Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics

A company uses analytics on employee and customer personal data to monitor insider trading risk and governance lapses. Under the Digital Personal Data Protection Act, 2023, which approach is consistent with the Act's core principle for such processing?

The consistent approach is to process personal data only for a lawful purpose, relying on consent or a recognised legitimate use, and to confine it to the specified purpose. The Act gives no blanket exemption for analytics or general business needs.

  1. AProcess the personal data for any purpose, since the company is a Data Fiduciary with legitimate business needs
  2. BProcess personal data only for a lawful purpose, with consent or a recognised legitimate use, and for the specified purposeCorrect
  3. CProcess personal data freely if the output is anonymised only after the analysis is complete and reported
  4. DProcess personal data without notice because analytics is exempt from all obligations

Explanation

The DPDP Act permits processing only for a lawful purpose, based on consent or a specified legitimate use, with purpose limitation in mind. There is no blanket exemption for analytics or for business convenience, and post-hoc anonymisation does not remove the lawful basis requirement.

Did you get it right without looking?

One question tells you little. A timed set on Data Analytics shows your real accuracy, how long you take and where you lose marks.

More Data Analytics questions