By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
ApniLawApniLawApniLaw
  • Home
  • Law Forum
  • Find Lawyers
  • Legal Services
  • Legal News
  • Legal Jobs
  • Legal Articles
    • Documentation
    • Marriage and Divorce
    • Land Dispute & Will
    • Civil
    • Criminal
    • Supreme Court
    • High Court
  • Bare Acts
    • BNSS
    • BNS
    • BSA
    • CrPC
    • DPDP
    • Hindu Marriage Act
    • IPC
    • POCSO
Reading: Section 43A of IT Act: When Can Companies Be Sued For Data Breach
Share
Notification Show More
Font ResizerAa
ApniLawApniLaw
Font ResizerAa
  • Supreme Court
  • High Court
  • Acts
  • Documentation
  • BNSS
  • Home
  • Law Forum
  • Find Lawyers
  • Legal Services
  • Legal News
  • Legal Jobs
  • Legal Articles
    • Documentation
    • Marriage and Divorce
    • Land Dispute & Will
    • Civil
    • Criminal
    • Supreme Court
    • High Court
  • Bare Acts
    • BNSS
    • BNS
    • BSA
    • CrPC
    • DPDP
    • Hindu Marriage Act
    • IPC
    • POCSO
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
ApniLaw > Blog > Acts > Section 43A of IT Act: When Can Companies Be Sued For Data Breach
Acts

Section 43A of IT Act: When Can Companies Be Sued For Data Breach

Amna Kabeer
Last updated: April 27, 2025 8:57 am
Amna Kabeer
1 month ago
Share
Data Breach
Data Breach
SHARE


Introduction: Companies Liable for Data Breaches Under Section 43A

The Information Technology (IT) Act, 2000 governs digital activities in India. It provides legal recognition to electronic records and digital signatures. It also sets rules for cybercrime, data protection, and electronic governance.
Under Section 43A of the IT Act, 2000, companies must protect sensitive personal data. If they fail to follow reasonable security practices, they can face legal action. Victims of data breaches can sue for compensation if negligence is proven.
The law, hence, holds companies accountable for weak data protection measures.

Contents
Introduction: Companies Liable for Data Breaches Under Section 43AWhat Is Section 43A Of The Information Technology Act, 2000?Who Is a Body Corporate Under Section 43A of the IT Act?What Are The SPDI Rules Under The IT Act?AnalysisConclusion


What Is Section 43A Of The Information Technology Act, 2000?


According to Section 43A of the IT act, if a company owns, controls, or operates a system that handles sensitive personal data, it must follow strong security practices.
When a company fails to do so due to negligence, it can cause harm. This includes wrongful loss or gain to individuals.
In such cases, the company must compensate the affected person. The law holds the company responsible for not protecting data properly.


Who Is a Body Corporate Under Section 43A of the IT Act?


Section 43A of IT Act, 2000 defines “body corporate” broadly. It includes companies, firms, sole proprietorships, and associations of individuals.
These entities must be involved in commercial or professional activities. This definition matters because Section 43A applies only to them.
They are responsible for protecting sensitive personal data in any computer system they own, control, or operate. Failure to secure such data can lead to compensation claims.

What Are The SPDI Rules Under The IT Act?


The (Sensitive Personal Data or Indormation) SPDI Rules fall under the IT Act, 2000. They were notified in 2011 under Section 87(2) with Section 43A. These rules apply to all companies and individuals in India.


SPDI includes: Passwords, Bank details and card information, Health records, Sexual orientation, Biometric data


Companies must get written consent before collecting SPDI.


Users can withdraw consent or update their data at any time.


SPDI can only be shared with third parties if: The user consents, or it’s required by law.
Data transfers are allowed if the recipient ensures equal protection and if the transfer is necessary for a contract or done with consent.
Firms must follow reasonable security practices.
Standards like IS/ISO/IEC 27001 are recommended for compliance.
SPDI should not be stored longer than needed.
Delete the data once the purpose is fulfilled.
Every company must appoint a grievance officer. Complaints must be resolved within 30 days.


Analysis


The SPDI Rules provide extra compliance guidelines.
They cover how companies should collect, store, and share sensitive personal data.
Experts debate whether Section 43A and the SPDI Rules fully align with the IT Act.
The IT Act mainly covers digital communication and electronic records.
A company is liable only if negligence causes wrongful gain or loss. Without proven harm, compensation under Section 43A does not apply.


Conclusion


In conclusion, a company must follow proper data protection practices.
If it fails to do so and causes wrongful loss or gain, it must pay compensation. This applies when negligence leads to harm due to poor data security. Therefore, Section 43A applies only to data processed or stored electronically. It does not cover data stored only in physical form unless used via electronic systems.

You Might Also Like

Section 305 CrPC: Procedure for Corporation or Registered Society as Accused

The Evolution And Implications Of The Land Acquisition Act In India

Married Sister Not Entitled to ‘Loss of Dependency’ Compensation in Motor Accident Case: Kerala High Court Rules

PC & Pre-Natal Diagnostic Techniques Act Offences Are Cognizable, FIR Not Barred By Law: Delhi HC

What Is Sexual Harassment at the Workplace? Section 2 (n) Of POSH Act Explained

TAGGED:BreachcompaniesCorporate LiabilityInformation Technology ActIT ActIT Act amendmentsIT Act offencesIT Act SummaryLegal Liabilitypersonal dataSECTION 43section 43A IT act
Share This Article
Facebook Email Print
Previous Article Offences in Digital Age Understanding IT Act Offences: A Simple Guide
Next Article High Court of Chhattisgarh Pension As Hard Earned Benefit Can’t Be Recovered Without Due Process: Chhattisgarh HC
2 Comments
  • Pingback: Is Hacking Always a Crime? Understanding Section 43 Of The IT Act - ApniLaw
  • Pingback: Pension As Hard Earned Benefit Can't Be Recovered Without Due Process: Chhattisgarh HC - ApniLaw

Leave a Reply Cancel reply

You must be logged in to post a comment.

Follow US

Find US on Social Medias
FacebookLike
XFollow
InstagramFollow
YoutubeSubscribe

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!
Popular News
Supreme Court Orders Expert Review Of Disputed NEET-UG 2024 Question By IIT Delhi Committee
News

Supreme Court Orders Expert Review Of Disputed NEET-UG 2024 Question By IIT Delhi Committee

Amna Kabeer
By Amna Kabeer
10 months ago
Criminal Family Background Not a Ground to Deny Passport: J&K High Court
Suicide Threats by Spouse Amount to Cruelty for Divorce: Bombay HC
ED Argues Against Arvind Kejriwal’s Plea in Liquor Policy Case Before Delhi High Court
Liquor Policy Case: Delhi CM Arvind Kejriwal Moves Supreme Court Against ED Arrest
- Advertisement -
- Advertisement -
Ad imageAd image

Your one-stop destination for legal news, articles, queries, and a directory of lawyers in India – all under one roof at ApniLaw.

Stay Updated

  • BNSS
  • News
  • Documentation
  • Acts
  • Supreme Court
  • High Court

Information

  • ApniLaw Services
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

Advertise

  • Advertise with us
  • Newsletters
  • Deal

Find Us on Socials

ApniLawApniLaw
Follow US
© ApniLaw 2025. All Rights Reserved.
bg-n
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..
Zero spam, Unsubscribe at any time.

More Interesting News

Data Breach - Cyber Attack - IT Act

Why Are Innocent People’s Bank Accounts Being Frozen in Cyber Crime Investigations?

How To Avoid Cyber Crimes That May Freeze Your Account?

Why Has the Police Frozen My Bank Account in India?

login
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?