Skip to content
Back to Blog
·9 min read·compliance

IT Act Section 43A: Data Security Obligations for Indian Companies

IT Act Section 43A requires Indian companies handling sensitive personal data to implement reasonable security practices or face civil compensation claims.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

IT Act Section 43A requires Indian companies that possess, deal, or handle any sensitive personal data or information to implement "reasonable security practices and procedures." If negligent handling causes wrongful loss or gain, the company becomes liable to pay compensation to the affected person — with no fixed statutory cap defined in the Act itself. This foundational data-security obligation predates the DPDP Act 2023 by fifteen years and continues to apply alongside it today.


The IT Act 2000: India's First Digital Law

The Information Technology Act 2000 gave legal recognition to electronic commerce, digital signatures, and early cybercrime offences — but contained no corporate data-security obligations. As digital business expanded through the 2000s, that gap was addressed by the Information Technology (Amendment) Act 2008, which inserted Section 43A and its companion provisions.

The full text of the IT Act is available at indiacode.nic.in and MeitY publishes guidance at meity.gov.in.


Section 43A: Compensation for Negligence in Handling Sensitive Data

Section 43A, inserted by the 2008 Amendment, imposes a specific civil liability on body corporates — defined broadly to include companies, firms, sole proprietorships, and other associations engaged in commercial or professional activity — that deal with sensitive personal data or information.

Three elements must be present: (1) the entity is a body corporate that possesses or handles SPDI; (2) it was negligent in implementing or maintaining reasonable security practices; (3) that negligence caused wrongful loss or gain to any person. When all three are present, the aggrieved person may seek compensation from the body corporate — the quantum is determined by an Adjudicating Officer under the IT Act, with no prescribed statutory cap in Section 43A itself.

⚠️
WARNING
Section 43A liability is civil, not criminal. However, a separate criminal dimension can arise under Section 72A if an employee or service provider discloses personal information in breach of a lawful contract — which carries imprisonment up to three years, or a fine, or both.

Section 72A: Wrongful Disclosure of Personal Information

Section 72A creates criminal liability for an intermediary or service provider who discloses personal information without consent and in breach of a lawful contract — covering IT vendors leaking client data or employees selling customer databases. Together, Sections 43A and 72A create a two-track framework: civil liability for the body corporate that fails to protect data, and criminal liability for individuals who disclose it.


Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The SPDI Rules 2011: What "Reasonable Security Practices" Actually Means

The phrase "reasonable security practices and procedures" in Section 43A was deliberately left flexible. Parliament delegated the definition to the Central Government, which exercised that power through the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, commonly called the SPDI Rules.

The SPDI Rules are the operational heart of India's pre-DPDP data-protection regime. They specify:

What Counts as Sensitive Personal Data or Information

The Rules define eight categories of SPDI that require heightened protection:

CategoryExamples
PasswordsAccount credentials, PINs
Financial informationBank account details, credit/debit card numbers
Physical, physiological, and mental health conditionsMedical records, prescriptions
Sexual orientationAny data revealing sexual preference
Medical records and historyTest results, diagnoses, treatment history
Biometric informationFingerprints, retina scans, facial recognition data
Information received from another body corporateAny SPDI shared in a B2B context
Ordinary contact information — name, address, phone, email — does not constitute SPDI unless combined with the above.

The Privacy Policy Requirement

Every body corporate that collects SPDI must publish a privacy policy on its website. The policy must state what information is collected, the purpose of collection, how it is disclosed, and reasonable security practices in place.

SPDI may be collected only with the prior written consent of the provider, for a lawful purpose. It must not be retained longer than necessary, and it must not be transferred to a third party without consent — with a narrow exception for data processors acting under contract.

What Satisfies "Reasonable Security Practices"

This is the most practically significant aspect. Rule 8 of the SPDI Rules states that a body corporate shall be deemed to have complied with reasonable security practices if it has implemented either:

    1. IS/ISO/IEC 27001, the international standard for information security management systems; or
    2. A documented, company-specific security programme approved and notified by the Central Government.
In practice, this means ISO/IEC 27001 certification is explicitly named in the SPDI Rules as a standard that satisfies the Section 43A obligation. A body corporate holding a valid ISO 27001 certificate has a strong legal defence if a Section 43A claim arises.
💡
TIP
ISO 27001 is not the only path to compliance, but it is the most defensible because it is explicitly named in Rule 8. Companies that adopt ISO 27001 are simultaneously satisfying the SPDI Rules' security standard and building the foundation for certifications such as SOC 2, DPDP Act compliance programmes, and enterprise sales requirements.

Law Evolution: From IT Act to DPDP Act

graph TD A[IT Act 2000
Digital transactions + cybercrimes] --> B[IT Amendment Act 2008
Inserts Section 43A + 72A] B --> C[SPDI Rules 2011
Defines SPDI + Reasonable Security Practices] C --> D[DPDP Act 2023
Digital Personal Data Protection] D --> E{Which law applies?} E --> F[Sensitive personal data
like health, financial, biometrics
SPDI Rules 2011 + Section 43A] E --> G[General digital personal data
name, email, address, identifiers
DPDP Act 2023] E --> H[Computer offences
hacking, unauthorized access, fraud
IT Act Sections 43, 66, 66C, 66D] E --> I[Employee disclosure breach
Section 72A applies
Criminal track] style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style E fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style F fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style G fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style H fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style I fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0

Key Obligations at a Glance

xychart-beta title "Section 43A Compliance Obligations by Effort Level" x-axis ["Privacy Policy", "Consent Mechanism", "Data Inventory", "Security Programme", "ISO 27001", "Incident Response", "Vendor Contracts", "Audit Trail"] y-axis "Relative Implementation Effort" 0 --> 10 bar [3, 4, 5, 6, 9, 7, 5, 6]

How the IT Act Coexists with the DPDP Act 2023

A common misconception is that the DPDP Act 2023 replaced or superseded the IT Act. It did not. Both statutes are in force simultaneously, and they regulate overlapping but distinct spaces.

The DPDP Act 2023 focuses on digital personal data in digital form. It introduces consent and data-principal rights, creates the Data Protection Board of India, and prescribes significant financial penalties for breaches. MeitY has published the Act and FAQs at meity.gov.in.

The IT Act and SPDI Rules remain in force alongside the DPDP Act for four reasons:

  1. SPDI Rules define sensitive-data categories that overlap with but are not identical to the DPDP Act's definitions — both must be read together until the SPDI Rules are formally amended.
  2. Cybercrime provisions (Sections 43, 66, 66B–D) remain the primary criminal law for hacking, identity theft, and fraud — unaffected by the DPDP Act.
  3. Section 72A criminal liability for wrongful disclosure by intermediaries continues unchanged.
  4. Section 43A civil compensation (via Adjudicating Officer) and DPDP Act penalties (via Data Protection Board) are separate proceedings with separate remedies.
🚨
DANGER
Companies that believe their DPDP Act compliance programme also satisfies Section 43A are taking a legal risk. The SPDI Rules impose specific technical and organisational requirements — including the ISO 27001 or documented security programme standard — that must be met independently. A gap between the two regimes leaves civil liability exposure under the IT Act.

8Categories of Sensitive Personal Data defined in SPDI Rules 2011 (MeitY, Rule 3)
2008Year Section 43A was inserted via IT Amendment Act (indiacode.nic.in)
2011Year SPDI Rules were notified under Section 43A (MeitY Gazette Notification, April 2011)
ISO/IEC 27001Explicitly named in SPDI Rule 8 as an accepted standard for "reasonable security practices"
2023Year DPDP Act was enacted — IT Act coexists, not repealed (MeitY)

Practical Obligations for Indian Companies

If you collect any of the eight SPDI categories, here is your minimum compliance checklist under Section 43A and the SPDI Rules:

ObligationWhat It RequiresRisk if Missing
Privacy PolicyPublished on website; cover collection purpose, disclosure, security measuresSection 43A civil liability
Prior Written ConsentExplicit consent before collecting SPDI; cannot be bundled into T&CsCompensation claim
Purpose LimitationCollect only what is needed; delete after purpose is fulfilledCompensation + reputational risk
Data Processor ContractsVendors handling SPDI must be contractually bound to the same standardsSection 72A exposure
Reasonable Security ProgrammeISO 27001 or documented approved programme covering CIA triadCore Section 43A negligence test
Grievance OfficerNamed individual with published contact; must respond within one monthRegulatory non-compliance
Incident ResponseIdentify, contain, and report breaches; feeds CERT-In reporting obligationsCompounded exposure
No Cross-border Transfer Without ConsentSPDI cannot go to foreign entities without consent or equivalent protectionSPDI Rule 7 liability

The Role of VAPT in Section 43A Compliance

Under the SPDI Rules, a documented, regularly tested security programme is a legal requirement, not merely a best practice. VAPT forms a core component because it provides evidence of active security testing (directly relevant to the "reasonable security practices" standard), generates remediation-driving findings, and supports ISO 27001 Annex A controls (A.12.6 technical vulnerability management, A.18.2 information security reviews). A company with documented VAPT reports and evidence of remediation is in a materially stronger legal position if a Section 43A claim arises.

Bachao.AI, built by Dhisattva AI Pvt Ltd, provides automated VAPT for Indian businesses through its platform. You can book a free VAPT scan to understand your current exposure under these obligations.

For further reading on how the DPDP Act 2023 interacts with these obligations, see our DPDP compliance guide and the rest of the Bachao.AI blog.


🎯Key Takeaway
Section 43A of the IT Act creates direct civil liability for any Indian body corporate that negligently handles sensitive personal data — financial information, health data, biometrics, and five other categories defined in the SPDI Rules 2011. The DPDP Act 2023 does not replace this obligation; both regimes apply in parallel. ISO/IEC 27001 is explicitly named in the SPDI Rules as a standard that satisfies "reasonable security practices," making certification both a legal defence and a business asset.

Frequently Asked Questions

Does Section 43A apply to startups and MSMEs, or only to large companies?
Section 43A applies to any "body corporate" — a term defined broadly in the IT Act to include companies, firms, sole proprietorships, and other associations engaged in commercial or professional activities. There is no size threshold. If your business collects health data, financial information, biometrics, or any other SPDI category, you are subject to Section 43A obligations regardless of revenue or employee count.
If my company complies with the DPDP Act 2023, is Section 43A automatically satisfied?
No. The two Acts operate under separate legal frameworks. The SPDI Rules 2011 require a documented security programme (ISO 27001 or equivalent) and specific consent and data-handling obligations that the DPDP Act does not fully replicate. Companies must assess both regimes independently.
What is the difference between Section 43A and Section 72A?
Section 43A imposes civil liability on the body corporate itself for negligent data security — the company pays compensation to the aggrieved person. Section 72A is a criminal provision targeting individuals (employees, intermediaries, service providers) who deliberately or negligently disclose personal information in breach of a lawful contract. The two sections address different actors — the company versus the individual — and operate on different legal tracks.
How does a company prove it has "reasonable security practices" under the SPDI Rules?
ISO/IEC 27001 certification is the clearest path — it is explicitly named in SPDI Rule 8. Alternatively, a documented security programme covering confidentiality, integrity, and availability can qualify. Companies that also maintain VAPT records and operate a formal incident response programme have the strongest evidentiary position if a claim arises.
Can a person file a Section 43A claim directly in court?
Initial jurisdiction lies with the Adjudicating Officer appointed under the IT Act, not with civil courts, for claims up to a statutory threshold defined under Section 46. Claims exceeding that threshold may proceed before a civil court. The Data Protection Board under the DPDP Act is a separate adjudicatory body with its own jurisdiction and procedures.
Are the SPDI Rules 2011 still in force after the DPDP Act 2023 was enacted?
Yes. As of the date of this post, the SPDI Rules 2011 remain in force. The DPDP Act 2023 did not expressly repeal them. MeitY is expected to review and align the subordinate rules under the IT Act with the new DPDP framework, but until formal amendment or repeal is notified, the SPDI Rules continue to create binding obligations for Indian body corporates.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →