AMLEGALS — Strategic Lawyering
Compliance

How to Transition from IT Act to DPDPA

Managing the regulatory change from existing data protection rules

Updated 30 December 2024

Executive Summary

Organisations that have complied with the IT Act 2000 and its rules face a transition to DPDPA's new framework. While some concepts carry over, significant differences require adjustment. This guide addresses practical transition planning from the old framework to the new.

Key Takeaways

  • 1
    Assess current IT Act compliance as the starting point for DPDPA transition
  • 2
    Identify where DPDPA requirements exceed IT Act obligations
  • 3
    Update consent mechanisms to meet new specificity requirements
  • 4
    Revise privacy notices to include all mandated content
  • 5
    Plan for enhanced rights enablement beyond IT Act requirements

1Understanding the Transition

DPDPA replaces the data protection provisions of the IT Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Organisations compliant with these existing rules are not automatically compliant with DPDPA. The transition requires gap assessment and remediation.

2Mapping Existing Compliance

Start by documenting current compliance status under existing rules.

1

IT Rules Compliance

Document how the organisation currently complies with IT Rules including privacy policy publication, consent practices, data collection limitations, and security practices.

2

Contractual Arrangements

Review existing data processing agreements and assess their alignment with DPDPA requirements.

3

Technical Controls

Inventory security controls implemented for IT Rules compliance. Many will remain relevant under DPDPA.

4

Sectoral Requirements

Note any sector-specific requirements that will continue alongside DPDPA.

3Identifying Key Differences

DPDPA differs from IT Rules in several significant ways.

1

Consent Specificity

DPDPA requires more specific consent than IT Rules. Generic consent for all processing is insufficient. Transition to purpose-specific, granular consent.

2

Data Principal Rights

DPDPA provides broader rights including comprehensive access, correction, and erasure. Update mechanisms to support these rights.

3

Breach Notification

DPDPA mandates breach notification to the Data Protection Board and affected individuals. IT Rules did not have equivalent requirements.

4

Cross-Border Transfers

DPDPA's approach to cross-border transfers differs from IT Rules. Reassess transfer compliance under the new framework.

5

Children's Data

DPDPA has specific requirements for children's data that go beyond IT Rules. Implement enhanced protections.

6

Penalties

DPDPA penalties are significantly higher than IT Act penalties. The risk calculus for non-compliance has changed.

4Consent Mechanism Updates

Consent under DPDPA requires greater specificity than many IT Rules consent mechanisms provided.

1

Review Current Consent

Assess existing consent mechanisms against DPDPA requirements. Are consents specific to purposes? Can they be withdrawn easily?

2

Redesign Collection

Where current consent is too broad, design new collection mechanisms that meet specificity requirements.

3

Fresh Consent

For processing that continues, determine whether fresh consent under DPDPA standards is needed or whether existing consent can be grandfathered.

4

Withdrawal Mechanisms

Implement withdrawal mechanisms meeting the 'as easy as giving consent' standard if not already in place.

5Privacy Notice Updates

DPDPA notices must include content that IT Rules did not require.

1

Content Audit

Compare current privacy policy against DPDPA notice requirements. Identify missing elements.

2

Restructure for Clarity

DPDPA emphasises comprehensibility. Consider restructuring notices that, while legally complete, are practically incomprehensible.

3

Add Required Elements

Incorporate all elements required by Section 5 and Rule 5 including grievance mechanism details, rights information, and retention periods.

4

Timing Adjustment

Ensure notices are provided at or before consent collection, not just available somewhere on the website.

6Rights Enablement

DPDPA rights are broader than IT Rules. Update mechanisms accordingly.

1

Access Request Procedures

Enhance access request procedures to provide comprehensive information about processing activities, not just data copies.

2

Erasure Capabilities

If erasure capabilities were limited under IT Rules, expand them to meet DPDPA requirements.

3

Grievance Mechanism

Formalise the grievance mechanism if the current process is informal. Appoint a grievance officer and publish contact details.

4

Response Timelines

Review response timelines against Rule requirements and adjust procedures if necessary.

7Transition Planning

Manage the transition systematically.

1

Gap Analysis

Conduct comprehensive gap analysis between current state and DPDPA requirements. Prioritise gaps by risk and effort.

2

Remediation Roadmap

Develop a remediation roadmap with timelines aligned to enforcement dates. Account for dependencies and resource constraints.

3

Stakeholder Communication

Communicate transition requirements to relevant stakeholders including IT, legal, HR, marketing, and business units.

4

Progress Tracking

Monitor progress against the roadmap. Escalate delays that threaten compliance by enforcement dates.

5

Testing

Test new mechanisms before relying on them for compliance. Verify that consent systems, rights processes, and breach procedures work as designed.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Transition It Act To DPDPA: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Transition It Act To DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Transition It Act To DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Transition It Act To DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Transition It Act To DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Transition It Act To DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Transition It Act To DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Transition It Act To DPDPA · DPDPA Exposure Assessment