Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Computer Hardware and Software

Kaveri Pharma uses a cloud provider whose data centres are located outside India to store employee personal data. The company's board asks the Company Secretary to identify the most appropriate compliance step from a technology and cyber law viewpoint. Which is the best course?

The company should review the cloud contract for security safeguards, data location, breach notification and Indian data protection and IT law requirements, because it stays accountable for the personal data. Contractual clauses cannot remove statutory duties, and outsourcing infrastructure does not transfer accountability to the provider.

  1. ANo review is needed because the provider owns the infrastructure
  2. BAssess the contract for security safeguards, data location, breach notification and applicable Indian data protection and IT law obligations, since the company remains accountable for the dataCorrect
  3. CTransfer all legal liability to the provider through a clause, which removes the company's obligations
  4. DStore the data only in plain text to allow easy audit by the provider

Explanation

Outsourcing storage does not remove the data fiduciary's or body corporate's duty to protect personal data under the IT Act and data protection law. Due diligence on safeguards, location, breach reporting and contractual terms is needed. A liability clause cannot extinguish statutory obligations, and plain-text storage weakens security.

Did you get it right without looking?

One question tells you little. A timed set on Computer Hardware and Software shows your real accuracy, how long you take and where you lose marks.

More Computer Hardware and Software questions