Compliance/India/MeitY Data-Security Framework
One ministry, five instruments: eight provisions leave evidence in the file.
MeitY’s rules ask body corporates to protect sensitive personal data with reasonable security practices. Vaultize adds records that stay with the data.
- IT Act 2000 s.43A · SPDI Rules 2011
- DPDP Act 2023 supersedes on commencement
- Capability mapping, not legal advice
43AIT Act s.43A
Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected.
Vaultize Seal · Discover & Classify
ITA
IT Act s.43A
1 of 1
- 43A
SPDI
SPDI Rules 2011
4 of 6
- R3
- R4
- R5
- R6
- R7
- R8
DPDP
DPDP Act 2023
1 of 5
- DPDP-4
- DPDP-8
- DPDP-11
- DPDP-12
- DPDP-16
CERT
CERT-In 2022
1 of 3
- CERT-ii
- CERT-iii
- CERT-iv
CLOUD
Cloud empanelment
0 of 1
- GI-Cloud
The answer in 30 seconds
Vaultize adds file-level records to eight provisions: section 43A, five SPDI Rules on classification, disclosure, transfer and security practices, the DPDP Act’s safeguards duty, and the CERT-In logging direction. Privacy policy, consent, grievance and reporting belong to the organisation.
The framework in one view
Five instruments. One question. Where file evidence lands.
There is no single MeitY certification. Select an instrument to see which of its provisions a governed file can evidence.
ITA
IT Act s.43A
Section 43A. Compensation for negligence in reasonable security practices over sensitive personal data. Omitted by the DPDP Act on commencement.
Outcomes the file can evidence
- How Vaultize contributes
- Encryption and rights sealed into the document, with per-access records, are practices designed to protect the information from unauthorised access, use, modification and disclosure.
- Evidence to retain
- Encryption at source. Sealed rights. Per-access records.
Provision by provision
What each provision asks. What the file can answer.
Section and rule wording is quoted from the IT Act, 2000, the SPDI Rules, 2011 and the DPDP Act, 2023; longer provisions are excerpted. Each row is a capability mapping, not legal advice. Take advice on which instrument applies and from when.
Using this page
Where these rows fit across MeitY’s instruments.
Section 43A and the SPDI Rules govern sensitive personal data until the DPDP Act commences for that provision, eighteen months from 13 November 2025. The rows above are evidence across that transition.
- 1
Identify the instrument
Body corporate under 43A and the SPDI Rules today; Data Fiduciary under the DPDP Act on commencement; the CERT-In Directions throughout.
- 2
Classify the data
Rule 3 categories now, personal data under the DPDP Act next.
- 3
Apply the practices
Rule 8 today, section 8(5) tomorrow. Seal rights and encryption into the documents. These rows belong here.
Bring the eight rows above as evidence of reasonable security practices that survive the transition to the DPDP Act.
- 4
Govern disclosure and transfer
Rules 6 and 7, then the DPDP Act’s processor and transfer provisions.
- 5
Keep the logs and evidence
CERT-In 180-day logs, and the documented programme’s own records.
Responsibility boundary
Practices support compliance. They are not the programme.
Vaultize contributes technical control measures and evidence for sensitive personal data held in documents. It does not write the documented information security programme, decide which instrument applies, or certify anything, and it does not claim MeitY empanelment. Read the Act, the Rules, the DPDP Act and the CERT-In Directions, and take qualified advice before relying on this page.
“The international Standard IS/ISO/IEC 27001 on “Information Technology - Security Techniques - Information Security Management System - Requirements” is one such standard referred to in sub-rule (1).”
Rule 8(2), SPDI Rules, 2011
Official references
Read the source before relying on the mapping.
Rule wording comes from the first item; section wording from the Act and the DPDP Act. The others are the Ministry’s own instruments and indexes.
- IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011G.S.R. 313(E) of 11 April 2011, as reproduced on WIPO Lex. Rules 3, 6, 7 and 8 are quoted on this page.
- The Digital Personal Data Protection Act, 2023Section 8(5) is quoted on this page; section 44(2)(a) omits section 43A of the IT Act on commencement.
- CERT-In Directions under section 70B(6), 28 April 2022Direction (iv) on 180-day logs is quoted on this page.
- MeitY Acts and PoliciesThe Ministry’s index of the instruments it administers.
A practical next step
Bring one document that carries sensitive personal data.
We will show which provisions the governed document can evidence today, under the SPDI Rules and under the DPDP Act. We will name the owner responsible for the rest.
