All insights
CommentaryLegal framework

Sensitive personal data: SPDI rules and the DPDP framework

How older SPDI terminology and the DPDP Act should be distinguished in current privacy assessments.

Data>Nuance

Indian businesses may encounter the term sensitive personal data in existing policies and contracts drafted under the SPDI Rules. The DPDP Act uses a different structure and should not be presented as if it contains the same classification terminology.

Why the distinction matters

Legacy documents may still inform contractual and security review, while an implementation programme for the DPDP Act must be mapped to its own requirements and any applicable rules.

Before reusing legacy wording, review the processing purpose, safeguards, notice language and current regulatory basis. Accurate labelling is essential for a credible privacy programme.

This publication is general information and is not legal advice for a specific organisation or matter.

Continue reading

DPDP Act

DPDP Act readiness for technology businesses

A practical first-pass framework for product, legal and security teams deciding what to document and implement first.

Read insight

Notice and consent

Notice under Section 5 of the DPDP Act

What a Data Fiduciary should review before putting consent and notice experiences into production.

Read insight

Start with context

Book a focused DPDP Act consultation.

Bring an upcoming launch, notice review, data mapping question, incident readiness issue or implementation deadline. We will help identify the right next step.