DPDP Act vs IT Act: What Has Changed? A Complete Guide to India’s New Data Protection Framework
- Loading...
India’s approach to digital privacy and data protection has undergone a major transformation with the introduction of the Digital Personal Data Protection Act, 2023 (DPDP Act).
Get a callback
For years, the Information Technology Act, 2000 (IT Act) and its associated rules provided an important legal framework for electronic transactions, cybersecurity and certain aspects of personal data protection. Section 43A of the IT Act, together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, addressed the protection of certain sensitive personal information.
The DPDP Act represents a significant shift because it is specifically designed around the processing and protection of digital personal data and establishes concepts such as Data Fiduciary, Data Principal, Consent Manager and the Data Protection Board of India.
The transition is particularly important for businesses that collect customer information through websites, mobile applications, forms, e-commerce platforms, CRMs, marketing tools and other digital systems.
In simple terms: The IT Act was primarily a broad technology and cyber law with a limited data-protection component, whereas the DPDP Act creates a dedicated framework for processing digital personal data.
What Is the IT Act, 2000?
The Information Technology Act, 2000 was India’s foundational legislation for giving legal recognition to electronic records and electronic transactions.
Over time, the IT Act evolved to cover several areas, including:
- Electronic records and digital signatures
- Electronic commerce
- Cyber offences
- Computer-related offences
- Intermediary liability
- Cybersecurity
- Data protection obligations in certain circumstances
- Compensation for failure to protect sensitive personal information
Section 43A was particularly relevant to data protection. It provided for compensation where a body corporate handling sensitive personal data or information was negligent in implementing and maintaining reasonable security practices and that negligence resulted in wrongful loss or wrongful gain.
The associated 2011 SPDI Rules also established requirements concerning sensitive personal data or information and reasonable security practices.
However, this framework was not equivalent to a comprehensive, standalone personal data protection law.
What Is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023.
Its stated objective is to regulate the processing of digital personal data while recognising an individual’s right to protect personal data and the need for lawful processing.
The Act introduces a dedicated vocabulary and compliance framework.
Key concepts include:
Data Principal: The individual to whom personal data relates.
Data Fiduciary: The person or organisation that determines the purpose and means of processing personal data.
Data Processor: An entity processing personal data on behalf of a Data Fiduciary.
Consent Manager: A registered entity designed to provide a platform through which Data Principals can give, manage, review and withdraw consent.
Personal Data: Data about an individual who is identifiable by or in relation to that data.
The Act also creates the Data Protection Board of India as the regulatory adjudicatory body for specified matters.
DPDP Act vs IT Act: Key Differences
| Parameter | IT Act, 2000 | DPDP Act, 2023 |
|---|---|---|
| Primary focus | Technology, electronic transactions and cyber law | Digital personal data protection |
| Data protection | Limited provisions under Section 43A and associated rules | Dedicated legal framework |
| Personal data approach | Focus historically included sensitive personal data/information | Broad framework for digital personal data |
| Individual rights | Limited data-specific rights under the earlier framework | Specific rights for Data Principals |
| Consent | Not structured as a comprehensive consent framework | Consent is a central lawful basis for processing |
| Data Fiduciary | No equivalent comprehensive concept | Clearly defined |
| Consent Manager | No equivalent framework | Specifically recognised |
| Data Protection Board | No dedicated data protection board under IT Act | Data Protection Board of India |
| Breach obligations | Existing cyber/security framework | Specific obligations under DPDP framework |
| Penalties | Various provisions with different consequences | Penalties can reach significant amounts under the Schedule |
| Regulatory approach | Broad technology/cyber legislation | Dedicated digital personal data protection legislation |
1. The Biggest Change: From IT Security to Data Governance
One of the most important differences between the two frameworks is their approach.
The IT Act’s data protection framework largely focused on whether organisations were taking reasonable security measures to protect certain information.
The DPDP Act goes further.
It addresses the entire lifecycle of digital personal data processing.
That means businesses need to think about questions such as:
- Why are we collecting this data?
- What data are we collecting?
- What is the lawful basis for processing?
- How are we informing the individual?
- How is consent obtained?
- Can consent be withdrawn?
- Who has access to the data?
- Which processors receive the data?
- How long should the data be retained?
- What happens when the purpose is fulfilled?
- How are data breaches handled?
- How can individuals exercise their rights?
This makes DPDP compliance much more of a data governance exercise, rather than simply an IT security exercise.
2. Consent Has Become Much More Important
Under the DPDP framework, consent is one of the major mechanisms for lawful processing.
The Act requires consent to be free, specific, informed and unambiguous, and it must involve a clear affirmative action. The notice and consent mechanism therefore becomes an important part of the user experience.
This has practical implications for businesses.
For example, consider a website that has:
- Contact forms
- Newsletter subscriptions
- Marketing cookies
- WhatsApp communication
- SMS marketing
- Email marketing
- Lead-generation forms
- Account registration
- Personalised advertising
Businesses need to understand what personal data is being collected and why.
A generic statement buried inside a privacy policy may not necessarily provide the same consent experience expected under a dedicated data protection framework.
3. The Individual Gets a More Defined Role
The DPDP Act formally refers to the individual as the Data Principal.
The framework gives Data Principals specific rights, including rights relating to:
- Access to information about personal data
- Correction and updating of personal data
- Erasure of personal data in applicable circumstances
- Grievance redressal
- Nomination
These rights create additional operational responsibilities for organisations.
A company may therefore need internal processes to answer questions such as:
“What personal data do you have about me?”
or
“Please correct my personal information.”
or
“Please delete my personal data.”
This is a major difference from the more limited data-protection structure under the older IT Act framework.
4. Section 43A Is Being Removed
This is one of the most important legal changes when comparing the IT Act with the DPDP Act.
Section 44 of the DPDP Act provides for amendments to other laws. Specifically, it provides that Section 43A of the Information Technology Act, 2000 shall be omitted.
This reflects the shift from the earlier IT Act-based data protection mechanism toward the dedicated DPDP framework.
However, businesses should not interpret this as meaning that cybersecurity obligations disappear.
The IT Act continues to contain numerous provisions dealing with cyber offences, unauthorised access, computer resources, intermediaries and other technology-related matters.
In other words:
DPDP does not replace the entire IT Act.
Instead, the data protection component is being reorganised under a dedicated legal framework.
5. “Sensitive Personal Data” vs Digital Personal Data
The terminology and scope also change significantly.
The earlier IT Act framework, particularly the SPDI Rules, focused on Sensitive Personal Data or Information (SPDI).
The DPDP Act instead uses the broader concept of digital personal data.
This is an important conceptual shift.
Businesses should therefore avoid assuming that only traditionally “sensitive” information requires attention.
Information such as:
- Name
- Mobile number
- Email address
- Identification information
- Account information
- Location-related information
- Online identifiers
can potentially become relevant to data protection obligations when associated with an identifiable individual.
6. New Obligations for Data Fiduciaries
The DPDP Act places explicit responsibilities on Data Fiduciaries.
Depending on the applicable provisions and implementation stage, organisations need to establish processes around:
Notice
Users need to receive information about the processing of their personal data.
Consent
Where consent is the applicable basis, businesses need mechanisms for obtaining and managing valid consent.
Security safeguards
Organisations need to implement appropriate technical and organisational measures to protect personal data.
Data breach response
Businesses need mechanisms for identifying, responding to and reporting personal data breaches as required.
Data retention and erasure
Personal data should not simply remain indefinitely in business systems when the purpose for processing no longer exists, subject to applicable legal requirements.
Rights management
Organisations need processes to respond to Data Principal requests.
This means DPDP compliance can involve legal, IT, cybersecurity, marketing, HR, product and operations teams.
7. Data Processors Become More Important
Modern businesses rarely process all personal data themselves.
A company may use:
- Cloud hosting providers
- CRM platforms
- Email marketing software
- Analytics platforms
- Payment gateways
- Customer-support software
- HR software
- Consent management platforms
- Advertising platforms
These organisations can act as data processors depending on the nature of the relationship and processing.
Therefore, DPDP compliance cannot be limited to the company’s own website.
Businesses should also understand where personal data travels after collection.
A proper data inventory or data-flow mapping exercise can help identify:
User → Website → CRM → Marketing platform → Analytics → Customer support → Cloud storage
Each stage can create data governance considerations.
8. Consent Management Becomes a Business Requirement
The DPDP framework also formally recognises the concept of a Consent Manager.
A Consent Manager can provide an interoperable mechanism through which Data Principals can give, manage, review and withdraw consent.
For businesses, this creates a new category of compliance technology.
A modern consent management solution can help organisations manage:
- Consent collection
- Consent records
- Consent withdrawal
- Preference management
- Consent logs
- Audit trails
- Data processing purposes
- Website/app consent experiences
This is particularly relevant for organisations operating large websites, apps and digital ecosystems.
9. Penalties Are Significantly More Structured
The DPDP Act introduces a dedicated penalty framework.
Its Schedule provides for financial penalties for specified breaches, with the potential for penalties of up to ₹250 crore for certain failures.
This is substantially different from thinking about data protection only in terms of compensation under the earlier Section 43A framework.
The key takeaway for businesses is:
Data protection is no longer something organisations should treat as an informal privacy-policy exercise.
Non-compliance can have significant financial and operational consequences.
10. DPDP Rules 2025 Add the Implementation Framework
The DPDP Act provides the legal framework, while the Digital Personal Data Protection Rules, 2025 provide important operational details.
The Central Government notified the Rules in November 2025.
Importantly, implementation is phased.
The notification provides different commencement dates for different provisions. Certain provisions came into force on publication, while other provisions are scheduled to take effect one year or eighteen months after publication of the notification.
This phased approach is important for businesses because “the DPDP Act exists” and “every provision is already operational” are not the same thing.
Organisations should therefore assess compliance against the applicable commencement timeline rather than assuming all provisions became enforceable simultaneously.
IT Act vs DPDP Act: What Does a Business Need to Do Differently?
The biggest practical difference is the shift from a narrow security-oriented approach toward a structured privacy and data governance programme.
Businesses should consider implementing the following:
1. Conduct a Personal Data Inventory
Identify:
- What personal data is collected?
- Where is it collected?
- Why is it collected?
- Where is it stored?
- Who can access it?
- Which third parties receive it?
- How long is it retained?
2. Review Privacy Notices
Your website privacy policy should not be treated as a generic document copied from another website.
It should accurately explain the organisation’s actual data processing activities.
3. Audit Consent Collection
Review:
- Website forms
- Cookie consent
- Newsletter subscriptions
- Marketing opt-ins
- Mobile apps
- Account registration
- Lead forms
- Communication preferences
The objective should be to determine whether consent mechanisms are appropriately designed and whether records can be maintained.
4. Implement Consent Management
For businesses handling significant volumes of personal data, a consent management platform can help centralise consent records and preferences.
A consent management system may also make it easier to demonstrate:
Who consented → For what purpose → When → Through which channel → Whether consent was withdrawn
5. Review Third-Party Vendors
Create a list of vendors that process personal data.
For example:
| Vendor Category | Potential Data |
| CRM | Name, email, phone |
| Email platform | Email address, communication history |
| Payment provider | Transaction information |
| Analytics platform | Online activity/identifiers |
| Cloud provider | Stored business/customer data |
| HR software | Employee information |
| Customer support | Customer communications |
The organisation should understand its contractual and operational relationship with these vendors.
DPDP Act vs IT Act: Is the IT Act Completely Replaced?
No.
This is one of the most common misconceptions.
The DPDP Act does not mean that the IT Act disappears.
The IT Act remains a major piece of India’s technology legislation, covering areas beyond personal data protection.
The DPDP Act instead creates a dedicated framework for digital personal data processing.
The DPDP Act itself specifically amends the IT Act by providing for the omission of Section 43A and certain related changes.
Therefore, businesses should think of the change as:
IT Act → Broad technology and cyber law
DPDP Act → Dedicated digital personal data protection framework
rather than:
IT Act → completely replaced by DPDP Act
DPDP Act vs IT Act: A Simple Example
Imagine an e-commerce company collects:
- Customer name
- Phone number
- Email address
- Delivery address
- Order history
Under the older IT Act framework
The organisation’s data security obligations could arise through the IT Act and associated SPDI/security framework depending on the information and circumstances.
Under the DPDP framework
The company needs to consider a much broader data governance lifecycle:
Collection → Notice → Consent/lawful use → Processing → Security → Processor management → User rights → Retention → Erasure → Breach management
The focus therefore shifts from:
“Is the data secure?”
to:
“Are we processing personal data lawfully, transparently and securely throughout its lifecycle?”
What Businesses Should Do Now
Businesses should start treating DPDP compliance as an ongoing operational programme rather than a one-time legal document exercise.
Recommended DPDP compliance checklist
-
Map all personal data collected by the organisation
-
Identify purposes for processing
-
Review website and app privacy notices
-
Audit consent mechanisms
-
Establish consent records and audit trails
-
Review data retention practices
-
Establish deletion/erasure procedures
-
Create processes for Data Principal requests
-
Review third-party data processors
-
Update relevant contracts and agreements
-
Implement appropriate security safeguards
-
Establish a personal data breach response process
-
Review marketing and advertising data practices
-
Assess whether the organisation may qualify as a Significant Data Fiduciary
-
Monitor the phased commencement of the DPDP Act and Rules
Frequently Asked Questions
Is DPDP Act the replacement for the IT Act?
No. The DPDP Act creates a dedicated framework for digital personal data protection. The IT Act continues to govern many other areas of technology and cyber law. The DPDP Act specifically provides for the omission of Section 43A of the IT Act.
What is the main difference between the IT Act and DPDP Act?
The IT Act is a broad technology and cyber law, whereas the DPDP Act is specifically focused on processing digital personal data and protecting the rights of individuals in relation to such data.
Is consent mandatory under the DPDP Act?
Consent is an important basis for processing under the Act, but the Act also recognises certain “legitimate uses” where processing can occur without consent subject to the applicable provisions.
Does DPDP apply only to large companies?
No. Its applicability depends on the nature and circumstances of processing rather than simply whether an organisation is a large company.
What is Section 43A of the IT Act?
Section 43A provided for compensation where a body corporate handling sensitive personal data or information was negligent in implementing reasonable security practices and that negligence caused wrongful loss or wrongful gain.
The DPDP Act provides for the omission of Section 43A as part of its amendments to the IT Act.
What are the maximum penalties under the DPDP Act?
The Schedule to the DPDP Act provides for penalties that can reach ₹250 crore for certain specified breaches.
Are the DPDP Rules 2025 notified?
Yes. The Digital Personal Data Protection Rules, 2025 were notified by the Government in November 2025, with provisions coming into force on a phased timeline.
Conclusion: DPDP Is a Shift From Security to Accountability
The comparison between the DPDP Act vs IT Act is ultimately about more than one law replacing another.
The real change is India’s movement from a relatively limited, security-focused approach to a more comprehensive framework for personal data governance, transparency, consent, individual rights and organisational accountability.
For businesses, the message is clear:
Privacy compliance should no longer be treated as only a privacy-policy requirement.
Organisations should understand what personal data they collect, why they collect it, how they obtain and manage consent where applicable, who processes the information, how long it is retained, how individuals can exercise their rights and how the organisation responds to data breaches.
With the DPDP Act and the notified DPDP Rules establishing a dedicated framework, businesses should begin building compliance into their website, applications, marketing systems, CRM, HR systems, vendor management and internal processes.
The organisations that treat privacy as an ongoing governance function—not merely a legal document—will be better positioned to build customer trust and adapt to India’s evolving digital regulatory environment.
Sources and Further Reading
- Digital Personal Data Protection Act, 2023: India Code – DPDP Act 2023
- Information Technology Act, 2000: India Code – IT Act 2000
- Digital Personal Data Protection Rules, 2025: MeitY – DPDP Rules 2025
- MeitY Acts and Policies: Ministry of Electronics & Information Technology