecom interception now rests on the Telecommunications Act, 2023, while computer interception remains under Section 69 of the IT Act.
- General criminal law. The BNS, BNSS and BSA supply general offences, procedure and electronic evidence rules.
- Open questions. Whether individuals should regain a compensation remedy once Section 43A goes, and how the Board and CERT-In will coordinate on breaches.
7. Quick Revision and Memory Aids
- 'Building rules stay, file rules move'. Cyber law vs data protection.
- '44(2): 43A out, 81 in, 87(2)(ob) out'. The three IT Act amendments.
- '44(1) and 44(3) now, 44(2) in May 2027'. Timing.
- 'Six to CERT-In, seventy-two to the Board'. Breach reporting.
- '38 prevails, 81 yields'. The conflict rule.
8. Frequently Asked Questions
Has Section 43A of the IT Act been omitted?
Its omission is enacted by Section 44(2)(a) of the DPDP Act but commences on 13 May 2027. Until then Section 43A and the SPDI Rules continue to apply.
Does the DPDP Act replace the IT Act?
No. It replaces only the IT Act's data protection provisions. Cybersecurity, cyber offences, intermediary regulation, electronic records and signatures remain in the IT Act.
9. Related Topics
- Topic 25: IT Act and Data Protection. The DPDP regime in detail.
- Topic 38: Subsequent Amendments. The wider rationalisation of the Act.