Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics
Legal and Ethical Issues in Data Analytics
Updated 11 October 2026 · Fact-checked
Legal and ethical issues in data analytics are the duties that apply when an organisation collects and analyses data. In India the main law is the Digital Personal Data Protection Act, 2023. It requires lawful purpose, consent or a permitted use, security, and respect for individual rights. Ethics adds fairness, transparency and avoiding bias.
Understand Legal and Ethical Issues in Data Analytics
Data analytics turns raw data into insight. When that data is about people, it becomes personal data, and the law and ethics step in. The question is simple: may you use this data, for what purpose, and how must you protect it?
In India, the Digital Personal Data Protection Act, 2023 (DPDP Act) governs digital personal data. It covers data collected in digital form, or collected in non-digital form and then digitised. The person the data relates to is the Data Principal. The entity that decides the purpose and means of processing is the Data Fiduciary. A party that processes data on behalf of a Data Fiduciary is a Data Processor.
The Act is built on a few ideas. Process personal data only for a lawful purpose, either with the Data Principal's consent or for a use the Act permits as a legitimate use. Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to what is necessary for the stated purpose. The Data Fiduciary must give a notice explaining what data is collected and why. It must keep data accurate, take reasonable security safeguards, and erase data once the purpose is served, unless law requires retention. If a personal data breach occurs, the Data Fiduciary must intimate it to the Data Protection Board of India and to each affected Data Principal. Data Principals have rights such as access to information, correction and erasure, grievance redressal, nomination, and the right to withdraw consent. Penalties for breach are financial and are imposed by the Data Protection Board of India.
For analytics this has real effects. You cannot reuse data collected for one purpose for an unrelated analysis without a valid basis. Keeping data forever "in case it is useful" conflicts with erasure duties. Anonymising or aggregating data reduces risk, but you must check that individuals cannot be re-identified.
Ethics goes beyond what the law requires. Bias arises when training data or models treat groups unfairly, for example a credit model that disadvantages a region. Transparency means people can understand how decisions are made. Accountability means a named person answers for outcomes. Data security protects against leaks and misuse. In an exam answer, link each issue to a duty and a practical control.
Before the DPDP Act, Section 43A of the IT Act, 2000, and the Sensitive Personal Data Rules made under it dealt with data protection. The DPDP Act amends the IT Act by omitting Section 43A (through Section 44(2) of the DPDP Act). Once that provision comes into force, the Section 43A and SPDI Rules framework is replaced by the DPDP Act. Check the notified commencement date in the official text before you state the position in an answer.
Key rules to remember
- Key roles under the DPDP Act
- Data Principal = the individual; Data Fiduciary = decides purpose and means; Data Processor = processes on behalf of the Fiduciary
- Always identify the role of each party first in a case question.
- Grounds for processing
- Lawful purpose = consent OR legitimate use permitted by the Act
- Consent must be free, specific, informed, unconditional and unambiguous.
- Core duties of a Data Fiduciary
- Notice + purpose limit + accuracy + security safeguards + breach reporting + erasure when purpose ends
- Use this list as a checklist for any analytics scenario.
- Rights of a Data Principal
- Access + correction and erasure + grievance redressal + nomination + withdrawal of consent
- Withdrawal of consent is easy to forget, so add it to every list of rights.
- Ethical principles in analytics
- Fairness + transparency + accountability + security + privacy
- Use these as headings when the question asks about ethics.
How to solve Legal and Ethical Issues in Data Analytics questions
Use this order for any case-based or descriptive question on legal and ethical issues in analytics.
- 1Read the facts and list what data is used, whose it is, and whether it is digital personal data.
- 2Identify the roles: Data Principal, Data Fiduciary and any Data Processor.
- 3State the relevant rule in plain words, such as consent, notice, purpose limitation or security safeguards.
- 4Apply the rule to the facts. Say clearly what the company did and where it falls short.
- 5Add the ethical dimension, such as bias, transparency or fairness, if the facts suggest it.
- 6Give a conclusion on compliance or risk.
- 7Suggest practical steps: consent mechanism, data minimisation, anonymisation, access controls, breach plan, audits.
Quickest way: Role, rule, risk, remedy
When to use it: Use it when time is short and the question is a short case or a 'discuss' question.
- Role: name the Data Fiduciary, Data Principal and Processor.
- Rule: state the one or two DPDP duties that matter most.
- Risk: say what goes wrong, such as misuse, breach or bias.
- Remedy: list two or three controls the company should adopt.
Common mistakes in Legal and Ethical Issues in Data Analytics
Treating all data as covered without checking that it is personal data.
Students memorise the Act and apply it everywhere.
Fix: First confirm the data relates to an identifiable individual. Fully anonymous aggregate data raises fewer issues.
Assuming consent alone allows any analysis.
Consent feels like a blanket permission.
Fix: Consent is tied to a stated purpose. New unrelated use needs a fresh valid basis.
Mixing up Data Fiduciary and Data Processor.
Both handle data, so the roles look similar.
Fix: The Fiduciary decides why and how. The Processor acts on its behalf. The Fiduciary stays responsible.
Writing only about law and ignoring ethics.
The Act is easier to memorise than ethical ideas.
Fix: Add a short line on bias, transparency and accountability whenever the question says 'ethical'.
Quoting penalty amounts or section numbers from memory.
Students try to sound precise.
Fix: Quote them only from the official text. Otherwise say the Board can impose financial penalties.
Giving a conclusion without practical steps.
Students stop once the law is stated.
Fix: Always end with controls the company can adopt.
Worked examples
Example 1
Surya Retail Ltd., an Indian company, collected customers' mobile numbers and purchase history online to issue bills. Its analytics team now wants to use the same data to build a profile for selling insurance products of a partner. Customers were not told about this. Advise on the legal position.
Show the solution
- Data: mobile numbers and purchase history are digital personal data, so the DPDP Act applies.
- Roles: Surya Retail is the Data Fiduciary. The customers are Data Principals.
- Rule: data may be processed for a lawful purpose, with consent given for a specified purpose, or under a permitted legitimate use. The notice must state the purpose.
- Application: the data was collected to issue bills. Profiling for a partner's insurance sales is a different purpose, and customers were not informed.
- Risk: unless consent for the new purpose or a legitimate use under the Act applies, the processing would be non-compliant, and sharing with a partner increases exposure.
- Remedy: issue a fresh notice, seek specific consent, allow customers to withdraw consent, and share data only under a contract with security obligations.
Answer: Surya Retail cannot use the data for insurance profiling without a valid basis for the new purpose. It should give notice, obtain specific consent and put safeguards in place before proceeding.
Example 2
A bank uses an analytics model to approve personal loans. It is found that applicants from certain localities are rejected far more often, although their repayment records are good. Discuss the ethical and legal issues and the steps the bank should take.
Show the solution
- Issue: the model shows bias. Locality is acting as an unfair proxy, so similar applicants are treated differently.
- Ethical principles hit: fairness and transparency. Applicants cannot understand why they were rejected, and accountability is unclear.
- Legal angle: the bias itself is mainly an ethical issue and a matter for sectoral regulation, such as the RBI's fair practices expectations for lenders. The DPDP Act link is narrower. The bank is a Data Fiduciary and must keep the applicants' personal data accurate and complete where it is likely to be used for a decision affecting them, and must have reasonable security safeguards. Applicants can seek correction of their data and use grievance redressal. They can also seek erasure, but the bank can refuse where it needs to retain the data for the specified purpose or to comply with law. These rights do not let them challenge the model's logic as such.
- Risk: reputational damage, complaints and attention from the sector regulator.
- Remedy: audit the training data, remove or test proxy variables, keep human review of rejections, document model logic, and set up a grievance process.
- Governance: assign an accountable officer and report to the board or risk committee.
Answer: The bank's model raises mainly an ethical bias and fairness problem, which sectoral rules on fair lending also cover. The DPDP Act link is limited to the accuracy and completeness of the applicants' data, their correction and erasure rights (erasure can be refused where retention is needed for the purpose or by law), and security. The bank should audit and retrain the model, add human review, explain decisions and offer redressal.
Exam tips
- Start every case answer by naming the roles under the DPDP Act. It earns easy marks.
- Write the rule, apply it to the facts, then conclude. Do not stop at definitions.
- Use a short list of controls at the end, such as consent, minimisation, anonymisation, security and breach plan.
- For 'ethical issues' questions, use headings like bias, transparency, privacy and accountability, with one example each.
- Read the official text of the Act before the exam, and cite section numbers or penalty figures only if you are sure of them.
Practice questions from Data Analytics
- A private bank in Pune applies analytics to customer transaction data and finds a cluster of accounts with many small deposits just under a …
- Which statement correctly distinguishes a data warehouse used for analytics from an operational transaction database?
- A listed Indian manufacturer studies its past sales records to understand why sales of one product line fell sharply in the last two quarter…
- A Pune healthcare analytics firm buys a dataset of patient records from a hospital, which it will combine with wearable-device data. Which s…
- A supermarket chain in Pune finds that customers who buy bread and butter very often also buy jam, and uses this to arrange shelves. Which d…
Legal and Ethical Issues in Data Analytics in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Legal and Ethical Issues in Data Analytics: frequently asked questions
How does the DPDP Act affect data analytics?
It limits analytics on personal data to a lawful purpose, usually with consent and notice. Companies must keep data secure, accurate and not retain it after the purpose ends. Data Principals can exercise rights such as access, correction and erasure.
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides the purpose and means of processing personal data. A Data Processor processes data on its behalf. The Fiduciary remains responsible for compliance.
What is algorithmic bias?
It is unfair or skewed output from an analytics model, often because training data is unrepresentative or contains past prejudice. It leads to different treatment of similar people. Audits and human review help reduce it.
Does anonymised data fall under the DPDP Act?
The Act is concerned with personal data about an identifiable individual. Properly anonymised data that cannot identify anyone carries lower risk. You should still check that re-identification is not possible.