Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Database Management
Database Security and Legal Aspects for CS Professional
Updated 11 October 2026 · Fact-checked
Database security means protecting stored data so it stays confidential, accurate and available. You do this with access control, encryption, backup, audit logs and secure coding against threats like SQL injection. In India, the IT Act, 2000, the SPDI Rules, 2011 and the DPDP Act, 2023 make these safeguards a legal duty.
Understand Database Security and Legal Aspects
A database holds the most valuable thing a company has: its data. Customer records, payroll, contracts and financial figures all sit there. If someone steals, changes or deletes this data, the business suffers and the law may hold the company responsible.
Security rests on three goals, called the CIA triad. Confidentiality means only authorised people see the data. Integrity means the data is accurate and is not changed without permission. Availability means authorised users can reach the data when needed. Every control you learn serves one or more of these goals.
The main controls are these:
- Access control: authentication (proving who you are), authorisation (what you may do) and the least privilege rule (give only the rights needed for the job). Role-based access groups users by role.
- Encryption: scrambles data so it is useless without the key. Use it for data at rest (stored) and in transit (moving over a network).
- Backup and recovery: regular copies, kept safely and tested by restoring them, so data survives deletion, ransomware or hardware failure.
- Audit: logs of who accessed or changed what and when. Logs support detection, investigation and proof of compliance.
- Secure coding and patching: validating input and applying updates so known flaws cannot be exploited.
Common threats include SQL injection (attacker types database commands into an input field and the application runs them), weak or default passwords, insider misuse, unpatched software, malware and ransomware, and misconfigured or exposed servers. SQL injection works because the application mixes user input with the query text. The best defence is parameterised queries, where input is always treated as data and never as a command.
The law adds duties on top. Under the Information Technology Act, 2000, Section 43A requires a body corporate handling sensitive personal data to keep reasonable security practices, and it must pay compensation for wrongful loss or gain caused by negligence. The SPDI Rules, 2011 explain what counts as reasonable security and mention IS/ISO/IEC 27001 as one accepted standard. Section 72A punishes disclosure of personal information in breach of a lawful contract. The Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to take reasonable security safeguards, to inform the Data Protection Board and affected Data Principals of a personal data breach, and it provides heavy monetary penalties. The DPDP Rules, 2025 bring its provisions into force in phases, so check the commencement position in your study material and the latest update.
Key rules to remember
- CIA triad
- Security = Confidentiality + Integrity + Availability
- Link each control in your answer to the goal it protects.
- Least privilege
- User rights = minimum rights needed for the job
- Pair it with role-based access control and periodic review of rights.
- Backup rule of thumb (3-2-1)
- 3 copies of data, on 2 different media, 1 copy off-site
- A common good practice, not a legal rule. A backup is reliable only if you test the restore.
- SQL injection defence
- Parameterised query + input validation + least-privilege database account
- Never build a query by joining user input into the SQL text.
- Section 43A, IT Act, 2000
- Negligence in keeping reasonable security practices for sensitive personal data → compensation for wrongful loss or gain
- Applies to a body corporate that possesses, deals with or handles such data in a computer resource it owns, controls or operates.
- Reasonable security practices (SPDI Rules, 2011)
- Documented information security programme and policy, matched to the data held; IS/ISO/IEC 27001 is one recognised standard
- A body corporate may follow another standard if it is approved and notified by the Central Government.
- DPDP Act, 2023: duties of Data Fiduciary
- Reasonable security safeguards + breach intimation to the Board and affected Data Principals
- Penalty for failing to take reasonable security safeguards can reach ₹250 crore as per the Act's Schedule.
How to solve Database Security and Legal Aspects questions
Use this method for any question on database security, a breach scenario or the legal position of a company holding data.
- 1Identify what is at stake: type of data (personal, sensitive, financial) and which CIA goal is hit.
- 2Name the threat or weakness in the facts, such as SQL injection, weak password, insider misuse or unencrypted backup.
- 3List the technical controls that fix it: access control, encryption, backup, audit logs, patching, secure coding.
- 4Add organisational controls: security policy, staff training, vendor contracts, incident response plan.
- 5State the legal provision: Section 43A and SPDI Rules for the IT Act position, Section 72A if disclosure breaches a contract, and DPDP Act duties on safeguards and breach intimation.
- 6Apply the law to the facts: was security reasonable, was there negligence, who is the Data Fiduciary or body corporate, what is the likely liability.
- 7Conclude with clear advice: immediate steps, compliance actions and what to document.
Quickest way: Threat, control, law in three lines
When to use it: When you have little time or the question carries few marks and asks you to explain, list or advise.
- Write the threat in one line and the CIA goal it breaks.
- Write four or five controls as bullets, each with a half-line reason.
- Close with the law: Section 43A with SPDI Rules, and the DPDP Act safeguard and breach duties, applied to the facts in one or two lines.
Common mistakes in Database Security and Legal Aspects
Listing controls without linking them to the threat in the question.
Students memorise a generic list of security measures.
Fix: Pick controls that answer the exact threat. For SQL injection, lead with parameterised queries and input validation, not just encryption.
Saying encryption alone makes a database secure.
Encryption sounds like a complete answer.
Fix: State that security is layered. Encryption protects data at rest and in transit, but it does not stop SQL injection or misuse by a user with valid rights.
Treating backup as a security control only for hardware failure.
Backups are taught under data recovery.
Fix: Mention ransomware, deletion and integrity loss too. Add that backups should be protected, kept off-site and restore-tested.
Quoting Section 43A as a criminal punishment.
Students mix up compensation and offence provisions.
Fix: Section 43A gives compensation for negligence in protecting sensitive personal data. Disclosure in breach of a lawful contract is the offence under Section 72A.
Ignoring the DPDP Act, 2023 or treating it as fully replacing every older rule at once.
Students learn either the old regime or the new Act, not the transition.
Fix: Name both. Explain that the DPDP Act sets security safeguard and breach intimation duties, and note that its provisions come into force in phases under the notified Rules.
Giving a legal answer with no conclusion on the facts.
Students stop after stating the section.
Fix: Always finish with analysis: was security reasonable, what compensation or penalty risk exists, and what the company should do now.
Worked examples
Example 1
A web application of Kaveri Retail Ltd builds this query: SELECT * FROM customers WHERE email = '
Show the solution
- Correction of the question: the query is built as SELECT * FROM customers WHERE email = '<input>' where <input> is whatever the user types in the login box.
- An attacker types: ' OR '1'='1
- The query becomes: SELECT * FROM customers WHERE email = '' OR '1'='1'
- The condition '1'='1' is always true, so the WHERE clause is true for every row and the database returns all customer records.
- Cause: the application joins user input into the query text, so the database cannot tell data from command.
- Fix: use parameterised (prepared) queries so input is always treated as a value. Also validate input, run the application with a least-privilege database account that cannot read or alter unrelated tables, hide detailed error messages, patch the software and log suspicious queries.
Answer: The attacker input makes the WHERE condition always true and exposes all rows. This is SQL injection. The main fix is parameterised queries, supported by input validation, least privilege, error handling, patching and audit logs.
Example 2
Meridian Finserv Ltd, an Indian company, stores customers' bank account details and passwords in its database. A former employee, whose access was never removed, copies the data and sells it. Customers have suffered financial loss. The company had no written security policy. Advise the company on its legal position and the steps to take.
Show the solution
- Identify the data and the failure: bank account details and passwords are sensitive personal data. Failures: access of a former employee not withdrawn, no audit review of access, no written security policy.
- IT Act position: Meridian is a body corporate handling sensitive personal data. Section 43A makes it liable to pay compensation for wrongful loss caused by negligence in keeping reasonable security practices. The SPDI Rules, 2011 expect a documented information security programme and policy. Having none weakens its defence.
- The former employee: unauthorised access and copying of data are contraventions under the IT Act, and the employee can face penal action. Selling the data in breach of the confidentiality terms may also attract Section 72A.
- DPDP Act, 2023: Meridian is a Data Fiduciary. It must take reasonable security safeguards and must inform the Data Protection Board and each affected Data Principal of the breach. Failure to take reasonable safeguards can attract a penalty, up to ₹250 crore under the Act's Schedule. Check which provisions are in force on the date of the incident.
- Immediate steps: remove all stale accounts, change passwords, contain the breach, preserve logs for evidence, report the incident to CERT-In as required under the applicable directions, and file a complaint with the police against the former employee.
- Preventive steps: adopt a written security policy aligned to IS/ISO/IEC 27001, enforce role-based access with least privilege, deprovision access on exit, encrypt sensitive fields and store passwords as hashes, monitor audit logs, take protected backups and train staff.
- Conclusion: Meridian is exposed to compensation claims and regulatory penalty because its safeguards were not reasonable. It should act on breach response now and fix its controls to reduce future liability.
Answer: Meridian is likely liable for negligence under Section 43A and the SPDI Rules, and faces DPDP Act duties on safeguards and breach intimation. The former employee faces action under the IT Act, including Section 72A where applicable. Meridian should contain and report the breach, preserve evidence, and adopt a written policy with access control, encryption, audit and backup.
Exam tips
- Structure every case answer as facts, controls, law, conclusion. Examiners reward a clear conclusion on the given facts.
- Learn Section 43A, Section 72A, the SPDI Rules and DPDP Act duties as a set, and say which is compensation and which is an offence.
- For SQL injection, show a short example query and the parameterised fix. It proves understanding quickly.
- Mention both the old IT Act provisions and the DPDP Act, 2023, and note the phased commencement instead of claiming one has fully replaced the other.
- Add practical compliance points, such as a written policy, access reviews, log retention and an incident response plan, to earn drafting and practice marks.
Practice questions from Database Management
- A company changes the physical storage of its employee records by adding an index and moving files to a new disk, and no application program…
- A company wants a data model in which records are organised as a tree, each child record having exactly one parent, and access follows fixed…
- Which of the following is a characteristic traditionally used to define big data, along with volume and variety?
- A fintech firm's DBMS lets the marketing team see only customer names and cities, while hiding PAN and Aadhaar columns stored in the same ba…
- In a bank's database, the customer table has the column AccountNo as its unique identifier, and the loan table has a column AccountNo that m…
Database Security and Legal Aspects: frequently asked questions
How do you secure a database from SQL injection?
Use parameterised queries so user input never becomes part of the command. Add input validation, run the application with a least-privilege database account, hide detailed error messages and keep software patched. Audit logs help you spot attempts early.
What are the main database security measures?
Access control with authentication and least privilege, encryption of data at rest and in transit, regular tested backups, audit logging, patching and secure coding. Policy and staff training support these technical measures.
Which Indian laws apply to database security?
The Information Technology Act, 2000 applies, especially Section 43A, Section 72A and the SPDI Rules, 2011. The Digital Personal Data Protection Act, 2023 adds duties on reasonable security safeguards and breach intimation for Data Fiduciaries. Read the commencement position in your study material.
What is the difference between Section 43A and Section 72A of the IT Act?
Section 43A deals with compensation when a body corporate is negligent in protecting sensitive personal data and causes wrongful loss or gain. Section 72A is a penal provision for disclosing personal information in breach of a lawful contract.