Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law

Sahyadri Insurance Ltd., a body corporate, stores sensitive personal data of policyholders in its own servers and uses it for big data analytics. Because it failed to maintain reasonable security practices, a breach caused wrongful loss to a policyholder. Under the Information Technology Act, 2000, what is the consequence for the company?

The company must pay damages by way of compensation to the affected policyholder. Section 43A applies where a body corporate handling sensitive personal data is negligent in maintaining reasonable security practices and thereby causes wrongful loss or wrongful gain to any person. Lawful analytics use does not excuse that negligence.

  1. AIt is liable to pay damages by way of compensation to the affected person, because it was negligent in implementing and maintaining reasonable security practicesCorrect
  2. BIt is liable only if the policyholder shows the company gained wrongfully, since wrongful loss alone does not suffice
  3. CIt escapes liability because analytics use is a lawful purpose
  4. DIt is liable only to an imprisonment term, not compensation

Explanation

Section 43A makes a body corporate handling sensitive personal data in a computer resource it owns, controls or operates liable to pay compensation where negligence in reasonable security practices causes wrongful loss or wrongful gain. Wrongful loss or wrongful gain is enough, so the second option is wrong. Lawful analytics purpose does not remove the duty to secure data, and the remedy is compensation.

Did you get it right without looking?

One question tells you little. A timed set on Data Analytics and Law shows your real accuracy, how long you take and where you lose marks.

More Data Analytics and Law questions