Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law
Introduction to Data Analytics and Big Data
Updated 11 October 2026 · Fact-checked
Data analytics is the process of examining data to find patterns and support decisions. Big data means data so large, fast and varied that ordinary tools cannot handle it. Analytics is descriptive, predictive or prescriptive. In the exam, define the term, apply it to the facts, then state the legal issues, such as Section 43A.
Understand Introduction to Data Analytics and Big Data
Data analytics is the practice of collecting, cleaning and examining data to find patterns, draw conclusions and support decisions. A bank that studies customer transactions to spot fraud is doing data analytics.
Big data is data that is too large, too fast-changing or too varied for traditional tools to store and process. It is usually described by the 'Vs': volume (how much), velocity (how fast it arrives), variety (structured tables, text, images, logs) and often veracity (how reliable it is). Sources include payment apps, e-commerce sites, sensors, social media and CCTV.
There are three main types of analytics. Descriptive analytics tells you what happened, for example monthly sales by region. Predictive analytics estimates what is likely to happen, for example which borrowers may default. Prescriptive analytics recommends what to do, for example the best loan limit or pricing for each customer. Each type builds on the one before it.
Organisations use analytics for credit scoring, fraud detection, targeted marketing, supply chain planning, compliance monitoring and risk management. Companies also use it for board reporting and for tracking regulatory filings.
The legal issues arise because analytics often runs on personal data. Key concerns are security of sensitive personal data, consent and purpose of use, profiling and bias, ownership of data, and cross-border transfer. Under the Information Technology Act, 2000, Section 43A makes a body corporate liable to pay compensation if it is negligent in keeping reasonable security practices for sensitive personal data and this causes wrongful loss or wrongful gain to any person. Sections 69B and 70B add duties to give technical assistance for traffic data monitoring and to comply with CERT-In's information requests and directions.
Key rules to remember
- Big data 'Vs'
- Volume + Velocity + Variety (+ Veracity)
- Use these to define big data. Veracity is often added as a fourth V; say so if you include it.
- Three types of analytics
- Descriptive = what happened; Predictive = what may happen; Prescriptive = what to do
- Learn them in this order. Each answers a different question.
- Section 43A liability test
- Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or wrongful gain = compensation to the person affected
- All elements must be present. The remedy is damages by way of compensation.
- Reasonable security practices (Section 43A, Explanation)
- Practices set by agreement between the parties, or by law in force; if neither exists, as prescribed by the Central Government
- Name this order of reference when the question asks what 'reasonable' means.
- Section 69B(4) penalty
- Intermediary intentionally or knowingly contravening 69B(2): imprisonment up to one year, or fine up to ₹1 crore, or both
- Applies to failure to give technical assistance to the authorised agency for traffic data.
- Section 70B(7) penalty
- Failure to provide information or comply with CERT-In direction: imprisonment up to one year, or fine up to ₹1 crore, or both
- Applies to service providers, intermediaries, data centres, body corporate and any other person. Courts take cognizance only on a complaint by an authorised officer of CERT-In.
How to solve Introduction to Data Analytics and Big Data questions
Use this method for any theory or case question on data analytics and big data. It gives you the provision, analysis and conclusion that examiners look for.
- 1Read the question and mark the keywords: type of analytics, kind of data, who holds it, what went wrong.
- 2Define the concept in one or two lines: data analytics, big data, or the specific type asked.
- 3Classify the facts: is the activity descriptive, predictive or prescriptive? Is the data personal or sensitive?
- 4Identify the legal issue: security failure, misuse of data, monitoring request, or incident reporting.
- 5State the rule in plain words with the section number only where you are sure: 43A, 69B or 70B.
- 6Apply the rule to the facts element by element. Note any element that is missing.
- 7Conclude clearly: liable or not, and what remedy or compliance step follows.
- 8Add one practical point such as a data security policy, consent record, vendor contract or incident response plan.
Quickest way: Define, Classify, Apply, Conclude
When to use it: Use when time is short, for a 5 to 8 mark question or the opening of a longer case answer.
- Define the term in one line.
- Classify it: descriptive, predictive or prescriptive, or the data type.
- Link to the law: 43A for security failure, 69B for traffic data assistance, 70B for CERT-In directions.
- Apply with the facts in two or three lines.
- Close with a one-line conclusion and one compliance step.
Common mistakes in Introduction to Data Analytics and Big Data
Treating big data and data analytics as the same thing.
The terms are used together in news and business writing.
Fix: Say big data is the data (large, fast, varied) and analytics is the process of examining data. Analytics can be done on small data too.
Mixing up predictive and prescriptive analytics.
Both look forward, so they seem alike.
Fix: Predictive says what is likely to happen. Prescriptive recommends the action to take. Remember: predict, then prescribe.
Applying Section 43A to any data leak.
Students remember the section as 'data protection' and skip its conditions.
Fix: Check for a body corporate, sensitive personal data, negligence in reasonable security practices, and wrongful loss or gain. Without these, the section does not apply.
Saying 'reasonable security practices' is a fixed list in the Act.
The word 'reasonable' sounds like a standard set in the section itself.
Fix: Explain that it is first what the agreement or any law specifies, and only in their absence what the Central Government prescribes.
Confusing the penalty and the complaint rules of Sections 69B and 70B.
Both carry up to one year imprisonment or fine up to ₹1 crore, so they blur together.
Fix: Link 69B(4) to intermediaries not helping the authorised agency with traffic data. Link 70B(7) to failure to give information or follow CERT-In directions, with cognizance only on a complaint by an authorised CERT-In officer.
Writing only definitions with no application to the facts.
Students prepare notes, not case answers.
Fix: After every rule, write one sentence beginning 'In this case...' and reach a conclusion.
Worked examples
Example 1
Aarav Retail Pvt. Ltd. studies last year's sales to see which products sold most, then uses a model to estimate next quarter's demand, and finally uses software that tells each store how many units to stock. Identify the type of analytics at each stage.
Show the solution
- Stage 1: studying last year's sales shows what happened. This is descriptive analytics.
- Stage 2: estimating next quarter's demand shows what is likely to happen. This is predictive analytics.
- Stage 3: software telling each store how many units to stock recommends an action. This is prescriptive analytics.
- The three stages move from understanding the past, to forecasting, to deciding.
Answer: Stage 1 is descriptive, stage 2 is predictive and stage 3 is prescriptive analytics.
Example 2
Meridian Finserv Pvt. Ltd. holds customers' financial details on servers it owns and runs analytics on them. It has no access controls or encryption policy. A hacker steals the data and customers suffer wrongful loss. Discuss Meridian's liability under the Information Technology Act, 2000.
Show the solution
- Provision: Section 43A makes a body corporate liable to pay compensation where it possesses, deals with or handles sensitive personal data in a computer resource it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices, and thereby causes wrongful loss or wrongful gain to any person.
- Body corporate: Meridian is a company, so it is covered.
- Data and resource: financial details of customers are typically treated as sensitive personal data (check against what the Central Government has prescribed), and they sit on servers Meridian owns and operates.
- Negligence: reasonable security practices are those set by agreement or law, and failing both, those prescribed by the Central Government. Having no access controls or encryption policy suggests a failure to meet them, unless the contract or rules require nothing more.
- Wrongful loss: customers suffered loss because of the breach, so the causal link with the negligence is present.
- Conclusion and practical point: Meridian is likely liable to pay compensation to the affected customers. It should adopt a documented security policy, restrict access, encrypt stored data and have an incident response plan.
Answer: Meridian is likely liable under Section 43A to pay damages by way of compensation to the affected customers, because all the elements of the section appear to be met.
Exam tips
- Learn the three analytics types with one business example each. Examiners often give a scenario and ask you to classify it.
- For legal issue questions, write provision, analysis, conclusion in that order and keep each part short.
- Quote the elements of Section 43A one by one and tick each against the facts.
- Cite section numbers only for 43A, 69B and 70B, where you are sure. For other points, state the rule without a number.
- End case answers with a practical compliance step such as a security policy, consent record or incident plan.
Practice questions from Data Analytics and Law
- A Mumbai analytics firm stores customer records on its own servers. Under the Information Technology Act, 2000, when does Section 43A make t…
- A Pune-based fintech firm holds customers' financial details on its own servers. A hacker exploits an unpatched flaw, but no customer suffer…
- A government-authorised officer, exercising powers under the IT Act, 2000, gains access to a company's electronic records during an inquiry …
- Section 43A defines 'reasonable security practices and procedures' by a sequence of sources. Which sequence correctly reflects the text?
- Under the Information Technology Act, 2000, a body corporate holding sensitive personal data in a computer resource it owns is negligent in …
Introduction to Data Analytics and Big Data in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Introduction to Data Analytics and Big Data: frequently asked questions
What is the difference between data analytics and big data?
Big data is the large, fast and varied data itself. Data analytics is the process of examining data, big or small, to find patterns and support decisions. Big data usually needs special tools for analytics.
What are the three types of data analytics?
Descriptive analytics explains what happened. Predictive analytics estimates what may happen. Prescriptive analytics recommends what action to take.
Which section of the IT Act deals with compensation for failure to protect data?
Section 43A. It makes a body corporate liable to pay compensation where it is negligent in keeping reasonable security practices for sensitive personal data and this causes wrongful loss or wrongful gain to any person.
Does the IT Act require companies to help CERT-In?
Yes. Under Section 70B, CERT-In may call for information and give directions to service providers, intermediaries, data centres, body corporate and others. Failure to comply can lead to imprisonment up to one year or fine up to ₹1 crore, or both.