Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law
Section 43A IT Act: Compensation for Failure to Protect Data
Updated 11 October 2026 · Fact-checked
Section 43A of the IT Act, 2000 makes a body corporate liable to pay damages by way of compensation if it handles sensitive personal data in a computer resource it owns, controls or operates, is negligent in maintaining reasonable security practices, and thereby causes wrongful loss or wrongful gain to any person.
Understand Section 43A: Compensation for Failure to Protect Data
Companies hold large amounts of personal data: bank details, health records, passwords. If they guard it carelessly and someone suffers, the law needs a way to compensate that person. Section 43A is that way.
The section applies to a body corporate. The Explanation defines this widely. It means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. So a small proprietor running a business is covered, not only a large company.
The data must be sensitive personal data or information, held in a computer resource the body corporate owns, controls or operates. The Act does not list what is sensitive. It says it means such personal information as the Central Government prescribes in consultation with professional bodies or associations. The list sits in rules made under section 87(2)(ob).
The duty is to implement and maintain reasonable security practices and procedures. These are practices designed to protect the information from unauthorised access, damage, use, modification, disclosure or impairment. They are first those specified in an agreement between the parties, or in any law in force. If there is neither, they are those the Central Government prescribes.
Liability needs three things together: negligence in maintaining those practices, wrongful loss or wrongful gain to a person, and a causal link ("thereby causes"). The remedy is compensation to the person affected. It is a civil remedy, not a jail term. Section 43A was inserted with effect from 27-10-2009.
Key rules to remember
- Section 43A liability
- Body corporate + sensitive personal data in computer resource it owns/controls/operates + negligence in reasonable security practices + wrongful loss or gain caused = liable to pay damages by way of compensation
- All elements must be present. Remedy is compensation to the affected person.
- Body corporate (Explanation (i))
- Any company, and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities
- Wider than a company under the Companies Act.
- Reasonable security practices (Explanation (ii))
- Agreement between the parties, or law in force; if neither, as prescribed by the Central Government
- Order of reference: agreement or law first, then prescribed rules.
- Sensitive personal data or information (Explanation (iii))
- Such personal information as may be prescribed by the Central Government in consultation with professional bodies or associations
- Rule-making power is in section 87(2)(ob).
- Residuary penalty (section 45)
- Penalty up to ₹1,00,000 plus compensation up to ₹10,00,000 (intermediary, company or body corporate) or ₹1,00,000 (any other person)
- Applies to contravention of rules, regulations, directions or orders where no penalty is separately provided.
How to solve Section 43A: Compensation for Failure to Protect Data questions
Treat every Section 43A question as a provision, analysis, conclusion problem. Test each element against the facts.
- 1State the provision: section 43A and its core rule in one or two lines.
- 2Check whether the defendant is a body corporate, using the wide Explanation (i).
- 3Check whether the data is sensitive personal data or information as prescribed, and whether it is held in a computer resource the body corporate owns, controls or operates.
- 4Identify the reasonable security practices: first any agreement or law, otherwise the prescribed rules.
- 5Decide whether the body corporate was negligent in implementing and maintaining them. Look for missing controls, ignored warnings or no policy.
- 6Check for wrongful loss or wrongful gain to a person, and whether the negligence caused it.
- 7Conclude: liable to pay damages by way of compensation to the affected person, or not liable, with the missing element named.
- 8Add a practical point: compliance policy, security audit, incident record, and the related provisions such as section 72A or section 45 if the facts fit.
Quickest way: Five-element checklist
When to use it: Use for short case questions when time is tight.
- Write: Who? Body corporate.
- Write: What data? Sensitive personal data in its computer resource.
- Write: What failing? Negligence in reasonable security practices.
- Write: What harm? Wrongful loss or gain, caused by the failing.
- Conclude: compensation to the affected person. Name any missing element.
Common mistakes in Section 43A: Compensation for Failure to Protect Data
Saying section 43A applies only to companies registered under the Companies Act.
Students read "body corporate" in the company law sense.
Fix: Quote Explanation (i): any company, and includes a firm, sole proprietorship or other association engaged in commercial or professional activities.
Applying section 43A to any personal data.
Students ignore the word "sensitive".
Fix: Check the data is sensitive personal data or information as prescribed by the Central Government. Ordinary data falls outside this section.
Holding the body corporate liable without negligence or without harm.
Students assume any data breach means liability.
Fix: Show both negligence in security practices and wrongful loss or gain caused thereby. Without them, section 43A is not satisfied.
Stating that section 43A imposes imprisonment.
Confusion with criminal offences in the Act.
Fix: The remedy is damages by way of compensation to the person affected.
Quoting the prescribed rules as being in the section itself.
Students merge the section and the rules.
Fix: Say the definitions of sensitive data and reasonable practices are to be prescribed by the Central Government, with rule power under section 87(2)(ob).
Confusing section 43A with section 72A.
Both concern personal data.
Fix: Section 43A is about negligent security and compensation. Section 72A is about disclosing personal information, with intent or knowledge of causing wrongful loss or gain, without consent or in breach of a lawful contract, with penalty up to ₹25,00,000.
Worked examples
Example 1
Medico Care Pvt Ltd stores patients' medical records on its own servers. It has no access controls and a former employee's login stays active. A hacker uses that login and the records are sold, causing financial loss to patient Ramesh. Can Ramesh claim under section 43A?
Show the solution
- Provision: under section 43A a body corporate handling sensitive personal data in a computer resource it owns, controls or operates, which is negligent in reasonable security practices and thereby causes wrongful loss or gain, must pay compensation.
- Body corporate: Medico Care Pvt Ltd is a company, so it qualifies.
- Data and resource: medical records are personal information of a kind generally treated as sensitive, subject to the prescribed rules, and sit on its own servers.
- Negligence: no access controls and an active login of a former employee show failure to maintain reasonable security practices against unauthorised access.
- Harm and causation: the hacker used that gap, and Ramesh suffered financial loss, so the loss is caused by the negligence.
Answer: Yes. All elements are met, so Medico Care Pvt Ltd is liable to pay damages by way of compensation to Ramesh. Sensitive status should be confirmed against the prescribed rules.
Example 2
Shree Traders, a sole proprietorship, keeps customers' names and phone numbers in a spreadsheet on its own computer. A power failure corrupts the file. No customer suffers any loss. Is Shree Traders liable under section 43A?
Show the solution
- Body corporate: a sole proprietorship engaged in commercial activity is included by Explanation (i).
- Data: names and phone numbers are personal information, but they are not obviously sensitive personal data as prescribed, so this element is doubtful.
- Negligence: no facts show a failure of reasonable security practices; a power failure alone does not prove it.
- Harm: no customer suffered wrongful loss or wrongful gain.
- Conclusion: the loss and causation elements fail, and the sensitivity and negligence elements are doubtful.
Answer: Shree Traders is not liable under section 43A. Although it is a body corporate, no wrongful loss or gain was caused to any person, and negligence and sensitive data are not shown.
Exam tips
- Write the section in your own words in the first line, then apply it. Examiners reward the provision, analysis, conclusion order.
- Always quote the three Explanation definitions. They are the easiest marks.
- Use the phrase "damages by way of compensation" and state that it is a civil remedy.
- For difference questions, compare with section 72A and section 45. Keep to what each section says and do not add figures you are unsure of.
- In case questions, name the missing element when you conclude no liability.
Practice questions from Data Analytics and Law
- Under Section 16 of the Digital Personal Data Protection Act, 2023, how does the Central Government regulate transfer of personal data by a …
- Which statement correctly distinguishes Section 69B from Section 43A of the IT Act, 2000?
- A CS is advising on Section 69B. Which statement is correct?
- Mehta Analytics Pvt Ltd holds sensitive personal data of customers on its own servers. Because it was negligent in maintaining reasonable se…
- Under Section 43A of the Information Technology Act, 2000, which entity is the primary subject of liability to pay damages by way of compens…
Section 43A: Compensation for Failure to Protect Data: frequently asked questions
What is section 43A of the IT Act, 2000?
It makes a body corporate liable to pay compensation when it is negligent in maintaining reasonable security practices for sensitive personal data in a computer resource it owns, controls or operates, and this causes wrongful loss or gain to a person. It was inserted with effect from 27-10-2009.
What is sensitive personal data under the IT Act?
Section 43A says it means such personal information as the Central Government prescribes in consultation with professional bodies or associations. The list is in the rules made under section 87(2)(ob).
What are reasonable security practices and procedures?
They are practices designed to protect information from unauthorised access, damage, use, modification, disclosure or impairment. They are those specified in an agreement between the parties or in any law in force. If there is neither, they are those prescribed by the Central Government.
Who can be held liable under section 43A?
Any body corporate, meaning a company, firm, sole proprietorship or other association of individuals engaged in commercial or professional activities. The section does not cover individuals acting outside such activity.
How is section 43A different from section 72A?
Section 43A is about negligent security and gives compensation to the affected person. Section 72A deals with a person who, under a lawful contract, accesses personal information and discloses it without consent or in breach of the contract, with intent or knowledge of causing wrongful loss or gain. Its penalty may extend to ₹25,00,000.