Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Data Analytics and Law: formula sheet

Full chapter guide

Key formulas

Big data 'Vs'
Volume + Velocity + Variety (+ Veracity)
Use these to define big data. Veracity is often added as a fourth V; say so if you include it.
Three types of analytics
Descriptive = what happened; Predictive = what may happen; Prescriptive = what to do
Learn them in this order. Each answers a different question.
Section 43A liability test
Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or wrongful gain = compensation to the person affected
All elements must be present. The remedy is damages by way of compensation.
Reasonable security practices (Section 43A, Explanation)
Practices set by agreement between the parties, or by law in force; if neither exists, as prescribed by the Central Government
Name this order of reference when the question asks what 'reasonable' means.
Section 69B(4) penalty
Intermediary intentionally or knowingly contravening 69B(2): imprisonment up to one year, or fine up to ₹1 crore, or both
Applies to failure to give technical assistance to the authorised agency for traffic data.
Section 70B(7) penalty
Failure to provide information or comply with CERT-In direction: imprisonment up to one year, or fine up to ₹1 crore, or both
Applies to service providers, intermediaries, data centres, body corporate and any other person. Courts take cognizance only on a complaint by an authorised officer of CERT-In.
Territorial reach of the IT Act
Section 1(2) and section 75: applies to the whole of India and to contraventions outside India if a computer, system or network located in India is involved
Applies irrespective of the nationality of the person under section 75(1).
Old section 43A test
Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or gain = compensation
Section 44(2)(a) of the DPDP Act omits section 43A. Use it to explain the earlier position.
Adjudication limit
Section 46(1A): adjudicating officer decides claims up to ₹5 crore; above ₹5 crore, the competent court
Adjudicating officer is not below the rank of Director to the Government of India or equivalent State officer.
Right to access
Section 11(1) DPDP: summary of data and processing + identities of Fiduciaries and Processors with whom data is shared + other prescribed information
Section 11(2) exempts sharing with an authorised Fiduciary on a written request for prevention, detection, investigation or prosecution of offences or cyber incidents.
Exemptions
Section 17(1): Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 do not apply in listed cases; section 17(2): the Act does not apply to notified State instrumentalities or qualifying research, archiving and statistical use
Section 17(3) lets the Central Government exempt notified Fiduciaries, including startups, from certain provisions.
Section 43A liability
Body corporate + sensitive personal data in computer resource it owns/controls/operates + negligence in reasonable security practices + wrongful loss or gain caused = liable to pay damages by way of compensation
All elements must be present. Remedy is compensation to the affected person.
Body corporate (Explanation (i))
Any company, and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
Wider than a company under the Companies Act.
Reasonable security practices (Explanation (ii))
Agreement between the parties, or law in force; if neither, as prescribed by the Central Government
Order of reference: agreement or law first, then prescribed rules.
Sensitive personal data or information (Explanation (iii))
Such personal information as may be prescribed by the Central Government in consultation with professional bodies or associations
Rule-making power is in section 87(2)(ob).
Residuary penalty (section 45)
Penalty up to ₹1,00,000 plus compensation up to ₹10,00,000 (intermediary, company or body corporate) or ₹1,00,000 (any other person)
Applies to contravention of rules, regulations, directions or orders where no penalty is separately provided.
Elements of liability under section 43A
Body corporate + SPDI in own/controlled/operated computer resource + negligence in reasonable security practices + wrongful loss or wrongful gain ⇒ compensation
All elements must be present. No loss or gain to anyone means no claim under this section.
Order of sources of reasonable security practices
Agreement between the parties → any law in force → practices prescribed by the Central Government
The prescribed practices apply only in the absence of an agreement or a law.
Meaning of body corporate (Explanation (i))
Any company + firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
Wider than a company under the Companies Act.
Meaning of SPDI (Explanation (iii))
Such personal information as may be prescribed by the Central Government
The list is in the SPDI Rules, 2011, made under section 87(2)(ob). Say that it is prescribed, not listed in the Act.
Rule-making power
Section 87(2)(ob): reasonable security practices and procedures and SPDI under section 43A
This is the statutory source of the SPDI Rules.
Who acts and how
Central Government → notification in Official Gazette → authorises any agency of the Government
Section 69B(1). State Governments are not named in this section, unlike section 69.
Purpose
Enhance cyber security + identify, analyse and prevent intrusion or spread of computer contaminant
The only stated purpose. Do not add grounds like public order or sovereignty, which belong to section 69.
Scope of monitoring
Traffic data or information generated, transmitted, received or stored in any computer resource
Section 69B(1).
Duty of intermediary
Provide technical assistance and extend all facilities to enable online access to the computer resource
Section 69B(2). Applies to the intermediary or any person in charge of the computer resource.
Procedure
Procedure and safeguards as may be prescribed
Section 69B(3). Cite that the Act leaves details to rules.
Penalty
Intermediary intentionally or knowingly contravening (2): imprisonment up to one year, or fine up to ₹1 crore, or both
Section 69B(4), as substituted by Act 18 of 2023 w.e.f. 30-11-2023. The earlier text was imprisonment up to three years and fine.
Traffic data
Data identifying or purporting to identify any person, computer system, network or location to or from which communication is or may be transmitted
Includes origin, destination, route, time, data, size, duration, type of underlying service and any other information.
Fiduciary responsibility
Data Fiduciary stays responsible for processing by itself or by its Data Processor (DPDP Act, s 8(1))
An agreement to the contrary does not remove this responsibility.
Use of processors
Processor engaged for offering goods or services only under a valid contract (s 8(2))
Always mention the contract in answers on outsourcing analytics.
Quality of data
Ensure completeness, accuracy and consistency if data is used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (s 8(3))
Key for profiling and automated decisions.
Security and breach
Reasonable security safeguards (s 8(5)); intimate Board and each affected Data Principal of a breach (s 8(6))
Form and manner of intimation are as prescribed.
Erasure
Erase data when consent is withdrawn or purpose is no longer served, whichever is earlier, unless law requires retention (s 8(7))
Also cause the processor to erase data given to it.
Correction and erasure rights
Data Principal may seek correction, completion, updating and erasure (s 12)
Erasure is not required if retention is necessary for the specified purpose or legal compliance (s 12(3)).
Cross-border transfer
Central Government may restrict transfer to notified countries (s 16(1)); stricter Indian laws continue to apply (s 16(2))
Transfer is not banned by default under this section.
Section 43A, IT Act
Negligence in reasonable security practices for sensitive personal data + wrongful loss or gain = compensation
Applies to a body corporate, which includes a firm or sole proprietorship engaged in commercial or professional activity.

Quick revision

  • Section 43A applies to a body corporate handling sensitive personal data or information in a computer resource it owns, controls or operates.
  • Liability under Section 43A needs negligence in implementing and maintaining reasonable security practices, plus wrongful loss or wrongful gain to a person.
  • The remedy under Section 43A is damages by way of compensation to the affected person.
  • 'Body corporate' includes a company, firm, sole proprietorship or other association engaged in commercial or professional activities.
  • Reasonable security practices can come from an agreement, from any law, or, if neither exists, from what the Central Government prescribes.
  • Section 87(2)(ob) gives the Central Government the rule-making power for Section 43A matters.
  • Section 69B lets the Central Government authorise a government agency, by notification, to monitor and collect traffic data for cyber security.
  • Under Section 69B(2), the intermediary or person in charge must give technical assistance and facilities when called upon by the authorised agency.
  • Section 69B(4): an intermediary who intentionally or knowingly contravenes may face imprisonment up to one year or a fine up to one crore rupees, or both.
  • DPDP Act Section 8(1): the Data Fiduciary stays responsible for processing, even by a Data Processor and despite any contrary agreement.
  • DPDP Act Section 8(2): a Data Processor can be engaged only under a valid contract.
  • DPDP Act Section 8(5) and (6): take reasonable security safeguards, and on a breach inform the Board and each affected Data Principal in the prescribed form and manner.

Common mistakes

  • Treating big data and data analytics as the same thing. Fix: Say big data is the data (large, fast, varied) and analytics is the process of examining data. Analytics can be done on small data too.
  • Mixing up predictive and prescriptive analytics. Fix: Predictive says what is likely to happen. Prescriptive recommends the action to take. Remember: predict, then prescribe.
  • Treating section 43A as fully operating law without mentioning the DPDP Act. Fix: Say that section 44(2)(a) of the DPDP Act omits section 43A, and use 43A to explain the earlier compensation rule.
  • Writing that the IT Act does not apply outside India. Fix: Cite sections 1(2) and 75: it applies if the conduct involves a computer, system or network located in India.
  • Saying section 43A applies only to companies registered under the Companies Act. Fix: Quote Explanation (i): any company, and includes a firm, sole proprietorship or other association engaged in commercial or professional activities.
  • Applying section 43A to any personal data. Fix: Check the data is sensitive personal data or information as prescribed by the Central Government. Ordinary data falls outside this section.
  • Saying section 43A applies only to companies registered under the Companies Act. Fix: Quote the Explanation: any company, and also a firm, sole proprietorship or other association engaged in commercial or professional activities.
  • Listing the types of SPDI as if they are written in the Act. Fix: Write that the Act leaves SPDI to be prescribed by the Central Government, and that the list is in the SPDI Rules, 2011.
  • Writing that 69B allows interception and decryption of messages. Fix: Remember 69B covers traffic data for cyber security. Interception, monitoring and decryption of information is section 69.
  • Quoting seven years' imprisonment for 69B default. Fix: Section 69B(4): up to one year, or fine up to ₹1 crore, or both. It needs intentional or knowing contravention.

Exam tips

  • Learn the three analytics types with one business example each. Examiners often give a scenario and ask you to classify it.
  • For legal issue questions, write provision, analysis, conclusion in that order and keep each part short.
  • Quote the elements of Section 43A one by one and tick each against the facts.
  • Cite section numbers only for 43A, 69B and 70B, where you are sure. For other points, state the rule without a number.
  • End case answers with a practical compliance step such as a security policy, consent record or incident plan.
  • Write every answer as provision, analysis, conclusion, and tie each step to the facts.
  • Always mention both the IT Act, 2000 and the DPDP Act, 2023, and show how section 43A was omitted.
  • Remember the numbers: ₹5 crore for the adjudicating officer, and sections 1, 11, 17, 46 and 75.