Sensitive Data Protection

Sensitive Data Protection Under India’s DPDP Act: A Practical Guide

India's DPDP Act has no sensitive-personal-data tier like GDPR Article 9. This guide maps what the Act requires for protecting personal data on websites and apps while Rules are still awaited.

Working summary: India’s DPDP Act does not copy GDPR’s sensitive or special-category list. Section 2(t) defines personal data once by identifiability. Higher duties attach mainly to who processes the data, whose data it is, and organisation scale, while high-harm fields still drive security and SDF risk assessment.

  • No statutory SPI tier: Size notice, consent, security, and rights for personal data as a whole.
  • Section 10: Volume and sensitivity are assessment factors for Significant Data Fiduciary notification, not a field-level class on their own.
  • Children (Section 9): Verifiable parental consent and limits on tracking and targeted ads directed at children.
  • Rule 6: Encryption, access control, logs, backups, and processor contracts as minimum reasonable security safeguards.
  • Vs GDPR: Keep separate EU Article 9 and India DPDP registers if you serve both.

What “sensitive data” means under India’s DPDP Act

Many teams arrive at India’s Digital Personal Data Protection Act, 2023 with a GDPR habit: they expect a statutory list of “sensitive” or “special category” personal data, plus stricter rules for those fields alone.

The Act does not work that way. Section 2(t) defines personal data once, by identifiability: data about an individual who is identifiable by or in relation to that data. The Gazette text does not create a separate sensitive-personal-data category. Higher duties attach mainly to who processes the data, whose data it is, and the size or class of the organisation, not to a named data type.

That does not mean health records, biometrics, or financial details need less care. It means your DPDP programme should size notice, consent, security, retention, and rights handling for personal data as a whole, while still treating high-harm fields as a risk input for safeguards and for Significant Data Fiduciary assessment.

Official sources this guide uses

  • The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), available via India Code and MeitY Gazette materials.
  • Commencement notification materials from MeitY, once published.
  • forthcoming DPDP Rules from MeitY (G.S.R. 846(E)), published 13 the eventual Rules notification, including Rule 6 on reasonable security safeguards.
  • For contrast only: GDPR Article 9 special categories (EU Regulation 2016/679), which do not apply as Indian law.

Commencement is staged. Several core operational provisions and Rules sit in the group that begins 18 months after the the eventual Rules notification gazette publication. Treat calendar dates computed from that period as interpretation until an official confirmation is published. Check the current MeitY and Gazette status before you lock a compliance calendar.

Where “sensitivity” actually appears

Section 10(1) lets the Central Government notify a Data Fiduciary, or a class of them, as a Significant Data Fiduciary after assessing relevant factors. One listed factor is “the volume and sensitivity of personal data processed.”

That sentence is an assessment factor for notification. It does not create a statutory class of data, and it does not by itself impose extra field-level duties. Extra SDF duties (India-based DPO, independent data auditor, DPIA and audit) arise only after notification under section 10, and only when that provision is in force and a notification has been made.

What still creates heavier practical duties

Children and persons with a lawful guardian (section 9)

Section 9 ties stricter rules to whose data you process: verifiable parental or guardian consent, limits on processing that is likely to have a detrimental effect on a child’s well-being, and restrictions on tracking, behavioural monitoring, and targeted advertising directed at children, subject to the Rules and schedules that apply when those provisions commence.

Significant Data Fiduciary notification (section 10)

If your organisation is notified as an SDF, expect additional accountability: a DPO based in India, an independent data auditor, and periodic DPIA and audit obligations, with further detail in the Rules (including Rule 13 for SDF measures once applicable).

Retention and erasure clocks in the Rules

The Third Schedule, read with Rule 8, sets shorter erasure timelines for named classes of Data Fiduciary at stated user thresholds. The trigger is class and scale, not a sensitivity label on a field.

Older Indian “SPDI” rules vs DPDP

India’s pre-DPDP vocabulary often used “sensitive personal data or information” under the Information Technology Act, 2000 framework and the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011. Rule 3 of those 2011 Rules listed categories such as passwords, financial information, health condition, sexual orientation, medical records, and biometric information.

The DPDP Act directs omission of section 43A of the IT Act and related rule-making power, but that amendment sits in a later commencement group. Do not assume the 2011 SPDI category is automatically transplanted into DPDP. Map controls to the Act and Rules text that actually apply on your go-live date.

Practical protection checklist for websites and apps

Even without a DPDP “sensitive” tier, high-harm personal data still drives risk. Use this checklist as an engineering and product map, then confirm legal interpretation with counsel.

1. Inventory what you collect

  • List forms, SDKs, analytics, support tools, KYC vendors, and file uploads.
  • Flag fields that would cause serious harm if leaked: health, biometrics used for identification, government IDs, payment data, precise location tied to identity, children’s data.
  • Record purpose, lawful ground (consent or a section 7 legitimate use where available), retention, and processors for each purpose.
  • Give clear notice before or at the time of collection, in plain language, covering purpose, rights, and how to withdraw consent where consent is the basis.
  • Keep consent purpose-specific. Do not bundle unrelated processing into one opaque accept button.
  • Store proof of notice and consent (or legitimate-use reliance) so you can show it later.

3. Reasonable security safeguards (Act section 8(5); Rules Rule 6)

Rule 6 sets a minimum list of safeguards Data Fiduciaries must take to prevent personal data breach, including for processing done by Data Processors. In summary, that list covers:

  • Securing personal data through encryption, obfuscation, masking, or virtual tokens mapped to the data.
  • Access control over computer resources used by the Fiduciary or Processor.
  • Logs, monitoring, and review so unauthorised access can be detected, investigated, and remediated.
  • Backups and continuity measures if confidentiality, integrity, or availability is compromised.
  • Retention of relevant logs and personal data for one year for detection and investigation, unless another law requires otherwise.
  • Contract terms that require Processors to take reasonable security safeguards.
  • Technical and organisational measures so the safeguards are actually observed.

Size these controls to the harm a breach would cause. High-harm fields usually need tighter access, stronger encryption at rest and in transit, stricter key management, and shorter production retention.

4. Breach readiness

  • Define what counts as a personal data breach for your systems.
  • Build an escalation path to leadership and to the Data Protection Board process required when the applicable intimation rules are in force.
  • Prepare Data Principal communication templates that state what happened, what data was involved, and what people can do.

5. Rights and grievance handling

  • Support access, correction, completion, updating, erasure, grievance redressal, and nomination as the Act provides.
  • Publish a working contact path (DPO or other responsible person when required).
  • Measure response times against the Rules once those timelines apply to you.

6. Processors and cross-border transfers

  • Contract for security, purpose limits, and deletion or return at end of service.
  • Track where personal data is stored and processed. Section 16 and related government directions govern transfers outside India; watch for blacklist or other restrictions as notified.

How this differs from GDPR Article 9

GDPR Article 9 prohibits processing of special categories of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, and data concerning sex life or sexual orientation), unless an Article 9(2) condition applies, and you also need an Article 6 lawful basis.

India’s DPDP Act does not copy that architecture. If you run a joint EU-India programme, keep separate registers: GDPR special-category conditions where the GDPR applies, and DPDP notice, consent or legitimate use, security, rights, and SDF or children’s rules where DPDP applies.

Common mistakes to avoid

  • Building a DPDP control matrix only around “sensitive” fields copied from GDPR or the 2011 SPDI Rules, while leaving ordinary personal data without notice, retention, or rights workflows.
  • Citing a non-existent “section 3(d)” sensitive-data clause. Section 3 of the Act runs through clause (c).
  • Waiting for an SDF label before encrypting databases or logging access to customer PII.
  • Treating analytics SDKs and support tools as out of scope because they are “just vendors.”

A workable rollout order

  1. Map personal data flows for your website and apps.
  2. Fix notice, consent withdrawal, and privacy policy accuracy.
  3. Implement Rule 6-style safeguards, starting with encryption, access control, and audit logs for production stores that hold customer personal data.
  4. Stand up breach and rights-request playbooks.
  5. Document children’s data and high-harm processing for future section 9 and section 10 assessments.
  6. Re-check commencement dates and any SDF or transfer notifications before you declare “done.”

Related in this series: GDPR Special Category Data: What Websites Must Protect, CCPA Sensitive Personal Information, Securing Sensitive Data: Consent, Encryption, and Access Controls, and Breach Response for Sensitive Data Under DPDP and GDPR.

Sources

  • Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023): India Code entry and MeitY Gazette text for sections 2(t), 3, 8, 9, 10, and related provisions.
  • forthcoming MeitY commencement notifications commencement notification (13 the eventual Rules notification).
  • forthcoming DPDP Rules from MeitY, G.S.R. 846(E) (13 the eventual Rules notification), especially Rule 6 (reasonable security safeguards) and SDF-related rules.
  • MeitY document library pages hosting the Rules PDF and corrigenda.
  • Regulation (EU) 2016/679, Article 9 (comparative reference only).
  • Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, Rule 3 (historical SPDI category; not a DPDP text substitute).

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, sensitive-data controls, breach response, or other privacy and data-protection measures. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 2 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *