0% found this document useful (0 votes)
2 views4 pages

DPDP

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's legislation that regulates the collection, use, and protection of personal data, granting individuals rights over their data. It establishes obligations for data fiduciaries, defines personal data, and outlines penalties for non-compliance, including the formation of a Data Protection Board. Key provisions include consent requirements, rights for data principals, and specific rules for processing children's data.

Uploaded by

avinash_georgian
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views4 pages

DPDP

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's legislation that regulates the collection, use, and protection of personal data, granting individuals rights over their data. It establishes obligations for data fiduciaries, defines personal data, and outlines penalties for non-compliance, including the formation of a Data Protection Board. Key provisions include consent requirements, rights for data principals, and specific rules for processing children's data.

Uploaded by

avinash_georgian
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

What is DPDPA?

Digital Personal Data Protection Act, 2023 is India’s law that governs how organizations collect, use, store,
share, and protect personal data of individuals, and gives individuals rights over their personal data.

Key Aspects & Terminologies

• Data Fiduciaries - Obligations on organizations that process personal data, requiring them to obtain consent,
use data only for specified purposes, protect data from breaches, and respond to individuals' requests
regarding their data
• Data Principals - The rights and duties of individuals, including the right to access, correct, and erase their
data and seek grievance redressal
• Processing - Any operation performed on PII, such as collection, storage, use, etc.
• Data Processor - An entity that processes data on behalf of a data fiduciary.
• Data Protection Board - It establishes the Data Protection Board of India (DPB) to oversee compliance and
impose penalties for non-compliant organizations
• Penalties - The Act introduces financial penalties for breaches of the provisions by data fiduciaries, up to INR
250 crore
• Scope - The DPDP Act applies to personal data that is collected in digital form or non-digital data, which is
digitized subsequently.

Page 1
What is Personal Data?

• Commonly worldwide known as PII (Personally Identifiable Information)


• DPDPA defines ‘Personal Data’ as ‘Any data about an individual who is identifiable by or in relation to such
data’

Information such as

• Directly Identifiable Data - Name, Phone number, Email address, Physical address, Aadhaar number,
Passport, Voter ID details etc.,
• PHI (Protected Health Information) - Medical Records, Health Insurance Information, Prescription
Details, Billing Information
• Indirectly Identifiable Data - IP address, Device identifiers, Online behavioral data (e.g., browsing history
linked to an individual), Transaction history linked to a user
• Sensitive Personal Data (Implied by Context of Sensitive Personal Data) – Biometrics, Health records,
Financial details (loan Amount, Repayment history, bank accounts)

Page 2
Obligations of Data Fiduciary

1. Processing of Personal Data


• Personal data can be processed only for a lawful purpose, with consent or for certain legitimate uses.
2. Notice
• Requires data fiduciaries to give notice to data principals about the personal data they collect and how it
will be processed.
3. Consent
• Obtaining valid consent from data principals for processing their personal data. Consent must be free,
specific, informed, and unambiguous.
4. Processing of Personal Data of Children
• Sets stricter rules for processing the personal data of children, requiring parental consent.
5. General Obligations
• Ensuring the accuracy and completeness of data.
• Implementing reasonable security safeguards.
• Providing grievance redressal mechanisms.
6. Additional Obligations of Significant Data Fiduciaries
• Appointing a Data Protection Officer (DPO).
• Conducting Data Protection Impact Assessments (DPIAs).
• Undergoing independent audits.

Page 3
Rights and Duties of Data Principal (Customer – Internal & External)

1. Right to Access Information about Personal Data


• Grant's data principals the right to access information about their personal data held by data
fiduciaries.

2. Right to Correction and Erasure


• Allows data principals to correct inaccurate or misleading personal data and to have their data erased
under certain conditions.

3. Right to Grievance Redressal


• Ensures data principals have the right to seek redressal for grievances related to the processing of
their personal data.

4. Right to Nominate
• Permits data principals to nominate another individual to exercise their rights in the event of their death
or incapacity

5. Duties of Data Principal


• Duties of data principals, such as not impersonating others and providing accurate information.

Page 4

You might also like