SPDI, Blocking and Interception Rules: What Still Binds You in 2026

Regulatory Explainer Cybersecurity 28 Jul 2026 Status: in-force-partial-sunset
TL;DR

Three sets of rules made under the Information Technology Act, 2000 remain operative in 2026 alongside the DPDP Rules 2025 and the IT Rules 2021. The SPDI Rules 2011 (G.S.R. 313(E), 11 April 2011) carry the Section 43A reasonable-security duty and lose their parent section on 13 May 2027 when Section 44(2)(a) of the DPDP Act 2023 commences. The Blocking Rules 2009 (G.S.R. 781(E)) have never been amended and were upheld in Shreya Singhal v. Union of India, (2015) 5 SCC 1. The Interception Rules 2009 (G.S.R. 780(E)) remain in force for non-telecom computer resources but were displaced for telecom service providers by the Telecom lawful-interception rules notified on 6 December 2024.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
8 min read
Continue with Veritect

Every Cybersecurity rule, sourced from the primary notification.

Try Veritect free Book a demo

Three sets of rules made under the Information Technology Act, 2000 still bind Indian businesses in 2026, and none of them is repealed by the DPDP regime yet. The SPDI Rules 2011 carry the Section 43A security duty until 13 May 2027. The Blocking Rules 2009 have never once been amended. The Interception Rules 2009 survive for everything that is not a telecom service. Compliance programmes built only around the DPDP Rules 2025 and the IT Rules 2021 are missing a live layer.

TL;DR for founders

If you handle passwords, payment details, health data or biometrics, the SPDI Rules 2011 still apply to you today — including the annual security audit under Rule 8(4) and the privacy-policy publication duty under Rule 4. They stop applying on 13 May 2027, when the DPDP Act removes their parent section. The catch: your ISO 27001 certificate is a named statutory safe harbour under the SPDI Rules but not under Rule 6 of the DPDP Rules 2025. Re-baseline before the switchover, not after.

Three rules, three parents, three different fates

Each rule-set answers to a different section of the IT Act 2000, and each is on a different trajectory.

Rule-set Parent section Gazette Status in 2026
SPDI Rules 2011 Section 43A G.S.R. 313(E), 11 Apr 2011 In force; parent section omitted 13 May 2027
Blocking Rules 2009 Section 69A G.S.R. 781(E), 27 Oct 2009 In force; zero amendments since 2009
Interception Rules 2009 Section 69 G.S.R. 780(E), 27 Oct 2009 In force for non-telecom computer resources only

All three trace to the Information Technology (Amendment) Act, 2008 (Act 10 of 2009), which inserted Sections 43A, 69 and 69A with effect from 27 October 2009. Before that amendment the IT Act had no horizontal civil-compensation anchor for data-protection failures at all.

SPDI Rules 2011 — the duty that expires in 2027

Section 43A of the IT Act 2000 makes a body corporate that is negligent in implementing and maintaining reasonable security practices, and thereby causes wrongful loss or gain, liable to pay compensation. "Body corporate" reaches a company, firm, sole proprietorship or other association engaged in commercial or professional activities — so a two-person startup is inside the perimeter and a government department acting sovereignly is outside it.

The operative obligations are four:

  • Rule 4 — publish a privacy policy, accessible, stating what is collected, why, the security practices followed and disclosure arrangements.
  • Rule 5 — prior written consent (including by electronic communication) before collection; notice of purpose, recipients and collecting agency; no retention beyond purpose; an option to review and withdraw consent.
  • Rule 6 and Rule 7 — disclosure to third parties needs prior permission unless contractually agreed or legally required; onward transfer, in India or abroad, only to an entity ensuring the same level of protection and only where necessary for a lawful contract.
  • Rule 8 — the reasonable-security standard, with a documented information security programme, and IS/ISO/IEC 27001 expressly named in Rule 8(2) as a qualifying standard. Rule 8(4) requires certification or audit by a Central-Government-approved auditor at least once a year, and again on any significant upgrade.

Section 44(2)(a) of the DPDP Act, 2023 omits Section 43A. Commencement is fixed at 13 May 2027 by the phased-commencement notifications of 13 November 2025 (G.S.R. 843(E), 844(E) and 845(E), issued alongside the DPDP Rules at G.S.R. 846(E)). On that date the SPDI Rules lose their rule-making anchor. No express rescission has issued yet; pending adjudication before an Adjudicating Officer under Section 46 of the IT Act 2000 is preserved by Section 6 of the General Clauses Act, 1897.

Two consequences deserve board attention. First, from 13 November 2025 to 13 May 2027 — an eighteen-month window — body corporates run both regimes. Second, the Rule 8(2) ISO 27001 safe harbour does not transfer: Rule 6 of the DPDP Rules 2025 prescribes its own minima, and the enforcement ceiling moves from an Adjudicating Officer's compensation award (historically in the range of ₹50,000 to ₹5 lakh in reported orders) to a Data Protection Board penalty of up to ₹250 crore under Section 33 and the Schedule to the DPDP Act.

💡 Running two data-protection regimes at once until May 2027? The Veritect Legal AI platform holds the SPDI Rules 2011 and the DPDP Rules 2025 side by side, clause against clause, so you can see exactly which obligation is discharged by your existing ISO 27001 programme and which needs a fresh control. Explore Veritect Legal AI →

Blocking Rules 2009 — frozen since notification, upheld in Shreya Singhal

Section 69A of the IT Act 2000 empowers the Central Government to direct blocking of information for public access on grounds co-extensive with the Article 19(2) restrictions. The Blocking Rules 2009 build a two-track procedure ending in the same place.

  • Rule 8 — standard track. The Designated Officer, an officer not below Joint Secretary rank, issues notice to the person or intermediary hosting the information, who has 48 hours to appear or file a written representation before the Committee for Examination of Request. The Committee — drawing members from the Ministry of Law and Justice, Ministry of Home Affairs, Ministry of Information and Broadcasting and CERT-In — recommends in writing; the Secretary approves; the Designated Officer directs the intermediary under Rule 9.
  • Rule 7 — emergency track. Where delay would be inexpedient, the Secretary may pass an interim direction on recorded reasons, and must place it before the Committee within 48 hours. Absent a confirmation recommendation, the interim direction lapses. The pre-decisional hearing is dispensed with.
  • Rule 14 — Review Committee, constituted under Rule 419A of the Indian Telegraph Rules, 1951, meeting at least once every two months, with power to set aside a direction and order unblocking.
  • Rule 16 — confidentiality over all requests, complaints and actions taken.

In Shreya Singhal v. Union of India, (2015) 5 SCC 1 (Nariman J., Chelameswar J. concurring, 24 March 2015), the Supreme Court struck down Section 66A, upheld Section 69A and the Blocking Rules 2009 as intra vires at paragraphs 109 to 119, and separately read down Section 79(3)(b) so that "actual knowledge" for safe-harbour loss must come from a court order or a government notification. The Court's reasoning turned on the narrowness of Section 69A, the Article 19(2) alignment of its grounds, and the requirement of written reasons capable of challenge under Article 226. Rule 16 confidentiality was not specifically ruled on, and remains the subject of pending constitutional challenge.

The practical point for 2026: the surrounding ecosystem has moved four times in five years — IT Rules 2021, the April 2023 consolidation, the Rule 3(1)(d) amendment of 15 November 2025 and the synthetic-media amendment of February 2026 — while the blocking procedure has not moved at all. A valid Rule 9 direction is also an "actual knowledge" event for Section 79 purposes, which is why a compliant takedown SOP needs a blocking rail and an intimation rail running together.

Interception Rules 2009 — narrowed, not retired

Section 69 of the IT Act 2000 authorises interception, monitoring or decryption of any information in any computer resource on six grounds, with Section 69(4) exposing a non-assisting intermediary to imprisonment up to seven years and fine. The Interception Rules 2009 were drafted to map the safeguards laid down for telephone tapping in People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301 onto electronic information: authorisation only by a Secretary-rank competent authority, recorded reasons, a copy to the Review Committee within seven working days (Rule 7), a 60-day validity renewable to a 180-day ceiling (Rule 11), Review Committee oversight every two months (Rule 22), and destruction of records every six months by the authority, or within two months of discontinuance by the intermediary (Rule 23).

The Telecom (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, notified on 6 December 2024 under Sections 20 to 22 of the Telecommunications Act, 2023 (Act 44 of 2023), displace the 2009 rules for telecom service providers. They do not displace them for stored information in a non-telecom computer resource. For platform-type services whose classification under the Telecommunications Act 2023 is still being settled, both regimes can apply, and an authorised officer may pick the more convenient one.

Founder checklist

  • Diarise 13 May 2027. Map every Rule 4 to Rule 8 SPDI control to its DPDP successor before the switchover, and note where Rule 6 of the DPDP Rules 2025 demands more than ISO 27001.
  • Keep the annual SPDI audit running. Rule 8(4) requires it at least once a year and on any significant system upgrade — it has not lapsed.
  • Add a blocking rail to your takedown SOP. A Rule 9 direction is a statutory command carrying a seven-year exposure under Section 69A(3), and simultaneously an "actual knowledge" trigger for Section 79 safe harbour.
  • Name your interception nodal officer. Rule 13 requires designated officers under a strict confidentiality duty; Section 69(4) is a seven-year offence for failure to assist.
  • Do not assume breach notification is covered. The SPDI Rules have none; your only pre-DPDP breach clocks are the CERT-In six-hour rule and your sectoral regulator.

Frequently Asked Questions

Q1: Do the SPDI Rules apply to data we receive from foreign clients?

A MeitY clarificatory press note of 24 August 2011 narrowed the Rules' operation to body corporates and persons located in India, and treated sensitive personal data provided by a foreign-located provider under a contractual arrangement as outside the Rules. That position was formalised through practice rather than by a rule-amendment instrument, so document the reliance rather than assuming it.

Q2: Is there an appeal from a Section 43A compensation order?

Yes. The Adjudicating Officer under Section 46 of the IT Act 2000 hears claims where the damage claimed does not exceed ₹5 crore; above that, jurisdiction vests in the competent court. Appeal lies to the Telecom Disputes Settlement and Appellate Tribunal, which absorbed the Cyber Appellate Tribunal from 26 May 2017, and thereafter to the High Court on a question of law.

Q3: Can we see the reasons for a blocking direction affecting our content?

Rule 16 of the Blocking Rules 2009 imposes strict confidentiality over requests and actions taken, which is why the reasons are typically not shared with the originator. That constraint is the subject of live constitutional challenge, argued against the publication-and-periodic-review principle in Anuradha Bhasin v. Union of India, (2020) 3 SCC 637. Shreya Singhal upheld the Rules as a whole but did not decide Rule 16 specifically.

Q4: Does an interception order have to be disclosed to the subject?

No. The design assumes the subject is unaware, and there is no statutory appeal. The Review Committee under Rule 22 is the only routine check. A subject who later learns of the order — often through criminal-trial disclosure — may challenge it under Article 226 on the PUCL ratio, particularly where reasons were not recorded or the 180-day ceiling was exceeded.

Q5: How do these rules interact with the CERT-In six-hour clock?

They do not displace it. Direction (ii) of the CERT-In Directions of 28 April 2022, issued under Section 70B(6) of the IT Act 2000, requires reporting of listed cyber incidents within six hours of noticing, and Direction (iv) requires 180 days of ICT logs held in India. Until 13 May 2027, a body corporate suffering a ransomware incident affecting sensitive personal data can be running the CERT-In clock, Section 43A exposure and phased DPDP obligations simultaneously.

Q6: What replaces Section 43A after 2027?

Section 8(5) of the DPDP Act, 2023, operationalised by Rule 6 of the DPDP Rules, 2025, for security safeguards, and Section 8(6) with Rule 7 for breach notification — a duty the SPDI Rules never contained. Enforcement moves from a compensation claim before an Adjudicating Officer to a penalty proceeding before the Data Protection Board of India, with appeal to TDSAT under Section 29 of the DPDP Act.


Beyond this brief Preview

Veritect Legal AI holds the full operative chain: the IT Act 2000 Sections 43A, 46, 69, 69A, 69B, 79 and 87(2) with their amendment footnotes; the SPDI Rules 2011, Blocking Rules 2009 and Interception Rules 2009 rule by rule; the DPDP Act 2023 with Section 44(2) and the DPDP Rules 2025; the Telecommunications Act 2023 with the lawful-interception rules of 6 December 2024; and the Shreya Singhal, PUCL and Anuradha Bhasin lines.

Practitioner-level content available on Veritect Legal AI:

  • SPDI Rule 4-8 to DPDP Rule 6 control-mapping worksheet for the 13 May 2027 switchover
  • Blocking-direction intake SOP with the 48-hour Rule 8 representation window
  • Interception nodal-officer designation note and Rule 11 / Rule 23 clock tracker
  • Section 46 adjudication defence outline for pending Section 43A claims
  • Parallel-regime calendar covering CERT-In, SPDI and phased DPDP obligations

Access Veritect Legal AI →


Primary Sources

Primary source

Title: IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; IT (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009; IT (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009
Issuer: Ministry of Electronics and Information Technology (then Department of Information Technology)
Effective: 2009-10-27
Gazette: G.S.R. 313(E) dated 11 April 2011 (SPDI Rules); G.S.R. 781(E) dated 27 October 2009 (Blocking Rules); G.S.R. 780(E) dated 27 October 2009 (Interception Rules)

Frequently asked

Are the SPDI Rules 2011 still in force in 2026?

Yes. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, notified vide G.S.R. 313(E) dated 11 April 2011, remain in force and have never been substantively amended. Their parent provision, Section 43A of the Information Technology Act, 2000, is scheduled for omission by Section 44(2)(a) of the Digital Personal Data Protection Act, 2023, which commences on 13 May 2027 under the phased-commencement notifications of 13 November 2025. Until that date a body corporate handling sensitive personal data runs the SPDI Rules and the DPDP obligations in parallel.

Does ISO 27001 certification still protect us after the DPDP Act fully commences?

Not automatically. Rule 8(2) of the SPDI Rules 2011 names IS/ISO/IEC 27001 as a standard that satisfies the reasonable-security requirement under Section 43A of the IT Act 2000 — a genuine statutory safe harbour. Rule 6 of the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) instead prescribes its own set of minima including encryption, access control, logging, continuity, log retention and contractual flow-down to processors. A certificate is evidence towards those minima but is not a named safe harbour. Re-baseline against Rule 6 before 13 May 2027.

What are the eight categories of sensitive personal data under the SPDI Rules?

Rule 3 of the SPDI Rules 2011 lists passwords; financial information such as bank account, credit card, debit card or other payment instrument details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; any detail relating to those clauses provided to a body corporate for a service; and any such information received by a body corporate for processing under lawful contract or otherwise. Information freely available in the public domain or furnished under the Right to Information Act, 2005 is excluded. This is a narrower closed list than 'personal data' under the DPDP Act, 2023, which covers all digital personal data.

Have the Blocking Rules 2009 been amended since the IT Rules 2021 came in?

No. The Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009, notified vide G.S.R. 781(E) dated 27 October 2009, have not been amended once since notification. That is unusual — the IT Rules 2021 were consolidated in April 2023 and amended again for Rule 3(1)(d) in November 2025 and for synthetic media in February 2026. Every Section 69A blocking direction issued in 2026 still runs on the 2009 procedure that the Supreme Court examined in Shreya Singhal v. Union of India, (2015) 5 SCC 1.

What happens if an intermediary refuses to comply with a blocking direction?

Section 69A(3) of the Information Technology Act, 2000 provides imprisonment which may extend to seven years and also a fine for an intermediary that fails to comply with a direction under Section 69A(1). Officers in default are exposed under Section 85 of the IT Act. Practically, intermediaries comply first and litigate afterwards — either before the Review Committee constituted under Rule 419A of the Indian Telegraph Rules, 1951, which must meet at least once every two months under Rule 14, or by writ petition under Article 226.

Which interception regime applies to a messaging app — the 2009 IT rules or the 2024 telecom rules?

It depends on how the service is classified. The Telecom (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024, notified on 6 December 2024 under Sections 20 to 22 of the Telecommunications Act, 2023, govern interception of telecommunication messages carried by an authorised telecom service provider. The IT (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009 continue to govern interception of information in a non-telecom computer resource, such as a platform's stored content database. Where a service is both a telecommunication service and an intermediary, both regimes can apply in parallel.

How long can an interception order under the 2009 IT rules stay in force?

Rule 11 limits a direction to sixty days from the date of issue, renewable, with a total ceiling of one hundred and eighty days. A fresh authorisation is required after that. The order is issued by a competent authority — the Secretary in the Ministry of Home Affairs for the Centre, or the Secretary in charge of the Home Department for a State or Union territory — must record reasons, and a copy must reach the Review Committee within seven working days under Rule 7. Records are destroyed every six months under Rule 23; an intermediary destroys its records within two months of discontinuance.

Is there any breach-notification duty in the SPDI Rules?

No. The SPDI Rules 2011 contain no breach-notification obligation — a significant gap that Section 8(6) of the DPDP Act, 2023 read with Rule 7 of the DPDP Rules, 2025 was drafted to close. Before the DPDP regime, breach reporting ran only through Direction (ii) of the CERT-In Directions of 28 April 2022 under Section 70B(6) of the IT Act 2000 — the six-hour clock — and through sectoral frameworks issued by the RBI, SEBI and IRDAI.

Tags

cybersecurity spdi-rules-2011 blocking-rules-2009 interception-rules-2009 section-43a section-69a dpdp-act-2023 shreya-singhal it-act-2000
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free