Skip to content

CS Professional · Environmental, Social and Governance (ESG) - Principles and Practice · Data Governance

Sunrise Retail Ltd, an Indian company, stores customers' sensitive personal data on its own servers. Its IT head skipped basic security procedures, and a breach caused wrongful loss to several customers. Under the Information Technology Act, 2000, what is the company's exposure?

The company must pay damages by way of compensation to the affected persons. Section 43A makes a body corporate liable when negligence in maintaining reasonable security practices over sensitive personal data in its own computer resource causes wrongful loss or wrongful gain to anyone.

  1. ALiable to pay damages by way of compensation to the persons affectedCorrect
  2. BLiable only to a warning from the Controller
  3. CNo liability, as data is stored on its own servers
  4. DLiable only if the customers had signed a written agreement

Explanation

Section 43A applies where a body corporate handling sensitive personal data in a computer resource it owns, controls or operates is negligent in maintaining reasonable security practices and thereby causes wrongful loss or gain. It must pay damages by way of compensation. Owning the servers is a condition for the section, not a defence, and a written agreement is only one way of specifying the security standard.

Did you get it right without looking?

One question tells you little. A timed set on Data Governance shows your real accuracy, how long you take and where you lose marks.

More Data Governance questions