Information Technology Act, 2000

IT Act Privacy vs DPDP Act Privacy: The Two Regimes Compared

Until the DPDP Act's final phase commences, India runs two data protection regimes at once: the IT Act's fragments, s.43A compensation, the SPDI Rules, the ss.72 and 72A offences, still operative, and the DPDP framework phasing in under the 2025 Rules. The regimes differ on every structural axis, what data, whose duty, what consent, which forum, whose money, and the comparison is now a fixture of examination papers. Topics 54, 39 and 87 built each side; this note, as asked, is the dedicated comparison.

1. The Structural Comparison

Axis by axis

Figure 1: Axis by axis

  • Architecture. The IT Act protects privacy through fragments serving different masters, a compensation section, two offences, an imagery offence, delegated rules; the DPDP Act is a single-purpose statute: one set of definitions, obligations, rights and enforcement for all digital personal data processing.
  • Protected data. s.43A guards only sensitive personal data or information, the SPDI Rules' closed list of passwords, financial information, health, sexual orientation, medical records and biometrics; the DPDP Act protects all digital personal data, any data about an identifiable individual, with no separate sensitive category, sensitivity surfacing instead through significant fiduciary designation and the children's chapter.
  • The actors. Body corporate against data fiduciary: the first a company-shaped noun caught only when handling SPDI in a computer resource it owns, controls or operates, the second a functional definition, whoever determines purpose and means, catching government bodies, firms and individuals alike, with the processor as its instrument. Provider of information against data principal: the SPDI Rules' individual is a source to be dealt with fairly; the DPDP principal is a rights-holder with access, correction, erasure, grievance and nomination.
  • Consent. SPDI consent is thin, obtained in writing or electronically for the collection, policy-centred and practically buried in terms; DPDP consent is free, specific, informed, unconditional and unambiguous with clear affirmative action, preceded by an itemised notice, withdrawable as easily as given, supplemented by defined legitimate uses and administered, at the principal's choice, through registered consent managers (Topic 87)
  • Security and breach. Reasonable security practices and procedures, ISO 27001 or an approved code, against reasonable security safeguards fixed by the fiduciary's own risk assessment under the 2025 Rules; and where the IT Act regime tells no one anything after a breach, the DPDP Act obliges intimation of every affected principal and the Board, the failure itself among the most heavily penalised defaults.

2. Enforcement and the Individual's Remedy

Where the injured person actually goes

Figure 2: Where the injured person actually goes

  • Forum against forum. The s.43A claim goes to the adjudicating officer under s.46, with appeal to the TDSAT, an adjudication between victim and body corporate; the DPDP complaint goes to the Data Protection Board of India, a digital-first regulator inquiring into breaches, with the same appellate destination, the TDSAT (Topics 55, 39)
  • Compensation against penalty. The deepest difference: s.43A pays the victim, damages by way of compensation measured by the wrongful loss or gain; the DPDP schedule fines the fiduciary, up to Rs 250 crore for failed security safeguards, the money going to the State, with no compensation jurisdiction in the Board. Under the DPDP regime the injured individual's monetary claim must travel outside the statute, in contract or tort, a structural gap the comparison question always rewards.
  • Offences against civil scheme. The IT Act adds criminal privacy protection, s.72 for officials, s.72A for service providers' wrongful disclosure, three years' imprisonment; the DPDP Act creates no offences and no imprisonment, a purely civil-penalty design, so after full transition the criminal edge of Indian data protection remains the IT Act's (Topic 65)

3. Transition: What Goes, What Survives

  • What goes. At the DPDP Act's final commencement phase, s.44(2) of that Act omits s.43A, deletes the SPDI rulemaking head s.87(2)(ob), and adds the DPDP Act to the s.81 proviso alongside the Copyright and Patents Acts; the SPDI Rules die with their parent provision (Topics 39, 84)
  • What survives. ss.72 and 72A continue as the criminal layer; s.66E and the intimate-imagery machinery of the intermediary rules continue for privacy-invasive content; s.69's interception safeguards and the Puttaswamy standards continue for surveillance, the DPDP Act replaces the civil data protection regime, not the IT Act's privacy offences or content rules (Topics 65, 70, 74)
  • Meanwhile. Until that phase, both regimes are simultaneously true: a 2026 breach can yield a s.43A compensation claim on the existing law and, as the corresponding DPDP obligations commence, fiduciary duties under the new, the examination answer that must be dated to be right (Topic 87)

⚠ Exam trap

Hold the four vocabulary pairs and never mix registers: SPDI against personal data, body corporate against data fiduciary, provider of information against data principal, reasonable security practices against security safeguards. The decisive functional contrast is remedial, s.43A compensates the victim through the adjudicating officer while the DPDP Board penalises the fiduciary for the State and compensates no one, both appealing to the TDSAT. And date the transition: s.43A lives until the final DPDP phase omits it, while ss.72, 72A and 66E survive the transition altogether.

4. Frequently Asked Questions

How does privacy protection under the IT Act differ from the DPDP Act?

The IT Act protects privacy in fragments: Section 43A compensation for negligent handling of the SPDI Rules' listed sensitive categories by a body corporate, criminal liability under Sections 72 and 72A for wrongful disclosure, and Section 66E for private imagery. The DPDP Act is a complete regime over all digital personal data: notice-based consent, purpose limitation, security safeguards, breach notification to principals and the Board, rights of access, correction and erasure, graded duties for significant fiduciaries, and Data Protection Board penalties up to Rs 250 crore. The IT Act pays the victim compensation; the DPDP Act fines the fiduciary and gives the individual no statutory compensation forum.

Does the DPDP Act repeal the IT Act's privacy provisions?

Only the civil core. On the final commencement phase, Section 43A stands omitted, the SPDI rulemaking clause in Section 87(2)(ob) goes with it, and the DPDP Act joins the Section 81 proviso. Sections 72 and 72A, Section 66E and the intermediary rules' privacy-content machinery all survive, so the criminal and content dimensions of privacy remain the IT Act's, with the DPDP Act carrying the data protection regime.

5. Related Topics

  • Topic 54: Section 43A and the SPDI Rules. The outgoing regime in full.
  • Topic 87: Privacy and Data Protection. The whole privacy arc including the DPDP framework.