Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Data Analytics and Law

Under Section 43A of the Information Technology Act, 2000, a body corporate that handles sensitive personal data in a computer resource it owns, controls or operates becomes liable to pay compensation when which of the following conditions is met?

Section 43A imposes compensation liability when a body corporate handling sensitive personal data is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to someone. Mere occurrence of a breach, or offshore storage, does not by itself create liability.

  1. AIt is negligent in implementing and maintaining reasonable security practices and procedures, and this causes wrongful loss or wrongful gain to any personCorrect
  2. BIt stores any personal data on a cloud server located outside India
  3. CIt fails to appoint a data protection officer within thirty days
  4. DIt suffers any cyber attack, whether or not it was negligent

Explanation

Section 43A makes liability depend on negligence in implementing and maintaining reasonable security practices and procedures, together with resulting wrongful loss or wrongful gain to a person. A cyber attack alone does not trigger liability, so the last option is wrong. Offshore storage and a data protection officer are not conditions in the section.

Did you get it right without looking?

One question tells you little. A timed set on Data Analytics and Law shows your real accuracy, how long you take and where you lose marks.

More Data Analytics and Law questions