Information Technology Act, 2000
SPDI Rules 2011 vs DPDP Rules 2025: The Two Rulebooks Compared
Topic 95 compared the parent statutes; the rulebooks deserve their own comparison, because that is where the working detail lives. The SPDI Rules, 2011 are a short code built on s.43A, sensitive categories, privacy policies and ISO-benchmarked security; the DPDP Rules, 2025, notified in November 2025, are the operating manual of a full regime, notice, consent managers, children's consent, breach timelines, retention, significant fiduciaries and the Board's procedure. Through the transition both are law at once. This note, as asked, compares them rulebook to rulebook.
1. The Comparison
Figure 1: Clause family by clause family
- Source and subject. The SPDI Rules are delegated legislation under s.87(2)(ob) with s.43A, confined to sensitive personal data or information, the closed list of passwords, financial information, health condition, sexual orientation, medical records and biometric information; the DPDP Rules are made under the DPDP Act and serve all digital personal data, with no sensitive sub-category at the rule level either (Topics 54, 95)
- Consent instrument. SPDI consent is obtained in writing or electronically for collection of sensitive data, the privacy policy carrying the disclosure burden, published and policy-shaped; the DPDP Rules build a notice-and-consent architecture, an itemised notice of the data, purpose, rights and complaint route in plain language, consent specific and withdrawable, and registered consent managers as an interoperable dashboard with their own registration conditions and obligations.
- Security standard. SPDI's reasonable security practices and procedures are satisfied by IS/ISO/IEC 27001 or an approved industry code, audited periodically, a benchmark model; the DPDP Rules prescribe minimum reasonable safeguards by reference to the fiduciary's risk, encryption or equivalent protection, access control, logging and monitoring, backups, and contractual flow-down to processors, a floor model with the fiduciary answerable for sufficiency.
- Breach. The SPDI Rules impose no breach notification at all, the gap CERT-In's incident reporting only partly filled; the DPDP Rules require intimation of every affected data principal and the Board, a prompt first intimation with prescribed particulars and a fuller report on the Rules' timeline, the duty whose failure sits in the schedule's highest penalty bands (Topics 64, 87)
- Disclosure and transfer. SPDI permits disclosure with consent or under law and transfer, in India or abroad, only to recipients ensuring the same level of protection; the DPDP side governs processors by contract, and cross-border transfer by the Act's blacklist design, restricted countries notified, with sectoral localisation continuing (Topic 87)
2. What the 2025 Rules Add
Figure 2: Machinery the SPDI world never had
- Children and guardians. Verifiable parental consent before processing a child's data, with identity and age assurance through the means the Rules prescribe, and the Act's bans on tracking and targeted advertising at children behind it, nothing comparable existing in the SPDI world.
- Significant data fiduciaries. The notified class carries a resident data protection officer, annual independent audits and periodic data protection impact assessments, the graded-duty idea the SPDI Rules never had.
- Retention and erasure. Purpose-spent data is erased; for notified classes of fiduciaries the Rules set outer retention periods with advance notice to the user before erasure, operationalising the right the SPDI regime lacked.
- The Board's procedure. A digital-first Data Protection Board, complaints, inquiries and penalty proceedings conducted electronically, with appeals to the TDSAT, replacing the s.46 adjudication route for data protection as the regime commences (Topics 55, 95)
- Commencement. The Rules phase the obligations in from their November 2025 notification, the Board and foundational provisions first and the operative duties over the following phases, the final phase retiring s.43A and the SPDI Rules with it (Topic 39)
⚠ Exam trap Compare at the rule level, not just the Act level: the SPDI Rules protect a closed sensitive list through privacy policies and an ISO benchmark with no breach duty, while the DPDP Rules protect all digital personal data through itemised notice, prescribed minimum safeguards, breach intimation of principals and the Board, verifiable parental consent, retention timelines, consent managers and a digital-first Board. Date them precisely, 2011 under s.43A against November 2025 under the DPDP Act, and remember that until the final phase both rulebooks operate, so a present-day answer must say which regime it is applying. |
3. Frequently Asked Questions
How do the DPDP Rules 2025 differ from the SPDI Rules 2011?
The SPDI Rules, made under Section 43A, protect only the listed sensitive categories, work through privacy policies and consent for collection, set security by the ISO 27001 benchmark or approved codes, and require no breach notification. The DPDP Rules, notified in November 2025 under the DPDP Act, operationalise protection of all digital personal data: itemised notice and withdrawable consent, registered consent managers, prescribed minimum security safeguards, breach intimation to every affected principal and the Data Protection Board, verifiable parental consent for children, retention and erasure timelines, significant fiduciary audits and the Board's digital-first procedure.
Do the SPDI Rules still apply after the DPDP Rules were notified?
Yes, during the transition. The DPDP regime commences in phases, and Section 43A with the SPDI Rules remains in force until the final phase brings the DPDP Act's schedule of IT Act amendments into effect, omitting Section 43A and the rulemaking clause behind the SPDI Rules. Until then a data incident can engage both rulebooks: the SPDI compensation analysis for negligent security, and whichever DPDP obligations have commenced for the fiduciary concerned.
4. Related Topics
- Topic 95: IT Act Privacy vs DPDP Privacy. The parent statutes compared.
- Topic 87: Privacy and Data Protection. The whole arc including both rulebooks.