Skip to content

CS Professional · Internal and Forensic Audit · Cyber Forensics

Sunrise Pharma Ltd, a company holding customers' sensitive personal data on servers it owns and operates, ignores basic access controls. A hacker exploits this and the data leak causes wrongful loss to several customers. Under Section 43A of the Information Technology Act, 2000, what is the primary consequence for the company?

The company must pay damages by way of compensation to the affected persons. Section 43A makes a body corporate liable when it is negligent in maintaining reasonable security practices for sensitive personal data and this causes wrongful loss or wrongful gain to anyone.

  1. AIt is liable to pay damages by way of compensation to the persons affectedCorrect
  2. BIt is liable only to imprisonment of its directors for life
  3. CIt escapes liability if the data was stored in a computer resource it controls
  4. DIt is liable only to a notice from the Indian Computer Emergency Response Team

Explanation

Section 43A applies where a body corporate handling sensitive personal data is negligent in implementing and maintaining reasonable security practices and thereby causes wrongful loss or gain. The remedy is damages by way of compensation to the affected person. Life imprisonment relates to cyber terrorism, not this section.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Forensics shows your real accuracy, how long you take and where you lose marks.

More Cyber Forensics questions