CS Professional · Environmental, Social and Governance (ESG) - Principles and Practice
Data Governance: formula sheet
Key formulas
- Core principles of data governance
- Accountability + Transparency + Data quality + Integrity + Security + Privacy + Lawful use
- Use these as a checklist when asked for principles. Explain each in one line.
- Section 43A liability test
- Body corporate + sensitive personal data in its computer resource + negligence in reasonable security practices + wrongful loss or gain = compensation
- All elements must be present. The remedy is damages by way of compensation to the person affected.
- Reasonable security practices (Section 43A Explanation)
- As per agreement between parties, else as per law in force, else as prescribed by the Central Government
- This is the order of reference for what counts as reasonable.
- Section 70B(7) penalty
- Failure to give information or comply with CERT-In direction: imprisonment up to 1 year or fine up to ₹1 crore, or both
- Applies to service providers, intermediaries, data centres, body corporate and any other person. Cognizance only on complaint by an authorised officer of CERT-In (Section 70B(8)).
- Section 69B(4) penalty
- Intermediary intentionally or knowingly contravening sub-section (2): imprisonment up to 1 year or fine up to ₹1 crore, or both
- Sub-section (2) requires the intermediary to give technical assistance to the authorised agency.
- Governance structure
- Board → Committee/Senior officer → Data owners → Data custodians → Users
- Oversight at the top, accountability in business functions, protection by custodians.
- Computer resource
- Computer resource = computer + computer system + computer network + data + computer data base + software
- Section 2(1)(k). It is the widest term, so use it when a question asks what the Act's powers can reach.
- Data
- Data = representation of information, knowledge, facts, concepts or instructions, formalised, and intended to be / being / already processed in a computer system or network
- Section 2(1)(o). It can be in any form, including printouts, storage media or computer memory.
- Electronic record
- Electronic record = data, record or generated data, image or sound, stored, received or sent in electronic form or micro film or computer generated micro fiche
- Section 2(1)(t). Electronic form is defined in clause (r).
- Intermediary
- Intermediary = any person who, on behalf of another, receives, stores or transmits a particular electronic record or provides any service with respect to it
- Section 2(1)(w). It includes telecom, network, internet and web-hosting service providers, search engines, online payment sites, auction sites, marketplaces and cyber cafes. It is judged record by record.
- Cyber security
- Cyber security = protecting information, equipment, devices, computer, computer resource, communication device and stored information from unauthorised access, use, disclosure, disruption, modification or destruction
- Section 2(1)(nb). Note the six harms listed.
- Originator and addressee
- Originator sends or causes to be sent; addressee is intended to receive; neither includes an intermediary
- Section 2(1)(za) and (b).
- Section 69B intermediary penalty
- Intentional or knowing contravention of s 69B(2): imprisonment up to one year, or fine up to ₹1 crore, or both
- As amended by Act 18 of 2023, effective 30-11-2023. Earlier text had up to three years and a fine.
- Who may access
- Controller OR any person authorised by him
- Section 29(1). The authorisation must come from the Controller.
- Trigger condition
- Reasonable cause to suspect a contravention of the provisions of Chapter VI
- Suspicion must be reasonable. Wording since 27-10-2009 is "this Chapter", replacing "this Act, rules and regulations made thereunder".
- What can be accessed
- Any computer system, apparatus, data or other material connected with the system
- Purpose: searching, or causing a search, to obtain information or data contained in or available to the system.
- Duty to assist
- Controller may, by order, direct any person in charge of or concerned with the operation of the system to give reasonable technical and other assistance
- Section 29(2). Assistance must be reasonable and considered necessary by the Controller.
- Relation to section 69
- Section 29(1) is without prejudice to section 69(1)
- Section 69 is a separate power for interception, monitoring and decryption on grounds such as security of the State and investigation of offences.
- Section 84A power
- Central Government MAY prescribe modes or methods for encryption
- Enabling power. The purpose is secure use of the electronic medium and promotion of e-governance and e-commerce.
- Rule-making link
- Section 87(2)(zh): rules on modes or methods for encryption under section 84A
- Rules are made by notification in the Official Gazette and the Electronic Gazette (section 87(1)).
- Parliamentary oversight
- Rules laid before each House for 30 days (section 87(3))
- The period may run over one session or two or more successive sessions. Modification or annulment does not affect things already done.
- Section 43A trigger
- Body corporate + sensitive personal data in own computer resource + negligence in reasonable security practices + wrongful loss or gain = compensation
- All elements must be present. Reasonable security practices may be set by agreement, by law, or by rules if neither exists.
- Who may authorise
- Central Government, by notification in the Official Gazette → authorises any agency of the Government
- Section 69B(1). The agency is authorised by notification, not by a private request.
- Purpose
- Enhance cyber security + identify, analyse and prevent intrusion or spread of computer contaminant
- The power is limited to cyber security. Do not add sovereignty or public order grounds; those belong to sections 69 and 69A.
- Subject matter
- Traffic data or information generated, transmitted, received or stored in any computer resource
- Traffic data covers origin, destination, route, time, data, size, duration, type of underlying service and other information.
- Duty of intermediary
- On being called upon: provide technical assistance + extend all facilities for online access
- Section 69B(2). Applies to the intermediary or any person in charge of the computer resource.
- Procedure and safeguards
- Such as may be prescribed
- Section 69B(3); rule-making power in section 87(2)(za).
- Penalty
- Intermediary who intentionally or knowingly contravenes s.69B(2): imprisonment up to 1 year, or fine up to ₹1 crore, or both
- Section 69B(4). Substituted by Act 18 of 2023 with effect from 30-11-2023.
- IT Act s. 43A liability test
- Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or gain = compensation to the affected person
- All elements must be present. The remedy is damages by way of compensation.
- Reasonable security practices (s. 43A Explanation)
- Practices to protect against unauthorised access, damage, use, modification, disclosure or impairment, as set by agreement, by law, or else as prescribed by the Central Government
- This is the order of reference: agreement or law first, then the prescribed standard.
- Significant Data Fiduciary duties (DPDP s. 10(2))
- Data Protection Officer (based in India, responsible to the Board, grievance contact) + independent data auditor + periodic DPIA + periodic audit + other prescribed measures
- Applies only after the Central Government notifies the fiduciary or class under s. 10(1).
- CERT-In powers (IT Act s. 70B(6) and (7))
- May call for information and give directions; failure to comply: imprisonment up to one year, or fine up to ₹1 crore, or both
- Court takes cognizance only on a complaint by an authorised officer of the agency (s. 70B(8)).
- Traffic data monitoring (IT Act s. 69B)
- Central Government notifies an agency; intermediary must give technical assistance; intentional or knowing contravention: up to one year imprisonment or fine up to ₹1 crore, or both
- The penalty applies to an intermediary. Procedure and safeguards are as prescribed.
Quick revision
- Data governance means policies, roles and controls for how data is collected, stored, used, secured and shared.
- The IT Act, 2000 leaves many procedural details to rules made by the Central Government under section 87.
- Section 29: the Controller or a person he authorises may access computer systems and data if there is reasonable cause to suspect a contravention of the provisions of that Chapter.
- Section 29(2): the Controller may by order direct the person in charge to give reasonable technical and other assistance.
- Section 84A: the Central Government may prescribe modes or methods for encryption.
- Purpose stated in section 84A: secure use of the electronic medium and promotion of e-governance and e-commerce.
- Section 69B: the Central Government authorises a Government agency by notification to monitor and collect traffic data to enhance cyber security.
- Section 69B(2): the intermediary or person in charge must provide technical assistance and facilities for online access.
- Section 69B(3): procedure and safeguards are as prescribed.
- Section 69B(4): an intermediary who intentionally or knowingly contravenes sub-section (2) faces imprisonment up to one year, a fine up to one crore rupees, or both.
- Traffic data covers data identifying a person, system, network or location, including origin, destination, route, time, size, duration or type of service.
- Case answers: state the provision, apply the facts, conclude, then add practical compliance points.
Common mistakes
- Treating data governance as only IT security. Fix: Say it covers ownership, quality, privacy, lifecycle and accountability, with security as one part. The board owns oversight.
- Applying Section 43A to any company holding any data. Fix: State all conditions: sensitive personal data, in a computer resource the body corporate owns, controls or operates, negligence in reasonable security practices, and wrongful loss or gain.
- Treating computer as only a desktop or laptop. Fix: Quote the definition: any electronic, magnetic, optical or other high-speed data processing device or system, including connected input, output, storage, software or communication facilities.
- Confusing computer resource with computer. Fix: Remember that computer resource also covers computer system, network, data, data base and software, so it is wider.
- Saying any police officer or any government officer can use section 29. Fix: Section 29 names only the Controller or a person authorised by him. Link agencies and interception to section 69.
- Writing that access needs proof of a contravention. Fix: The test is reasonable cause to suspect. Proof is not required before access. Suspicion must still have a reasonable basis.
- Writing that section 84A makes encryption compulsory for every company. Fix: Use the word "may". The section only empowers the Central Government to prescribe modes or methods. Any duty arises from rules or other laws.
- Stating specific algorithms or key lengths as being in section 84A. Fix: Say the section names none. Details come only from what the Government prescribes.
- Mixing section 69B with section 69 (interception, monitoring, decryption). Fix: Section 69B is for traffic data and cyber security. Section 69 covers interception, monitoring or decryption of information for grounds like sovereignty, public order or investigation, by recorded written order.
- Quoting the old penalty of three years and fine. Fix: The current text reads imprisonment up to one year, or fine up to one crore rupees, or both, from 30-11-2023.
Exam tips
- Write a clear definition first. Examiners reward a crisp opening before the detail.
- In case questions, tick off each condition of Section 43A against the facts, then conclude.
- Use the four-part framework and the principles list as headings in your answer so marks are easy to find.
- Quote the penalty figures only for Sections 70B(7) and 69B(4), and do not attach them to Section 43A.
- End with the ESG link and one practical drafting or compliance point, such as a board-approved data policy.
- Learn the definitions of computer resource, data, electronic record and intermediary almost word for word. Examiners reward accuracy of elements.
- In case-based questions, name the party first (originator, addressee or intermediary) and then state the duty that follows.
- Quote section 69B(4) in its current form: up to one year, or fine up to ₹1 crore, or both.