Skip to content

Corporate and Economic Laws · Laws and Regulations related to Cyber Security and Data Privacy

Data Protection and Privacy Framework in India for CMA Final

Updated 11 October 2026 · Fact-checked

India's data protection framework protects personal data through the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. Section 43A of the IT Act made a body corporate pay compensation for negligent handling of sensitive data. Section 44 of the DPDP Act omits section 43A. To solve questions, identify the law, the party and the duty breached.

Understand Data Protection and Privacy Framework

Personal data is information about an identifiable person. Some of it is more harmful if leaked, such as financial or health details. The IT Act called this sensitive personal data or information, and left the Central Government to prescribe what it covers.

Section 43A of the IT Act, 2000 put a duty on a body corporate. The term includes any company, and also a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. If such a body possessed, dealt with or handled sensitive personal data in a computer resource it owns, controls or operates, and was negligent in implementing and maintaining reasonable security practices and procedures, and this caused wrongful loss or wrongful gain to any person, it was liable to pay damages by way of compensation to the person affected.

Reasonable security practices and procedures means practices designed to protect the information from unauthorised access, damage, use, modification, disclosure or impairment. They are those specified in an agreement between the parties, or in any law for the time being in force. If there is neither, they are those prescribed by the Central Government in consultation with professional bodies or associations.

The regime has since changed. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 says that section 43A shall be omitted from the IT Act. Section 44(2)(c) also omits clause (ob) of section 87(2), the rule-making power for reasonable security practices and sensitive data under section 43A. So the DPDP Act is the main personal data law going forward. Read the section 43A rules as the earlier position and as the base for old-style questions.

The IT Act keeps other security provisions. Section 70 lets the government declare a computer resource affecting Critical Information Infrastructure a protected system. Section 70B makes CERT-In the national agency for cyber incident response. Read this page together with the IT Act topics.

Key rules to remember

Section 43A liability test (IT Act)
Body corporate + sensitive personal data or information in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or wrongful gain to a person ⇒ damages by way of compensation
All elements must be present. Without negligence or without wrongful loss or gain, section 43A is not attracted.
Body corporate (section 43A Explanation)
Any company, including a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
The meaning is wider than a company under the Companies Act.
Reasonable security practices (section 43A Explanation)
Practices to protect against unauthorised access, damage, use, modification, disclosure or impairment, as set by (1) agreement, or (2) any law in force, or (3) if neither, the Central Government's prescription
Agreement or law comes first. The Central Government prescribes only in their absence.
Sensitive personal data or information
Such personal information as may be prescribed by the Central Government in consultation with professional bodies or associations
The Act does not list the items. The list was left to rules.
Present status of section 43A
DPDP Act, 2023, section 44(2)(a): section 43A shall be omitted; section 44(2)(c): section 87(2) clause (ob) omitted
Section 44(2)(c) removes the rule-making power linked to section 43A.
CERT-In directions (section 70B(6) and (7))
Failure to give information called for or comply with a direction ⇒ imprisonment up to 1 year or fine up to ₹1 crore or both
The fine limit was raised from one lakh by Act 18 of 2023, w.e.f. 30-11-2023.
Protected system (section 70)
Unauthorised access or attempt to a protected system ⇒ imprisonment up to 10 years and fine
The appropriate Government declares the system by notification.

How to solve Data Protection and Privacy Framework questions

Use this method for any case or theory question on data protection and privacy.

  1. 1Identify who holds the data and whether it is a body corporate as defined in the Explanation to section 43A.
  2. 2Classify the data: ordinary personal data, or sensitive personal data or information as prescribed.
  3. 3Find the duty: what reasonable security practices applied, under an agreement, a law, or the Central Government's prescription?
  4. 4Check for negligence and for wrongful loss or wrongful gain to a person.
  5. 5State the consequence: compensation under old section 43A, or the position after section 44 of the DPDP Act.
  6. 6Mention linked provisions if relevant, such as section 70 for protected systems or section 70B for CERT-In directions.
  7. 7Conclude with a clear one-line answer.

Quickest way: Four-check test for section 43A

When to use it: Use for MCQs and short case questions asking whether a body corporate is liable.

  1. Body corporate? Includes firms and sole proprietors in commerce or profession.
  2. Sensitive data in its own computer resource?
  3. Negligent in security practices?
  4. Wrongful loss or gain caused? If all four are yes, compensation is payable. Then add that section 43A is now omitted by the DPDP Act.

Common mistakes in Data Protection and Privacy Framework

  • Saying section 43A still applies without qualification.

    Older notes and books still show it as in force.

    Fix: State that section 44(2)(a) of the DPDP Act, 2023 omits section 43A. Use it as the earlier position.

  • Treating body corporate as only a company registered under the Companies Act.

    Students read the term in its everyday sense.

    Fix: Quote the Explanation: any company, including a firm, sole proprietorship or other association engaged in commercial or professional activities.

  • Applying liability without negligence or without loss or gain.

    Students focus on the data breach alone.

    Fix: Check each element. Negligence and wrongful loss or wrongful gain are both required.

  • Listing the sensitive data items as if the Act names them.

    Students memorise lists from rules.

    Fix: Say the Act leaves it to the Central Government to prescribe the information.

  • Mixing up section 70 and section 70B.

    Both deal with cyber security and appear close together.

    Fix: Section 70 is protected systems and Critical Information Infrastructure. Section 70B is CERT-In as national incident response agency.

  • Quoting the old one lakh fine under section 70B.

    Older material has not been updated.

    Fix: Write that the fine may extend to one crore rupees.

Worked examples

Example 1

Shreeji Traders, a partnership firm in Surat, stores customers' sensitive personal data on its own server. It uses no security measures that its agreement with customers required. A hacker steals the data and a customer suffers wrongful loss. Under the IT Act, 2000 as originally framed, is the firm liable?

Show the solution
  1. Body corporate: the Explanation to section 43A includes a firm engaged in commercial activities, so Shreeji Traders qualifies.
  2. The data is held in a computer resource the firm owns or controls, and it is sensitive personal data.
  3. Reasonable security practices can be specified in an agreement between the parties. The firm ignored the agreed measures, so it was negligent.
  4. The customer suffered wrongful loss as a result.
  5. All elements of section 43A are met.

Answer: Yes. The firm was liable to pay damages by way of compensation to the affected customer under section 43A. That section has since been omitted by section 44(2)(a) of the DPDP Act, 2023, so a present-day answer must be based on the DPDP Act.

Example 2

State what the DPDP Act, 2023 did to section 43A of the IT Act, 2000, and the related rule-making power.

Show the solution
  1. Section 44 of the DPDP Act deals with amendments to certain Acts.
  2. Section 44(2)(a) provides that section 43A of the IT Act shall be omitted.
  3. Section 44(2)(c) omits clause (ob) of section 87(2), which let the Central Government make rules on reasonable security practices and sensitive personal data under section 43A.
  4. Section 44(2)(b) also amends section 81 of the IT Act to refer to the DPDP Act.

Answer: The DPDP Act, 2023 removed the compensation provision, section 43A, from the IT Act. It also removed the related rule-making clause (ob) in section 87(2).

Exam tips

  • Write section 43A elements as a list. Examiners reward each element applied to the facts.
  • Always add the current position: section 43A is omitted by section 44(2)(a) of the DPDP Act, 2023.
  • In MCQs, watch for the body corporate definition and the three-level order for reasonable security practices: agreement, law, then Central Government.
  • Remember the numbers: protected system access up to ten years; CERT-In default up to one year or fine up to ₹1 crore.
  • For case questions, name the data holder, the data type, the lapse and the loss before concluding.

Practice questions from Laws and Regulations related to Cyber Security and Data Privacy

Data Protection and Privacy Framework in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Data Protection and Privacy Framework: frequently asked questions

Is section 43A of the IT Act still in force?

No. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 provides that section 43A shall be omitted. Study it for background and for questions framed on the earlier law.

What is a body corporate under section 43A?

It means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. This is wider than a company under the Companies Act.

What are reasonable security practices and procedures?

They are practices designed to protect information from unauthorised access, damage, use, modification, disclosure or impairment. They are as specified in an agreement or in any law, and failing both, as prescribed by the Central Government.

Who defines sensitive personal data under the IT Act?

The Act says it means such personal information as the Central Government prescribes in consultation with professional bodies or associations. The Act itself does not list the items.