munotes®

Reasonable Security Practices and the SPDI Rules

Chapter Twenty-Three

Syllabus topic 1.4, "Information Security"

Pages 126 to 133 of 948

In one line

Eight rules made in 2011 are still India's operative data protection law, and they say what a company must do with your sensitive personal information and what counts as protecting it properly.

In the wording a student can write in an exam: the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, made under clause (ob) of section 87(2) read with section 43A of the Information Technology Act, 2000, define sensitive personal data or information, require a body corporate handling it to publish a privacy policy, to obtain written consent for a lawful and necessary purpose, to limit retention and use, to permit review and correction, to allow withdrawal of consent, to restrict disclosure and transfer, and to implement documented reasonable security practices of which IS/ISO/IEC 27001 is one recognised standard.

Why these rules still matter

Because section 43A is still in force. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 provides for the omission of section 43A, and notification G.S.R. 843(E) of 13 November 2025 placed section 44(2) in the eighteen-month stage, so it commences on 13 May 2027. Until then section 43A stands and so do these Rules. Chapter 190 sets out the staging.

And because they supply the standard by which section 43A is judged. Section 43A makes a body corporate liable to pay damages by way of compensation where it is negligent in implementing and maintaining reasonable security practices and procedures while possessing, dealing or handling sensitive personal data or information. The Explanation to the section leaves both expressions to be prescribed, and these Rules are what was prescribed. Chapter 1040 works the section.

Rule 1: the instrument and its date

Rule 1 names the Rules and commences them. They are the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, notified as G.S.R. 313(E) on 11 April 2011 under clause (ob) of section 87(2) read with section 43A, and they came into force on the date of their publication in the Official Gazette.

The parent power is worth a sentence of its own. Clause (ob) was inserted by the amendment of 2008 along with section 43A itself, so the Rules are not a general privacy code made under a general power. They exist only to fill the two expressions section 43A left blank, and nothing in them can travel beyond that section.

Three sets were notified on the same day, G.S.R. 313(E) here, G.S.R. 315(E) for cyber cafes and G.S.R. 316(E) for electronic service delivery, with the now superseded intermediaries guidelines as G.S.R. 314(E). Chapters 1430 and 370 take the other two.

munotes.in126

Reasonable Security Practices and the SPDI Rules

Rule 2: the definitions that decide who is covered

Rule 2(1)(c): "body corporate" means the body corporate as defined in clause (i) of the Explanation to section 43A, which is any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities.

That excludes the Government. A Government department is not a body corporate engaged in commercial or professional activities, so section 43A and these Rules do not reach it, which was the largest single gap in Indian data protection law before the DPDP Act.

Rule 2(1)(i): "personal information" means any information that relates to a natural person which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person.

The words "in combination with other information available or likely to be available" are wider than students expect. Information that identifies nobody on its own is personal information if the holder has, or is likely to have, the other pieces.

Rule 2(1)(b) defines biometrics as technologies measuring and analysing human body characteristics, naming fingerprints, eye retinas and irises, voice patterns, facial patterns, hand measurements and DNA, for authentication purposes.

Rule 2(1)(d) defines cyber incidents, and rule 2(1)(h) defines password to include an encryption or decryption key.

Rule 3: sensitive personal data or information

The list is closed and it is short. Sensitive personal data or information means personal information consisting of information relating to:

(i) password; (ii) financial information such as bank account or credit card or debit card or other payment instrument details; (iii) physical, physiological and mental health condition; (iv) sexual orientation; (v) medical records and history; (vi) biometric information; (vii) any detail relating to the above clauses as provided to a body corporate for providing service; and (viii) any of the information received under the above clauses by a body corporate for processing, stored or processed under lawful contract or otherwise.

The proviso is important and often forgotten. Any information that is freely available or accessible in the public domain, or furnished under the Right to Information Act, 2005 or any other law for the time being in force, is not sensitive personal data or information for the purposes of these Rules.

What is not on the list is as instructive as what is. A name, an address, a telephone number, an email address, an identity number, caste, religion, political opinion and criminal record are all personal information and none of them is sensitive under rule 3. So the strict obligations in rules 5 and 6 do not attach to them.

Compare the Digital Personal Data Protection Act 2023, which abandons the sensitive category altogether and applies one set of obligations to all digital personal data. Chapter 1050 works it, and the comparison is a good examination point.

munotes.in127

Reasonable Security Practices and the SPDI Rules

Rule 4: the privacy policy

Rule 4(1) requires the body corporate, or any person collecting on its behalf, to provide a privacy policy for handling of or dealing in personal information including sensitive personal data or information, and to ensure that it is available for view by those who have provided information under a lawful contract.

The policy must be published on the website, and rule 4(2) requires it to provide for: clear and easily accessible statements of its practices and policies; the type of personal or sensitive personal data or information collected; the purpose of collection and usage; disclosure of information including sensitive personal data or information as provided in rule 6; and the reasonable security practices and procedures as provided under rule 8.

Rule 5: collection

This is the longest rule and it contains nine obligations.

Rule 5(1): consent in writing. The body corporate shall obtain consent in writing through letter or fax or email from the provider of the sensitive personal data or information regarding the purpose of usage before collection.

Rule 5(2): lawful purpose and necessity. It shall not collect sensitive personal data or information unless the information is collected for a lawful purpose connected with a function or activity of the body corporate, and the collection is considered necessary for that purpose. Two conditions, both required.

Rule 5(3): notice at collection. While collecting directly from the person, it shall take reasonable steps to ensure the person knows the fact that the information is being collected, the purpose, the intended recipients, and the name and address of the agency collecting it and the agency that will retain it.

Rule 5(4): retention limit. It shall not retain the information for longer than is required for the purposes for which it may lawfully be used or is otherwise required under any other law.

Rule 5(5): purpose limitation. The information shall be used for the purpose for which it has been collected.

Rule 5(6): review and correction. It shall permit the providers, as and when requested, to review the information they provided, and shall ensure that anything found inaccurate or deficient is corrected or amended as feasible. The proviso relieves the body corporate of responsibility for the authenticity of what the provider supplied.

Rule 5(7): the option not to give, and withdrawal. Prior to collection it shall provide an option to the provider not to provide the data sought. The provider shall also have an option, at any time, to withdraw consent given earlier, in writing. Where the provider does not give or later withdraws consent, the body corporate shall have the option not to provide goods or services for which the information was sought.

munotes.in128

Reasonable Security Practices and the SPDI Rules

Rule 5(8): it shall keep the information secure as provided in rule 8.

Rule 5(9): the Grievance Officer. It shall address any discrepancies and grievances of the provider in a time bound manner, and for that purpose shall designate a Grievance Officer and publish his name and contact details on its website. The Grievance Officer shall redress grievances expeditiously but within one month from receipt.

Rule 6: disclosure

Rule 6(1): disclosure to a third party requires prior permission from the provider, unless the disclosure has been agreed to in the contract between them, or the disclosure is necessary for compliance of a legal obligation.

The proviso is the Government exception. Information shall be shared without obtaining prior consent with Government agencies mandated under the law to obtain it for the purpose of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution, and punishment of offences. The agency shall send a request in writing stating clearly the purpose, and shall also state that the information obtained shall not be published or shared with any other person.

Rule 6(2): notwithstanding sub-rule (1), sensitive personal data or information shall be disclosed to any third party by an order under the law for the time being in force.

Rule 6(3): the body corporate shall not publish the sensitive personal data or information.

Rule 6(4): the third party receiving it shall not disclose it further.

Rule 7: transfer, including outside India

A body corporate may transfer sensitive personal data or information, including any information, to any other body corporate or person in India or located in any other country, that ensures the same level of data protection that is adhered to by the body corporate as provided under these Rules.

The transfer may be allowed only if it is necessary for the performance of the lawful contract between the body corporate and the provider, or where the provider has consented to the transfer.

Two conditions, and both must be met: an equivalent level of protection at the destination, and either necessity for the contract or consent. There is no adequacy list and no approval requirement, which makes rule 7 far lighter than Chapter V of the European General Data Protection Regulation, and chapter 690 draws the comparison.

Rule 8: reasonable security practices

Rule 8(1) states the standard. A body corporate is considered to have complied if it has implemented security practices and standards and has a comprehensive documented information security programme and information security policies containing managerial, technical, operational and physical security control measures commensurate with the information assets being protected with the nature of business. In the event of a breach, it shall be required to demonstrate, as and when called upon by the agency mandated under the law, that it has implemented security control measures as per its documented programme and policies.

munotes.in129

Reasonable Security Practices and the SPDI Rules

Rule 8(2) names a standard: IS/ISO/IEC 27001 on Information Technology, Security Techniques, Information Security Management System, Requirements, is one such standard. It is not the only one, and it is not mandatory.

Rule 8(3) allows an industry association whose members follow other codes of best practice to have those codes approved and notified by the Central Government.

Rule 8(4) is the deeming provision, and it has a condition. A body corporate which has implemented either IS/ISO/IEC 27001 or approved codes shall be deemed to have complied, provided that such standard or codes have been certified or audited on a regular basis by entities through independent auditor duly approved by the Central Government. The audit is to be carried out at least once a year or when the body corporate undertakes a significant upgradation of its process and computer resource.

So a certificate obtained once and never audited does not attract the deeming, and that is the most commonly missed point in the whole of these Rules.

The obligations at a glance

RuleObligationThe trap
4Publish a privacy policy covering practices, types collected, purpose, disclosure and securityMust be available for view by the provider, not merely on file
5(1)Written consent by letter, fax or email, before collectionOral or implied consent is not enough for sensitive data
5(2)Lawful purpose and necessityTwo conditions, not one
5(3)Notice of the fact, purpose, recipients, and the collecting and retaining agenciesThe two agencies must be named separately
5(4), 5(5)Retention limit and purpose limitation
5(6)Review and correction on requestThe body corporate is not responsible for the authenticity of what was supplied
5(7)Option not to provide, and to withdrawOn withdrawal the body corporate may refuse the service
5(9)Grievance Officer named on the website, redress within one monthA named individual, not an address
6Disclosure needs prior permission; the Government exception; no publication; no onward disclosureThe Government must request in writing and must state that it will not publish or share
7Transfer needs equivalent protection and either necessity or consentApplies to transfers within India as well
8Documented programme with four families of control; demonstrate on demandThe deeming in 8(4) needs a regular independent audit

A worked example

Sahyadri Wellness runs a chain of diagnostic clinics and a mobile application.

munotes.in130

Reasonable Security Practices and the SPDI Rules

What it holds. Names, addresses and phone numbers, which are personal information but not sensitive under rule 3. Medical records and test results, which are sensitive under rule 3(iii) and (v). Payment card details, sensitive under rule 3(ii). Fingerprints used to log staff in, sensitive under rule 3(vi).

What rule 5 requires for the sensitive items. Written consent by letter, fax or email before collection, stating the purpose of usage. A lawful purpose connected with its activity, which diagnosis plainly is, and necessity, which is where collecting a patient's sexual orientation for a routine blood test would fail. Notice at collection naming Sahyadri as collector and its cloud provider as the agency that will retain the data. Retention no longer than required. Use only for the stated purpose, so using the records to market a health insurance product is a breach of rule 5(5) unless that purpose was stated and consented to.

A patient asks to see and correct her record. Rule 5(6) requires Sahyadri to permit review and to correct what is inaccurate as feasible.

A patient withdraws consent. Rule 5(7) allows her to do so in writing, and allows Sahyadri to decline to provide the service for which the information was sought.

The police ask for a patient's records. Rule 6's proviso allows disclosure without consent to a Government agency mandated under the law, for one of the listed purposes, on a written request stating the purpose and stating that the information will not be published or shared. A telephone request does not satisfy it.

Sahyadri wants to move its records to a cloud provider in Singapore. Rule 7 permits it if the provider ensures the same level of protection as these Rules require and the transfer is necessary for the performance of the contract with the patient or the patient has consented.

Then the breach. Fourteen thousand records are taken. Section 43A asks whether Sahyadri was negligent in implementing and maintaining reasonable security practices, and rule 8(1) makes that a question about its documented programme and whether it can demonstrate implementation. If it holds a current IS/ISO/IEC 27001 certification that has been audited annually by an approved independent auditor, rule 8(4) deems compliance. If the certification lapsed two years ago, it does not.

What this does NOT mean

It does not mean these Rules apply to the Government. They apply to a body corporate as defined in section 43A, which is an entity engaged in commercial or professional activities.

It does not mean all personal information is protected by rules 5 and 6. Those rules operate on sensitive personal data or information as rule 3 defines it. A name and address are personal information and are not sensitive.

munotes.in131

Reasonable Security Practices and the SPDI Rules

It does not mean an ISO certificate is a complete answer. Rule 8(4) deems compliance only where the standard has been certified or audited regularly by an approved independent auditor.

It does not mean these Rules survive 2027. They are made under section 43A, and when section 44(2) of the DPDP Act commences on 13 May 2027 the parent provision goes. What happens to rules made under a repealed section is a question section 6 of the General Clauses Act, 1897 will have to answer.

Quick revision

  • G.S.R. 313(E), 11 April 2011, made under section 87(2)(ob) read with section 43A. Eight rules. Still in force.
  • Body corporate excludes the Government. Personal information, rule 2(1)(i), includes information identifying a person in combination with other information the body corporate has or is likely to have.
  • Rule 3, sensitive: password; financial information; physical, physiological and mental health condition; sexual orientation; medical records and history; biometrics; details of the above given for a service; and such information received for processing. Proviso: not information freely available in the public domain or furnished under the RTI Act or any other law.
  • Rule 4: privacy policy, published, covering practices, types, purpose, disclosure and security.
  • Rule 5: written consent before collection; lawful purpose and necessity; notice of fact, purpose, recipients and both agencies; retention limit; purpose limitation; review and correction; option not to give and to withdraw, with the right to refuse service; Grievance Officer named on the website, redress within one month.
  • Rule 6: disclosure needs prior permission unless contracted for or legally obliged; Government exception on a written request stating the purpose and a no-publication undertaking; no publication; no onward disclosure.
  • Rule 7: transfer, in India or abroad, needs equivalent protection plus necessity or consent.
  • Rule 8: documented programme with managerial, technical, operational and physical controls, demonstrable on demand; IS/ISO/IEC 27001 is one standard; the deeming in 8(4) requires a regular audit by an approved independent auditor.

Test yourself

1. List the categories of sensitive personal data or information and state the proviso. Password; financial information such as bank account, credit card, debit card or other payment instrument details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; any detail relating to those clauses provided to a body corporate for providing a service; and any such information received by a body corporate for processing, stored or processed under lawful contract or otherwise. The proviso excludes information freely available or accessible in the public domain, or furnished under the Right to Information Act, 2005 or any other law in force.

2. What form must consent take under rule 5(1), and what may the body corporate do if consent is withdrawn? Consent must be in writing through letter, fax or email, obtained from the provider regarding the purpose of usage, before collection. Under rule 5(7) the provider may withdraw consent at any time in writing, and the body corporate then has the option not to provide the goods or services for which the information was sought.

munotes.in132

Reasonable Security Practices and the SPDI Rules

3. On what conditions may a Government agency obtain sensitive personal data without the provider's consent? Under the proviso to rule 6(1) the agency must be mandated under the law to obtain such information, the purpose must be verification of identity or prevention, detection, investigation including cyber incidents, prosecution or punishment of offences, the agency must send a request in writing stating clearly the purpose, and it must also state that the information obtained shall not be published or shared with any other person.

4. When is a body corporate deemed to have complied with reasonable security practices? Under rule 8(4), where it has implemented IS/ISO/IEC 27001 or codes of best practice approved and notified under rule 8(3), provided that the standard or codes have been certified or audited on a regular basis by entities through an independent auditor duly approved by the Central Government. Without that regular independent audit the deeming does not operate and the body corporate must satisfy rule 8(1) on its own terms.

5. Are these Rules still in force, and why is that surprising? Yes. It is surprising because section 44(2)(a) of the Digital Personal Data Protection Act, 2023 provides for the omission of section 43A, the parent provision, and most commentary written since 2023 states that section 43A has gone. Notification G.S.R. 843(E) dated 13 November 2025 placed section 44(2) in the eighteen-month stage, so it comes into force on 13 May 2027, and until then both section 43A and these Rules apply.

munotes.in133

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!