Skip to content

CS Professional · Environmental, Social and Governance (ESG) - Principles and Practice · Data Governance

Nirmal Pharma Ltd's board is checking what 'reasonable security practices and procedures' means when no contract with its data providers specifies any standard and no law prescribes one. Under the IT Act, 2000, which standard then applies?

The practices prescribed by the Central Government, in consultation with professional bodies or associations, apply. Under Section 43A, reasonable security practices are first those in an agreement or law; only when neither exists does the Central Government's prescribed standard become the benchmark.

  1. AWhatever the company's board decides internally
  2. BPractices prescribed by the Central Government in consultation with professional bodies or associationsCorrect
  3. CPractices set by the Controller case by case
  4. DPractices set by the Chairperson of the Data Protection Board

Explanation

The Explanation to Section 43A states that reasonable security practices are those specified in an agreement or in any law in force. In the absence of both, they are those prescribed by the Central Government in consultation with professional bodies or associations it deems fit. Internal board choice is not the statutory fallback.

Did you get it right without looking?

One question tells you little. A timed set on Data Governance shows your real accuracy, how long you take and where you lose marks.

More Data Governance questions