India IT Rules 2011
Also known as: IT Rules 2011, ITR 2011, SPDI Rules, Reasonable Security Practices Rules
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — MeitY (Ministry of Electronics and Information Technology, India)
Official site Official change log Subscribe to India IT Rules 2011 (RSS)
The rules made under section 43A of India's Information Technology Act that define what "reasonable security practices" means for any body corporate handling sensitive personal data in India. The Digital Personal Data Protection Act 2023 omits section 43A once that provision of the Act is brought into force, so these rules carry the operative obligations only until then; the Act's own rules were notified in November 2025.
Timeline
No changes recorded yet — we are watching, and nothing has been published.
Monitoring
Watched by 1 official source. Watching since 30 September 2026.