Authorised Indian Partner for Proton Data Security, USA
Tel: +91 80 26539077•Mob: +91 9243049222•mail@quridge.net

Information Technology Act, 2000 & Rules

IT Act Data Destruction Compliance in India

The IT Act does not prescribe a destruction method. It does make the security and eventual disposal of your information a legal obligation. Here is what that means for media handling, and what a compliant process looks like.

1. What the IT Act actually says

The relevant provisions are short and technology-neutral:

  • Section 43A — a body corporate in possession of personal information, and failing to take reasonable security safeguards, is liable to pay compensation to the affected person. "Reasonable security safeguards" is the phrase everything hangs on.
  • Section 70A — applies to bodies performing professional services, requiring security practices in line with information security standards.
  • Section 70 & the IT (Reasonable Security) Rules — the rules set out what reasonable security should include, leaving the technology choices to the organisation.
  • Section 72 — penalties for unauthorised access to a computer system, and for unauthorised disclosure of information contained in it.

None of these name a machine. All of them make the outcome the thing that matters: information in your custody must not end up in someone else's hands. A retired hard drive in an e-waste channel is a way for that to happen.

2. Why a degausser is a "reasonable safeguard"

Courts and regulators do not test whether you bought a specific product. They ask whether your controls were reasonable for the risk. A defensible control has four properties, and a degausser has all four:

  1. Appropriate to the medium. Magnetic media is purged magnetically; flash and optical media are physically destroyed. The method matches the risk.
  2. Repeatable and documented. A register per asset means you can evidence the control rather than assert it.
  3. Independent of the device's condition. A failed drive still gets sanitised. Software-based controls fail exactly when the media is most likely to be sensitive.
  4. Verifiable. Per-cycle field verification means the record can be trusted.

3. A compliant IT Act media process

StageControlEvidence
AcquireMedia is recorded in the asset register with classificationAsset register entry
ClassifyData classification determines the required sanitisation levelClassification on the asset record
ScheduleRetired media is queued for destruction, not stored indefinitelyDestruction queue / job ticket
SecureMedia held in a locked area until processed; general waste bins cannot accept mediaPhysical control, access list
Purge magnetic mediaDegauss to NIST 800-88 purge level with per-cycle verificationCycle verification value in the register
Destroy flash and opticalShred or crushDestruction register entry
Physically destroyCrush the sanitised magnetic mediaDestruction register entry
DisposeScrap through an authorised e-waste recyclerRecycler authorisation, weighment receipt
RetainRegister retained for at least the longest data retention periodRecords management policy
ReviewPeriodic independent review of the disposal processInternal / external audit report

4. Section 43A in practice: what a court or customer asks

In a dispute or a customer due-diligence exercise, the questions are predictable. Prepare the answers in advance:

  • What is your written information security and media disposal policy? Produce the document and its version history.
  • What were the controls for decommissioned and failed media? Produce the process and the register.
  • Can you show a specific asset was destroyed, by when, and with what evidence? Produce the register row with the cycle verification.
  • How do you ensure third parties performing disposal follow your standard? Produce the contract, the audit rights and the sampled results.
  • How do you prevent media reaching general waste? Produce the physical control description and the bin segregation arrangement.

5. IT Act and DPDP Act together

Most Indian organisations now run one documented media destruction process and map it to both statutes plus their contractual and certification obligations. That avoids duplicated work and — more importantly — avoids the gap where one policy covers one law and misses the other.

ObligationSourceWhat it needs from the destruction process
Reasonable security safeguards for personal informationIT Act s.43A, s.70A and RulesDocumented, appropriate, evidenced media disposal
Erasure and deletion of personal digital dataDPDP Act 2023 and RulesDeletion that is complete, timely and provable, including on retired media
Media sanitisation to an international standardNIST 800-88 (contractual / certification)Purge for magnetic media, destroy for flash, with verification
NSA/CSS evaluated equipmentGovernment, PSU, defence tender clausesProton T-4 / T-5, PDS-75 / PDS-100
Independent review of security arrangementsRBI / sectoral directionsA process that can be sampled and audited
E-waste handling and documentationE-Waste (Management) RulesAuthorised recycler with a traceable downstream chain

6. Practical steps for an Indian organisation this quarter

  1. Inventory every medium currently in a store room, a returned-hardware shelf and a scrap bin.
  2. Identify any medium holding customer or personal data that has not been sanitised.
  3. Segregate media bins from general waste, and label them.
  4. Write or revise the media disposal policy, naming the method per media type.
  5. Adopt a destruction register format and require it for every batch.
  6. Decide on equipment: buy, rent, or contract an ITAD vendor — and document the choice.
  7. Train and authorise operators; keep training records.
  8. Run a first sanitised destruction batch and close it out with a signed register.
  9. Add the review point to the annual audit plan.

Frequently asked questions

Straight answers to the questions Indian buyers ask most often. Cannot find yours? Call us — we answer technical questions on the phone.

Does the IT Act require a specific destruction method?
No. The IT Act's security obligations under Section 70A, and the IT (Reasonable Security) Rules, operate at the level of "reasonable security safeguards" and "standards". They do not prescribe degaussing, shredding or any particular technology.
So why does the IT Act matter for media destruction?
Because it makes the security of your information a legal obligation rather than a best practice, and because Section 72 makes you liable for unauthorised access or disclosure. A drive that leaks is an unauthorised disclosure of data you were obliged to secure.
Does the IT Act overlap with the DPDP Act?
Substantially, and they run in parallel. The IT Act's obligations attach to information processed in the course of electronic transactions; the DPDP Act's attach specifically to personal digital data. For a degausser or a shredder the practical requirements are the same, so most organisations document both against one process.
What are the IT (Reasonable Security) Rules about?
The rules set out what a reasonable security safeguard should cover — controls over access, monitoring, encryption, and the protection of information including its disposal. They are deliberately technology-neutral, so your policy must make the specific choices.
Is Section 43A relevant?
Section 43A makes compensation mandatory for failure to take reasonable security safeguards, and Section 70A applies to bodies performing professional services. Both increase the practical cost of a mishandled drive, which is why the disposal control needs to be documented and evidenced.

Turn the policy into a working process

Send us your current IT security or media disposal policy. We will specify the equipment, supply the register format, and arrange operator training on delivery.

Request a quote Call +91 9243049222