CS Professional · Environmental, Social and Governance (ESG) - Principles and Practice
Data Governance for CS Professional ESG Paper
Data governance is the set of policies, roles, controls and accountabilities that decide how an organisation collects, stores, uses, secures and shares data. For this chapter, you learn the framework, then the IT Act, 2000 provisions on access (s. 29), encryption (s. 84A) and traffic data monitoring (s. 69B), and apply them to company cases.
What this chapter covers
This chapter covers how organisations manage data as an asset and a risk. It starts with the concept and framework of data governance: ownership, policies, quality, security, privacy and accountability. It then moves to the Information Technology Act, 2000 and three specific provisions: access to computers and data (section 29), modes and methods for encryption (section 84A) and monitoring and collection of traffic data (section 69B). It closes with cyber security, data protection and corporate practice.
The IT Act portions are narrow and precise. You are expected to state what the section says, who holds the power, what duty falls on others and what safeguards or penalties apply. The framework portions are broader. You are expected to link them to what a company secretary actually does: policies, board oversight, disclosures and compliance checks.
The chapter sits in the Governance and Sustainability part of Paper 1, which carries 65 marks. Data governance connects to board-level governance, risk management (cyber risk is a core enterprise risk) and ESG reporting, where data security and privacy appear under the social and governance pillars. Use these links when you write case answers.
Paper 1 is a written, case-based paper, and this chapter lets you score through precise statutory answers and practical advice. Questions on narrow sections reward students who remember exact wording, such as who may authorise monitoring and what penalty applies. Questions on the framework reward structured answers that apply principles to a company's facts. Because the chapter ties to risk management and ESG reporting, the same material also helps you in other parts of the paper.
Data Governance: topics in the order to study them
- 1Concept and Framework of Data GovernanceIt gives you the vocabulary and structure that every later section and case answer builds on.
- 2Information Technology Act, 2000: OverviewYou need the Act's scope and its rule-making design before reading individual sections.
- 3Access to Computers and Data (Section 29)It is the shortest of the three sections and shows how a statutory power and a duty to assist are framed.
- 4Encryption Modes and Methods (Section 84A)It is a one-line enabling power, best learned together with the rule-making power in section 87.
- 5Monitoring and Collection of Traffic Data (Section 69B)It is the longest of the three, with authorisation, assistance, safeguards and penalty, so study it after the simpler ones.
- 6Cyber Security, Data Protection and Corporate PracticeIt brings the framework and the sections together into the compliance steps and board practices you will use in case answers.
How to prepare Data Governance
Treat this chapter as two layers: a framework you can explain in your own words and a few sections you must state accurately. Prepare both, then practise applying them to facts.
- Read the framework topic and build a one-page map: policy, roles, data quality, security, privacy, monitoring, accountability. Be ready to explain each in two lines.
- Read the IT Act overview and note that many details are left to rules made by the Central Government under section 87, including those for sections 69B and 84A.
- For section 29, learn the four elements: who (the Controller or a person authorised by him), when (reasonable cause to suspect a contravention of the provisions of that Chapter), what (access to computer system, apparatus, data or material) and the power to direct reasonable technical and other assistance.
- For section 84A, learn that the Central Government may prescribe modes or methods for encryption, for secure use of the electronic medium and for promotion of e-governance and e-commerce.
- For section 69B, learn the sequence: Central Government authorises an agency by notification, the intermediary or person in charge gives technical assistance, procedure and safeguards are prescribed, and intentional or knowing contravention by an intermediary is punishable with imprisonment up to one year, a fine up to one crore rupees, or both. Also learn the definition of traffic data.
- Write short practice answers in the format of provision, facts, analysis and conclusion. Use an Indian company example, such as a fintech firm asked for technical assistance by an authorised agency.
- Finish with the corporate practice topic: list board oversight, policies, access controls, incident response and disclosures, and tie each to the legal provisions you studied.
Common mistakes in Data Governance
Mixing up section 29 and section 69B powers
Fix: Remember that section 29 is the Controller's power tied to suspected contravention of that Chapter, while section 69B is an authorised Government agency's power tied to cyber security and traffic data.
Stating the old penalty under section 69B
Fix: Write the current text: imprisonment up to one year, or a fine up to one crore rupees, or both.
Treating section 84A as a compulsory encryption standard on companies
Fix: State it accurately: it is an enabling power of the Central Government to prescribe modes or methods, and the rules decide the detail.
Confusing traffic data with content
Fix: Use the definition: traffic data identifies persons, systems or locations and covers origin, destination, route, time, size, duration and type of service.
Writing theory without applying it to the facts
Fix: In every case answer, quote the rule briefly, link it to the named company and facts, and give a clear conclusion with a compliance action.
Ignoring the framework topics because they seem descriptive
Fix: Prepare a structured framework answer and the corporate practice list, since case questions often need both the law and the governance response.
Last-day revision: Data Governance
- Data governance means policies, roles and controls for how data is collected, stored, used, secured and shared.
- The IT Act, 2000 leaves many procedural details to rules made by the Central Government under section 87.
- Section 29: the Controller or a person he authorises may access computer systems and data if there is reasonable cause to suspect a contravention of the provisions of that Chapter.
- Section 29(2): the Controller may by order direct the person in charge to give reasonable technical and other assistance.
- Section 84A: the Central Government may prescribe modes or methods for encryption.
- Purpose stated in section 84A: secure use of the electronic medium and promotion of e-governance and e-commerce.
- Section 69B: the Central Government authorises a Government agency by notification to monitor and collect traffic data to enhance cyber security.
- Section 69B(2): the intermediary or person in charge must provide technical assistance and facilities for online access.
- Section 69B(3): procedure and safeguards are as prescribed.
- Section 69B(4): an intermediary who intentionally or knowingly contravenes sub-section (2) faces imprisonment up to one year, a fine up to one crore rupees, or both.
- Traffic data covers data identifying a person, system, network or location, including origin, destination, route, time, size, duration or type of service.
- Case answers: state the provision, apply the facts, conclude, then add practical compliance points.
Data Governance practice questions
- The Central Government notifies an agency to monitor and collect traffic data to enhance cyber security. The agency calls upon Dhwani Networ…
- An authorised Government agency, acting under a Section 69B notification, asks Nimbus Hosting, an intermediary, for technical assistance to …
- A company secretary is asked who lays down the procedure and safeguards that an authorised agency must follow while monitoring and collectin…
- A listed company's CS is preparing a note for the board on regulatory access to its systems. Which statement correctly distinguishes Section…
- Board member Rohit asks the CS how the Digital Personal Data Protection Act, 2023 changed the Information Technology Act, 2000 for compensat…
- CERT-In calls upon Deccan Data Centres Ltd to furnish information on a ransomware incident affecting its clients and directs it to apply cer…
- Veda Textiles Ltd, a listed company, asks its company secretary who has the power to prescribe the modes or methods of encryption that compa…
- A compliance officer reviews what counts as 'traffic data' under Section 69B for her company's data governance policy. Which item falls with…
Data Governance in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Data Governance: frequently asked questions
Which sections of the IT Act matter in the Data Governance chapter?
The chapter focuses on section 29 (access to computers and data), section 84A (modes or methods for encryption) and section 69B (monitoring and collection of traffic data). Also know section 87, which gives the Central Government rule-making power, including for 69B and 84A.
Who can access a computer system under section 29?
The Controller or any person authorised by him, if there is reasonable cause to suspect a contravention of the provisions of that Chapter. The Controller may also direct the person in charge to give reasonable technical and other assistance.
What is the penalty under section 69B of the IT Act?
An intermediary who intentionally or knowingly contravenes the duty to provide technical assistance under section 69B(2) is punishable with imprisonment up to one year, or a fine up to one crore rupees, or both.
Do I need to memorise section numbers for this chapter?
Yes for the three named sections, because answers should cite the provision. Learn the substance first, then attach the section number, and apply both to the facts in the question.