Before 2023, Indian privacy compliance meant the SPDI Rules, 2011 (issued under Section 43A of the IT Act). The DPDP Act 2023 supersedes most of that framework. The practical differences:
Scope
SPDI: only “sensitive personal data” (passwords, financials, health, biometrics) got real protection.
DPDP: covers all digital personal data, with no sensitive/non-sensitive distinction.
Consent
SPDI: consent required mainly for sensitive data, often buried in terms.
DPDP: consent must be free, specific, informed, unconditional, and as easy to withdraw as to give — plus itemised notices.
Enforcement
SPDI: compensation claims under S.43A — rarely enforced in practice.
DPDP: a dedicated Data Protection Board with penalties up to ₹250 crore per instance.
What survives from the old regime
The IT Act’s security-practices expectations and the grievance-officer concept carry forward. If you built SPDI-era processes (reasonable security, grievance handling), keep them — then layer DPDP’s consent, notice, and rights machinery on top.
This article is general information, not legal advice.