Skip to content

Environmental, Social and Governance (ESG) - Principles and Practice · Data Governance

Cyber Security and Data Protection for Companies in India

Updated 11 October 2026 · Fact-checked

Cyber security and data protection practice means a company protects data with policies, technical controls and accountable people, so it meets legal duties under the IT Act, 2000 and the DPDP Act, 2023. In an answer, state the provision, apply it to the facts, then conclude with the compliance steps.

Understand Cyber Security, Data Protection and Corporate Practice

Data is a company asset and a source of risk. A breach can cause loss to customers, penalties, and damage to trust. For this reason, regulators and ESG frameworks treat data security as a governance issue and not only an IT issue.

Start with two ideas. Cyber security protects systems and data from unauthorised access, damage, use, modification, disclosure or impairment. Data protection governs how personal data is collected, used and kept, and what rights people have over it. Security is a tool; protection is the legal duty it serves.

The IT Act, 2000 gives several hooks. Section 43A makes a body corporate that handles sensitive personal data in a computer resource it owns, controls or operates liable to pay compensation if it is negligent in keeping reasonable security practices and thereby causes wrongful loss or wrongful gain. Section 70B makes CERT-In the national agency for cyber incidents. It can call for information and give directions to service providers, intermediaries, data centres, body corporates and others. Section 69B lets the Central Government authorise an agency to monitor and collect traffic data for cyber security. Section 66F punishes cyber terrorism.

The DPDP Act, 2023 adds duties for Data Fiduciaries. Under section 10, the Central Government may notify a Data Fiduciary or class as a Significant Data Fiduciary based on factors such as volume and sensitivity of data and risk to Data Principals. Such a fiduciary must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits. Section 17 lists exemptions, for example for processing needed for a court-approved scheme of merger or demerger.

In practice, the board owns the risk. The company adopts a data governance and information security policy, assigns roles, controls access, trains staff, tests incident response, and reports on it. The Company Secretary links the policy to the law, the board and disclosures.

Key rules to remember

IT Act s. 43A liability test
Body corporate + sensitive personal data in a computer resource it owns, controls or operates + negligence in reasonable security practices + wrongful loss or gain = compensation to the affected person
All elements must be present. The remedy is damages by way of compensation.
Reasonable security practices (s. 43A Explanation)
Practices to protect against unauthorised access, damage, use, modification, disclosure or impairment, as set by agreement, by law, or else as prescribed by the Central Government
This is the order of reference: agreement or law first, then the prescribed standard.
Significant Data Fiduciary duties (DPDP s. 10(2))
Data Protection Officer (based in India, responsible to the Board, grievance contact) + independent data auditor + periodic DPIA + periodic audit + other prescribed measures
Applies only after the Central Government notifies the fiduciary or class under s. 10(1).
CERT-In powers (IT Act s. 70B(6) and (7))
May call for information and give directions; failure to comply: imprisonment up to one year, or fine up to ₹1 crore, or both
Court takes cognizance only on a complaint by an authorised officer of the agency (s. 70B(8)).
Traffic data monitoring (IT Act s. 69B)
Central Government notifies an agency; intermediary must give technical assistance; intentional or knowing contravention: up to one year imprisonment or fine up to ₹1 crore, or both
The penalty applies to an intermediary. Procedure and safeguards are as prescribed.

How to solve Cyber Security, Data Protection and Corporate Practice questions

Use this method for any case or policy question on cyber security and data protection.

  1. 1Read the facts and list who the company is: body corporate, Data Fiduciary, intermediary or possible Significant Data Fiduciary.
  2. 2Identify the data involved: sensitive personal data, personal data, or traffic data.
  3. 3Name the event or issue: a breach, a government or CERT-In request, a policy gap, or an audit requirement.
  4. 4State the provision in plain words with its exact conditions, and cite a section only when you are sure of it.
  5. 5Apply each condition to the facts one by one, and note which condition is met or missing.
  6. 6Conclude on liability or compliance, such as compensation payable or duty to assist.
  7. 7Add practical steps: policy, access controls, incident response, training, board reporting, and documentation.
  8. 8Link to ESG: say how the governance step reduces data privacy and cyber risk and supports disclosures.

Quickest way: Who, what data, which duty

When to use it: Use this when time is short and the question has a short fact pattern.

  1. Who is the entity? Pick the label: body corporate, Data Fiduciary, Significant Data Fiduciary or intermediary.
  2. What data? Sensitive personal data points to s. 43A. Traffic data points to s. 69B. A cyber incident points to s. 70B.
  3. Which duty or liability follows? Write it in one sentence.
  4. Finish with two or three controls the board should put in place.

Common mistakes in Cyber Security, Data Protection and Corporate Practice

  • Treating s. 43A as applying to any company that suffers a breach.

    Students remember the heading and skip the conditions.

    Fix: Check for sensitive personal data, negligence in reasonable security practices, and wrongful loss or gain. Without negligence there is no s. 43A liability.

  • Saying every company must appoint a Data Protection Officer under DPDP s. 10.

    The DPO duty is remembered without its trigger.

    Fix: Section 10(2) applies to a Significant Data Fiduciary, which the Central Government must notify under s. 10(1).

  • Mixing up the s. 69B and s. 70B roles.

    Both deal with cyber security and agencies.

    Fix: Remember s. 69B as monitoring and collecting traffic data by an authorised agency. Remember s. 70B as CERT-In, the national incident response agency.

  • Stating the old penalty figures, such as three years or one lakh.

    Older notes are still in circulation.

    Fix: Use the current text: up to one year or a fine up to ₹1 crore, or both, under ss. 69B(4) and 70B(7).

  • Writing only the law and leaving out practical compliance steps.

    Students treat it as a pure law question.

    Fix: Always add policy, controls, audit, training and board oversight, since the paper is case based.

  • Assuming the DPDP Act applies with no exemptions.

    Section 17 is skipped.

    Fix: Check s. 17 for exemptions, such as processing for enforcing a legal right or for a court-approved merger or demerger scheme.

Worked examples

Example 1

Nilgiri Finserve Ltd, a company, stores customers' sensitive personal data on its own servers. It ignored known security gaps and did not maintain reasonable security practices. Hackers accessed the data and a customer, Meera, suffered wrongful loss. Advise on liability and the practical steps the board should take.

Show the solution
  1. Provision: s. 43A of the IT Act makes a body corporate liable to pay compensation where it handles sensitive personal data in a computer resource it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices, and thereby causes wrongful loss or wrongful gain to any person.
  2. Entity: Nilgiri is a company, so it is a body corporate.
  3. Data and system: the data is sensitive personal data held on its own servers, so it owns, controls or operates the resource.
  4. Negligence: it ignored known gaps, so it failed to maintain reasonable security practices.
  5. Loss: Meera suffered wrongful loss as a result.
  6. Conclusion: all elements are met, so Nilgiri is liable to pay damages by way of compensation to Meera.
  7. Practical steps: adopt an information security policy, close known vulnerabilities, restrict access, encrypt data, run periodic audits, train staff, set up incident response including reporting to CERT-In as directed, and have the board review cyber risk regularly.

Answer: Nilgiri Finserve Ltd is liable under s. 43A of the IT Act to compensate Meera, because it was negligent in maintaining reasonable security practices over sensitive personal data. The board should put in place a documented security policy, controls, audits and incident response.

Example 2

A large online platform, Bharat Retail Pvt Ltd, has been notified by the Central Government as a Significant Data Fiduciary under the DPDP Act, 2023. List the additional obligations it must meet and the role of the Data Protection Officer.

Show the solution
  1. Provision: s. 10(2) sets out the added duties of a Significant Data Fiduciary, which arise because of notification under s. 10(1).
  2. Duty 1: appoint a Data Protection Officer.
  3. Role of the DPO: represents the fiduciary under the Act, is based in India, is an individual responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal.
  4. Duty 2: appoint an independent data auditor to evaluate compliance with the Act.
  5. Duty 3: carry out periodic Data Protection Impact Assessment, covering the rights of Data Principals, the purpose of processing, and assessment and management of risk to those rights.
  6. Duty 4: undertake periodic audit and other prescribed measures.
  7. Practical point: the company Secretary should maintain the DPIA and audit records and report to the board.

Answer: Bharat Retail must appoint an India-based Data Protection Officer who is responsible to the Board and handles grievances, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits, along with any other prescribed measures.

Exam tips

  • Quote the conditions of s. 43A in order: body corporate, sensitive data, negligence, wrongful loss or gain. Examiners reward the analysis.
  • Use the correct penalty figures: up to one year or fine up to ₹1 crore, or both, for ss. 69B(4) and 70B(7).
  • Close each answer with practical compliance steps such as policy, audit, training and board reporting.
  • Do not cite a section number you are unsure of. State the rule in plain words instead.
  • Link data security to ESG governance and risk in a sentence or two to show wider understanding.

Practice questions from Data Governance

Cyber Security, Data Protection and Corporate Practice: frequently asked questions

What is the difference between cyber security and data protection?

Cyber security is about protecting systems and data from attacks and misuse. Data protection is about the lawful handling of personal data and the rights of individuals. A company needs both, and security controls help meet the legal duties.

Who is a Significant Data Fiduciary?

It is a Data Fiduciary or class of fiduciaries notified by the Central Government under s. 10 of the DPDP Act. The assessment considers factors such as volume and sensitivity of data and risk to Data Principals.

What does CERT-In do?

The Indian Computer Emergency Response Team is the national agency for cyber incident response under s. 70B. It collects and analyses incident information, issues alerts and guidelines, and can direct companies to provide information.

Is compensation under s. 43A automatic after a data breach?

No. The company must have been negligent in implementing and maintaining reasonable security practices, and that negligence must cause wrongful loss or wrongful gain. Both must be shown on the facts.