0% found this document useful (0 votes)
36 views3 pages

India’s Personal Data Protection Bill Explained

The document discusses data protection laws in India. It defines personal and non-personal data, and explains that data protection aims to minimize privacy intrusions from personal data collection and use. A data protection bill was introduced to establish a legal framework after the right to privacy was recognized. The bill creates rights for data principals over their personal data and establishes a Data Protection Authority. However, critics argue the bill allows broad exemptions for government agencies and processing of personal data without consent in some cases.

Uploaded by

yagnesh2005
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
36 views3 pages

India’s Personal Data Protection Bill Explained

The document discusses data protection laws in India. It defines personal and non-personal data, and explains that data protection aims to minimize privacy intrusions from personal data collection and use. A data protection bill was introduced to establish a legal framework after the right to privacy was recognized. The bill creates rights for data principals over their personal data and establishes a Data Protection Authority. However, critics argue the bill allows broad exemptions for government agencies and processing of personal data without consent in some cases.

Uploaded by

yagnesh2005
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

DATA PROTECTION IN INDIA

What is personal data?

Data can be broadly classified into two types: personal and non-personal data.  Personal data
pertains to characteristics, traits or attributes of identity, which can be used to identify an
individual.   Non-personal data includes aggregated data through which individuals cannot be
identified.  For example, while an individual’s own location would constitute personal data;
information derived from multiple drivers’ location, which is often used to analyse traffic
flow, is non-personal data.  Data protection refers to policies and procedures seeking to
minimise intrusion into the privacy of an individual caused by collection and usage of their
personal data.  

Why was a bill introduced?

Data protection currently falls under the purview of the IT Act. However, after the Right to
Privacy judgment, the need for a specific legislation for data protection was realised. In
furtherance of this realisation a committee was set up to look into the possible provisions of a
legislation. The objects and reasons clause of the 2019 bill claims to have derived its
provisions from the recommendations of this expert committee chaired by Justice B N
Srikrishna. The bill is currently under review and is being analysed by a joint parliamentary
committee.

The bill’s preamble identifies three motivations for the creation of such a legislation:

 “The right to privacy is a fundamental right and it is necessary to protect personal data
as an essential facet of informational privacy.”
 “The growth of the digital economy has expanded the use of data as a critical means
of communication between persons.”
 “It is necessary to create a collective culture that fosters a free and fair digital
economy, respecting the informational privacy of individuals, and ensuring
empowerment, progress and innovation through digital governance and inclusion.”

A critical reason behind the introduction of such a bill was in the interest of maintain data
sovereignty, as a lot of data from Indians is stored in foreign data hubs, especially the west.
The need for data localization and sovereignty was realized post the shocking disclosure by
Edward Snowden on the usage of such data. The worrisome situation led to the creation of
data protection laws around the world, famously the GDPR in the European Union. The
Indian PDP Bill is said to be modelled majorly on the lines of the GDPR.

The bill has created certain rights and obligations for the persons and groups involved in data
transactions. The data principal, whom the data belongs to, has the right to seek confirmation
on the processing, correction and deletion of their data. Confirmation is to be taken from the
principal before the transfer of data to other entities. All processing of data will be on the
basis of the consent of the principal.

The bill has created certain other classifications as well. A data fiduciary is an entity (govt. or
company) or an individual who decides the means and purpose of processing personal data.
The processing of any and all personal data by fiduciaries should be for a certain lawful
purpose and subject to limitations. The fiduciaries also need to implement security safeguards
and maintain grievance redressal mechanisms. The amount of security and other mechanisms
would be specified on the basis of the volume of data a fiduciary maintains. Greater volume
would lead to greater security mechanisms. Any personally sensitive data would be processed
only after a data protection impact assessment.
The bill requires social media companies, called significant data fiduciaries, based on the
volume of their data and turnover, to develop their own user verification mechanism.
A Data Protection Authority is also provided for under the Bill, which would be the redressal
forum for any violations of the bill.

Contentions against the Bill

The PDP Bill has received a great deal of criticism for certain provisions. While the bill has
created an important framework of rules and regulations vis-à-vis corporates and other
private entities with the citizens, the provisions with regard to the government have been
heavily criticised. The government has the authority to exempt any of its agencies in the
interest of the security of the state, public order etc. Processing of personal data is also
exempted from provisions of the Bill for certain other purposes such as prevention,
investigation, or prosecution of any offence, or research and journalistic purposes.  Further,
personal data of individuals can be processed without their consent in certain circumstances
such as: (i) if required by the State for providing benefits to the individual, (ii) legal
proceedings, (iii) to respond to a medical emergency. Furthermore, the government has the
right to seek and extract data from fiduciaries for the “better targeting of services”.

Suggested links:

[Link]

[Link]
bill

[Link]
bill-pub-80985

Common questions

Powered by AI

Both the Indian Personal Data Protection Bill and the GDPR emphasize data sovereignty and individual rights, but their applications vary. The Indian bill is driven by concerns over foreign control of Indian data and stresses data localization to retain sovereignty. Both legislations prioritize consent, the right to confirm, correct, and delete data, but GDPR provides even more stringent rules like the right to be forgotten and data portability. GDPR's framework is fully operational with EU-wide applicability, unlike India's bill, which is still subject to reviews and has exemptions for government agencies that lack in GDPR .

Data fiduciaries, which include both governmental and private entities, are responsible for determining the purposes and means of processing personal data. They must process data only for lawful purposes and are required to implement security safeguards commensurate with the data volume they manage. This means a heightened responsibility for those managing large datasets, potentially leading to increased operational costs and a more stringent focus on security protocols. This requirement aims to enhance data security and privacy for individuals, but likewise imposes significant regulatory burdens on fiduciaries .

Failure to comply with security requirements can lead to significant consequences under the Personal Data Protection Bill. Businesses may face penalties, legal liabilities, and reputational damage, affecting consumer trust and shareholder confidence. Non-compliance also increases the risk of data breaches, leading to potential financial losses and long-term operational disruptions. In severe cases, failure could result in bans or restrictions on the business's operations within India .

The mandate for social media companies, categorized as significant data fiduciaries, to develop user verification mechanisms aims to enhance transparency and accountability, potentially curbing anonymity-related issues like misinformation and cybercrime. However, this could also raise privacy concerns, as it involves collecting more user data, which could conflict with user privacy ideals. Additionally, implementing these systems could be technologically challenging and financially demanding for companies, influencing their operations in India .

Data in India is classified into personal and non-personal data. Personal data is related to the characteristics, traits, or attributes of identity, which can be used to identify an individual, such as their location. Non-personal data includes aggregated data where individuals cannot be identified, such as traffic flow data from multiple users. Differentiating between these is crucial for effective data protection policies because personal data demands stricter privacy safeguards due to its identification potential .

The Data Protection Authority is envisaged as a regulatory body responsible for monitoring and enforcing compliance with the Personal Data Protection Bill. It serves as a redressal forum for violations, ensuring accountability and transparency in data processing activities. Its role is crucial as it oversees the adherence to data protection norms, addresses grievances, and initiates action against non-compliance, thereby maintaining the legislation's integrity and protecting individual data privacy .

The bill has been criticized for allowing the government to exempt its agencies from compliance under the guise of state security, public order, and other reasons like legal proceedings without individual consent. It grants extensive leeway to the government to process data without consent for certain justified circumstances. These powers could undermine individual privacy rights and may lead to concerns about misuse or overreach by state entities, reinforcing public skepticism regarding the balance between national security and individual rights .

The Personal Data Protection Bill mandates that data processing should be based on the consent of the data principal. This requires organizations to seek confirmation from the individual before processing, correcting, or deleting personal data. It also demands explicit consent before transferring data to other entities, ensuring individuals have control over their data. While this empowers individuals and enhances privacy, it could pose operational challenges for organizations, potentially increasing compliance costs and altering data management practices .

The bill aims to foster a free and fair digital economy while protecting informational privacy by embedding privacy-enhancing principles such as consent and rights over personal data. It encourages digital innovation through data governance structures, enabling data localization to safeguard data sovereignty while allowing lawful data processing by fiduciaries. By mandating transparency and accountability, the bill seeks to build trust in digital systems, which is vital for economic growth amid the digital transformation .

The bill requires that personally sensitive data undergo a data protection impact assessment before processing. This involves analyzing the potential risks sensitive data processing may have on privacy and compliance with the bill’s provisions. It serves to identify and mitigate any privacy risks associated with handling such data, ensuring additional protective measures are in place to prevent misuse or exposure, thereby enhancing data security for sensitive information .

You might also like