Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Data Analytics and Law: CS Professional Chapter Guide

Data Analytics and Law covers the legal rules that govern how Indian entities collect, analyse and protect data. You study the IT Act, 2000 (Section 43A compensation, Section 69B traffic data monitoring, rule-making power in Section 87) and the DPDP Act, 2023 duties. In the exam, apply the provision to the facts and conclude.

What this chapter covers

This chapter in Elective 4.4, Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice, links the technology of data analytics to the law that controls it. You first learn what data analytics and big data are. Then you learn which Indian laws apply when a company collects, stores and analyses data.

The core is two statutes. The Information Technology Act, 2000 gives you Section 43A (compensation when a body corporate is negligent in protecting sensitive personal data) and Section 69B (government power to monitor and collect traffic data for cyber security). Section 87 tells you that the detail, such as reasonable security practices and the procedure for traffic data monitoring, sits in rules made by the Central Government. The Digital Personal Data Protection Act, 2023 adds the general obligations of a Data Fiduciary in Section 8.

This chapter feeds the rest of the paper. Cyber security topics use the same ideas of security safeguards and breach. AI topics raise the same privacy and ethics questions. Because the paper is case-based, you will be asked to read a short fact pattern, name the provision, test the facts against it and give a conclusion with a practical compliance step.

Questions from this chapter are usually fact-based, so you can score well if you know the exact wording of each provision and apply it step by step. Section 43A, Section 69B and Section 8 of the DPDP Act are short, so precise conditions are easy to learn and easy to lose marks on if you paraphrase loosely. The same ideas, such as security safeguards, breach and consent, also help you in other chapters of the paper, so the effort pays back more than once.

Data Analytics and Law: topics in the order to study them

  1. 1Introduction to Data Analytics and Big DataStart here because you need the vocabulary (data types, analytics, big data) before any law makes sense.
  2. 2Legal Framework for Data Analytics in IndiaThis gives you the map of statutes and rules, so each later section has a place to sit.
  3. 3Section 43A: Compensation for Failure to Protect DataIt is a clear, condition-based section, so it is the best first provision to master.
  4. 4Reasonable Security Practices and Sensitive Personal Data RulesSection 43A leaves 'reasonable security practices' and 'sensitive personal data' to be prescribed, so read the rules right after the section.
  5. 5Section 69B: Monitoring and Collection of Traffic DataIt is a government power with duties on intermediaries, so study it once the private-sector duty under Section 43A is clear.
  6. 6Privacy, Data Protection and Ethical Issues in AnalyticsKeep this last: it pulls everything together with DPDP Act Section 8 duties and ethics, and it suits long case answers.

How to prepare Data Analytics and Law

Treat this chapter as a set of short provisions plus a framework. Learn the wording first, then practise applying it to facts.

  1. Read the introduction topic once and write a one-page glossary of terms such as big data, analytics, personal data and traffic data.
  2. Learn Section 43A by its elements: body corporate, sensitive personal data or information, a computer resource it owns, controls or operates, negligence in reasonable security practices, and wrongful loss or wrongful gain. Remember the remedy is damages by way of compensation.
  3. Note the three Explanation definitions in Section 43A and who prescribes what. Then link them to Section 87(2)(ob), which empowers the Central Government to make rules on these matters.
  4. Learn Section 69B in parts: the authorisation by notification, the technical assistance duty of the intermediary or person in charge, the prescribed procedure and safeguards, and the punishment for an intermediary who intentionally or knowingly contravenes. Know the definition of traffic data.
  5. Read DPDP Act Section 8 sub-section by sub-section. Make a checklist: responsibility for processors, valid contract, accuracy, technical and organisational measures, security safeguards, breach intimation, erasure, contact information, grievance redress.
  6. Practise three or four short case studies. For each, write: the provision, the facts that meet or miss its conditions, the conclusion, and one compliance step the company should take.
  7. In the last days, rewrite each provision from memory and compare it with the text, checking every condition.

Common mistakes in Data Analytics and Law

  • Saying Section 43A applies to any organisation or any data.

    Fix: Check each element: body corporate, sensitive personal data or information, own, control or operate the computer resource, negligence, and wrongful loss or gain.

  • Claiming compensation under Section 43A without proving negligence and loss.

    Fix: State that liability needs negligence in reasonable security practices and resulting wrongful loss or gain. Then test the facts against both.

  • Defining 'reasonable security practices' from general knowledge only.

    Fix: Use the Explanation: practices to protect from unauthorised access, damage, use, modification, disclosure or impairment, as set by agreement, by law, or as prescribed by the Central Government.

  • Mixing up Section 69B with interception or blocking powers.

    Fix: Tie Section 69B to traffic data and cyber security. Remember traffic data covers origin, destination, route, time, size, duration and type of service, not the content as such.

  • Thinking a Data Fiduciary is free of blame when a Data Processor causes the breach.

    Fix: Quote DPDP Act Section 8(1): the Data Fiduciary is responsible irrespective of any agreement to the contrary, including for processing by its Data Processor.

  • Writing a theory essay on privacy without applying it to the facts.

    Fix: Follow provision, analysis, conclusion. Add a practical step such as a processor contract, breach procedure, erasure policy or grievance mechanism.

Last-day revision: Data Analytics and Law

  • Section 43A applies to a body corporate handling sensitive personal data or information in a computer resource it owns, controls or operates.
  • Liability under Section 43A needs negligence in implementing and maintaining reasonable security practices, plus wrongful loss or wrongful gain to a person.
  • The remedy under Section 43A is damages by way of compensation to the affected person.
  • 'Body corporate' includes a company, firm, sole proprietorship or other association engaged in commercial or professional activities.
  • Reasonable security practices can come from an agreement, from any law, or, if neither exists, from what the Central Government prescribes.
  • Section 87(2)(ob) gives the Central Government the rule-making power for Section 43A matters.
  • Section 69B lets the Central Government authorise a government agency, by notification, to monitor and collect traffic data for cyber security.
  • Under Section 69B(2), the intermediary or person in charge must give technical assistance and facilities when called upon by the authorised agency.
  • Section 69B(4): an intermediary who intentionally or knowingly contravenes may face imprisonment up to one year or a fine up to one crore rupees, or both.
  • DPDP Act Section 8(1): the Data Fiduciary stays responsible for processing, even by a Data Processor and despite any contrary agreement.
  • DPDP Act Section 8(2): a Data Processor can be engaged only under a valid contract.
  • DPDP Act Section 8(5) and (6): take reasonable security safeguards, and on a breach inform the Board and each affected Data Principal in the prescribed form and manner.

Data Analytics and Law practice questions

Data Analytics and Law in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Data Analytics and Law: frequently asked questions

What is Section 43A of the IT Act, 2000 in simple words?

It makes a body corporate pay compensation when it is negligent in keeping reasonable security practices for sensitive personal data in a computer resource it owns, controls or operates, and this causes wrongful loss or wrongful gain to someone. You must show negligence and the resulting loss or gain.

Who makes the rules on reasonable security practices and sensitive personal data?

Where there is no agreement or other law, the Central Government prescribes them in consultation with professional bodies or associations. Section 87(2)(ob) gives the power to make rules on these matters.

What does Section 69B deal with?

It lets the Central Government authorise a government agency to monitor and collect traffic data or information in any computer resource to enhance cyber security. Intermediaries must give technical assistance, and the procedure and safeguards are prescribed by rules.

How does the DPDP Act, 2023 connect to this chapter?

Section 8 sets the general obligations of a Data Fiduciary, such as security safeguards, breach intimation, erasure and grievance redress. In a case answer, you can use it alongside the IT Act provisions to advise on compliance.

How should I write answers from this chapter?

State the provision, apply its conditions to the facts one by one, and give a clear conclusion. Add one practical compliance point, such as a contract with a processor or a breach response plan.