Section 43A and Data Protection Today
Chapter One Hundred Three
Syllabus topic 4, "Cyber crimes under the Information Technology Act"
Pages 498 to 501 of 802
In one line
A body corporate that handles sensitive personal data and is negligent about reasonable security practices must compensate anyone it thereby causes wrongful loss or wrongful gain to, and the section survives until the eighteen month tranche of the 2023 data protection statute takes effect.
In the wording a student can write in an exam: section 43A of the Information Technology Act, 2000 provides that where a body corporate possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, it shall be liable to pay damages by way of compensation to the person so affected.
Why the section was inserted
Section 43 protects the owner of the system. It gives a remedy to the person whose computer was accessed or whose data was copied. It gives nothing to the individual whose personal information was in that data.
Section 43A gives the individual a remedy. It was inserted by Act 10 of 2009 with effect from 27 October 2009, and for fourteen years it was the whole of India's statutory data protection law.
The provision itself
The four ingredients.
One, a body corporate. Defined in the Explanation as any company, and including a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities.
Two, sensitive personal data or information possessed, dealt with or handled in a computer resource which the body corporate owns, controls or operates. Defined in the Explanation as such personal information as may be prescribed by the Central Government in consultation with such professional bodies or associations as it thinks fit.
Three, negligence in implementing and maintaining reasonable security practices and procedures. Defined in the Explanation as practices and procedures designed to protect the information from unauthorised access, damage, use, modification, disclosure or impairment, as specified in an agreement between the parties, or as specified in any law for the time being in force, and, in the absence of either, as prescribed by the Central Government in consultation with professional bodies.
Four, causation of wrongful loss or wrongful gain to any person.
The consequence. Liability to pay damages by way of compensation to the person so affected.
Broken down
The standard is set by the parties first. The Explanation puts an agreement between the parties ahead of any law and ahead of anything the Government prescribes. So a contract can fix what "reasonable" means for the purposes of this section.
Only then a law, and only then the rules. If there is no agreement, a statute governs; if there is neither, the prescribed practices apply.
The rest of this chapter
Module one is free. The rest of this chapter comes with the LL.M. Criminal Law and Criminal Administration Semester 1 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or notes only: ₹499
Or solved papers only: ₹499
Free either way: question papers, the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.