Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law
Reasonable Security Practices and Sensitive Personal Data Rules
Updated 11 October 2026 · Fact-checked
Under section 43A of the IT Act, 2000, a body corporate handling sensitive personal data must follow reasonable security practices and procedures. These are set by agreement, by any law in force, or, failing both, by the Central Government's rules (the SPDI Rules, 2011). If it is negligent and causes wrongful loss or gain, it pays compensation.
Understand Reasonable Security Practices and Sensitive Personal Data Rules
Start with the problem. Companies hold personal data such as passwords, health records and financial details. If they guard it badly and someone is harmed, the law needs a way to make the company pay. Section 43A does this.
The section applies to a body corporate. The Act's Explanation defines it widely: any company, and also a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. So a small proprietor can be covered too.
The section protects sensitive personal data or information (SPDI). The Act does not list it. It says SPDI means such personal information as the Central Government prescribes in consultation with professional bodies or associations. The list sits in the rules made under section 87(2)(ob), which covers both reasonable security practices and SPDI under section 43A. These are commonly called the SPDI Rules, 2011.
The section also does not list the security practices. The Explanation says reasonable security practices and procedures are those designed to protect information from unauthorised access, damage, use, modification, disclosure or impairment. They come from three sources, in this order: (1) an agreement between the parties, (2) any law in force, and (3) if neither exists, the practices prescribed by the Central Government. Under the SPDI Rules, a body corporate is treated as having met the standard if it has a documented information security programme and policies, with managerial, technical, operational and physical controls matching the information assets. IS/ISO/IEC 27001 is the standard the rules name as one example. A body corporate following another code approved and notified by the Central Government can also qualify.
Liability needs three things together: the body corporate holds SPDI in a computer resource it owns, controls or operates; it was negligent in implementing and maintaining reasonable security; and that negligence caused wrongful loss or wrongful gain to a person. The remedy is damages by way of compensation to the affected person.
Key rules to remember
- Elements of liability under section 43A
- Body corporate + SPDI in own/controlled/operated computer resource + negligence in reasonable security practices + wrongful loss or wrongful gain ⇒ compensation
- All elements must be present. No loss or gain to anyone means no claim under this section.
- Order of sources of reasonable security practices
- Agreement between the parties → any law in force → practices prescribed by the Central Government
- The prescribed practices apply only in the absence of an agreement or a law.
- Meaning of body corporate (Explanation (i))
- Any company + firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
- Wider than a company under the Companies Act.
- Meaning of SPDI (Explanation (iii))
- Such personal information as may be prescribed by the Central Government
- The list is in the SPDI Rules, 2011, made under section 87(2)(ob). Say that it is prescribed, not listed in the Act.
- Rule-making power
- Section 87(2)(ob): reasonable security practices and procedures and SPDI under section 43A
- This is the statutory source of the SPDI Rules.
How to solve Reasonable Security Practices and Sensitive Personal Data Rules questions
Use this sequence for any case-based question on section 43A and the SPDI Rules. It follows the provision, analysis, conclusion pattern.
- 1Identify the entity. Is it a body corporate as defined in the Explanation to section 43A? Companies, firms, sole proprietorships and associations in commercial or professional activity qualify.
- 2Identify the data. Is it sensitive personal data or information as prescribed under the SPDI Rules, 2011? Ordinary personal data outside the prescribed list is not covered.
- 3Check the computer resource. Was the data held in a computer resource the body corporate owns, controls or operates?
- 4Find the applicable security standard in order: agreement between the parties, then any law in force, then the prescribed practices. Mention IS/ISO/IEC 27001 and the documented security programme if the facts show them.
- 5Test for negligence. Compare what the company did with the standard: policies, controls, audits, access restrictions.
- 6Test for harm. Was there wrongful loss or wrongful gain to a person, and was it caused by the lapse?
- 7Conclude. If all elements are met, the body corporate must pay damages by way of compensation to the affected person. State the conclusion clearly and note practical compliance steps.
Quickest way: Five-check shortcut for section 43A
When to use it: Use it when a short case gives you a data breach and asks whether the company is liable.
- Who: body corporate?
- What: SPDI held in its own computer resource?
- Standard: agreement, law, or prescribed practices; was ISO 27001 or a documented programme in place?
- Fault: negligence in implementing and maintaining it?
- Harm: wrongful loss or gain caused? If all five are yes, compensation is payable.
Common mistakes in Reasonable Security Practices and Sensitive Personal Data Rules
Saying section 43A applies only to companies registered under the Companies Act.
Students read 'body corporate' in the company law sense.
Fix: Quote the Explanation: any company, and also a firm, sole proprietorship or other association engaged in commercial or professional activities.
Listing the types of SPDI as if they are written in the Act.
Students merge the Act with the SPDI Rules.
Fix: Write that the Act leaves SPDI to be prescribed by the Central Government, and that the list is in the SPDI Rules, 2011.
Treating ISO 27001 as compulsory for everyone.
It is the best-known example, so it is remembered as a mandate.
Fix: Say it is an example standard named in the rules. Agreement or other law can set the standard, and a notified code approved by the Central Government can also be followed.
Awarding compensation whenever a breach happens.
Students ignore negligence and the need for wrongful loss or gain.
Fix: Show that negligence in security practices and resulting wrongful loss or gain must both be present.
Forgetting the order of sources of the standard.
The Explanation is long and students skim it.
Fix: Memorise: agreement, then law in force, then prescribed practices in the absence of both.
Confusing section 43A compensation with criminal punishment.
Other sections such as 70B(7) carry imprisonment and fine.
Fix: Section 43A gives damages by way of compensation to the affected person. It does not itself prescribe imprisonment.
Worked examples
Example 1
Sharma Traders, a partnership firm in Jaipur, stores customers' bank account details and passwords on its own server. It has no written security policy and no access controls. A hacker steals the data and withdraws ₹2,40,000 from a customer's account. Advise whether section 43A applies.
Show the solution
- Entity: a firm engaged in commercial activity is a body corporate under the Explanation to section 43A.
- Data: passwords and bank account details are financial information, which the SPDI Rules treat as sensitive personal data. The Act itself leaves the list to the prescribed rules.
- Resource: the server is owned and operated by the firm, so the computer resource condition is met.
- Standard: no agreement or other law is given, so the prescribed practices apply. These expect a documented information security programme with suitable controls. The firm had none, which shows negligence.
- Harm: the customer suffered a wrongful loss of ₹2,40,000, caused by the weak security.
- All elements are satisfied.
Answer: Section 43A applies. Sharma Traders, as a body corporate, is liable to pay damages by way of compensation to the affected customer. It should adopt a documented security programme, for example aligned to IS/ISO/IEC 27001.
Example 2
Nova Software Ltd holds employee health records in its own systems and follows IS/ISO/IEC 27001 with regular audits. An attacker uses a previously unknown flaw and leaks some records, but no one suffers any loss and no one gains wrongfully. Can an employee claim compensation under section 43A?
Show the solution
- Entity and data: Nova is a company, and health records are sensitive personal data under the SPDI Rules.
- Resource: the records are in Nova's own systems.
- Standard: Nova follows IS/ISO/IEC 27001 with audits, which the SPDI Rules recognise as a reasonable security standard. Nothing on the facts shows negligence.
- Harm: the facts state that there is no wrongful loss or gain to anyone.
- Section 43A needs negligence and wrongful loss or gain. Both are missing.
Answer: No claim lies under section 43A. There is no negligence in implementing and maintaining reasonable security practices, and no wrongful loss or gain to any person.
Exam tips
- Quote the Explanation to section 43A for body corporate, reasonable security practices and SPDI. Examiners reward exact conditions.
- Always state that SPDI and the detailed practices are prescribed by the Central Government under section 87(2)(ob), and name the SPDI Rules, 2011.
- In case questions, structure the answer as provision, facts applied, conclusion, and add one or two compliance steps such as a documented security policy and ISO 27001 alignment.
- Do not quote section numbers other than those you know. Sections 43A, 87, 16, 69B and 70B are safe from the supplied text.
Practice questions from Data Analytics and Law
- A telecom intermediary, Bharat Netlink Ltd, is called upon by an agency authorised under Section 69B(1) to enable online access to a server …
- Which statement correctly distinguishes Section 69B from Section 43A of the IT Act, 2000?
- A sectoral law already imposes a stricter restriction on transferring a class of personal data outside India than anything the Central Gover…
- Quantum Insights Pvt Ltd, a body corporate, holds sensitive personal data in its own servers for analytics. It neglects reasonable security …
- Under the Information Technology Act, 2000, a statute requires that certain information be in writing. An analytics firm in Pune stores that…
Reasonable Security Practices and Sensitive Personal Data Rules: frequently asked questions
What is reasonable security practices and procedures under section 43A?
They are practices designed to protect information from unauthorised access, damage, use, modification, disclosure or impairment. They are set by agreement between the parties or by any law in force. If neither exists, the Central Government's prescribed practices apply.
Is IS/ISO/IEC 27001 mandatory under the SPDI Rules?
No. It is a recognised example of a standard that a body corporate can follow to show reasonable security practices. Other notified codes approved by the Central Government can also be followed, and an agreement or other law may set the standard.
What is sensitive personal data or information in India?
Under section 43A, it is such personal information as the Central Government prescribes in consultation with professional bodies. The SPDI Rules, 2011 contain the prescribed list, which covers items such as passwords and financial information.
Who pays compensation under section 43A?
The body corporate pays, and the person affected receives damages. Liability arises only if it was negligent in maintaining reasonable security practices and that caused wrongful loss or wrongful gain.