CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice
Data Analytics and Law: formula sheet
Key formulas
- Big data 'Vs'
- Volume + Velocity + Variety (+ Veracity)
- Use these to define big data. Veracity is often added as a fourth V; say so if you include it.
- Three types of analytics
- Descriptive = what happened; Predictive = what may happen; Prescriptive = what to do
- Learn them in this order. Each answers a different question.
- Section 43A liability test
- Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or wrongful gain = compensation to the person affected
- All elements must be present. The remedy is damages by way of compensation.
- Reasonable security practices (Section 43A, Explanation)
- Practices set by agreement between the parties, or by law in force; if neither exists, as prescribed by the Central Government
- Name this order of reference when the question asks what 'reasonable' means.
- Section 69B(4) penalty
- Intermediary intentionally or knowingly contravening 69B(2): imprisonment up to one year, or fine up to ₹1 crore, or both
- Applies to failure to give technical assistance to the authorised agency for traffic data.
- Section 70B(7) penalty
- Failure to provide information or comply with CERT-In direction: imprisonment up to one year, or fine up to ₹1 crore, or both
- Applies to service providers, intermediaries, data centres, body corporate and any other person. Courts take cognizance only on a complaint by an authorised officer of CERT-In.
- Territorial reach of the IT Act
- Section 1(2) and section 75: applies to the whole of India and to contraventions outside India if a computer, system or network located in India is involved
- Applies irrespective of the nationality of the person under section 75(1).
- Old section 43A test
- Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or gain = compensation
- Section 44(2)(a) of the DPDP Act omits section 43A. Use it to explain the earlier position.
- Adjudication limit
- Section 46(1A): adjudicating officer decides claims up to ₹5 crore; above ₹5 crore, the competent court
- Adjudicating officer is not below the rank of Director to the Government of India or equivalent State officer.
- Right to access
- Section 11(1) DPDP: summary of data and processing + identities of Fiduciaries and Processors with whom data is shared + other prescribed information
- Section 11(2) exempts sharing with an authorised Fiduciary on a written request for prevention, detection, investigation or prosecution of offences or cyber incidents.
- Exemptions
- Section 17(1): Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 do not apply in listed cases; section 17(2): the Act does not apply to notified State instrumentalities or qualifying research, archiving and statistical use
- Section 17(3) lets the Central Government exempt notified Fiduciaries, including startups, from certain provisions.
- Section 43A liability
- Body corporate + sensitive personal data in computer resource it owns/controls/operates + negligence in reasonable security practices + wrongful loss or gain caused = liable to pay damages by way of compensation
- All elements must be present. Remedy is compensation to the affected person.
- Body corporate (Explanation (i))
- Any company, and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
- Wider than a company under the Companies Act.
- Reasonable security practices (Explanation (ii))
- Agreement between the parties, or law in force; if neither, as prescribed by the Central Government
- Order of reference: agreement or law first, then prescribed rules.
- Sensitive personal data or information (Explanation (iii))
- Such personal information as may be prescribed by the Central Government in consultation with professional bodies or associations
- Rule-making power is in section 87(2)(ob).
- Residuary penalty (section 45)
- Penalty up to ₹1,00,000 plus compensation up to ₹10,00,000 (intermediary, company or body corporate) or ₹1,00,000 (any other person)
- Applies to contravention of rules, regulations, directions or orders where no penalty is separately provided.
- Elements of liability under section 43A
- Body corporate + SPDI in own/controlled/operated computer resource + negligence in reasonable security practices + wrongful loss or wrongful gain ⇒ compensation
- All elements must be present. No loss or gain to anyone means no claim under this section.
- Order of sources of reasonable security practices
- Agreement between the parties → any law in force → practices prescribed by the Central Government
- The prescribed practices apply only in the absence of an agreement or a law.
- Meaning of body corporate (Explanation (i))
- Any company + firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
- Wider than a company under the Companies Act.
- Meaning of SPDI (Explanation (iii))
- Such personal information as may be prescribed by the Central Government
- The list is in the SPDI Rules, 2011, made under section 87(2)(ob). Say that it is prescribed, not listed in the Act.
- Rule-making power
- Section 87(2)(ob): reasonable security practices and procedures and SPDI under section 43A
- This is the statutory source of the SPDI Rules.
- Who acts and how
- Central Government → notification in Official Gazette → authorises any agency of the Government
- Section 69B(1). State Governments are not named in this section, unlike section 69.
- Purpose
- Enhance cyber security + identify, analyse and prevent intrusion or spread of computer contaminant
- The only stated purpose. Do not add grounds like public order or sovereignty, which belong to section 69.
- Scope of monitoring
- Traffic data or information generated, transmitted, received or stored in any computer resource
- Section 69B(1).
- Duty of intermediary
- Provide technical assistance and extend all facilities to enable online access to the computer resource
- Section 69B(2). Applies to the intermediary or any person in charge of the computer resource.
- Procedure
- Procedure and safeguards as may be prescribed
- Section 69B(3). Cite that the Act leaves details to rules.
- Penalty
- Intermediary intentionally or knowingly contravening (2): imprisonment up to one year, or fine up to ₹1 crore, or both
- Section 69B(4), as substituted by Act 18 of 2023 w.e.f. 30-11-2023. The earlier text was imprisonment up to three years and fine.
- Traffic data
- Data identifying or purporting to identify any person, computer system, network or location to or from which communication is or may be transmitted
- Includes origin, destination, route, time, data, size, duration, type of underlying service and any other information.
- Fiduciary responsibility
- Data Fiduciary stays responsible for processing by itself or by its Data Processor (DPDP Act, s 8(1))
- An agreement to the contrary does not remove this responsibility.
- Use of processors
- Processor engaged for offering goods or services only under a valid contract (s 8(2))
- Always mention the contract in answers on outsourcing analytics.
- Quality of data
- Ensure completeness, accuracy and consistency if data is used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (s 8(3))
- Key for profiling and automated decisions.
- Security and breach
- Reasonable security safeguards (s 8(5)); intimate Board and each affected Data Principal of a breach (s 8(6))
- Form and manner of intimation are as prescribed.
- Erasure
- Erase data when consent is withdrawn or purpose is no longer served, whichever is earlier, unless law requires retention (s 8(7))
- Also cause the processor to erase data given to it.
- Correction and erasure rights
- Data Principal may seek correction, completion, updating and erasure (s 12)
- Erasure is not required if retention is necessary for the specified purpose or legal compliance (s 12(3)).
- Cross-border transfer
- Central Government may restrict transfer to notified countries (s 16(1)); stricter Indian laws continue to apply (s 16(2))
- Transfer is not banned by default under this section.
- Section 43A, IT Act
- Negligence in reasonable security practices for sensitive personal data + wrongful loss or gain = compensation
- Applies to a body corporate, which includes a firm or sole proprietorship engaged in commercial or professional activity.
Quick revision
- Section 43A applies to a body corporate handling sensitive personal data or information in a computer resource it owns, controls or operates.
- Liability under Section 43A needs negligence in implementing and maintaining reasonable security practices, plus wrongful loss or wrongful gain to a person.
- The remedy under Section 43A is damages by way of compensation to the affected person.
- 'Body corporate' includes a company, firm, sole proprietorship or other association engaged in commercial or professional activities.
- Reasonable security practices can come from an agreement, from any law, or, if neither exists, from what the Central Government prescribes.
- Section 87(2)(ob) gives the Central Government the rule-making power for Section 43A matters.
- Section 69B lets the Central Government authorise a government agency, by notification, to monitor and collect traffic data for cyber security.
- Under Section 69B(2), the intermediary or person in charge must give technical assistance and facilities when called upon by the authorised agency.
- Section 69B(4): an intermediary who intentionally or knowingly contravenes may face imprisonment up to one year or a fine up to one crore rupees, or both.
- DPDP Act Section 8(1): the Data Fiduciary stays responsible for processing, even by a Data Processor and despite any contrary agreement.
- DPDP Act Section 8(2): a Data Processor can be engaged only under a valid contract.
- DPDP Act Section 8(5) and (6): take reasonable security safeguards, and on a breach inform the Board and each affected Data Principal in the prescribed form and manner.
Common mistakes
- Treating big data and data analytics as the same thing. Fix: Say big data is the data (large, fast, varied) and analytics is the process of examining data. Analytics can be done on small data too.
- Mixing up predictive and prescriptive analytics. Fix: Predictive says what is likely to happen. Prescriptive recommends the action to take. Remember: predict, then prescribe.
- Treating section 43A as fully operating law without mentioning the DPDP Act. Fix: Say that section 44(2)(a) of the DPDP Act omits section 43A, and use 43A to explain the earlier compensation rule.
- Writing that the IT Act does not apply outside India. Fix: Cite sections 1(2) and 75: it applies if the conduct involves a computer, system or network located in India.
- Saying section 43A applies only to companies registered under the Companies Act. Fix: Quote Explanation (i): any company, and includes a firm, sole proprietorship or other association engaged in commercial or professional activities.
- Applying section 43A to any personal data. Fix: Check the data is sensitive personal data or information as prescribed by the Central Government. Ordinary data falls outside this section.
- Saying section 43A applies only to companies registered under the Companies Act. Fix: Quote the Explanation: any company, and also a firm, sole proprietorship or other association engaged in commercial or professional activities.
- Listing the types of SPDI as if they are written in the Act. Fix: Write that the Act leaves SPDI to be prescribed by the Central Government, and that the list is in the SPDI Rules, 2011.
- Writing that 69B allows interception and decryption of messages. Fix: Remember 69B covers traffic data for cyber security. Interception, monitoring and decryption of information is section 69.
- Quoting seven years' imprisonment for 69B default. Fix: Section 69B(4): up to one year, or fine up to ₹1 crore, or both. It needs intentional or knowing contravention.
Exam tips
- Learn the three analytics types with one business example each. Examiners often give a scenario and ask you to classify it.
- For legal issue questions, write provision, analysis, conclusion in that order and keep each part short.
- Quote the elements of Section 43A one by one and tick each against the facts.
- Cite section numbers only for 43A, 69B and 70B, where you are sure. For other points, state the rule without a number.
- End case answers with a practical compliance step such as a security policy, consent record or incident plan.
- Write every answer as provision, analysis, conclusion, and tie each step to the facts.
- Always mention both the IT Act, 2000 and the DPDP Act, 2023, and show how section 43A was omitted.
- Remember the numbers: ₹5 crore for the adjudicating officer, and sections 1, 11, 17, 46 and 75.