Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security Practices
Information Technology Act 2000 (No. 21 of 2000), s.43A; Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), 11 April 2011), rr. 3, 4, 5, 6, 8
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 11 April 2011.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a body corporate that possesses, deals in, or handles the sensitive personal data or information of a person, meaning a password, a financial account or payment-instrument detail, a physical, physiological, or mental health condition, sexual orientation, a medical record or history, or biometric information, in a computer resource it owns, controls, or operates; information that is freely available in the public domain or obtainable under the Right to Information Act, 2005 is not sensitive personal data or information under these Rules.
- Implement and maintain a comprehensive, documented information security programme with managerial, technical, operational, and physical control measures commensurate with the information assets you protect and the nature of your business; certifying to the international Standard IS/ISO/IEC 27001, or to a Central-Government-approved industry code of best practice, satisfies this duty as a matter of law, provided the certification is audited by an independent, government-approved auditor at least once a year or after a significant upgrade to your process or computer resource.
- Obtain the data provider's written consent, by letter, fax, or email, before collecting their sensitive personal data or information, let them decline or withdraw that consent, publish a privacy policy on your website, and designate a Grievance Officer who must resolve a complaint within one month.
- Negligently failing to implement or maintain these practices, where it causes wrongful loss or wrongful gain to any person, exposes you to an uncapped compensation claim under section 43A of the Information Technology Act; no criminal penalty attaches to section 43A itself.
- This duty is in effect now and is repealed once section 44(2) of the Digital Personal Data Protection Act, 2023 commences, currently scheduled for 13 May 2027; the DPDPA's own security-safeguards duty (section 8(5)) does not commence until the same date, so these Rules remain the operative standard until then.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Criminal exposure note
Section 43A creates only a civil compensation liability; no provision of the Information Technology Act makes a negligent failure to implement reasonable security practices and procedures, standing alone, a criminal offence.
Who enforces it
Enforcement body
No dedicated regulator is named. A claim for compensation under section 43A is adjudicated by an officer the Central Government appoints under section 46, whose jurisdiction reaches a claim up to five crore rupees; a claim above that amount is heard by the competent civil court instead.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A body corporate, meaning any company, firm, sole proprietorship, or other association of individuals engaged in commercial or professional activities, that possesses, deals in, or handles sensitive personal data or information, meaning a password, a financial account or payment-instrument detail, a physical, physiological, or mental health condition, sexual orientation, a medical record or history, or biometric information, in a computer resource it owns, controls, or operates, must implement and maintain reasonable security practices and procedures: a comprehensive, documented information security programme with managerial, technical, operational, and physical control measures commensurate with the information assets it protects.
Certification to the international Standard IS/ISO/IEC 27001 is deemed to satisfy this duty as a matter of law. That certification must be audited by an independent, government-approved auditor at least once a year. The same Rules require the body corporate to publish a privacy policy on its website. The body corporate must also appoint a Grievance Officer.
Section 43A of the Information Technology Act makes a body corporate negligent in implementing or maintaining this programme liable to pay uncapped compensation to any person it causes wrongful loss or wrongful gain.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official Gazette notification text, mirrored via WIPO Lex
the Ministry of Electronics and Information Technology's own hosted copy of this notification returned no extractable text through the crawler