AMLEGALS — Strategic Lawyering
DPDPA concepts · Data categories

Sensitive personal data under the DPDPA: what actually changed

Many organisations built their earlier compliance around the idea of “sensitive personal data”. The DPDPA takes a different approach. Understanding that shift matters, because mapping old categories onto the new Act leads to the wrong controls in the wrong places.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

A single gold band encircling layered data forms on a dark navy background
Short answer

The Digital Personal Data Protection Act, 2023 does not create a separate legal category of “sensitive personal data”. It applies a single definition of personal data and, with limited exceptions, the same obligations to all of it. This is a deliberate change from the earlier regime under the Information Technology Act, 2000 and the 2011 SPDI Rules, which defined sensitive personal data or information such as passwords, financial information, health, sexual orientation and biometric data, and attached extra rules to it. Under the DPDPA, heightened protection is targeted by situation rather than by category: Section 9 imposes strict rules on the personal data of children, and Section 10 imposes additional obligations on Significant Data Fiduciaries. Certain data also remains governed by its own sector laws, for example Aadhaar data under its own Act and some financial data under sector regulators. So while the label “sensitive personal data” no longer carries legal weight under the DPDPA itself, the sensitivity of data still matters practically for risk, for Section 8(5) security safeguards, and for a Data Protection Impact Assessment.

  • Sensitive data
  • SPDI Rules
  • Data categories
  • Health data
  • Biometric data
  • Section 8
Separate category
None under the DPDPA itself
Old regime
SPDI Rules, 2011 under the IT Act, 2000
Heightened duties
Children (Section 9), SDFs (Section 10)
Still relevant
Risk, Section 8(5) safeguards, DPIA

How the old regime treated sensitive data

Under the Information Technology Act, 2000 and the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011, certain data was labelled sensitive personal data or information. This included passwords, financial information such as bank or card details, physical and mental health condition, sexual orientation, medical records and biometric information.

That category triggered extra requirements, for example consent in writing and a published privacy policy. Many Indian compliance programmes were designed around this list.

The DPDPA’s single-category approach

The DPDPA defines personal data as any data about an individual who is identifiable by or in relation to such data. It does not subdivide this into sensitive and non-sensitive. The core obligations, consent or a lawful legitimate use, notice, purpose limitation, accuracy, security safeguards and breach notification, apply to personal data as a whole.

This simplifies the legal test but shifts the work. Instead of asking “is this on the sensitive list”, an organisation asks “what is the risk of this processing” and applies controls proportionate to that risk.

Where heightened protection still applies

The Act targets stronger duties by situation rather than by data label.

  • Children: Section 9 requires verifiable parental consent and prohibits tracking and targeted advertising, whatever the data involved.
  • Significant Data Fiduciaries: Section 10 adds a DPIA, a data audit and a dedicated Data Protection Officer in India.
  • Security: Section 8(5) requires reasonable security safeguards, and higher-risk data warrants stronger safeguards in practice.
  • Sector law: Aadhaar, and some financial and health data, remain subject to their own statutes and regulators.

What this means for your data map

The sensitivity of data has not stopped mattering. It has moved from a legal category to a risk input. A Data Protection Impact Assessment, and the security safeguards under Section 8(5), should reflect the greater harm that can flow from health, financial or biometric data.

The practical error to avoid is carrying the old SPDI list into a DPDPA programme as if it were still the legal test. The list is useful for risk ranking; it is no longer the trigger for distinct legal duties under the Act.

How AMLEGALS advises on data categories

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team maps where higher-risk data sits, aligns security safeguards and the DPIA to that risk, and clarifies which data remains governed by sector law alongside the DPDPA.

Questions and answers

Sensitive Personal Data Under DPDPA: common questions

Does the DPDPA define sensitive personal data?

No. The DPDPA applies one definition of personal data and generally the same obligations to all of it, rather than a separate sensitive category.

What happened to the SPDI Rules?

The sensitive personal data regime under the 2011 SPDI Rules, made under the IT Act, 2000, is being replaced by the DPDPA framework, which does not use that category.

Does sensitivity still matter in practice?

Yes. Sensitivity drives risk, which shapes the Section 8(5) security safeguards and the Data Protection Impact Assessment, even though it is not a separate legal category.

How is health or financial data treated?

As personal data under the DPDPA, and additionally under any sector law that applies, such as financial regulators or, for Aadhaar, its own Act.

Should we keep our old sensitive data classification?

Keep it as a risk-ranking tool, not as the legal trigger. Under the DPDPA, duties follow risk and situation, not a fixed sensitive list.

Contact

Reclassify your data for the DPDPA

Share what categories of data you hold. The AMLEGALS data privacy team will align your classification and controls with the Act.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Sensitive Personal Data Under DPDPA: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Sensitive Personal Data Under DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Sensitive Personal Data Under DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Sensitive Personal Data Under DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Sensitive Personal Data Under DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Sensitive Personal Data Under DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Sensitive Personal Data Under DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Sensitive Personal Data Under DPDPA · DPDPA Exposure Assessment