Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law
Privacy, Data Protection and Ethical Issues in Analytics
Updated 11 October 2026 · Fact-checked
Privacy and data protection in analytics means using personal data lawfully, securely and fairly while analysing it. In India, the DPDP Act, 2023 sets Data Fiduciary duties such as valid contracts with processors, accuracy, security safeguards, breach intimation and erasure. Section 43A of the IT Act adds compensation for poor security of sensitive data.
Understand Privacy, Data Protection and Ethical Issues in Analytics
Analytics turns raw data into insight. When the data is about people, the insight can also expose them. Purchase history, location and browsing trails can reveal health, income or habits. That is the privacy risk.
The law uses simple roles. A Data Principal is the person the data is about. A Data Fiduciary decides why and how the data is processed. A Data Processor processes it on the fiduciary's behalf. The fiduciary stays responsible even when a processor does the work, and even if an agreement says otherwise (DPDP Act, section 8(1)).
Three analytics issues come up often. Consent and purpose: data collected for one purpose should not quietly be reused for another. Profiling: building a picture of a person from many data points, which can lead to decisions that affect them. Where data is used for such decisions or is shared with another Data Fiduciary, the fiduciary must ensure its completeness, accuracy and consistency (section 8(3)). Anonymisation: removing identifiers so data cannot be tied to a person. It reduces risk, but weak anonymisation can be reversed by linking datasets, so treat it as a safeguard and not a guarantee.
Ethics goes beyond the law. Ask whether the analysis is fair, transparent and explainable, and whether it creates bias or harm. Good practice: collect only what you need, keep it only as long as needed, secure it, and be able to explain how decisions are made.
The organisation must also have accountability tools: technical and organisational measures (section 8(4)), reasonable security safeguards (section 8(5)), a grievance mechanism (section 8(10)) and published contact details of a Data Protection Officer or a person who can answer questions (section 8(9)). Under the IT Act, section 43A makes a body corporate liable to pay compensation if it is negligent in maintaining reasonable security practices for sensitive personal data and this causes wrongful loss or gain.
Key rules to remember
- Fiduciary responsibility
- Data Fiduciary stays responsible for processing by itself or by its Data Processor (DPDP Act, s 8(1))
- An agreement to the contrary does not remove this responsibility.
- Use of processors
- Processor engaged for offering goods or services only under a valid contract (s 8(2))
- Always mention the contract in answers on outsourcing analytics.
- Quality of data
- Ensure completeness, accuracy and consistency if data is used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (s 8(3))
- Key for profiling and automated decisions.
- Security and breach
- Reasonable security safeguards (s 8(5)); intimate Board and each affected Data Principal of a breach (s 8(6))
- Form and manner of intimation are as prescribed.
- Erasure
- Erase data when consent is withdrawn or purpose is no longer served, whichever is earlier, unless law requires retention (s 8(7))
- Also cause the processor to erase data given to it.
- Correction and erasure rights
- Data Principal may seek correction, completion, updating and erasure (s 12)
- Erasure is not required if retention is necessary for the specified purpose or legal compliance (s 12(3)).
- Cross-border transfer
- Central Government may restrict transfer to notified countries (s 16(1)); stricter Indian laws continue to apply (s 16(2))
- Transfer is not banned by default under this section.
- Section 43A, IT Act
- Negligence in reasonable security practices for sensitive personal data + wrongful loss or gain = compensation
- Applies to a body corporate, which includes a firm or sole proprietorship engaged in commercial or professional activity.
How to solve Privacy, Data Protection and Ethical Issues in Analytics questions
Use this order for any case-based question on privacy and ethics in analytics.
- 1Identify the facts: who collected the data, who analyses it, whose data it is, and what went wrong.
- 2Assign roles: Data Principal, Data Fiduciary, Data Processor.
- 3Name the issue: consent or purpose, profiling, accuracy, anonymisation, security, breach, retention, cross-border transfer or ethics.
- 4State the provision in plain words with the section, for example DPDP Act section 8(5) for security safeguards.
- 5Apply it to the facts. Say what the organisation did and what it should have done.
- 6Add the IT Act angle where sensitive data was held insecurely: section 43A compensation.
- 7Conclude with the likely liability and practical steps: contract with processor, safeguards, breach notice, erasure, grievance channel.
Quickest way: Role, Duty, Gap, Fix
When to use it: Use when time is short and the question is a short case or a 'discuss' question.
- Role: name fiduciary, processor and principal in one line.
- Duty: pick the one or two section 8 duties most relevant.
- Gap: show where the facts fall short of the duty.
- Fix: give two practical compliance actions and end with the section 43A or ethics point if relevant.
Common mistakes in Privacy, Data Protection and Ethical Issues in Analytics
Saying the processor alone is liable when an outsourced analytics vendor leaks data.
Students focus on who made the error.
Fix: State that the Data Fiduciary remains responsible for processing by its processor under section 8(1).
Treating anonymised data as completely risk free.
The word suggests permanent safety.
Fix: Explain that anonymisation lowers risk but datasets can be linked to re-identify people, so safeguards still apply.
Claiming that data must always be erased on request.
Students remember the right but skip the exception.
Fix: Add that erasure is not required where retention is necessary for the specified purpose or legal compliance (sections 8(7) and 12(3)).
Saying section 16 bans all transfer of data outside India.
The heading sounds restrictive.
Fix: Say the Central Government may restrict transfer to notified countries, and stricter Indian laws continue to apply.
Applying section 43A to any personal data.
Students ignore the wording.
Fix: Section 43A covers sensitive personal data or information, as prescribed, held by a body corporate, and needs negligence plus wrongful loss or gain.
Giving only ethics talk with no legal provision.
Ethics feels easier to write about.
Fix: Pair each ethical point, such as fairness or accuracy, with its legal hook, such as section 8(3).
Worked examples
Example 1
Veda Retail Ltd. hires an analytics firm to profile customers and decide credit offers. The firm's server is breached and customer data is exposed. Veda says the vendor is responsible. Advise.
Show the solution
- Roles: Veda is the Data Fiduciary, the analytics firm is the Data Processor, customers are Data Principals.
- Section 8(1): the fiduciary is responsible for processing done on its behalf by a processor, irrespective of any contrary agreement. Veda's argument fails.
- Section 8(2): the processor must be engaged under a valid contract. Veda should check the contract exists and covers security.
- Section 8(5): the fiduciary must take reasonable security safeguards, including for processing by its processor.
- Section 8(6): Veda must intimate the Board and each affected Data Principal of the breach in the prescribed form and manner.
- Section 8(3): as the profiling affects credit decisions, Veda must ensure the data is complete, accurate and consistent.
- If the data is sensitive personal data and negligence caused wrongful loss, section 43A of the IT Act may also give affected persons compensation.
Answer: Veda remains responsible. It must give breach intimation to the Board and affected customers, strengthen safeguards and its processor contract, and may also face compensation claims under section 43A.
Example 2
A bank holds an ex-customer's data after account closure and a marketing team wants to use it for analytics. The customer asks for erasure. Discuss.
Show the solution
- Roles: the bank is the Data Fiduciary, the ex-customer is the Data Principal.
- Section 12(3): on a request, the fiduciary must erase data unless retention is necessary for the specified purpose or legal compliance.
- Section 8(7): data must also be erased when consent is withdrawn or the purpose is no longer served, unless law requires retention.
- Illustration II to section 8: a bank must keep identity records for the period law requires, so it may retain that part.
- Marketing analytics is not a legal retention need. That data must be erased, and the processor must also erase any copy given to it (section 8(7)(b)).
- Ethically, the bank should not repurpose the data without a fresh basis.
Answer: The bank may retain only the data it must keep under law, such as identity records for the legally required period. All other data, including that for marketing analytics, must be erased, and processors must be made to erase it too.
Exam tips
- Write the section number with each duty, but only use numbers you are sure of; the section 8 sub-sections above are safe.
- Always name the roles first. It sets up the whole answer.
- Include one practical compliance step, such as a processor contract, breach plan or grievance channel, since answers are judged on drafting and compliance points.
- For 'discuss ethical issues' questions, cover privacy, consent, bias, transparency and accountability, each with a short example.
- Mention both the DPDP Act and section 43A of the IT Act when security failure is in the facts.
Practice questions from Data Analytics and Law
- Quantum Insights Pvt Ltd, a body corporate, holds sensitive personal data in its own servers for analytics. It neglects reasonable security …
- Under the Information Technology Act, 2000, a statute requires that certain information be in writing. An analytics firm in Pune stores that…
- A telecom intermediary, Bharat Netlink Ltd, is called upon by an agency authorised under Section 69B(1) to enable online access to a server …
- A foreign national, sitting abroad, uses a computer network located in Hyderabad to contravene the IT Act, 2000 while mining a company's dat…
- For purposes of Section 43A of the IT Act, 2000, what does 'sensitive personal data or information' mean?
Privacy, Data Protection and Ethical Issues in Analytics in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Privacy, Data Protection and Ethical Issues in Analytics: frequently asked questions
Is anonymised data covered by privacy law?
Properly anonymised data no longer identifies a person, so risk is much lower. But if it can be linked back to a person, it is still personal data in effect. In answers, say anonymisation is a safeguard and its strength must be tested.
Who is responsible if a vendor does the analytics?
The Data Fiduciary. Section 8(1) of the DPDP Act makes it responsible for processing by its Data Processor, and the processor must be engaged under a valid contract.
What must an organisation do after a personal data breach?
It must give the Data Protection Board and each affected Data Principal intimation of the breach in the prescribed form and manner (section 8(6)). It should also investigate and strengthen safeguards.
Can personal data be sent abroad for analytics?
Section 16 lets the Central Government restrict transfer to notified countries or territories. Other Indian laws with stricter rules continue to apply. Transfer is therefore allowed unless restricted.
How is section 43A different from the DPDP Act?
Section 43A gives compensation where a body corporate is negligent in reasonable security practices for sensitive personal data and causes wrongful loss or gain. The DPDP Act sets wider duties for Data Fiduciaries on all digital personal data.