Information Technology Act, 2000
IT Act and Data Protection: From Section 43A to the DPDP Act
For fourteen years, India's data protection law was a single section of the IT Act, Section 43A, and the SPDI Rules made under it. The Digital Personal Data Protection Act, 2023 replaces that arrangement with a full statute, and its own Section 44 amends the IT Act to make room for it. Topic 8 explained the old regime in detail and Topic 18 the constitutional background. This note focuses on the transition: how the two regimes compare, what changes in the IT Act and when, what survives, what the DPDP Rules require, what happens to claims already pending, and how an organisation should prepare.
1. Moving House, One Room at a Time
A family moving to a bigger house does not move everything in one day. The kitchen moves first, then the bedrooms, and for a while some things are in the old house and some in the new. India's data protection law is moving house in the same way: the Data Protection Board was set up first, consent managers come next, and the main duties, together with the omission of Section 43A, follow in May 2027. Until then, the old house is still lived in.
Figure 1: The phased transition from the IT Act to the DPDP Act
2. The Two Regimes Compared
Figure 2: Section 43A and the SPDI Rules compared with the DPDP Act
- From narrow to general. The IT Act protected only 'sensitive' personal data, such as passwords, financial and health information and biometrics. The DPDP Act covers all digital personal data, and personal data collected on paper and later digitised.
- From companies to everyone. Section 43A bound only bodies corporate. The DPDP Act binds every Data Fiduciary, including government, though Section 17 allows exemptions.
- From security to accountability. The old duty was essentially to keep sensitive data secure. The new Act adds purpose limitation, accuracy, breach notification, erasure, grievance redressal and special duties for children and significant fiduciaries.
- From compensation to penalty. The most important change in remedy: a victim under Section 43A receives compensation; under the DPDP Act the Board imposes penalties paid into the Consolidated Fund of India, with no compensation to the individual.
3. How the DPDP Act Amends the IT Act (Section 44(2))
Section 44(2), Digital Personal Data Protection Act, 2023 The Information Technology Act, 2000 shall be amended in the following manner, namely: (a) section 43A shall be omitted; (b) in section 81, in the proviso, after the words and figures 'the Patents Act, 1970', the words and figures 'or the Digital Personal Data Protection Act, 2023' shall be inserted; and (c) in section 87, in sub-section (2), clause (ob) shall be omitted. |
- Section 43A omitted. The civil compensation remedy for negligent handling of sensitive personal data disappears, replaced by the DPDP Act's duties and penalties.
- Section 81 amended. The IT Act's overriding clause will not restrict rights under the DPDP Act, just as it does not restrict rights under the Copyright and Patents Acts. Section 38 of the DPDP Act adds that the DPDP Act prevails over any other law in case of conflict.
- Section 87(2)(ob) omitted. The power to make rules on reasonable security practices and sensitive personal data under Section 43A goes, so the SPDI Rules lose their legal basis.
- Timing. These amendments are scheduled to take effect with the DPDP Act's substantive provisions in May 2027. Until then, Section 43A and the SPDI Rules remain fully in force.
- Section 44(3). Separately amends Section 8(1)(j) of the RTI Act to exempt all personal information from disclosure, removing the public interest test, which has been widely criticised.
4. What Survives in the IT Act
Figure 3: What stays in the IT Act and what goes
- Offences and penalties stay. Identity theft (s.66C) and capturing or publishing private images (s.66E) remain offences, and disclosure by officials (s.72, up to ₹5 lakh) and disclosure of personal information in breach of contract (s.72A, up to ₹25 lakh) remain civil penalties after the Jan Vishwas Act. The DPDP Act creates no offences, so the IT Act continues to supply criminal sanctions for serious privacy wrongs.
- Civil remedy under Section 43 stays. Compensation for downloading or copying data without permission (s.43(b)) survives, so an individual may still claim compensation for unauthorised access.
- Security and State powers stay. CERT-In's powers, interception and traffic data provisions, and preservation duties of intermediaries continue.
5. The DPDP Rules, 2025
Figure 4: Key requirements of the DPDP Rules, 2025
- Notified. On 13 November 2025, with commencement in three phases: immediately for the Board and administrative provisions, after twelve months for consent managers, and after eighteen months for the substantive obligations.
- Breach. A Data Fiduciary must inform affected Data Principals without delay and give the Board a detailed report within 72 hours of becoming aware of a breach.
- Security. Reasonable safeguards include encryption or masking, access controls, and keeping logs for at least one year.
- Erasure. Large e-commerce, gaming and social media platforms must erase personal data after three years of user inactivity, giving 48 hours' notice before doing so, unless retention is required by law.
- Children. Verifiable parental consent, for example through identity records or a DigiLocker-based token.
- Significant Data Fiduciaries. Annual data protection impact assessment and audit, and possible restrictions on transferring notified categories of data.
Figure 5: Maximum penalties under the Schedule to the DPDP Act
6. Transition Issues
- Pending Section 43A claims. Under Section 6 of the General Clauses Act, the repeal of a provision does not affect rights, liabilities or proceedings already accrued or pending, unless a different intention appears. The Supreme Court in Fibre Boards (P) Ltd. v. CIT, (2015) 10 SCC 333 held that 'omission' is a form of repeal for this purpose. Claims for breaches before May 2027 should therefore continue under Section 43A.
- Two regulators. Until May 2027 data wrongs go to adjudicating officers under the IT Act; afterwards, personal data breaches go to the Data Protection Board, while unauthorised access claims under Section 43 remain with adjudicating officers.
- Overlap with offences. A single leak may attract a DPDP penalty against the company and a Section 72A penalty against the individual who leaked the data, besides prosecution under Section 66 or 66C if done dishonestly or fraudulently.
- The State. Government bodies, never bound by Section 43A, become Data Fiduciaries under the DPDP Act, subject to exemptions under Section 17.
7. A Compliance Roadmap
- Now to May 2027. Continue SPDI compliance: privacy policy, written consent for sensitive data, ISO/IEC 27001 or equivalent security, grievance officer.
- Build notice and consent. Draft itemised notices, consent flows that can be withdrawn as easily as given, and parental consent for children.
- Prepare for breaches. Incident response that meets both CERT-In's six-hour rule and the DPDP 72-hour report.
- Plan erasure and rights. Retention schedules, erasure processes, and a system for access, correction and grievance requests.
⚠ Exam trap Three errors to avoid. First, Section 43A has not yet been omitted; the omission takes effect with the DPDP Act's substantive provisions, scheduled for May 2027. Secondly, the DPDP Act does not repeal the IT Act's privacy provisions; Sections 66C and 66E (offences) and 72 and 72A (civil penalties since 2023) continue. Thirdly, the DPDP Act gives penalties to the State, not compensation to the victim. |
8. Quick Revision and Memory Aids
- 'Moving house, one room at a time'. The phased transition.
- '44(2): omit 43A, amend 81, omit 87(2)(ob)'. The three amendments.
- 'Nov 2025, Nov 2026, May 2027'. The phases.
- '250, 200, 200, 150, 50, 10,000'. The penalty ladder.
9. Frequently Asked Questions
How does the DPDP Act amend the IT Act?
Section 44(2) omits Section 43A, inserts a reference to the DPDP Act in the proviso to Section 81, and omits the rule-making power in Section 87(2)(ob). These changes are scheduled to take effect in May 2027.
10. Related Topics
- Topic 8: Privacy and Data Protection. The SPDI Rules in detail.
- Topic 39: DPDP Act and the Transition. The division between cyber law and data protection.