Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
AI / PRIVACY / CYBER RELEVANCE
Relevant to legacy handling of financial, health and biometric datasets used by AI systems.
AI: ModeratePrivacy: HighCybersecurity: High
READ FIRST
- Rule 3 - SPDI
- Rule 4 - privacy policy
- Rule 5 - collection/consent
- Rules 6 - 8 - disclosure, transfer and security
PURVIEW
Prescribes reasonable security practices and procedures for bodies corporate handling sensitive personal data or information under the IT Act framework. Although the DPDP regime changes the modern privacy landscape, this Ruleset remains relevant where the IT Act’s Section 43A framework applies or where legacy legal analysis is required. For AI, it is useful for understanding security expectations around sensitive datasets, access controls, governance and technical safeguards that can still inform the handling of high-risk personal information in AI systems.
Classification and legal status. Binding subordinate legislation within its historical statutory field; now largely a legacy framework alongside the DPDP regime.