HomeLatest NewsCyber SecurityFacebook Cambridge Analytica Scandal: Article 72A of Information Technology Act not enough to protect user’s data

Facebook Cambridge Analytica Scandal: Article 72A of Information Technology Act not enough to protect user’s data

As per section 72A, securing access and providing ‘any material containing personal information about an-other person’ without consent of that person, or in breach of contract of a service is punishable with imprisonment or fine, or both.

Preferred Source of Google

Facebook’s sharing of user data with has attracted widespread attention, to the extent that the US Federal Trade Commission would be probing to determine whether user data had in fact been shared by Facebook with Cambridge Analytica. The United States is very mature in terms of having and privacy regime. It remains to be seen as to what impact this is likely to have on Facebook in the long run. However, owing to this incident, the reputation of Facebook has definitely taken a beating, with many users having started to delete their Facebook accounts.

The Supreme in India has established the has a fundamental right. Although India presently does not have a specific law covering data protection or privacy, there are other regulations which do in fact provide some coverage in cases where user data is used or shared without their consent. For ex-ample, section 72A of the Information Technology Act specifically provides such a protection to user’s da-ta. As per section 72A, securing access and providing ‘any material containing personal information about another person’ without consent of that person, or in breach of contract of a service is punishable with im-prisonment or fine, or both.

The section is however qualified by the fact that the intent behind securing such information should be to cause wrongful loss or wrongful gain. It remains to be seen whether sharing user information without their consent, which violates their fundamental right, would automatically result in a wrongful gain/loss to qualify such acts as an offence under the IT Act.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →

Prashant Phillips is Partner & Practice Head, Lakshmikumaran & Sridharan Attorneys. Views are personal.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

India logged 29 lakh cyber incidents in 2025, up 85% in two years

India recorded 29.44 lakh cyber security incidents in 2025, an 85 per cent increase from 2023, the government told the Lok Sabha. CERT-In has empanelled 237 security auditing organisations and trained over 11 lakh participants through awareness programmes.

RELATED ARTICLES