Three sets of rules made under the Information Technology Act, 2000 still bind Indian businesses in 2026, and none of them is repealed by the DPDP regime yet. The SPDI Rules 2011 carry the Section 43A security duty until 13 May 2027. The Blocking Rules 2009 have never once been amended. The Interception Rules 2009 survive for everything that is not a telecom service. Compliance programmes built only around the DPDP Rules 2025 and the IT Rules 2021 are missing a live layer.
TL;DR for founders
If you handle passwords, payment details, health data or biometrics, the SPDI Rules 2011 still apply to you today — including the annual security audit under Rule 8(4) and the privacy-policy publication duty under Rule 4. They stop applying on 13 May 2027, when the DPDP Act removes their parent section. The catch: your ISO 27001 certificate is a named statutory safe harbour under the SPDI Rules but not under Rule 6 of the DPDP Rules 2025. Re-baseline before the switchover, not after.
Three rules, three parents, three different fates
Each rule-set answers to a different section of the IT Act 2000, and each is on a different trajectory.
| Rule-set | Parent section | Gazette | Status in 2026 |
|---|---|---|---|
| SPDI Rules 2011 | Section 43A | G.S.R. 313(E), 11 Apr 2011 | In force; parent section omitted 13 May 2027 |
| Blocking Rules 2009 | Section 69A | G.S.R. 781(E), 27 Oct 2009 | In force; zero amendments since 2009 |
| Interception Rules 2009 | Section 69 | G.S.R. 780(E), 27 Oct 2009 | In force for non-telecom computer resources only |
All three trace to the Information Technology (Amendment) Act, 2008 (Act 10 of 2009), which inserted Sections 43A, 69 and 69A with effect from 27 October 2009. Before that amendment the IT Act had no horizontal civil-compensation anchor for data-protection failures at all.
SPDI Rules 2011 — the duty that expires in 2027
Section 43A of the IT Act 2000 makes a body corporate that is negligent in implementing and maintaining reasonable security practices, and thereby causes wrongful loss or gain, liable to pay compensation. "Body corporate" reaches a company, firm, sole proprietorship or other association engaged in commercial or professional activities — so a two-person startup is inside the perimeter and a government department acting sovereignly is outside it.
The operative obligations are four:
- Rule 4 — publish a privacy policy, accessible, stating what is collected, why, the security practices followed and disclosure arrangements.
- Rule 5 — prior written consent (including by electronic communication) before collection; notice of purpose, recipients and collecting agency; no retention beyond purpose; an option to review and withdraw consent.
- Rule 6 and Rule 7 — disclosure to third parties needs prior permission unless contractually agreed or legally required; onward transfer, in India or abroad, only to an entity ensuring the same level of protection and only where necessary for a lawful contract.
- Rule 8 — the reasonable-security standard, with a documented information security programme, and IS/ISO/IEC 27001 expressly named in Rule 8(2) as a qualifying standard. Rule 8(4) requires certification or audit by a Central-Government-approved auditor at least once a year, and again on any significant upgrade.
Section 44(2)(a) of the DPDP Act, 2023 omits Section 43A. Commencement is fixed at 13 May 2027 by the phased-commencement notifications of 13 November 2025 (G.S.R. 843(E), 844(E) and 845(E), issued alongside the DPDP Rules at G.S.R. 846(E)). On that date the SPDI Rules lose their rule-making anchor. No express rescission has issued yet; pending adjudication before an Adjudicating Officer under Section 46 of the IT Act 2000 is preserved by Section 6 of the General Clauses Act, 1897.
Two consequences deserve board attention. First, from 13 November 2025 to 13 May 2027 — an eighteen-month window — body corporates run both regimes. Second, the Rule 8(2) ISO 27001 safe harbour does not transfer: Rule 6 of the DPDP Rules 2025 prescribes its own minima, and the enforcement ceiling moves from an Adjudicating Officer's compensation award (historically in the range of ₹50,000 to ₹5 lakh in reported orders) to a Data Protection Board penalty of up to ₹250 crore under Section 33 and the Schedule to the DPDP Act.
💡 Running two data-protection regimes at once until May 2027? The Veritect Legal AI platform holds the SPDI Rules 2011 and the DPDP Rules 2025 side by side, clause against clause, so you can see exactly which obligation is discharged by your existing ISO 27001 programme and which needs a fresh control. Explore Veritect Legal AI →
Blocking Rules 2009 — frozen since notification, upheld in Shreya Singhal
Section 69A of the IT Act 2000 empowers the Central Government to direct blocking of information for public access on grounds co-extensive with the Article 19(2) restrictions. The Blocking Rules 2009 build a two-track procedure ending in the same place.
- Rule 8 — standard track. The Designated Officer, an officer not below Joint Secretary rank, issues notice to the person or intermediary hosting the information, who has 48 hours to appear or file a written representation before the Committee for Examination of Request. The Committee — drawing members from the Ministry of Law and Justice, Ministry of Home Affairs, Ministry of Information and Broadcasting and CERT-In — recommends in writing; the Secretary approves; the Designated Officer directs the intermediary under Rule 9.
- Rule 7 — emergency track. Where delay would be inexpedient, the Secretary may pass an interim direction on recorded reasons, and must place it before the Committee within 48 hours. Absent a confirmation recommendation, the interim direction lapses. The pre-decisional hearing is dispensed with.
- Rule 14 — Review Committee, constituted under Rule 419A of the Indian Telegraph Rules, 1951, meeting at least once every two months, with power to set aside a direction and order unblocking.
- Rule 16 — confidentiality over all requests, complaints and actions taken.
In Shreya Singhal v. Union of India, (2015) 5 SCC 1 (Nariman J., Chelameswar J. concurring, 24 March 2015), the Supreme Court struck down Section 66A, upheld Section 69A and the Blocking Rules 2009 as intra vires at paragraphs 109 to 119, and separately read down Section 79(3)(b) so that "actual knowledge" for safe-harbour loss must come from a court order or a government notification. The Court's reasoning turned on the narrowness of Section 69A, the Article 19(2) alignment of its grounds, and the requirement of written reasons capable of challenge under Article 226. Rule 16 confidentiality was not specifically ruled on, and remains the subject of pending constitutional challenge.
The practical point for 2026: the surrounding ecosystem has moved four times in five years — IT Rules 2021, the April 2023 consolidation, the Rule 3(1)(d) amendment of 15 November 2025 and the synthetic-media amendment of February 2026 — while the blocking procedure has not moved at all. A valid Rule 9 direction is also an "actual knowledge" event for Section 79 purposes, which is why a compliant takedown SOP needs a blocking rail and an intimation rail running together.
Interception Rules 2009 — narrowed, not retired
Section 69 of the IT Act 2000 authorises interception, monitoring or decryption of any information in any computer resource on six grounds, with Section 69(4) exposing a non-assisting intermediary to imprisonment up to seven years and fine. The Interception Rules 2009 were drafted to map the safeguards laid down for telephone tapping in People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301 onto electronic information: authorisation only by a Secretary-rank competent authority, recorded reasons, a copy to the Review Committee within seven working days (Rule 7), a 60-day validity renewable to a 180-day ceiling (Rule 11), Review Committee oversight every two months (Rule 22), and destruction of records every six months by the authority, or within two months of discontinuance by the intermediary (Rule 23).
The Telecom (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, notified on 6 December 2024 under Sections 20 to 22 of the Telecommunications Act, 2023 (Act 44 of 2023), displace the 2009 rules for telecom service providers. They do not displace them for stored information in a non-telecom computer resource. For platform-type services whose classification under the Telecommunications Act 2023 is still being settled, both regimes can apply, and an authorised officer may pick the more convenient one.
Founder checklist
- Diarise 13 May 2027. Map every Rule 4 to Rule 8 SPDI control to its DPDP successor before the switchover, and note where Rule 6 of the DPDP Rules 2025 demands more than ISO 27001.
- Keep the annual SPDI audit running. Rule 8(4) requires it at least once a year and on any significant system upgrade — it has not lapsed.
- Add a blocking rail to your takedown SOP. A Rule 9 direction is a statutory command carrying a seven-year exposure under Section 69A(3), and simultaneously an "actual knowledge" trigger for Section 79 safe harbour.
- Name your interception nodal officer. Rule 13 requires designated officers under a strict confidentiality duty; Section 69(4) is a seven-year offence for failure to assist.
- Do not assume breach notification is covered. The SPDI Rules have none; your only pre-DPDP breach clocks are the CERT-In six-hour rule and your sectoral regulator.
Frequently Asked Questions
Q1: Do the SPDI Rules apply to data we receive from foreign clients?
A MeitY clarificatory press note of 24 August 2011 narrowed the Rules' operation to body corporates and persons located in India, and treated sensitive personal data provided by a foreign-located provider under a contractual arrangement as outside the Rules. That position was formalised through practice rather than by a rule-amendment instrument, so document the reliance rather than assuming it.
Q2: Is there an appeal from a Section 43A compensation order?
Yes. The Adjudicating Officer under Section 46 of the IT Act 2000 hears claims where the damage claimed does not exceed ₹5 crore; above that, jurisdiction vests in the competent court. Appeal lies to the Telecom Disputes Settlement and Appellate Tribunal, which absorbed the Cyber Appellate Tribunal from 26 May 2017, and thereafter to the High Court on a question of law.
Q3: Can we see the reasons for a blocking direction affecting our content?
Rule 16 of the Blocking Rules 2009 imposes strict confidentiality over requests and actions taken, which is why the reasons are typically not shared with the originator. That constraint is the subject of live constitutional challenge, argued against the publication-and-periodic-review principle in Anuradha Bhasin v. Union of India, (2020) 3 SCC 637. Shreya Singhal upheld the Rules as a whole but did not decide Rule 16 specifically.
Q4: Does an interception order have to be disclosed to the subject?
No. The design assumes the subject is unaware, and there is no statutory appeal. The Review Committee under Rule 22 is the only routine check. A subject who later learns of the order — often through criminal-trial disclosure — may challenge it under Article 226 on the PUCL ratio, particularly where reasons were not recorded or the 180-day ceiling was exceeded.
Q5: How do these rules interact with the CERT-In six-hour clock?
They do not displace it. Direction (ii) of the CERT-In Directions of 28 April 2022, issued under Section 70B(6) of the IT Act 2000, requires reporting of listed cyber incidents within six hours of noticing, and Direction (iv) requires 180 days of ICT logs held in India. Until 13 May 2027, a body corporate suffering a ransomware incident affecting sensitive personal data can be running the CERT-In clock, Section 43A exposure and phased DPDP obligations simultaneously.
Q6: What replaces Section 43A after 2027?
Section 8(5) of the DPDP Act, 2023, operationalised by Rule 6 of the DPDP Rules, 2025, for security safeguards, and Section 8(6) with Rule 7 for breach notification — a duty the SPDI Rules never contained. Enforcement moves from a compensation claim before an Adjudicating Officer to a penalty proceeding before the Data Protection Board of India, with appeal to TDSAT under Section 29 of the DPDP Act.
Beyond this brief Preview
Veritect Legal AI holds the full operative chain: the IT Act 2000 Sections 43A, 46, 69, 69A, 69B, 79 and 87(2) with their amendment footnotes; the SPDI Rules 2011, Blocking Rules 2009 and Interception Rules 2009 rule by rule; the DPDP Act 2023 with Section 44(2) and the DPDP Rules 2025; the Telecommunications Act 2023 with the lawful-interception rules of 6 December 2024; and the Shreya Singhal, PUCL and Anuradha Bhasin lines.
Practitioner-level content available on Veritect Legal AI:
- SPDI Rule 4-8 to DPDP Rule 6 control-mapping worksheet for the 13 May 2027 switchover
- Blocking-direction intake SOP with the 48-hour Rule 8 representation window
- Interception nodal-officer designation note and Rule 11 / Rule 23 clock tracker
- Section 46 adjudication defence outline for pending Section 43A claims
- Parallel-regime calendar covering CERT-In, SPDI and phased DPDP obligations
Primary Sources
- Information Technology Act, 2000 (consolidated) — India Code: https://www.indiacode.nic.in/handle/123456789/1999
- IT (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009 — India Code: https://upload.indiacode.nic.in/showfile?actid=AC_CEN_45_76_00001_200021_1517807324077&type=rule&filename=blocking_for_access_of_information_rule_2009.pdf
- Digital Personal Data Protection Act, 2023 — India Code: https://www.indiacode.nic.in/handle/123456789/20168
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY: https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa
- Phased commencement notifications G.S.R. 843(E), 844(E), 845(E) dated 13 November 2025 — eGazette: https://egazette.gov.in/
- Telecommunications Act, 2023 (Act 44 of 2023) — India Code: https://www.indiacode.nic.in/bitstream/123456789/20101/1/A2023-44.pdf
- Telecom (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024 — DoT: https://dot.gov.in/relatedlinks/telecommunications-act-2023
- CERT-In Directions dated 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- Ministry of Electronics and Information Technology — statute and rule repository: https://www.meity.gov.in/
- Ministry of Home Affairs — competent authority under the Interception Rules 2009: https://www.mha.gov.in/
- Telecom Disputes Settlement and Appellate Tribunal: https://tdsat.gov.in/
- Supreme Court of India — judgment portal: https://www.sci.gov.in/