Skip to content

CS Professional · Environmental, Social and Governance (ESG) - Principles and Practice · Data Governance

Nakshatra Pay Ltd's board is drafting its data governance framework. The company has a contract with a bank specifying the security practices to be followed for customer data, and no other law prescribes any. Which statement correctly reflects what counts as 'reasonable security practices and procedures' under section 43A of the IT Act, 2000?

The practices specified in the agreement between the parties govern. Section 43A treats reasonable security practices as those set out in an agreement or in law, and only if neither exists do the practices prescribed by the Central Government apply.

  1. APractices specified in the agreement between the parties apply, and the Central Government's prescribed practices apply only in the absence of an agreement or lawCorrect
  2. BOnly practices prescribed by the Central Government count, regardless of any agreement
  3. COnly practices decided by the company's board count
  4. DPractices are reasonable only if they include encryption modes under section 84A

Explanation

The Explanation to section 43A says reasonable security practices are those specified in an agreement between the parties or in any law in force, and failing both, those prescribed by the Central Government. Here the contract exists, so it governs. Section 84A only empowers the Government to prescribe encryption modes and does not define reasonableness.

Did you get it right without looking?

One question tells you little. A timed set on Data Governance shows your real accuracy, how long you take and where you lose marks.

More Data Governance questions