Compliance Guides6 minutes

Transitioning from SPDI Rules to DPDP Act 2023: A Legal Guide for Enterprise Data Defensibility

General Counsels must navigate the transition from the old IT Act regime to the DPDP Act 2023. This guide explains new obligations under the Rules 2025, from itemised notices to 72-hour breach reporting, and how to structure verifiable compliance.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Overview

General Counsels and Legal Heads face a fundamental shift in liability allocation. Section 44 of the Digital Personal Data Protection Act, 2023 explicitly omits Section 43A of the Information Technology Act, 2000. This marks the end of the old compliance framework that relied on static privacy policies. The territorial scope now covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India.

With 277 days remaining until the hard compliance deadline of 13 May 2027, enterprise legal teams must rebuild their data handling frameworks. Defensibility against regulator inquiries requires auditable evidence trails and active vendor oversight, rather than mere paper compliance. Failing to upgrade these controls will directly increase outside counsel spend during investigations.

What the DPDP Act Says

Section 4 of the Act establishes that a Data Fiduciary may process the personal data of a Data Principal only for a lawful purpose. The basis for this processing is either the consent of the Data Principal or certain legitimate uses outlined in Section 7. Section 1 confirms the title and commencement structure of the Act, shifting the regulatory focus toward operational duties and immediate accountability.

The Act replaces the previous compensation framework for failure to protect data with direct regulatory oversight. Legal teams must update their limitation of liability and indemnification clauses in Processor contracts to reflect this new statutory reality. The Data Protection Board of India will judge compliance based on demonstrable technical controls, not just contractual promises.

DPDP Act vs Rules 2025: What Changed

While the Act provides the statutory foundation, the DPDP Rules, 2025 notified in November 2025 dictate the exact operational mechanics. A major departure from old practices is the requirement for detailed, itemised notices delivered before or alongside consent requests. General privacy policies are no longer sufficient to secure valid data processing rights.

The Rules operationalise verifiable parental consent, demanding specific age-gating and authorisation workflows that standard web forms cannot handle. For Significant Data Fiduciaries, the Rules outline precise duties for periodic audits and data protection impact assessments. These granular requirements mean compliance requires continuous technical enforcement across the entire enterprise architecture.

What Every Data Fiduciary Must Do Now

Transitioning to this new regime requires overhauling consent mechanisms and Processor oversight. Legal teams must assess whether their current technology stack can maintain dynamic records of consent that withstand regulatory scrutiny. Managing these records on basic spreadsheets is a common starting point for internal teams, but this approach breaks at scale when facing thousands of data subjects and complex revocation requests.

Enterprises must mandate that Processors adhere to strict data handling protocols, backed by precise indemnity clauses. Tooling becomes essential for managing multi-team workflows, logging data lifecycles, and ensuring defensibility during an audit. Establishing these operational evidence trails is what separates true compliance from theoretical legal risk.

Breach Notification Specifics

Incident response under the new regime is highly prescriptive and time-bound. The DPDP Rules, 2025 mandate that in the event of a personal data breach, the Data Fiduciary must provide intimation to affected Data Principals without delay. Simultaneously, a detailed report must be submitted to the Data Protection Board within 72 hours.

This dual-track reporting obligation requires tight coordination between security, product, and legal teams to investigate, contain, and draft notifications under extreme time pressure. Relying on ad-hoc email chains for incident response exposes the enterprise to severe enforcement risk and complicates engagement with the regulator.

Common Misconceptions

A persistent myth is that the new law retains old data classifications for health or financial records. The DPDP Act 2023 has no separate classifications based on data type; instead, risk and processing volume dictate obligations like Significant Data Fiduciary designation. Applying old compliance models to the new law leaves massive operational gaps.

Another misunderstanding involves the legal basis for processing data. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, such as responding to medical emergencies or managing employment purposes. Additionally, cross-border data transfers operate on a negative list where transfers are permitted unless the Central Government restricts a specific territory, which is entirely different from other international frameworks.

Implementation Checklist

1. Map all data processing activities to either consent or Section 7 legitimate uses. (In-house feasible for initial scoping)

2. Overhaul privacy notices to meet the itemised requirements of the Rules, 2025. (In-house feasible)

3. Implement dynamic consent capture and revocation logs across all digital properties. (Tooling-assisted)

4. Revise Processor contracts to include DPDP-specific indemnities and audit rights. (In-house feasible)

5. Deploy verifiable parental consent workflows for users under eighteen. (Tooling-assisted)

6. Configure breach reporting workflows to meet the 72-hour Data Protection Board deadline. (Tooling-assisted)

7. Prepare defensible evidence packages for potential regulatory inquiries. (Tooling-assisted)

Penalties and Enforcement Risk

The Data Protection Board of India holds the authority to impose significant financial penalties for non-compliance. Failure to implement reasonable security safeguards can result in penalties up to 250 crore rupees. Failure to notify data breaches carries a penalty ceiling of 200 crore rupees.

These penalties are proportionate to the severity and duration of the violation, meaning early mitigation directly reduces liability. General Counsels must view this transition not just as a legal checkbox, but as a core component of enterprise risk management and safe harbour defensibility.

How ComplyDP Helps

Defensibility against regulatory audits requires an infrastructure built for scale and exactness. ComplyDP automates the transition to DPDP Rules 2025 compliance through precise consent lifecycle tracking, vendor oversight, and automated 72-hour breach reporting workflows. Let your outside counsel handle complex legal strategy while our platform manages the operational evidence trails. Discover your operational gaps today by visiting freescan.complydp.com to evaluate your readiness.

Sources

Frequently asked questions

How does the DPDP Act 2023 change liability compared to the old IT Act rules?

Section 44 of the DPDP Act explicitly omits Section 43A of the IT Act, moving away from a light-touch compensation framework. The new law introduces direct regulatory oversight by the Data Protection Board with penalties reaching up to 250 crore rupees for security failures.

Do we still need special controls for health and financial data?

The new framework does not classify information into special protected categories based on data type. Instead, compliance obligations scale based on the volume and risk of processing, which may lead to a Significant Data Fiduciary designation.

What are the strict timelines for notifying data breaches?

Under the DPDP Rules 2025, Data Fiduciaries must provide intimation to affected Data Principals without delay. Additionally, they must submit a detailed breach report to the Data Protection Board within 72 hours.

Do we need to secure consent for every single data processing activity?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Legitimate uses cover specific scenarios like responding to medical emergencies, complying with court judgments, and managing employment purposes.

How much time is left to implement these changes?

There are exactly 277 days remaining until the DPDP hard compliance deadline of 13 May 2027. Legal teams must use this time to revise processor contracts, implement audit workflows, and secure verifiable parental consent systems.