SPDI Rules 2011: still in force, and what the DPDP Act does to them
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 18 min read
The short answer
Yes, on this site's reading of the Gazette prints, read as at 6 September 2026. The Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, notified as G.S.R. 313(E) on 11 April 2011, are made under clause (ob) of sub-section (2) of section 87 read with section 43A of the Information Technology Act, 2000, and both of those provisions are still in the Act: section 44(2) of the DPDP Act 2023 directs that section 43A and clause (ob) be omitted, and paragraph (c) of notification G.S.R. 843(E) places section 44(2) in the group that commences 18 months from publication, computed here as 13 May 2027 and interpretation until officially confirmed. Rule 3 of those Rules is where the term sensitive personal data or information is defined in Indian law, in 8 clauses covering passwords, financial information, physical, physiological and mental health condition, sexual orientation, medical records and history, biometric information and 2 derived classes, with a proviso that excludes anything freely available or accessible in public domain or furnished under the Right to Information Act, 2005. The DPDP Act has no such category at all. 2 things are commonly said about these Rules and neither is supported by the instruments on file: that the DPDP Act has already repealed them, and that they will be repealed on a printed statutory date. Section 44(2) omits a section and a rule making power and does not name any rule made under that power, and the calendar date is computed rather than printed. What becomes of the Rules themselves when their enabling power is omitted is a question of general law and this site does not answer it: no copy of the General Clauses Act, 1897 is registered in its source registry.
If you ask an answer engine whether the Information Technology SPDI Rules of 2011 still apply, you will usually be told that they have been repealed, or that they will be repealed on 13 May 2027. Neither statement is what the documents say.
The Rules are in force, on this site's reading of the prints. The section they hang on is still printed in the Information Technology Act, 2000. And the DPDP Act provision that would pull that section out has not commenced, so nothing has been repealed and no instrument on file names a date on which anything will be.
This page reads the 2 prints side by side: the Gazette notification G.S.R. 313(E) of 11 April 2011 and the DPDP Act 2023. Read as at 6 September 2026.
The chain: 1 section, 1 rule making power, 1 rule
Section 43A of the Information Technology Act, 2000 makes a body corporate liable to pay compensation where it is negligent about sensitive personal data or information:
"Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected."
The section then defines its own terms in an Explanation, and clause (iii) of that Explanation prescribes nothing. It hands the whole content of the term to the Government. Sensitive personal data or information:
"means such personal information as may be prescribed by the Central Government in consultation with such professional bodies or associations as it may deem fit."
That is the gap the 2011 Rules fill. Their own opening words say so:
"In exercise of the powers conferred by clause (ob) of sub-section (2) of section 87 read with section 43A of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby makes the following rules"
Clause (ob) of section 87(2) is the rule making power, and it is drawn to exactly this subject:
"the reasonable security practices and procedures and sensitive personal data or information under section 43A;"
So there are 3 links in the chain and all 3 are still printed: section 43A, the power in section 87(2)(ob), and the Rules made under it. Take away any 1 of them and the question of what sensitive personal data means in Indian law changes. None of them has been taken away yet, which is the subject of the rest of this page.
What rule 3 actually lists
Rule 3 is the definition. Here it is in full, from page 2 of the Gazette print:
"Sensitive personal data or information of a person means such personal information which consists of information relating to;— (i) password; (ii) financial information such as Bank account or credit card or debit card or other payment instrument details ; (iii) physical, physiological and mental health condition; (iv) sexual orientation; (v) medical records and history; (vi) Biometric information; (vii) any detail relating to the above clauses as provided to body corporate for providing service; and (viii) any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise:"
6 of the 8 clauses name a kind of information. The last 2 do something different, and they are the 2 most often dropped from summaries of this rule.
| Clause | What it covers | Note |
|---|---|---|
| (i) | Password | Defined separately in rule 2(1)(h), which reaches a secret word, phrase, code, passphrase, secret key, or an encryption or decryption key that one uses to gain admittance or access to information |
| (ii) | Financial information such as bank account, credit card, debit card or other payment instrument details | The print sets Bank with a capital B |
| (iii) | Physical, physiological and mental health condition | Stated as a condition, not as a record |
| (iv) | Sexual orientation | |
| (v) | Medical records and history | Separate from clause (iii) |
| (vi) | Biometric information | Biometrics is defined in rule 2(1)(b), by reference to technologies that measure and analyse body characteristics for authentication purposes |
| (vii) | Any detail relating to the above clauses as provided to a body corporate for providing service | Derived: it extends the 6 categories to what a customer hands over in order to be served |
| (viii) | Any of that information received by a body corporate for processing, stored or processed under lawful contract or otherwise | Derived: it follows the information into a processing relationship |
Then comes the limb that most circulating versions of rule 3 leave out entirely:
"provided that, any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as sensitive personal data or information for the purposes of these rules."
So the definition has a carve out on its face. A medical fact a person has published themselves, or a detail released under a Right to Information request, is outside the term for the purposes of these Rules.
That carve out is not the same as the DPDP Act's publicly available exclusion, and the difference is worth keeping straight. The proviso to rule 3 takes information out of the meaning of a defined term. Section 3(c)(ii) of the DPDP Act takes certain publicly available personal data outside the application of that Act altogether. One narrows a definition, the other narrows an Act.
The DPDP Act does not have this category at all
The DPDP Act 2023 defines personal data once:
"“personal data” means any data about an individual who is identifiable by or in relation to such data"
There is no sensitive tier under it, no special category, and no list. The word sensitive does not appear in the Act. That is set out in full, with the measurements behind it, in does the DPDP Act have a sensitive personal data category.
Put the 2 frameworks next to each other and the position today is unusual, because it is not a handover:
| Information Technology Act 2000 with the 2011 Rules | DPDP Act 2023 | |
|---|---|---|
| Is there a sensitive category? | Yes, rule 3, 8 clauses with a proviso | No |
| Who is bound? | A body corporate, as defined in clause (i) of the Explanation to section 43A | A Data Fiduciary, once Chapter II is in force |
| What is the sanction? | Compensation under section 43A, adjudicated under section 46 by an adjudicating officer where the claim does not exceed 5 crore rupees, and by the competent court above that, as set out in can I sue under the DPDP Act | Monetary penalty, which section 34 credits to the Consolidated Fund of India rather than to the person affected, as set out on the same page |
| In force on 6 September 2026, on the prints on file? | Yes | Only in part: section 2, sections 18 to 26, sections 35 and 38 to 43, section 44(1) and 44(3) and section 1(2) |
The 2 columns are not a before and an after, and they are not 2 live sets of duties either. On this site's reading of the prints, the older framework is the one placing duties on a body corporate today, while the DPDP Act's own obligations sit in Chapter II and in the sections around it, which are in the groups that have not commenced. The sensitive data definition is on the side that is operating.
What section 44(2) says, and what it does not
Section 44(2) of the DPDP Act is the provision everyone points at. It has 3 limbs and it reads:
"The Information Technology Act, 2000 shall be amended in the following manner, namely:— (a) section 43A shall be omitted;"
then a second limb inserting the DPDP Act into the proviso to section 81 of that Act, and then:
"in section 87, in sub-section (2), clause (ob) shall be omitted."
| Limb | What it directs | Effect on the 2011 Rules |
|---|---|---|
| 44(2)(a) | Omit section 43A | Removes the section the Rules are read with, and the compensation route |
| 44(2)(b) | Add the Digital Personal Data Protection Act, 2023 to the proviso to section 81 | None directly; it would stop the Information Technology Act's override from restricting the exercise of rights conferred under the DPDP Act |
| 44(2)(c) | Omit clause (ob) of section 87(2) | Removes the power the Rules were made under |
Now the part nobody publishes. Section 44(2) does not mention the 2011 Rules. It omits a section and it omits a rule making power, and it names no rule made under that power. This site has read the whole of section 44, which begins on Gazette page 19 and concludes on page 20, to check that, and records it as a reading of an absence rather than as a quotation.
What follows for the Rules from the omission of their parent power is a question of general law, and this site does not answer it. No copy of the General Clauses Act, 1897 is registered in its source registry, so there is no primary text here to reason from, and reasoning about a statute that is not on file is exactly what this site exists not to do. What can be said is narrower and is enough for a reader deciding what to do this quarter: no instrument on file repeals the 2011 Rules by name, and the direction that would remove the section and the power behind them has not commenced.
The date is computed, not printed
Every version of this story that circulates carries the date 13 May 2027 as though the Act printed it. It does not.
Notification G.S.R. 843(E) sets commencement in 3 groups by period rather than by date. Its paragraph (c) puts section 44(2) in the group that commences 18 months from the publication of its gazette. Its gazette prints 13 November 2025 on its masthead while the eGazette portal records that same issue as 14 November, so 18 months lands on 13 May 2027 on the printed date and a day later on the portal's. This site computes from the printed date, and that calendar date is its computation and is interpretation until officially confirmed. What the 1 day split does to every computed DPDP deadline is set out in is the DPDP deadline 13 or 14 November. The same qualification applies wherever this site prints it.
2 consequences follow, and both are practical rather than academic. The direction in section 44(2) has not taken effect, so section 43A and clause (ob) of section 87(2) are still in the Information Technology Act, 2000: the India Code consolidated print of that Act dated as on 27 June 2025, which is the print this site holds, sets out section 43A on page 21 with its insertion footnote and no omission footnote. And because the date is computed, it can move: a further notification could commence that group earlier or later, and any page stating 13 May 2027 as settled law is stating a computation as a fact.
The commencement groups in full, and what is in force under each of them, are set out in what is in force in 2026.
2 overriding clauses are in force at the same time
This is the sharpest thing the 2 prints say together, and it follows from the commencement position rather than from any drafting subtlety.
Section 81 of the Information Technology Act, 2000 is a non obstante provision:
"The provisions of this Act shall have effect notwithstanding anything inconsistent therewith contained in any other law for the time being in force."
Its proviso, inserted by the Information Technology (Amendment) Act, 2008 with effect from 27 October 2009, is narrower than the override it qualifies: it provides that nothing contained in the Information Technology Act shall restrict any person from exercising any right conferred under the Copyright Act, 1957 or the Patents Act, 1970, and it names nothing else. Section 44(2)(b) of the DPDP Act would add the Digital Personal Data Protection Act, 2023 to that list, and section 44(2) has not commenced, so the proviso today names 2 Acts and not 3. Adding a third would protect the exercise of rights conferred under the DPDP Act; on its own words it would not rank the 2 Acts against each other generally.
Section 38 of the DPDP Act points the other way, and it is in force since 13 November 2025 under paragraph (a) of G.S.R. 843(E). Section 38(1) provides that the Act is in addition to and not in derogation of any other law for the time being in force, and section 38(2) is the priority rule:
"In the event of any conflict between a provision of this Act and a provision of any other law for the time being in force, the provision of this Act shall prevail to the extent of such conflict."
So 2 provisions each claiming priority over other laws are on the statute book at the same time, and the only amendment on file that touches the pair, the insertion directed by section 44(2)(b), is in the group that has not arrived and would not by its own words settle a general conflict between the 2 Acts. This site reads that as a real overlap and takes no position on how a court would resolve it: no judgment on the point is registered here, and the conflict is thin in practice today, because most of the DPDP Act's operative duties are themselves in the 18 month group and so there is little for them to conflict with yet.
It is worth knowing anyway, for a reason that has nothing to do with litigation. A compliance programme that treats the DPDP Act as having already displaced the older framework is not making a cautious assumption. It is making the assumption that section 44(2) has commenced, and it has not.
What a body corporate owes today
If the 2011 Rules bind you, these are the duties as the print sets them out. This is a description of the text, not advice about your position.
| Rule | Duty as printed |
|---|---|
| 4 | Provide a privacy policy for handling personal information including sensitive personal data or information, make it available for view by such providers of information who have provided it under lawful contract, and publish it on the website. Clauses (i) to (v) fix what it must provide for, including the type of information collected under rule 3, the purpose of collection and usage, disclosure as provided in rule 6 and the security practices under rule 8 |
| 5(1) | Obtain consent in writing, through letter or Fax or email, from the provider of the sensitive personal data or information, regarding the purpose of usage, before collection |
| 5(2) to 5(8) | Collect only for a lawful purpose connected with a function or activity and only where necessary for it; when collecting directly from the person concerned, take such steps as are reasonable in the circumstances to ensure that person knows the information is being collected, why, who will receive it and who is collecting and retaining it; do not keep it longer than required; use it only for the purpose collected; allow review, and correction or amendment as feasible; give an option not to provide it and an option to withdraw consent in writing, with the option not to supply the goods or services for which it was sought if it is withdrawn; and keep it secure as provided in rule 8 |
| 5(9) | Designate a Grievance Officer, publish the name and contact details on the website, and redress grievances within the period the rule states |
| 6 | Get prior permission before disclosing sensitive personal data or information to a third party, subject to the contract and legal obligation exceptions and the Government agency proviso; do not publish it; and the receiving third party must not disclose it further; and rule 6(2) provides, notwithstanding rule 6(1), for disclosure to a third party by an order under the law for the time being in force |
| 7 | Transfer only to a body corporate or person, in India or in any other country, that ensures the same level of data protection provided for under the Rules, and only where necessary for a lawful contract or where the person has consented |
| 8 | Rule 8(1) is a test rather than a duty: a body corporate is considered to have complied with reasonable security practices if it has a comprehensive documented information security programme and policies with control measures commensurate with the information assets protected and the nature of business. The duty in the sub rule is to demonstrate that programme when called upon by the agency mandated under the law after an information security breach |
3 of those are worth a second look, because they are the ones that differ most from what a reader who has been preparing for the DPDP Act will expect.
Consent under rule 5(1) is in a named form. The print says:
"Body corporate or any person on its behalf shall obtain consent in writing through letter or Fax or email from the provider of the sensitive personal data or information regarding purpose of usage before collection of such information."
Letter, Fax or email. Not a checkbox, and not by implication.
The grievance clock in rule 5(9) is fixed on the face of the rule:
"The Grievance Officer shall redress the grievances or provider of information expeditiously but within one month"
That is 1 month, and the print runs on from the date of receipt of grievance. The words grievances or provider of information are the Gazette's own, set that way on the page. It is a different clock from anything in the DPDP framework, and it applies now.
The transfer rule is rule 7, and it is a same level of protection test rather than a list of approved countries:
"A body corporate or any person on its behalf may transfer sensitive personal data or information including any information, to any other body corporate or a person in India, or located in any other country, that ensures the same level of data protection that is adhered to by the body corporate as provided for under these Rules."
Compare that with the position the DPDP Act takes on transfers, which is a restriction by notified country rather than by adequacy of protection, in cross border transfers under the DPDP Act.
Rule 8 is the reasonable security practices limb, and it names a standard without requiring it:
"The international Standard IS/ISO/IEC 27001 on "Information Technology - Security Techniques - Information Security Management System - Requirements" is one such standard referred to in sub-rule (1)."
One such standard. Rule 8(3) provides for industry codes of best practices approved and notified by the Central Government as an alternative, and rule 8(4) attaches the certification and audit condition to both routes, at least once a year or on significant upgradation of process and computer resource.
The 5 claims that do not survive the prints
| Circulating claim | What the documents say |
|---|---|
| The DPDP Act has repealed the SPDI Rules | Section 44(2), which directs the omission of section 43A and of section 87(2)(ob), is in the 18 month commencement group of paragraph (c) of G.S.R. 843(E) and has not commenced. And section 44(2) never mentions the Rules |
| The SPDI Rules will be repealed on 13 May 2027 | No instrument on file states that date. 13 May 2027 is computed from an 18 month period and the publication date of 13 November 2025, and it is interpretation until officially confirmed. What is directed on commencement is the omission of a section and a rule making power, not the repeal of a rule. What becomes of the Rules when the power behind them goes is a question of general law this site does not answer |
| Sensitive personal data is a DPDP concept | The DPDP Act defines personal data once, by identifiability, and has no sensitive category. The definition of sensitive personal data or information in Indian law sits in rule 3 of the 2011 Rules |
| The SPDI list is 6 categories | Rule 3 has 8 clauses, and clauses (vii) and (viii) are derived limbs that carry the first 6 into service and processing relationships. It also has a proviso excluding information freely available or accessible in public domain or furnished under the Right to Information Act, 2005 |
| Section 81 of the Information Technology Act has been amended so that it no longer overrides the DPDP Act | That amendment is directed by section 44(2)(b) of the DPDP Act, and section 44(2) has not commenced. On the India Code print dated as on 27 June 2025 the proviso to section 81 names the Copyright Act, 1957 and the Patents Act, 1970 and no other Act |
What this page is scoped to
The archived print is the Gazette notification as published on 11 April 2011: 5 pages, rules 1 to 8, ending with the closing words of rule 8(4). It carries no amendment footnote and no signature block, so this page states what rules 1 to 8 contain and makes no claim about anything printed after them.
It also makes no claim that these Rules have or have not been amended, clarified or supplemented since April 2011. No amending instrument is registered in this site's source registry, and an absence from that registry is a statement about what a search of official channels found, not a certified negative. If you are relying on the exact wording for a decision that matters, read the print itself; it is linked from the sources on this page.
The Information Technology Act, 2000 print on file is the India Code consolidated text dated as on 27 June 2025, so it states that Act as consolidated on that day and cannot speak for anything after it.
What to do
Work out which framework reaches your organisation, and for which activity, with the applicability checker and the role and actor checker. Both answer on the DPDP framework; the Information Technology Act position turns on whether you are a body corporate within clause (i) of the Explanation to section 43A, which is a question about your legal form rather than about your data.
For what the older section 43A route offers a person who has actually been harmed, and why it is an adjudication rather than a lawsuit, see can I sue under the DPDP Act. For why the DPDP Act has no sensitive category to import, see does the DPDP Act have a sensitive personal data category. The official DPDP text is at Section 38 and Section 44.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Role and Actor Checker
Work out your likely role for a processing activity, such as Data Fiduciary or Data Processor.
Open
Section 44, official text with sources →Section 38, official text with sources →Does the DPDP Act have a sensitive personal data category? →Can I sue under the DPDP Act? →What is in force in 2026 →
Information technology ActSensitive personal dataDefinitionsCurrent statusMyth correctionSection 44Security