Information Technology Act, 2000
Section 43A and SPDI Rules 2011: Data Protection and the DPDP Transition
For fifteen years, India's data protection law has lived in one section and one set of rules: Section 43A, inserted in 2008, and the SPDI Rules of 2011. They oblige companies holding sensitive personal data to keep it reasonably secure, and make negligence compensable. The DPDP Act, 2023 will replace them, but not yet: the omission of Section 43A is scheduled for 13 May 2027, so this remains the law in force and in the exams. Topics 8, 25 and 39 covered the constitutional setting and the transition; this note is the complete study of Section 43A and the SPDI Rules themselves, with the comparisons that matter.
1. The Warehouse That Keeps Your Valuables
When you hand valuables to a warehouse, the law of bailment demands reasonable care, and the keeper pays for losses his carelessness causes. Section 43A applies that idea to the most personal cargo, passwords, finances, health, and to corporate keepers: a body corporate that is careless with the sensitive data it holds pays the person harmed. The SPDI Rules are the warehouse manual, saying how the cargo may be accepted, stored, shown, shipped and guarded.
2. Section 43A: The Elements
Section 43A, Information Technology Act, 2000 (inserted in 2008) Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected. Explanation. (i) 'body corporate' means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities; (ii) 'reasonable security practices and procedures' means security practices and procedures designed to protect such information from unauthorised access, damage, use, modification, disclosure or impairment, as may be specified in an agreement between the parties or as may be specified in any law for the time being in force and in the absence of such agreement or any law, such reasonable security practices and procedures, as may be prescribed by the Central Government; (iii) 'sensitive personal data or information' means such personal information as may be prescribed by the Central Government. |
Figure 1: The four elements of Section 43A
- Body corporate. Wider than 'company': it takes in firms, sole proprietorships and associations of individuals, provided they are engaged in commercial or professional activities. Government departments and purely non-commercial bodies fall outside, one of the provision's criticised gaps.
- Possessing, dealing or handling SPDI. In a computer resource the body corporate owns, controls or operates, which includes outsourced processors handling data for others.
- Negligence in implementing security practices. The fault is negligence in implementing and maintaining reasonable security practices, not the breach itself. A company that maintained the prescribed practices and was still beaten by a sophisticated attack has a defence; a company with no audits, no encryption and shared passwords does not.
- Reasonable security practices and procedures. A three-step definition: what the parties' agreement specifies; else what any law specifies; else what the Central Government prescribes, which is where the SPDI Rules and ISO/IEC 27001 come in.
- Wrongful loss or wrongful gain. The negligence must cause wrongful loss or wrongful gain to a person, carrying the penal code's sense: loss of property to which one is legally entitled, and gain of property to which one is not.
- Compensation. Damages by way of compensation to the person affected, without any ceiling. Claims up to ₹5 crore go to the adjudicating officer under Section 46, larger ones to the civil court.
3. Sensitive Personal Data or Information
Figure 2: The SPDI categories under Rule 3
- The list (Rule 3). Passwords; financial information such as bank account, credit and debit card and other payment details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; any detail relating to these supplied for providing a service; and information received under these heads for processing or storage.
- The exclusion. Information freely available or accessible in the public domain, or furnished under the RTI Act or any other law, is not SPDI.
- Personal vs sensitive. The Rules define personal information broadly (any information capable of identifying a person), but the heavy duties, consent, transfer limits, security, attach to the sensitive sub-set. The DPDP Act abandons this two-tier design and covers all digital personal data.
4. The SPDI Rules, 2011: Complete Scheme
Figure 3: The SPDI Rules from policy to grievance
- Privacy policy (Rule 4). Every body corporate handling personal information must publish a privacy policy on its website, stating the type of data collected, the purpose, the disclosure practices and the reasonable security practices followed.
- Consent for collection (Rule 5(1)). SPDI may be collected only with the consent of the provider, obtained in writing or by any mode of electronic communication, regarding the purpose of use, before collection.
- Collection limitation (Rule 5(2), (3)). Collection only for a lawful purpose connected with a function or activity of the body corporate, and only if necessary for that purpose; the provider must know that data is being collected, its purpose, the intended recipients, and the agencies collecting and retaining it.
- Purpose limitation (Rule 5(5)). The information may be used only for the purpose for which it was collected.
- Retention (Rule 5(4)). SPDI may not be retained longer than is required for the purpose, or than the law demands.
- Options and review (Rule 5(6), (7)). The provider may review and correct his information, may decline to give consent, and may withdraw consent later, in writing; the body corporate may then decline the service.
- Disclosure to third parties (Rule 6). Disclosure needs the provider's prior permission, unless it was agreed in the contract or is required by law; government agencies may obtain it for verification, prevention, investigation and like purposes by a written request; SPDI must not be published; and the receiving third party must not disclose it further.
- Transfer of sensitive data (Rule 7). Transfer, within India or abroad, only to a body that ensures the same level of data protection, and only where necessary for the performance of the lawful contract or with the provider's consent.
- Reasonable security standard (Rule 8). A comprehensive documented information security programme with managerial, technical, operational and physical controls. ISO/IEC 27001 is the named standard; industry codes approved by the Government also qualify; and compliance must be audited by an approved auditor at least annually and after significant upgrades.
- Grievance Officer (Rule 5(9)). A named Grievance Officer, with contact details published on the website, who must redress grievances within one month.
- The 2011 clarification. A Government clarification confirmed that Rules 5 and 6 apply to bodies corporate collecting from natural persons in India, and that outsourcing processors serving foreign clients under contract are outside the consent rules.
5. The Comparisons
Figure 4: Section 43A and Section 72A
- Section 43A vs Section 72A. 43A is negligence-based compensation from the body corporate for insecure systems; 72A punishes the person who, with intent or knowledge of wrongful loss or gain, discloses personal information obtained under a lawful services contract, now a civil penalty of up to ₹25 lakh (see Topic 40). One targets careless keepers, the other treacherous insiders, and one incident can engage both.
Figure 5: Section 43A and the DPDP Act compared
- Section 43A vs the DPDP Act. 43A protects only SPDI, binds only bodies corporate, and pays the victim; the DPDP Act covers all digital personal data, binds every Data Fiduciary including the State (subject to exemptions), imposes positive duties of notice, consent, breach reporting and erasure, and penalises through the Board, up to ₹250 crore, with no compensation to the individual.
- What the individual loses and gains. The compensation remedy disappears with 43A, a real loss; in exchange the individual gets enforceable rights, breach notification and a regulator that can act without his complaint.
6. The Transition
Figure 6: From Section 43A to the DPDP Act
- Scheduled omission of Section 43A. Section 44(2)(a) of the DPDP Act omits Section 43A, and Section 44(2)(c) omits Section 87(2)(ob), the rule-making power behind the SPDI Rules. Under the phased commencement notified in November 2025, these amendments take effect on 13 May 2027, with the DPDP Act's core duties (see Topic 39)
- SPDI Rules during the transitional period. Until that date, Section 43A and the SPDI Rules remain fully in force: consent, privacy policies, ISO 27001 audits, the Grievance Officer and the compensation remedy all continue, and compliance programmes must run both regimes in parallel as DPDP obligations phase in.
- Accrued claims. Omission is a form of repeal, so claims that accrued while Section 43A was in force are preserved by Section 6 of the General Clauses Act (Fibre Boards, (2015) 10 SCC 333) unless a contrary intention appears.
⚠ Exam trap Tense matters. Until 13 May 2027, write that Section 43A and the SPDI Rules are in force and the DPDP Act's core duties are yet to commence; after that date, the positions reverse. And keep the fault lines straight: Section 43A requires negligence in security practices, Section 43 requires no fault at all, and Section 72A requires intent or knowledge. |
7. Quick Revision and Memory Aids
- 'The careless warehouse pays'. The idea of s.43A.
- 'Body, SPDI, negligence, wrongful loss or gain'. The four elements.
- 'Pass-Fin-Health-Sex-Med-Bio'. The SPDI categories.
- 'Policy, consent, purpose, retention, disclosure, transfer, security, grievance'. The SPDI Rules in order.
- 'Agreement, law, prescription'. The three-step test of reasonable security.
- '27001 and one month'. The security standard and the grievance deadline.
- '43A sleeps on 13 May 2027'. The scheduled omission.
8. Frequently Asked Questions
Is Section 43A still in force?
Yes. Its omission by Section 44(2)(a) of the DPDP Act is enacted but commences on 13 May 2027 with the DPDP Act's core obligations. Until then, Section 43A and the SPDI Rules, 2011 continue to govern sensitive personal data held by bodies corporate.
What counts as sensitive personal data under the SPDI Rules?
Passwords; financial information such as bank account and card details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; related details supplied for services; and information received under these heads for processing, excluding information freely available in the public domain or furnished under law.
9. Related Topics
- Topic 39: DPDP Act and the Transition. The amendments and their timing.
- Topic 53: Section 43. The companion contravention for unauthorised access.