How the old regime treated sensitive data
Under the Information Technology Act, 2000 and the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011, certain data was labelled sensitive personal data or information. This included passwords, financial information such as bank or card details, physical and mental health condition, sexual orientation, medical records and biometric information.
That category triggered extra requirements, for example consent in writing and a published privacy policy. Many Indian compliance programmes were designed around this list.
The DPDPA’s single-category approach
The DPDPA defines personal data as any data about an individual who is identifiable by or in relation to such data. It does not subdivide this into sensitive and non-sensitive. The core obligations, consent or a lawful legitimate use, notice, purpose limitation, accuracy, security safeguards and breach notification, apply to personal data as a whole.
This simplifies the legal test but shifts the work. Instead of asking “is this on the sensitive list”, an organisation asks “what is the risk of this processing” and applies controls proportionate to that risk.
Where heightened protection still applies
The Act targets stronger duties by situation rather than by data label.
- Children: Section 9 requires verifiable parental consent and prohibits tracking and targeted advertising, whatever the data involved.
- Significant Data Fiduciaries: Section 10 adds a DPIA, a data audit and a dedicated Data Protection Officer in India.
- Security: Section 8(5) requires reasonable security safeguards, and higher-risk data warrants stronger safeguards in practice.
- Sector law: Aadhaar, and some financial and health data, remain subject to their own statutes and regulators.
What this means for your data map
The sensitivity of data has not stopped mattering. It has moved from a legal category to a risk input. A Data Protection Impact Assessment, and the security safeguards under Section 8(5), should reflect the greater harm that can flow from health, financial or biometric data.
The practical error to avoid is carrying the old SPDI list into a DPDPA programme as if it were still the legal test. The list is useful for risk ranking; it is no longer the trigger for distinct legal duties under the Act.
How AMLEGALS advises on data categories
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team maps where higher-risk data sits, aligns security safeguards and the DPIA to that risk, and clarifies which data remains governed by sector law alongside the DPDPA.

