Which of the following are classified as Sensitive Personal Data or Information under Section 43A of ITAA,
2008? (Choose all that apply.)
Correct Answer: A,B,E,F
According to the DSCI Privacy Framework and as aligned with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, under Section
43A of the Information Technology Act, 2008, the following are considered Sensitive Personal Data or Information (SPDI):
* Password
* Financial Information(such as bank account or credit card details)
* Biometric Information(such as fingerprints, retina scans, etc.)
* Medical Records and History
However,Sexual OrientationandCaste and Religious Beliefsare not explicitly included in the list of SPDI under Section 43A of the ITAA, 2008, though they may be protected under broader privacy considerations or sectoral regulations.
This classification helps in mandating appropriate security measures to protect such sensitive data, failure of which can result in compensation for damages to the affected individual due to negligence by the data processor or controller.