The rapid growth of digital technology has led to an unprecedented increase in the collection, storage, and processing of personal data. In India, the Information Technology Act, 2000 (IT Act) plays a foundational role in regulating cyber activities and protecting sensitive personal data. This research paper examines the role of the IT Act and its allied rules, particularly the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), in safeguarding sensitive personal data. The paper analyses key provisions such as Section 43A, which imposes liability on corporations for negligence in data protection, and Section 72A, which penalizes unauthorized disclosure of information. It further explores judicial interpretations and landmark cases that have shaped the understanding of data privacy in India. The study also evaluates the limitations of the IT Act in the context of emerging digital challenges and compares it with recent developments like the Digital Personal Data Protection Act, 2023. The findings highlight that while the IT Act provides a basic framework for data protection, it is insufficient in addressing modern data privacy concerns. The paper concludes with recommendations for strengthening the legal framework to ensure comprehensive protection of sensitive personal data.This research paper critically examines the role of the IT Act in protecting sensitive personal data, evaluates its effectiveness, identifies its limitations, and suggests necessary reforms to align it with global standards.
Paul et al. (Thu,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: