LEGALWEBSITE.inEvery page. Every law. No surprises. All articles
Data protection 5 min readReviewed 5 September 2026

SPDI Rules, 2011: the older regime that still applies

Section 43A of the IT Act and the 2011 Rules on sensitive personal data — the privacy-policy contents, written consent, disclosure and the ISO 27001 security benchmark.

Where the obligation comes from

Section 43A of the Information Technology Act, 2000 makes a body corporate that possesses, deals with or handles sensitive personal data or information in a computer resource it owns or controls liable to pay compensation if it is negligent in implementing and maintaining reasonable security practices and thereby causes wrongful loss or gain. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 supply the detail.

Rule 3 defines sensitive personal data or information as passwords, financial information such as bank account, credit card, debit card or other payment instrument details, physical, physiological and mental health condition, sexual orientation, medical records and history, and biometric information. Information freely available in the public domain or furnished under the Right to Information Act is excluded.

What the Rules require

  • Rule 4: publish a privacy policy on the website that states the type of information collected, the purpose, disclosure practices and security practices, and is clear and easily accessible.
  • Rule 5(1): obtain consent in writing, including by fax or electronic means, from the provider of the information before collecting sensitive personal data.
  • Rule 5(3): tell the provider that the information is being collected, the purpose, the intended recipients, and the name and address of the agency collecting and retaining it.
  • Rule 5(7): give the provider the option not to provide the data, and the ability to withdraw consent in writing.
  • Rule 5(9): designate a Grievance Officer whose name and contact details are published on the website, and redress grievances within one month.
  • Rule 6: obtain prior permission before disclosing sensitive personal data to a third party, except where required by law or agreed in the contract.
  • Rule 7: transfer only to a person ensuring the same level of data protection, and only where necessary for the performance of a lawful contract or where consented to.
  • Rule 8: reasonable security practices means a documented information security programme; compliance with IS/ISO/IEC 27001 is one recognised standard.

How it sits alongside the DPDP Act

Section 44(3) of the DPDP Act, 2023 omits Section 43A of the IT Act with effect from the date that provision is brought into force. Until that happens, the 2011 Rules continue to apply to sensitive personal data, and the safest position for a business is to satisfy both regimes: the 2011 Rules' privacy-policy contents and written consent, and the DPDP Act's notice, withdrawal, erasure and grievance requirements.

Sources

  • The Information Technology Act, 2000 — Section 43A
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — Rules 3 to 8
  • The Digital Personal Data Protection Act, 2023 — Section 44(3)

This note is general information about published law, not legal advice on your facts. For advice, speak to our team.

Check your own site against this

The audit reads your live pages and grades them provision by provision.

Run a free audit

Read next