Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law

Legal Framework for Data Analytics in India: IT Act 2000 and DPDP Act 2023

Updated 11 October 2026 · Fact-checked

The legal framework for data analytics in India is the set of laws that control how personal data is collected, processed and protected. It rests on the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. To solve a question, identify the data, the actor, the law that applies, and the consequence.

Understand Legal Framework for Data Analytics in India

Data analytics means collecting data, cleaning it and drawing patterns from it. When the data relates to identifiable people, the law steps in. Analytics is not banned. The law asks how you got the data, why you use it, and how well you protect it.

The Information Technology Act, 2000 is the base law for cyberspace. Under section 1(2) it extends to the whole of India. It also applies to any offence or contravention committed outside India by any person. Section 75 explains this: the Act applies to a contravention outside India, irrespective of nationality, if the act involves a computer, computer system or computer network located in India. So a foreign analytics firm using Indian computer systems can be caught.

The IT Act once had section 43A. It made a body corporate handling sensitive personal data or information in a computer resource it owns, controls or operates liable to pay compensation if it was negligent in keeping reasonable security practices and thereby caused wrongful loss or wrongful gain. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 (DPDP Act) says section 43A shall be omitted. Check the notified commencement status of that provision before you write that it is already in force. Always state that the DPDP Act is the newer, specific law for personal data.

The DPDP Act brings in the roles of Data Fiduciary (who decides purpose and means), Data Processor and Data Principal (the person the data is about). Section 11 gives the Data Principal a right to access: a summary of the personal data being processed and the processing activities, and the identities of other Data Fiduciaries and Data Processors with whom it has been shared. This right applies against a Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7.

The Act also has exemptions. Section 17 lets some processing go ahead without parts of the Act, for example to enforce a legal right, for court or regulatory functions, for crime prevention, or for a court-approved merger or demerger. Research, archiving or statistical use is exempt only if the data is not used for any decision specific to a Data Principal and prescribed standards are followed. An exam answer must show both the rule and its exception.

Key rules to remember

Territorial reach of the IT Act
Section 1(2) and section 75: applies to the whole of India and to contraventions outside India if a computer, system or network located in India is involved
Applies irrespective of the nationality of the person under section 75(1).
Old section 43A test
Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or gain = compensation
Section 44(2)(a) of the DPDP Act omits section 43A. Use it to explain the earlier position.
Adjudication limit
Section 46(1A): adjudicating officer decides claims up to ₹5 crore; above ₹5 crore, the competent court
Adjudicating officer is not below the rank of Director to the Government of India or equivalent State officer.
Right to access
Section 11(1) DPDP: summary of data and processing + identities of Fiduciaries and Processors with whom data is shared + other prescribed information
Section 11(2) exempts sharing with an authorised Fiduciary on a written request for prevention, detection, investigation or prosecution of offences or cyber incidents.
Exemptions
Section 17(1): Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 do not apply in listed cases; section 17(2): the Act does not apply to notified State instrumentalities or qualifying research, archiving and statistical use
Section 17(3) lets the Central Government exempt notified Fiduciaries, including startups, from certain provisions.

How to solve Legal Framework for Data Analytics in India questions

Use this method for any case-based question on the legal framework for analytics. Write provision, analysis, conclusion.

  1. 1Identify the facts: who holds the data, what type it is, and what the analytics is for.
  2. 2Name the actor: body corporate, Data Fiduciary, Data Processor or Data Principal.
  3. 3State the governing law: IT Act, 2000 for cyber contraventions and jurisdiction, DPDP Act, 2023 for personal data duties.
  4. 4Quote the relevant rule in plain words with its conditions, such as section 43A elements or the section 11 access right.
  5. 5Check territorial reach under sections 1(2) and 75 of the IT Act if a foreign element exists.
  6. 6Check exemptions under section 17 of the DPDP Act before concluding that a duty applies.
  7. 7State the remedy and forum, for example compensation, adjudicating officer up to ₹5 crore, or court above that.
  8. 8Conclude clearly and add one practical compliance point, such as security safeguards or an access-request process.

Quickest way: Four-point legal check

When to use it: Use when time is short and the question is a short fact pattern.

  1. Who: label every party with its legal role.
  2. What: personal data, sensitive data, or non-personal data.
  3. Which law: IT Act for reach, security and forum; DPDP Act for personal data rights and exemptions.
  4. So what: exemption, remedy, forum, then one line of advice.

Common mistakes in Legal Framework for Data Analytics in India

  • Treating section 43A as fully operating law without mentioning the DPDP Act.

    Older notes and the 43A heading are very familiar.

    Fix: Say that section 44(2)(a) of the DPDP Act omits section 43A, and use 43A to explain the earlier compensation rule.

  • Writing that the IT Act does not apply outside India.

    Students assume Indian law stops at the border.

    Fix: Cite sections 1(2) and 75: it applies if the conduct involves a computer, system or network located in India.

  • Forgetting the elements of 43A, such as negligence and wrongful loss or gain.

    Students remember only the idea of data protection.

    Fix: List body corporate, sensitive data, own or controlled computer resource, negligence, wrongful loss or gain.

  • Stating the adjudication limit wrongly.

    Confusion between ₹5 crore and other monetary limits.

    Fix: Remember section 46(1A): up to ₹5 crore the adjudicating officer, above it the competent court.

  • Saying every analytics use of personal data needs full compliance.

    Students skip section 17.

    Fix: Check the exemptions, such as research or statistical use without decisions about a specific person, or court-approved mergers.

  • Quoting section numbers you are unsure of.

    Pressure to look precise.

    Fix: Quote only sections you know well and describe the rest in plain words.

Worked examples

Example 1

DataMint Pvt Ltd, a Bengaluru analytics company, stores customers' sensitive financial data on its own servers. Poor security lets a hacker steal it, and a customer suffers wrongful loss. Advise on liability under the IT Act, noting the DPDP Act.

Show the solution
  1. Provision: section 43A made a body corporate liable to pay compensation where it handled sensitive personal data in a computer resource it owns, controls or operates and was negligent in reasonable security practices, causing wrongful loss or gain.
  2. Analysis: DataMint is a company, hence a body corporate. The data sits on its own servers. Weak security suggests negligence, and the customer suffered wrongful loss.
  3. Newer law: section 44(2)(a) of the DPDP Act omits section 43A, so the personal data duties of a Data Fiduciary under the DPDP Act are the current focus once that provision is in force.
  4. Forum: a compensation claim up to ₹5 crore goes to the adjudicating officer under section 46(1A) of the IT Act, and above that to the competent court.

Answer: On the facts, the elements of section 43A are met and DataMint would be liable to pay compensation. Because section 43A is omitted by the DPDP Act, advise DataMint to treat the DPDP Act as the governing framework and to strengthen security safeguards.

Example 2

Zenith Analytics Ltd processes the data of Indian users from a server located outside India and later claims the IT Act does not apply to it. Also, a user asks for a summary of the data held. Advise.

Show the solution
  1. Provision on reach: section 75(1) applies the Act to contraventions outside India irrespective of nationality. Under section 75(2), this holds if the conduct involves a computer, computer system or computer network located in India.
  2. Analysis: if Zenith's conduct involves a computer system or network located in India, the IT Act can apply even though its server is abroad. If no Indian system is involved, section 75(2) is not met.
  3. Right to access: under section 11(1) of the DPDP Act, a Data Principal who earlier gave consent can ask the Data Fiduciary for a summary of her personal data and the processing activities, and the identities of other Fiduciaries and Processors with whom it was shared.
  4. Exception: section 11(2) excludes sharing with an authorised Fiduciary on a written request to prevent, detect or investigate offences or cyber incidents, or for prosecution or punishment of offences.

Answer: Zenith's argument fails if its conduct involves a computer, system or network in India. Zenith should respond to the user's request with the summary and details required by section 11(1), withholding only the sharing covered by section 11(2).

Exam tips

  • Write every answer as provision, analysis, conclusion, and tie each step to the facts.
  • Always mention both the IT Act, 2000 and the DPDP Act, 2023, and show how section 43A was omitted.
  • Remember the numbers: ₹5 crore for the adjudicating officer, and sections 1, 11, 17, 46 and 75.
  • Add one practical compliance line, such as a security audit or an access-request procedure.
  • Do not quote a section you cannot recall; explain the rule in plain words.

Practice questions from Data Analytics and Law

Legal Framework for Data Analytics in India in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Legal Framework for Data Analytics in India: frequently asked questions

What is the main law for data analytics in India?

The Information Technology Act, 2000 governs cyberspace, security and adjudication, and the Digital Personal Data Protection Act, 2023 governs personal data processing. Together they form the core framework. Answer with both.

Is section 43A of the IT Act still in force?

Section 44(2)(a) of the DPDP Act says section 43A shall be omitted. In your answer, explain 43A as the earlier rule and treat the DPDP Act as the specific personal data law. Check the commencement notifications for the exact date.

Does the IT Act apply to a foreign company?

Yes, in some cases. Section 75 applies the Act to contraventions outside India by any person, irrespective of nationality, if the conduct involves a computer, computer system or network located in India.

Who decides compensation claims under the IT Act?

Under section 46, an adjudicating officer decides claims where the damage does not exceed ₹5 crore. Claims above ₹5 crore go to the competent court.

Are there cases where the DPDP Act does not apply to analytics?

Yes. Section 17 lists exemptions, such as enforcing a legal right, regulatory functions, crime investigation and court-approved mergers. It also exempts research, archiving or statistical use if the data is not used for a decision specific to a Data Principal and prescribed standards are followed.